December 20, 2021
Health plans, their employer and other health plan sponsors, fiduciaries and vendors as well as health care providers, healthcare clearinghouses, their vendors that are business associates covered by the Privacy, Security and Breach Notification Rules of the Health Insurance Portability & Accountability Act (“HIPAA”) are urged to act promptly to take well-documented steps to confirm and protect electronic protected health information and systems against the increasingly common hacking and other common cybersecurity threats in light of the rising cyber-hacking and other cybersecurity threats and exposures.
As implemented and enforced by the Department of Health & Human Services Office of Civil Rights (“OCR”), HIPAA generally requires that health plans, health care providers, healthcare clearinghouses and their service providers that qualify as business associates (hereafter “covered entities”) safeguard the privacy and security of individually identifiable protected health information (“protected health information”) in paper, electronic or other form against use, access or disclosure other than as allowed by HIPAA. Along with its general restrictions upon use, access or disclosure of protected health information, HIPAA also requires that covered entities and their business associates take the special precautions to protect electronic protected health information (“ePHI”) against improper access, use, disclosure or loss required by the OCR HIPAA Security Rule. Meanwhile, the OCR HIPAA Breach Notification Rule requires that covered entities notify affected individuals, OCR and in the case of breaches involving records of more than 500 individuals, the media in accordance with the OCR Breach Notification Rule following breach of unsecured protected health information.
OCR has an established policy of investigating all breach reports involving more than 500 individuals and these investigations commonly result in settlements that extract agreements by affected covered entities or business associates to pay huge resolution payments to avoid being assessed significantly larger civil liability penalties authorized by HIPAA. See e.g., Clinical Laboratory Pays $25,000 To Settle Potential HIPAA Security Rule Violations (May 25, 2021); Health Insurer Pays $5.1 Million to Settle Data Breach Affecting Over 9.3 Million People (January 15, 2021); Aetna Pays $1,000,000 to Settle Three HIPAA Breaches (October 28, 2020); Health Insurer Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People (September 25, 2020); HIPAA Business Associate Pays $2.3 Million to Settle Breach Affecting Protected Health Information of Over 6 million Individual – (September 23, 2020); Lifespan Pays $1,040,000 to OCR to Settle Unencrypted Stolen Laptop Breach (July 27, 2020); Small Health Care Provider Fails to Implement Multiple HIPAA Security Rule Requirements (July 23, 2020).
A review of the OCR data base of unsecured electronic protected health information breaches reveals that OCR has received a wave of required unsecured electronic health information breach notifications impacting 500 or more individuals arising from hacking of electronic systems or e-mail since January 1, 2021, including notices from Apple Blossom Family Practice VA Healthcare Provider (500 individuals/Network Server Hacking/IT Incident); Network Server; Texas ENT Specialists TX Healthcare Provider (535,489 individuals/ Network ServerHacking/IT Incident0; Eduro Healthcare, LLC UT Healthcare Provider (8059 individuals/Hacking/IT Incident Email); Sacramento County Department of Health Services CA Healthcare Provider (2096 individuals/Hacking/IT Incident Email); Weddell Pediatric Dental Specialists, LLC IN Healthcare Provider (5356 individuals/Hacking/IT Incident Email); Javery Pain Institute MI Healthcare Provider (1387 individuals/Hacking/IT Incident Email); OSR Physical Therapy AZ Healthcare Provider (714 individuals/Hacking/IT Incident Email}; Nippon Life Insurance Company of America NY Health Plan (4109 individuals/Unauthorized Access/Disclosure Email); Bansley and Kiener, LLP IL Business Associate (50119 /Hacking/IT Incident Network Server) Baylor Scott & White Medical Center – Waxahachie TX Healthcare Provider (883 individuals/Unauthorized Access/Disclosure Electronic Medical Record); Bansley and Kiener, LLP IL Business Associate (2297 individuals/Hacking/IT Incident Network Server); Bansley and Kiener, LLP IL Business Associate (2711/Hacking/IT Incident Network Server); Bansley and Kiener, LLP IL Business Associate (15,814/Hacking/IT Incident Network Server); Mertz Manufacturing Inc Health Insurance Plan OK Health Plan (868 individuals/Hacking/IT Incident Network Server); Department of Behavioral Health and Developmental Services VA Healthcare Provider (4037 individuals/Unauthorized Access/Disclosure Other) Great Plains Manufacturing, Inc KS Health Plan (4110 individuals/Hacking/IT Incident Network Server); and Roy Varughese, M.D. TX Healthcare Provider (2916 individuals/Hacking/IT Incident Email). These recent breach notifications represent only the latest in a rising tide of hacking associated data breach notifications that OCR has received in recent years.
While provider breach reports still are the most common, health plan data breaches are becoming increasingly common. Between January 1 and December 20, 2021, for instance, OCR reported having open investigations arising from health plan breaches of unsecured protected health information reported after December 31, 2021 by Mertz by Manufacturing Inc Health Insurance Plan OK Health Plan; Great Plains Manufacturing, Inc KS Health Plan; Region IV Area Agency on Aging MI Health Plan; Kaiser Permanente MD Health Plan; Iowa Total Care, Inc. IA Health Plan; Maritz Holdings Inc. MO Health Plan; State of TN Finance & Administration TN Health Plan; Providence Health Plan OR Health Plan as well as a plethora of previously health plan associated breaches reported prior to 2021.
While health plan breach notifications generally have lagged far behind provider notifications in number, reported health plan breaches generally have resulted the largest civil monetary penalty or resolution payments largely due to the massive number of individuals affected by these breaches. See e.g., Health Insurer Pays $5.1 Million to Settle Data Breach Affecting Over 9.3 Million People (January 15, 2021); Aetna Pays $1,000,000 to Settle Three HIPAA Breaches (October 28, 2020); Health Insurer Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People (September 25, 2020); HIPAA Business Associate Pays $2.3 Million to Settle Breach Affecting Protected Health Information of Over 6 million Individual (September 23, 2020). In fact, health plan breaches account for the top three largest resolution agreements to date. The biggest among these resolution agreements is the still record-setting $16 million resolution agreement between health insurance giant, Anthem, Inc. and OCR that Anthem entered into to settle potential HIPAA violations OCR uncovered in its investigation of breaches of the electronic protected health information of 79 million remains OCR’s largest. See Record $16M Anthem HIPAA Settlement Signals Need To Tighten HIPAA Compliance & Risk Management
In January, 2021, OCR announced New York health insurer, Excellus Health Plan, Inc., would pay $5.1 million to settle potential HIPAA violations related to a breach affecting over 9.3 million people. The settlement resulted from OCR’s investigation of a September 9, 2015 breach report that cyber-attackers gained unauthorized access to its information technology systems. Excellus Health Plan reported that the breach began on or before December 23, 2013 and ended on May 11, 2015. The hackers installed malware and conducted reconnaissance activities that ultimately resulted in the impermissible disclosure of the protected health information of more than 9.3 million individuals, including their names, addresses, dates of birth, email addresses, Social Security numbers, bank account information, health plan claims, and clinical treatment information. The resolution payment is the second largest collected by OCR to date.
In October, 2020, OCR announced a resolution agreement with Aetna Life Insurance Company and affiliated covered entity (Aetna) where Aetna paid a $1 million resolution payment to settle potential HIPAA violations that arose from Aetna’s filing of hacking related breach reports in 2017 and OCR’s September 2021 announcement of a resolution agreement where Premera Blue Cross (PBC) agreed to pay $6.85 million to OCR (the second largest in OCR history) to settle potential HIPAA violations related to a breach affecting over 10.4 million people. This resolution represents the third largest payment to resolve a HIPAA investigation in OCR history.
The magnitude of these three recordbreaking resolution agreements sends a strong signal that health plans and other covered entities impacted by hacking incidents should expect little sympathy or quarter from OCR. OCR Director Roger Severino drove this point home when he warned in OCR’s announcement of the Aetna resolution agreement, “Hacking continues to be the greatest threat to the privacy and security of individuals’ health information. In this case, a health plan did not stop hackers from roaming inside its health record system undetected for over a year which endangered the privacy of millions of its beneficiaries. …. We know that the most dangerous hackers are sophisticated, patient, and persistent. Health care entities need to step up their game to protect the privacy of people’s health information from this growing threat.”
Coupled with these warnings, the series of alerts issued by OCR urging health plans and other HIPAA covered entities to guard their electronic systems and electronic protected health information against various hacking, malware and other cybersecurity threats send a clear message to health plans and other HIPAA regulated covered entities and business associates to constantly monitor and reconfirm the adequacy of their own HIPAA privacy, security, breach notification and other procedures and protections or be prepared to face similar sanctions from OCR.
Along side the OCR warnings, employment and union sponsored health plans, their insurers, business associates and fiduciaries also now face additional pressure to take prudent steps to secure their health plans’ protected health information and electronic data systems against improper use, access, destruction or disclosure under April, 2021 Employee Benefit Security Administration (“EBSA”) guidance package that for the first time officially recognizes cybersecurity as included in the fiduciary responsibilities of employee benefit plan fiduciaries under the Employee Retirement Income Security Act (“ERISA”) and addition of cybersecurity to its plan audits. As a result, in addition to complying with HIPAA, ERISA-covered health plan fiduciaries and sponsors also should be prepared to demonstrate that plan fiduciaries have taken the steps prudently necessary to guard health and other employee benefit plan data and systems against cybersecurity threats. In light of this guidance health plan fiduciaries and sponsors generally will want to ensure that at minimum, they can demonstrate that the health plan and health plan vendor cybersecurity safeguard meet or exceed the recommendations included in the following guidance materials published by EBSA as part of this cybersecurity announcement and any other steps that are prudent to guard against cybersecurity threats:
- Tips for Hiring a Service Provider: Helps plan sponsors and fiduciaries prudently select a service provider with strong cybersecurity practices and monitor their activities, as ERISA requires.
- Cybersecurity Program Best Practices: Assists plan fiduciaries and record-keepers in their responsibilities to manage cybersecurity risks.
- Online Security Tips: Offers plan participants and beneficiaries who check their retirement accounts online basic rules to reduce the risk of fraud and loss.
In light of this OCR and EBSA guidance, health plan sponsors, fiduciaries and vendors and other HIPAA covered entities and business associates are urged to take documented steps to audit and strengthen as needed their safeguards against hacking and other cybersecurity threats including:
- In the case of any health plan or health plan vendor, taking well documented steps to assess and tighten as necessary their health plan systems and data security to meet or exceed the recommendation outlined in the EBSA cybersecurity guidance or otherwise necessary to prudently guard their plans and plan data and systems against cybersecurity threats.
- Reviewing and monitoring on a documented, ongoing basis the adequacy and susceptibilities of existing practices, policies, safeguards of their own organizations, as well as their business associates and their vendors within the scope of attorney-client privilege taking into consideration data available from OCR, data regarding known or potential susceptibilities within their own operations as well as in the media, and other developments to determine if additional steps are necessary or advisable.
- Updating policies, privacy and other notices, practices, procedures, training and other practices as needed to promote compliance and defensibility.
- Renegotiating and enhancing service provider agreements to detail the specific compliance, audit, oversight and reporting rights, workforce and vendor credentialing and access control, indemnification, insurance, cooperation and other rights and responsibilities of all entities and individuals that use, access or disclose, or provide systems, software or other services or tools that could impact on security; to clarify the respective rights, procedures and responsibilities of each party in regards to compliance audits, investigation, breach reporting, and mitigation; and other relevant matters.
- Verifying and tightening technological and other tracking, documentation and safeguards and controls to the use, access and disclosure of protected health information and systems.
- Conducting well-documented training as necessary to ensure that members of the workforce of each covered entity and business associate understand and are prepared to comply with the expanded requirements of HIPAA, understand their responsibilities and appropriate procedures for reporting and investigating potential breaches or other compliance concerns, and understand as well as are prepared to follow appropriate procedures for reporting and responding to suspected
violations or other indicia of potential security concerns. - Tracking and reviewing on a systemized, well-documented basis actual and near miss security threats to evaluate, document decision-making and make timely adjustments to policies, practices, training, safeguards and other compliance components as necessary to identify and resolve risks.
- Establishing and providing well-documented monitoring of compliance that includes board level oversight and reporting at least quarterly and sooner in response to potential threat indicators.
- Establishing and providing well-documented timely investigation and redress of reported
violations or other compliance concerns. - Establishing contingency plans for responding in the event of a breach.
- Establishing a well-documented process for monitoring and updating policies, practices and other efforts in response to changes in risks, practices and requirements.
- Preparing and maintaining a well-documented record of compliance, risk, investigation and other security activities.
- Pursuing other appropriate strategies to enhance the covered entity’s ability to demonstrate its compliance commitment both on paper and in operation.
Because susceptibilities in systems, software and other vendors of business associates, covered entities and their business associates should use care to assess and manage business associate and other vendor associated risks and compliance as well as tighten business associate and other service agreements to promote the improved cooperation, coordination, management and oversight required to comply with the new breach notification and other HIPAA requirements by specifically mapping out these details.
Leaders of covered entities or their business associates also are cautioned that while HIPAA itself does not generally create any private right of action for victims of breach under HIPAA, breaches may create substantial liability for their organizations or increasingly, organizational leaders under state data privacy and breach, negligence or other statutory or common laws. In addition, physicians and other licensed parties may face professional discipline or other professional liability for breaches violating statutory or ethical standards. Meanwhile, the Securities and Exchange Commission has indicated that it plans to pursue enforcement against leaders of public health care or other companies that fail to use appropriate care to ensure their organizations comply with privacy and data security obligations and the Employee Benefit Security Administration recently has issued guidance recognizing prudent data security practicces as part of the fiduciary obligations of health plans and their fiduciaries.
Finally, health plans and other covered entities are reminded that appropriate strategic planning and use of attorney-client privilege and other evidentiary tools can critically impact the defensibility of pre-breach, breach investigation and post-breach investigation and decision-making. Because HIPAA, EBSA and other rules typically require prompt investigation and response to known or suspected hacking or other cybersecurity threats, health plans and other covered entities or business associates should seek the assistance of experienced legal counsel to advise and assist in these activities to understand the potential availability and proper use of these and other evidentiary rules as part of the compliance planning process as well as to prepare for appropriate use in the event of a known or suspected incident to avoid unintentional compromise of these protections.
For Additional Information Or Assistance
If you need have questions or need assistance with health, benefit, payroll, investment or other data, systems or other privacy or security related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help. Longtime scribe for the American Bar Association Joint Committee on Employee Benefits agency meeting with OCR and author of leading publications on HIPAA and other privacy and data security concerns, Ms. Stamer also regularly assists clients and provides input to Congress, OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications. She also is a highly-sought out speaker on privacy and data security who serves on the planning faculty and speaks for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here. If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters, e-mail Ms. Stamer or call (214) 452-8297.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here.
Important Information About This Communication
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2021 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™
Comments Off on HIPAA & ERISA Fiduciary Rules Drive Imperative To Protect Health Plan Data & Systems From Hacking & Other Cyber Threats |
Corporate Compliance, Cybercrime, Cybersecurity, ERISA, fiduciary duty, Fiduciary Responsibility, Health Plans, HIPAA, HIPAA, Privacy, tpa |
Permalink
Posted by Cynthia Marcotte Stamer
October 19, 2021
Businesses, their employee benefit plan fiduciaries, their employer and other sponsors, their record keepers, financial advisors and other service providers and other business partners face growing pressure to shore up cyber security and cyber breach compliance and other safeguards to defend against a slew of new and ongoing federal cyber security and breach regulatory and enforcement the Biden-Harris Administration is rolling out in its effort to stem the rising tide of cybersecurity incidents.
Agencies Targeting Businesses, US Entities & Their Leaders For CyberSecurity & CyberBreach Regulation & Enforcement
On October 6, 2021, Deputy Attorney General Lisa O. Monaco announced plans to civilly prosecute federal government contractors that fail to follow required cyber security standards under the False Claims Act under a new Civil Cyber-Fraud Initiative to be led by DOJ’s Civil Division’s Commercial Litigation Branch, Fraud Section. While adding new exposures to the already substantial exposures federal government contractors and grant recipients already face for failing to comply with applicable cybersecurity and cyberbreach notifications under federal and state laws, the Civil Cyber-Fraud Initiative also provides more evidence that the Biden-Harris Administration is serious about moving forward on its broader strategy to stem the recurrent waves of disruptive cyber breaches and other security incidents buffeting U.S. public and private institutions and citizens by ramping up cybersecurity regulations, oversight and enforcement against all U.S. organizations. See e.g., New DOJ Civil Cyber-Fraud Initiative Pressures Federal Contractors & Grant Recipients To Tighten Cybersecurity Controls, Training & Other Safeguards. May 12, 2021 Executive Order on Improving the Nation’s Cybersecurity; July 28, 2021 National Security Memorandum on Improving Cybersecurity for Critical Infrastructure Control Systems.
The DOJ Civil Cyber-Fraud Initiative is the latest in a growing list of new regulatory and enforcement programs placing pressure on U.S. businesses and their leaders to get serious about cybersecurity. Examples of some of the more far reaching of these new or continuing programs include:
Under the Civil Cyber-Fraud Initiative, DOJ plans to use the False Claims Act to prosecute pursue cyber security related fraud by government contractors and grant recipients. According to DOJ, the initiative will hold accountable entities or individuals that put U.S. information or systems at risk by knowingly providing deficient cyber security products or services, knowingly misrepresenting their cyber security practices or protocols, or knowingly violating obligations to monitor and report cyber security incidents and breaches. Federal contractors and grant recipients submitting claims for federal funds will be considered to have filed a false claim in violation of the False Claims Act if their cyber security and cyber breach practices are not compliant with applicable federal requirements when the payment is requested.
- Federal Health Program Participating Health Care Providers And Plans.
The DOJ Cyber-Fraud Initiative follows a similar interpretation of the Department of Health & Human Services (“HHS”) Office Inspector General (“OIG”) about the cybersecurity and cyberbreach compliance requirements health care providers and health plan issuers participating in Medicare and certain other federally funded health care programs (“Medicare Participating Providers”) are accountable to meet under the Conditions of Participation for those programs. HHS OIG’s construction of these Conditions of Participation as including cybersecurity and cyberbreach compliance signs that Medical Participating Providers with deficient cybersecurity practices now may risk program disqualification and False Claims Act liability along with their already well-known exposure to civil monetary penalties under the Health Insurance Portability & Accountability Act (“HIPAA”) protected health information privacy, security and data breach rules.
- Health & Other Employee Benefit Plans.
Health plans and other employee benefit plans, their fiduciaries, record keepers and service providers also face growing cybersecurity responsibilities and risks. While HHS Office of Civil Rights (“OCR”) continues to clarify and expand its interpretation, investigation and enforcement of HIPAA privacy, security and data breach rules against health plans, health care providers, health care clearinghouses and their business associates, the Department of Labor Employee Benefit Security Administration is turning up the heat on employee benefit plan fiduciaries to prudently protect their employee benefit plan assets and participants against cyberthreats.
On April 14, 2021, the Department of Labor Employee Benefit Security Administration (“EBSA”) made official its interpretation of the duty of prudence applicable to employee benefit plan fiduciaries under Section 404 of the Employee Retirement Income Security Act (“ERISA”) includes a duty for ERISA-covered employee benefit plan fiduciaries to take “appropriate precautions” to mitigate risks to plan participants and assets from both internal and external cybersecurity threats. The April 14 announcement makes official EBSA’s interpretation of the duty of prudence applicable to fiduciaries of ERISA-covered employee benefit plans as extending to a duty to act prudently to safeguard plan assets and plan participants against cybersecurity threats.
Concern about cyberthreats to private employee benefit plans covered by ERISA, their participants and beneficiaries has soared as massive data breaches Federal Thrift Savings Plan, Anthem, Capital One, the Public Employees Retirement Association of New Mexico and other employee benefit plans, their vendors and service providers increasingly have impacted millions of employee benefit plans, their accounts and participants.
While Congress chose to subject health plans to the detailed health privacy, security and breach rules of HIPAA and financial and certain other employee benefit plan service providers to consumer financial disclosure and data information security requirements of laws like Gramm-Leach-Bliley Act and the Fair and Accurate Credit Transactions Act, and even employers and others conducting background and other credit checks to the Fair Credit Reporting Act, growing awareness of the cyberthreat to employee benefits has not prompted Congress to date to extend those laws or otherwise to enact express statutory requirements for employee benefit plans and their fiduciaries. However, private litigants and others increasingly have speculated that a fiduciary duty to safeguard plan asset against cyberthreats might be subsumed in the obligation of fiduciaries under Section 404 of ERISA at all times to act with “the care, skill, prudence, and diligence under the circumstances then prevailing that a prudent man acting in a like capacity and familiar with such matters would use in the conduct of an enterprise of a like character and with like aims.” See, e.g., See Record $16M Anthem HIPAA Settlement Signals Need to Tighten Your Health Plan HIPAA Compliance & Risk Management.
While EBSA has worked to formulate its recently announced positions, private litigants increasingly have begun debating the applicability and effect of ERISA on cyberbreaches involving ERISA regulated plans. See e.g., In re Anthem, Inc. Data Breach Litig., No. 15-CV-04739-LHK, 2015 WL 7443779, at *1 (N.D. Cal. Nov. 24, 2015)(holding Anthem entitled under ERISA to remove claims to federal court and refusing employee benefit plan participants’ motion to remand to state court state claims arising from data breach); In re Anthem, Inc. Data Breach Litig., No. 15-MD-02617-LHK, 2016 WL 3029783 (N.D. Cal. May 27, 2016)(refusing to dismiss participant claims against non-Anthem defendants for lack of standing), motion reconsideration denied In re Anthem, Inc. Data Breach Litig., No. 15-CV-04739-LHK, 2016 WL 324386 (N.D. Cal. Jan. 27, 2016); Bartnett v. Abbott Lab’ys, No. 20-CV-02127, 2021 WL 428820, at *5 (N.D. Ill. Feb. 8, 2021) (dismissing breach of fiduciary duty claim based on inadequate evidence); In re: Premera Blue Cross Customer Data Sec. Breach Litig., No. 3:15-MD-2633-SI, 2017 WL 539578, at *21 (D. Or. Feb. 9, 2017). While mostly unsuccessful to date for procedural or factual sufficiency reasons, the preemption issues argued in many of these cases support concerns that under the proper circumstances ERISA could apply to breaches involving plans or their participants. As these and other actions continue to wind their way through the courts, EBSA also has begun to acknowledge that ERISA plan fiduciaries duties of prudence include cybersecurity responsibilities.
EBSA’s first official recognition of a cybersecurity responsibility by plan fiduciaries appears in the Default Electronic Disclosure by Employee Pension Benefit Plans Under ERISA Final Rule (the “Electronic Disclosure Rule”), which took effect July 27, 2020 . In the discussion of its requirements regarding website-based electronic disclosures in Subpart (e)(3), the Electronic Disclosure Rule requires that “[T]he administrator must take measures reasonably calculated to ensure that the website protects the confidentiality of personal information relating to any covered individual.” Similarly, the requirements for using e-mail to provide electronic disclosures in Subsection (k)(4) of the Electronic Disclosure Rule require the plan administrator to take “measures reasonably calculated to protect the confidentiality of personal information relating to the covered individual.” While recognizing these cyber security responsibilities in the Electronic Disclosure Rule, however, EBSA explained in the Preamble to the Electronic Disclosure Rule that it decided not to include more cumbersome cybersecurity requirements in the Electronic Disclosure Rule out of concern over the cost and other burdens of such requirements. Nevertheless, the Electronic Disclosure Rule imposed a responsibility by plan fiduciaries of employee benefit plans making electronic disclosures to ensure that electronic recordkeeping systems have in place reasonable controls, adequate records management practice, and other measures calculated to protect Personally Identifiable Information.
EBSA’s April 14, 2021 reflects EBSA now views the fiduciary responsibilities of ERISA-covered employee benefit plan fiduciaries generally as including the responsibility to take “appropriate precautions” to mitigate risks to plan participants and assets from both internal and external cybersecurity threats. Beyond acknowledging a duty to take prudent steps to protect plans assets and participants against internal and external cybersecurity threats, EBSA also shared the following three resources to help plan sponsors, fiduciaries and participants to safeguard benefit plans and personal information against emerging cyber threats:
- Tips for Hiring a Service Provider: Helps plan sponsors and fiduciaries prudently select a service provider with strong cybersecurity practices and monitor their activities, as ERISA requires.
- Cybersecurity Program Best Practices: Assists plan fiduciaries and record-keepers in their responsibilities to manage cybersecurity risks.
- Online Security Tips: Offers plan participants and beneficiaries who check their retirement accounts online basic rules to reduce the risk of fraud and loss.
- Participants in Securities Markets, Market Infrastructure Providers & Vendors.
Meanwhile the Securities and Exchange Commission (“SEC”) also has made clear its expectation that all firms participating in the securities markets, market infrastructure providers and vendors will appropriately monitor, assess and manage their cybersecurity risk profiles, including their operational resiliency. Consistent with the shared understanding of best cybersecurity practices shared with the agencies, the SEC guidance makes clear its market involved and impacting regulated entities are accountable for maintaining and enforcing appropriate internal and external controls to prevent, detect and redress cybersecurity threats, including appropriate board governance and risk management, access rights and controls, data loss prevention,mobile security, incident response and resiliency, vendor management, training and awareness and other practices. See SEC Office of Compliance Inspections and Examinations Cybersecurity and Resiliency Observations. Recently announced enforcement actions demonstrate that the SEC is acting on its promise to go after SEC regulated entities that breach these expectations. See, e.g., SEC Announces Three Actions Charging Deficient Cybersecurity Procedures.
These and other recently announced federal regulatory and enforcement developments send a clear message to businesses and their leadership, employee benefit plan sponsors, fiduciaries, record keepers and other vendors, SEC securities market involved organizations and others to clean up their cybersecurity compliance and risk management. Beyond the governmental enforcement risks these developments signal, these and other emerging regulatory developments provide added fuel for the already substantial private litigant and government complaints, investigations and prosecutions against businesses, their leaders, their employee benefit plan fiduciaries, record keepers and other service providers,and others. and their leaders unable to defend the adequacy of their cybersecurity related practices.
Raise Cybersecurity Compliance & Defenses To Mitigate Risks & Liabilities
In the face of these developments, all businesses, employee benefit plan fiduciaries, their employer and other sponsors, record keepers and other vendors and their leaders should prioritize cybersecurity compliance, risk management, oversight and controls. As part of these efforts, organizations and their leaders should move quickly to position themselves to defend against potential investigation and enforcement risks created by these emerging policies. These efforts should seek to ensure compliance with all applicable statutory, regulatory and contractual requirements as well as institutionalize the necessary operational controls to protect systems, data and operations from cyber breaches and other threats, to detect and redress cyber events promptly, and to ensure that the organization otherwise can demonstrate both their compliance efforts, as well as their timely prudent detection, investigation, reporting, mitigation and remediation in response to actual or suspected cyber threats or other compliance breaches.
Efforts should begin by taking carefully crafted, well-documented documented steps to prudently evaluate and strengthen cybersecurity and breach safeguards and compliance, as well as prudently to assess and verify those of their vendors and others involved with their employee benefit plans or their administration within the scope of attorney-client privilege.
Assessments should take into account all existing required statutory, regulatory, and contractual controls and practices, documentation and other procedures. In addition, organizations should consider the advisability of adopting other “best practice” safeguards or actions taking into account relevant agency guidance and resources, government or other contracts, other industry or related standards, known and suspected breaches, “red flags” and threats, their own, their vendor and business partner and other risk profiles and experience, and other factors likely to be viewed as prudent under the circumstances.
In assessing, designing and administering the cybersecurity processes, organizations and their leaders should give due attention to assessing and addressing the adequacy of their internal and external controls to ensure the adequacy of their systems, processes, oversight and response practices and capabilities as of the time of the assessment and on an ongoing basis. Beyond establishing required policies and formal controls, organization should ensure that their organizations have in place the necessary policies and practices to monitor and control cyberthreats arising from conduct and risks created by employees and other internal workforce, vendors and other parties interacting with the business and its operations. As part of these efforts, most organizations will need to evaluate their contractual obligations and requirements for vendors, suppliers and others interacting with their businesses. Beyond general contractual compliance obligations, organizations should weigh requiring contractors, suppliers and other business partners to make specific commitments to maintain and monitor compliance and other risks, to provide timely notice and reports, to cooperate with audits and investigations necessary or advisable to respond to private or government complaints, government or other investigation, reporting or other requirements, their own compliance and risk assessments, audits and investigations and other compliance and risk management efforts. Organizations also should give careful attention and review the adequacy of protections and responsibilities arising from contractual cybersecurity and breach notice, investigation, cooperation, indemnification, insurance and other associated protections and cooperation.
Organizations also should consider establishing and administering processes for independent monitoring of regulatory, news, and other reports that could provide early warning of potential cybersecurity weaknesses, threats and breaches.
All processes should include appropriate governance, oversight and reporting to provide for ongoing monitoring and oversight necessary to identify and respond to evolving risks arising in the course of their operations as well as consistent practices for carefully documenting their compliance and risk management compliance efforts.
Because of the frequently high cost of breach investigation, response and mitigation, most organizations will want to consider securing cyber liability or other coverage, require vendors and other business partners to provide cyber liability indemnifications backed up with insurance or other adequate assurance of their ability to fulfill these financial responsibilities.
More Information
We hope this update is helpful. For more information about or assistance with these or other workforce, internal controls and compliance or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications.
Scribe for the ABA JCEB Annual Agency Meeting with HHS-OCR, and author of the “Medical Privacy” Chapter in the BNA/ERISA Litigation Treatise, the “Other Torts Chapter” in the BNA/ABA E-Heath & Other Torts Treatise, “Privacy and the Pandemic Workshop” for the Association of State and Territorial Health Plans, as well as a multitude of other highly regarded data privacy and security, workforce and health care change and crisis management and other highly regarded publications and presentations, Ms. Stamer is widely recognized for her decades of pragmatic, leading edge work, scholarship and thought leadership on health and other privacy and data security and other health industry legal, public policy and operational concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer’s work throughout her 30 plus year career has focused heavily on working with private and public employer, health care and managed care, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns. In the course of this work, she has had extensive involvement in the design, administration and defense of payroll, employee benefit, insurance, securities, trade secret and other confidential information and other internal and external record and data systems and processes as well as investigation, reporting, redress and mitigation of cyber and other incidents.
As a part of this work, she has continuously and extensively worked with domestic and international health and other employee benefit plans, their sponsors, fiduciaries, administrators, and insurers; managed care and insurance organizations; hospitals, health care systems, clinics, skilled nursing, long term care, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing, utilization management, management services organizations, group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; consultants; investors; EHR, claims, payroll and other technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, self-insured health and other employee benefit plans, their sponsors, fiduciaries, administrators and service providers, insurers and other payers, health industry advocacy and other service providers and groups and other health and managed care industry clients as well as federal and state legislative, regulatory, investigatory and enforcement bodies and agencies. She also has extensive experience dealing with OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; JCHO and other accreditation and quality organizations; private litigation and other federal and state health care industry actions: regulatory and public policy advocacy; training and discipline; enforcement; and other strategic and operational concerns.
American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, current RPTE Welfare Benefit Committee Co-Chair and former Chair of its Fiduciary Responsibility, Plan Terminations and Distributions and Defined Contribution Plan Committees, a former JCEB Council Representative, Past Chair of the ABA Managed Care & Insurance Interest Group, former SHRM Consultants Board and Region IV Chair, former Texas Association of Business Board, BACPAC Board and Dallas Chapter Chair, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas.
Ms. Stamer also shares her extensive publications and thought leadership as well as leadership involvement in a broad range of other professional and civic organizations. For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here.
IMPORTANT NOTICE ABOUT THIS COMMUNICATION
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation considering the specific facts and circumstances presented in their unique circumstance at any time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any situation and does not necessarily address all relevant issues. Because developments could impact the currency and completeness of this discussion, the author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access of this publication. Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein. ©2021 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™.
Comments Off on Federal Agencies Take Aim At Businesses, Benefit Plan Fiduciaries & Service Providers & Others With Lax CyberSecurity & CyberBreach Compliance; Build Defenses By Strengthening Internal & External Controls & Risk Managment |
Association Health Plan, Corporate Compliance, corporate governance, Cybercrime, Cybersecurity, Data Breach, Data Security, EBSA, Employee Benefits, Employer, Employers, ERISA, fiduciary duty, Fiduciary Responsibility, Government Accountability, Government Contractors, government employer, government plan, group health plan, health benefit, Health Benefits, health Care, Health Care Fraud, Health Care Sharing Ministries, health insurance, health insurance marketplace, Health IT, health plan, Health Plans, health reform, HIPAA, HIPAA, Medicare Part D, multiple employer plan (Meps), Personal Health Records, Personal Health Recordss, Privacy, Protected Health Information, Public Policy, Retirement Plans, SEC |
Permalink
Posted by Cynthia Marcotte Stamer
October 11, 2021
Federal government contractors and grant recipients should tighten cyber security policies, practices and internal controls to mitigate their exposure to civil False Claims Act claims by the Department of Justice (“DOJ”) under a new DOJ Civil Cyber-Fraud Initiative announced by DOJ last week. The new initiative adds False Claims Act civil liability to the already substantial civil liability that government contractors and other businesses already face for failing to comply with applicable cyber security and cyber breach notifications under federal and state laws. In the face of these added liabilities, federal contractors and grant recipients should act quickly to audit their cyber security and cyber breach practices, tighten cyber security and breach detection; oversight, credentialing and controls over employees, contractors and others with access to facilities and systems and take other appropriate action to prevent and remediate compliance deficiencies and risks.
Federal Government Contractors Bear Cybersecurity Responsibilities
Federal government contractors can face cyber security and breach responsibilities under a myriad of federal laws, regulations and contracting standards which are incorporated into their government contracts as part of conditions for participation in the applicable contract or program. For example, businesses that sell products to the U.S. government generally are required to comply with 15 basic safeguarding requirements and procedures to protect systems used to collect, process, maintain, use, share, disseminate, or dispose of Federal Contract Information (FCI) set forth in FAR 52.202.21. Companies that produce products used by the Department of Defense (DoD) may be required to comply with the minimum cybersecurity standards set by DFARS if those products aren’t commercially available off-the-shelf (COTS). DFARS 252.204-7012 requires contractors with CUI to follow NIST SP 800-171, report cyber incidents, report cybersecurity gaps. DFARS 252.204-7019 (interim) requires primes and subcontractors to submit self-assessment of NIST 800-171 controls through the Supplier Performance Risk System (SPRS). DFARS 252.204-7020 (interim) requires primes and subcontractors give the DoD access to their infrastructure to verify the self-assessment (via DMCA) and requires contractors roll requirements down to subcontractors. Meanwhile, DFARS 252.204-7021 (interim) governs the rollout of the Cybersecurity Maturity Model Certification program over 5 years. These requirements are in addition to any cyber security or cyber breach requirements otherwise applicable to government contractors or grant recipients under laws such as the Fair & Accurate Credit Transactions Act (“FACTA”) that also might apply to other businesses that do not do business with the federal government.
New DOJ Civil Cyber-Fraud Initiative Against Government Contractors Heightens Enforcement & Liability Risks
On October 6, 2021, Deputy Attorney General Lisa O. Monaco announced plans to civilly prosecute federal government contractors that fail to follow required cyber security standards under the False Claims Act under a new Civil Cyber-Fraud Initiative to be led by DOJ’s Civil Division’s Commercial Litigation Branch, Fraud Section.
According to the DOJ announcement, DOJ expects the initiative to:
- Build broad resiliency against cyber security intrusions across the government, the public sector and key industry partners.
- Hold contractors and grantees to their commitments to protect government information and infrastructure.
- Support government experts’ efforts to timely identify, create and publicize patches for vulnerabilities in commonly used information technology products and services.
- Ensure that companies that follow the rules and invest in meeting cyber security requirements are not at a competitive disadvantage.
- Reimburse the government and the taxpayers for the losses incurred when companies fail to satisfy their cyber security obligations.
- Improve overall cyber security practices that will benefit the government, private users and the American public.
Under the Civil Cyber-Fraud Initiative, DOJ plans to use the False Claims Act to prosecute pursue cyber security related fraud by government contractors and grant recipients. According to DOJ, the initiative will hold accountable entities or individuals that put U.S. information or systems at risk by knowingly providing deficient cyber security products or services, knowingly misrepresenting their cyber security practices or protocols, or knowingly violating obligations to monitor and report cyber security incidents and breaches.
The False Claims Act is the government’s primary civil tool to redress false claims for federal funds and property involving government programs and operations. The DOJ’s Civil Cyber-Fraud Initiative does not create new cyber security and cyber breach obligations to promote these goals. Rather, it piggybacks on already existing federal mandates by adding False Claims Act civil liability to the already substantial civil liability that government contractors and grant recipients already risk for failing to maintain and administer their data security and data breach practices in accordance with applicable federal laws. Under the new Civil Cyber-Fraud Initiative, DOJ has signaled it intends to include compliance with applicable cyber security and cyber breach reporting requirements applicable to contractors as part of the obligations of government contractors and grant recipients to comply with applicable law as a condition of eligibility to participate in federal programs and receive federal funds. Federal contractors and grant recipients submitting claims for federal funds will be considered to have filed a false claim in violation of the False Claims Act if their cyber security and cyber breach practices are not compliant with applicable federal requirements when the payment is requested.
Companies and individuals found to have violated the False Claims Act generally are liable for treble damages plus a penalty that is linked to inflation. In addition to allowing the United States to pursue perpetrators of fraud on its own, the FCA allows private citizens to file suits on behalf of the government (called “qui tam” suits) against those who have defrauded the government. Private citizens who successfully bring qui tam actions may receive a portion of the government’s recovery. Many DOJ Fraud Section investigations and lawsuits arise from such qui tam actions and result in often large recoveries by DOJ and the reporting whistleblowers. As a result of availability of whistleblower recoveries, government contractors should anticipate that disgruntled employees, contractors, or others with whom they do business with knowledge of data breaches or other cybersecurity weaknesses may be incentivized to act as whistleblowers.
Cyber Risks Already Substantial Cyber Risks
The False Claims Act exposure under the new DOJ Civil Cyber-Security initiative adds to the already substantial and mounting risks that government contractors already face under an ever-expanding tapestry of federal, state and in some instances, international statutes, regulations and rulings.
Along with any exposures specifically applicable to it as a government contractor, depending on the nature of the business and the data it collects, the business also likely falls subject to duties to safeguard the confidentiality and security of wide range of electronic or other personal financial, tax and other data under various federal and state laws such as FACTA, the Internal Revenue Code, the Health Insurance Portability & Accountability Act (HIPAA), state identity theft, and a host of other statutes and regulations, contractual agreements, or both.
Due to the nature of their activities and involvements, some of the most significant of these obligations may arise from electronic crime related provisions of the Criminal Code of the United States, which by virtue of their criminal nature trigger potential organizational compliance program responsibilities under the U.S. Sentencing Commission Organizational Guidelines for government contractors and other covered entities such as 18 U.S. Code § 1028 – Fraud and related activity in connection with identification documents, authentication features, and information; 18 U.S.C. § 1029. Fraud and Related Activity in Connection with Access Devices; and 18 U.S.C. § 1030. Fraud and Related Activity in Connection with Computers.
However, government contractors also can face cybersecurity responsibilities, breach notification and other obligations and liabilities under a wide range of other civil laws and regulations. For instance, FACTA generally requires covered entities that collect or use certain personal financial information to conduct due diligence, monitor the security of records and adopt disposal practices that are reasonable and appropriate to prevent the unauthorized access to – or use of – information in a consumer report. As implemented by the Federal Trade Commission regulations, entities with covered accounts must develop and implement written identity theft prevention programs designed to help identify, detect, and respond to patterns, practices, or specific activities – known as “red flags” – that could indicate identity theft.
Beyond these federal obligations, government contractors, like other businesses, also typically are exposed to liability under a wide variety of cyber security, cyber breach notification and other obligations and liabilities under state laws, regulations and common law. See, e.g. here. While the particulars vary based on the state, the nature of the business, where and how the business collects and maintains its data and other factors, the applicable state electronic confidentiality and data security requirements in most states and under some federal laws increasingly include express duties to take steps to protect data, to monitor from breaches and other threats, and/or to notify subjects of the breached data and in some cases, regulators and the public within a short period after a breach happens. Businesses operating in multiple states typically faces exposure under the laws of each jurisdiction where it operates with data impacted by the breach.
Because cyber security events increasingly create business and financial losses, investigation and defense costs, penalties and other liabilities and costs, cyber security breaches and other events also increasingly that fuel shareholder disclosure obligations and shareholder lawsuits. Indeed, former Securities and Exchange Commission Chair Mary Jo White in May, 2016 characterized cyber security as the biggest risk facing the financial system See here. In response to investor risks from cyber security events, the SEC has required regulated entities to make disclosures about these risks to investors since 2011. See CF Disclosure Guidance: Topic No. 2 – Cybersecurity. Given this guidance, it should come as no surprise that the SEC has imposed substantial fines against entities following a breach. See e.g. R.T. Jones reaches settlement with SEC in data breach case; Morgan Stanley Fined $1 Million for Client Data Breach.
Act To Manage Compliance & Risks
In the face of these added liabilities, federal contractors and grant recipients should act quickly to work with qualified legal counsel within the scope of attorney-client privilege to audit the adequacy of their existing cyber security and cyber breach practices under applicable federal statutes and contracts and other relevant laws and regulations as well as to confirm that adequate breach notification has been made for any existing or past breaches. To the extent that the audit uncovers any potential deficiencies in prior breach notification or other compliance, the federal contractor or grant recipient general will want to seek guidance from legal counsel regarding the advisable steps, if any, to take to mitigate and resolve outstanding liabilities, particularly in light of whistleblower liabilities. In addition to examining past and current compliance risks, government contractors and grant recipients also will want to explore advisable steps and documentation that will position their organizations to demonstrate their appropriate monitoring and maintenance of ongoing compliance or otherwise strengthen their defenses against potential cyber breaches as well as whistleblower and retaliation claims arising from employees or others seeking to use these exposures as leverage for settlements or claims. Given the potential magnitude of the liability, businesses generally not only need to take well documented steps properly to safeguard sensitive electronic sensitive personal information and systems holding or using it as well as be prepared to promptly provide notice in the event of any breach with the short time contemplated by law.
As part of these efforts, businesses and their leaders will want to ensure their compliance efforts include both adoption of all required formal policies, appropriate credentialing of employees, contractors and others accessing systems or facilities, well documented operational compliance and risk audits, documented risk assessment and response, compliance hotline reporting and investigation, suitable up-the-ladder reporting, and other appropriate procedures to facilitate rapid identification of potential concerns and other operational compliance.
Effective internal and external workforce credentialing, training, management and oversight are key to the success of these efforts, particularly because cyber breaches and other data threats often leverage internal access created by workforce infiltration, susceptibilities created by social engineering or other opportunities created from lax workforce or contractor compliance with security controls or both. See, e.g., Insider threat: The human element of cyberrisk.
Effective internal monitoring and reporting protocols also are essential to ensure rapid breach identification, investigation and notification. These protocols also should be developed and implemented to ensure timely disclosure and management of any breaches within required time frames.
In recognition of the typically high financial and operational costs of breach investigation, notification and defense, organizations also should weigh the advisability of securing and requiring business partners to secure cyber insurance or other protection to help mitigate these costs in the event of a cyber event.
While the conduct of these assessments inevitably will require the involvement of outside consulting services, business leaders also are cautioned to use care to take appropriate steps to protect these interactions by arranging to engage these services pursuant to attorney-client privilege to help shield sensitive information likely to be uncovered through compliance, risk management or investigation activities. Likewise, given the short time allowed for breach mitigation and notification, businesses should weigh carefully whether to engage regulatory counsel to assist with the initial breach notification and mitigation, separate and apart from cyber litigation defense counsel that might be available under applicable cyber insurance policies unless the proposed litigation defense counsel has proven cyber and other regulatory knowledge, experience and qualifications handling breach mitigation and notification events.
More Information
We hope this update is helpful. For more information about or assistance with these or other workforce, internal controls and compliance or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications. As a significant part of her work, Ms. Stamer has worked extensively on pandemic, business and other crisis planning, preparedness and response for more than 30 years.
Scribe for the ABA JCEB Annual Agency Meeting with HHS-OCR, Vice Chair of the ABA International Section Life Sciences Committee, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and the ABA RPTE Employee Benefits & Other Compensation Group, Ms. Stamer is most widely recognized for her decades of pragmatic, leading edge work, scholarship and thought leadership on health and other privacy and data security and other health industry legal, public policy and operational concerns. Ms. Stamer’s work throughout her 30 plus year career has focused heavily on working with health care and managed care, health and other employee benefit plan, insurance and financial services and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns. As a part of this work, she has continuously and extensively worked with domestic and international health plans, their sponsors, fiduciaries, administrators, and insurers; managed care and insurance organizations; hospitals, health care systems, clinics, skilled nursing, long term care, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing, utilization management, management services organizations, group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; consultants; investors; EHR, claims, payroll and other technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, self-insured health and other employee benefit plans, their sponsors, fiduciaries, administrators and service providers, insurers and other payers, health industry advocacy and other service providers and groups and other health and managed care industry clients as well as federal and state legislative, regulatory, investigatory and enforcement bodies and agencies.
This involvement encompasses helping health care systems and organizations, group and individual health care providers, health plans and insurers, health IT, life sciences and other health industry clients prevent, investigate, manage and resolve sexual assault, abuse, harassment and other organizational, provider and employee misconduct and other performance and behavior; manage Section 1557, Civil Rights Act and other discrimination and accommodation, and other regulatory, contractual and other compliance; vendors and suppliers; contracting and other terms of participation, medical billing, reimbursement, claims administration and coordination, Medicare, Medicaid, CHIP, Medicare/Medicaid Advantage, ERISA and other payers and other provider-payer relations, contracting, compliance and enforcement; Form 990 and other nonprofit and tax-exemption; fundraising, investors, joint venture, and other business partners; quality and other performance measurement, management, discipline and reporting; physician and other workforce recruiting, performance management, peer review and other investigations and discipline, wage and hour, payroll, gain-sharing and other pay-for performance and other compensation, training, outsourcing and other human resources and workforce matters; board, medical staff and other governance; strategic planning, process and quality improvement; meaningful use, EHR, HIPAA and other technology, data security and breach and other health IT and data; STARK, ant kickback, insurance, and other fraud prevention, investigation, defense and enforcement; audits, investigations, and enforcement actions; trade secrets and other intellectual property; crisis preparedness and response; internal, government and third-party licensure, credentialing, accreditation, HCQIA and other peer review and quality reporting, audits, investigations, enforcement and defense; patient relations and care; internal controls and regulatory compliance; payer-provider, provider-provider, vendor, patient, governmental and community relations; facilities, practice, products and other sales, mergers, acquisitions and other business and commercial transactions; government procurement and contracting; grants; tax-exemption and not-for-profit; privacy and data security; training; risk and change management; regulatory affairs and public policy; process, product and service improvement, development and innovation, and other legal and operational compliance and risk management, government and regulatory affairs and operations concerns. to establish, administer and defend workforce and staffing, quality, and other compliance, risk management and operational practices, policies and actions; comply with requirements; investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; JCHO and other accreditation and quality organizations; private litigation and other federal and state health care industry actions: regulatory and public policy advocacy; training and discipline; enforcement; and other strategic and operational concerns.
Author of “Privacy and the Pandemic Workshop” for the Association of State and Territorial Health Plans, as well as a multitude of other health industry matters, workforce and health care change and crisis management and other highly regarded publications and presentations, the American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting and a former Council Representative, Past Chair of the ABA Managed Care & Insurance Interest Group, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, and a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her extensive publications and thought leadership as well as leadership involvement in a broad range of other professional and civic organizations. For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here.
IMPORTANT NOTICE ABOUT THIS COMMUNICATION
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author and Solutions Law Press, Inc.™ reserve the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc.™ disclaim, and have no responsibility to provide any update or otherwise notify anyone any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication. Readers acknowledge and agree to the conditions of this Notice as a condition of their access of this publication. Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein. ©2020 Cynthia Marcotte Stamer. Limited non-exclusive right to republish granted to Solutions Law Press, Inc.™.
Comments Off on New DOJ Civil Cyber-Fraud Initiative Pressures Federal Contractors & Grant Recipients To Tighten Cybersecurity Controls, Training & Other Safeguards |
Corporate Compliance, corporate governance, Cybercrime, Cybersecurity, Data Breach, Data Security, Employers, Federal Sentencing Guidelines, Government Accountability, Government Contractors, government plan, Identity Theft, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
September 9, 2021
The Biden- Harris Administration today announced it will require a multitude of US employees to adopt and enforce workplace COVID-19 vaccination mandates for their workers.
The mandate requirement generally will apply to all federal workers, government contractors and subcontractors, health care workers of facilities participating in Medicare or Medicaid And any employer with more than 100 employees.All Medicare and Medicaid certified health care facilities, and a broad range of other employers must prepare to meet impending new federal COVID-19 vaccine mandates announced by the Biden-Harris Administration today.
According to today’s announcements all healthcare facilities participating in Medicare or Medicaid, Federal government employees, federal government contractors or subcontractors and any business employing 100 or more employees will be required to ensure all staff are vaccinated against COVID-19.
The Biden-Harris Administration says the new health industry COVID-19 vaccine will be implemented through emergency regulations to be issued in October.
According to today’s announcement, the Centers for Medicare & Medicaid Service (“CMS”) in collaboration with the Centers for Disease Control (“CDC”) will issue an Interim Final Rule with Comment Period for health care providers in October that will apply vaccine mandates hospitals, dialysis facilities, ambulatory surgical settings, nursing homes and home health agencies, among others, as a condition for participating in the Medicare and Medicaid programs. This announcement expends the healthcare industry mandate beyond it’s originally planned applicability to nursing homes when announced last month.
In addition to the health industry mandate, the Biden-Harris Administration also announcementI it would impose new vaccine mandates for all federal government workers, government contractors and subcontractors, and all employers employing more than 100 employees.
In it’s announcement of the impending vaccination requirements, CDC urged health care facilities to prepare now to meet the new mandate in October. CMS expects certified Medicare and Medicaid facilities to act in the best interest of patients and staff by complying with new COVID-19 vaccination requirements.
The Administration is urging covered workers not currently vaccinated to begin the vaccination process immediately and facilities and employers to use all available resources to support employee vaccinations, including employee education and clinics, as they work to meet new federal requirements.
Beyond potential federal program participation losses, the new vaccine mandates likely adds vaccination to the list of safety safeguards that employers can expect to be required to enforce as part of the occupational safety rules of the Occupational Safety and Health Administration (“OSHA”).
While legal challenges to the mandate requirements are likely, most business andw that have not already adopted vaccine mandates are expected to adopt these mandates rather than face business losses and other sanctions.
Businesses that were supportive of mandates but fearful of the burdens of administering required accommodations under the Americans with Disabilities Act (”ADA”) or other civil rights laws are likely to welcome the Administration‘s new position. Unlike voluntary mandates, the ADA accommodation requirements do not apply to vaccination requirements required by law.
The new mandates also mean that businesses generally need to be concerned about potential OSHA exposure for failing to implement or enforce the mandates. OSHA already is sanctioning employers for violating COVID-19 related OSHA requirements. For instance, OSHA nailed Lakewood Resource and Referral Center Inc., dba Center for Education Medicine and Dentistry (CHEMED) with heavy fines for allegedly violating applicable COVID-19 safety guidelines in January, 2021.
In a July 23, 2021 citation letter, OSH proposes to fine CHEMED $273,064.00 for willfully violating OSHA by not providing a medical evaluation to determine each employee’s ability to use a N95 respirator, before the employee was fit tested or required to use the respirator in the workplace to protect against SARS-CoV-2 virus while testing suspected COVID-19 individuals.
In addition to the proposed fine, the citation also orders CHEMED to take a series of corrective actions and to post notices in the workplace informing workers of the violation.
Along with the CHEMED citation, OSH also cited a staffing agency contracted to provide nursing staffing to CHEMED, Homecare Therapies for also failing to conduct medical evaluations and fit tests. It received two violations and a proposed fine of $13,653.
In the face of these potential consequences, most covered health care facilities and other employers impacted by the mandate are likely to implement mandates unless and until these requirements are struct down by the courts or withdrawn.
Assuming the Administration follows appropriate procedures to adopt the rules, most legal commentators do not expect the legal challenges opposing the mandate orders to be successful in the courts particularly after the Supreme Court refused to overturn or hear arguments for overturning a unanimous decision of a three-judge panel of the United States Court of Appeals for the Seventh Circuit in Klassen v. Trustees of Indiana University that refused to enjoin a vaccine mandate imposed by Indiana University as a condition of student or staff in person participation in classes or other activities.
While most healthcare and other covered businesses are not expected to challenge the rules, compliance us likely to trigger backlash from some unvaccinated workers strongly opposed to becoming vaccinated. Employers may find that some employees will resign their employment or take other tactics to avoid becoming vaccinated. Even those who elect to become vaccinated to retain their employment are likely to express opposition and dissatisfaction that could create liability exposures for the employers if it becomes a basis for retaliation claim.
Employers in Texas and certain other states that have adopted rules restricting or prohibiting vaccine, mask or other mandates also may face challenges based on the state rules.
In light of these and other uncertainties and challenges, Healthcare and Other or Employers generally should seek legal advice and assistance from legal counsel experienced with the relevant health care, labor and employment, privacy and other concerns.
More Information
This article is republished by permission of the author, Cynthia Marcotte Stamer. To review the original work, see here.
Solutions Law Press, Inc. invites you to receive future updates by registering here and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here. For specific information about the these or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years working as an on demand, special project, consulting, general counsel or other basis with domestic and international business, charitable, community and government organizations of all types, sizes and industries and their leaders on labor and employment and other workforce compliance, performance management, internal controls and governance, compensation and benefits, regulatory compliance, investigations and audits, change management and restructuring, disaster preparedness and response and other operational, risk management and tactical concerns.
Most widely recognized for her work with health care, life sciences, insurance and data and technology organizations, she also has worked extensively with health plan and insurance, employee benefits, financial, transportation, manufacturing, energy, real estate, accounting and other services, public and private academic and other education, hospitality, charitable, civic and other business, government and community organizations. and their leaders.
Ms. Stamer has extensive experience advising, representing, defending, and training domestic and international public and private business, charitable, community and governmental organizations and their leaders, employers, employee benefit plans, their fiduciaries and service providers, insurers, and others has published and spoken extensively on these concerns. As part of these involvements, she has worked, published and spoken extensively on these and other human resources, employee benefits, compensation, worker classification and other workforce and other services; insurance; health care; workers’ compensation and occupational disease; business reengineering, disaster and distress; and many other performance, risk management, compliance, public policy and regulatory affairs, and other operational concerns.
A former lead advisor to the Government of Bolivia on its pension project, Ms. Stamer also has worked internationally and domestically as an advisor to business, community and government leaders on these and other legislative, regulatory and other legislative and regulatory design, drafting, interpretation and enforcement, as well as regularly advises and represents organizations on the design, administration and defense of workforce, employee benefit and compensation, safety, discipline, reengineering, regulatory and operational compliance and other management practices and actions.
Ms. Stamer also serves in leadership of a broad range of professional and civic organizations and provides insights and thought leadership through her extensive publications, public speaking and volunteer service with a diverse range of organizations including as Chair of the American Bar Association (“ABA”) Intellectual Property Section Law Practice Management Committee, Vice Chair of the International Section Life Sciences and Health Committee, Past ABA RPTE Employee Benefits & Other Compensation Group Chair and Council Representative and current Welfare Benefit Committee Co-Chair, Past Chair of the ABA Managed Care & Insurance Interest Group, past Region IV Chair and national Society of Human Resources Management Consultant Forum Board Member, past Texas Association of Business BACPAC Chair, Regional Chair and Dallas Chapter Chair, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation and many others.
For more information about these concerns or Ms. Stamer’s work, experience, involvements, other publications, or programs, see www.cynthiastamer.com, on Facebook, on LinkedIn or Twitter or e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns.
©2021 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™
Comments Off on Biden-Harris To Require many Employers To Mandate Employee Vaccinations |
Accommodation, ADA, board of directors, Civil Rights, Construction, Corporate Compliance, corporate governance, COVID, COVID-19, EEOC, employee, Employee Handbook, Employer, Employers, Employment, health Care, Hiring, Hospitality, HR, Human Resources, Internal Controls, Internal Investigations, Joint Employer, Management, OFCCP, Pandemic, Privacy, vaccination mandate, Worker, Workforce | Tagged: COVID, Employer, vaccine mandate |
Permalink
Posted by Cynthia Marcotte Stamer
August 3, 2021
Comments Off on California Medical Privacy Rules Changed 7/1. https://slphealthcareupdate.com/2021/08/03/california-medical-privacy-rules-eased-new-7-1-2021-rules-allow-greater-flexibility-on-disclosures-a-breach-and-give-agency-more-fine-flexibility-https-www-cdph-ca-gov-programs-ols-cdph%20docume/ |
Association Health Plan, compliance, Consumer Protection, Corporate Compliance, Cybercrime, Data Breach, Data Security, Electronic Medical Record, EMR, enforcement, health benefit, Health Benefits, health Care, health plan, Health Plans, HIPAA, HIPAA, Insurance, Internal Investigations, Managed Care, Privacy, Risk Management, third party administrators, tpa, Trade secret |
Permalink
Posted by Cynthia Marcotte Stamer
June 26, 2020
Earlier this week, the Internal Revenue Service (“IRS”) announced that employee benefit plan participants that already took a required minimum distribution (RMD) in 2020 from certain retirement accounts now has the opportunity through August 31, 2020 to roll those funds back into a retirement account following the Coronavirus Aid, Relief, and Economic Security (CARES) Act RMD waiver for 2020. The announcement of this relief covers one of a long and growing list of special tax and other COVID-19 responsive special rules and requirements that may change requirements, provide special relief or both for businesses and individuals that every business leader and individual should carefully monitor and respond to appropriately.
Retirement Plan Rollover Relief
On July 23, 2020, the IRS announced its extension of the 60-day rollover period for any RMDs already taken this year to August 31, 2020 to give taxpayers time to take advantage of this opportunity in Notice 2020-51 (PDF). The Notice also answers questions regarding the waiver of RMDs for 2020 under the Coronavirus Aid, Relief, and Economic Security Act, known as the CARES Act.
The CARES Act enabled any taxpayer with an RMD due in 2020 from a defined-contribution retirement plan, including a 401(k) or 403(b) plan, or an IRA, to skip those RMDs this year. This includes anyone who turned age 70 1/2 in 2019 and would have had to take the first RMD by April 1, 2020. This waiver does not apply to defined-benefit plans.
In addition to the rollover opportunity, an IRA owner or beneficiary who has already received a distribution from an IRA of an amount that would have been an RMD in 2020 can repay the distribution to the IRA by August 31, 2020. The notice provides that this repayment is not subject to the one rollover per 12-month period limitation and the restriction on rollovers for inherited IRAs.
The notice provides two sample amendments that employers may adopt to give plan participants and beneficiaries whose RMDs are waived a choice as to whether or not to receive the waived RMD.
Other COVID-19 Tax Rules & Relief
The guidance and relief in Notice 2020-51 highlights only one of a long list of special COVID-19 associated tax rules and relief that could apply to a business, its employees or employee benefit plan participants or both including the following:
- IR-2020-127, IRS announces rollover relief for required minimum distributions from retirement accounts that were waived under the CARES Act
- IR-2020-126, IRS extends July 15, other upcoming deadlines for tornado victims in parts of the South; provides other relief
- IR-2020-124, Relief for taxpayers affected by COVID-19 who take distributions or loans from retirement plans
- IR-2020-122, IRS outlines changes to health care spending available under CARES Act
- IR-2020-121, IRS alert: Economic Impact Payments belong to recipient, not nursing homes or care facilities
- IR-2020-120, Treasury, IRS provide tax relief to investors and businesses affected by COVID-19 in new markets tax credit transactions
- IR-2020-119, IRS provides guidance on employer leave-based donation programs that aid victims of the COVID-19 pandemic
- IR-2020-118, IRS reminder: File now, choose direct deposit or schedule tax payments electronically before the July 15 deadline
- IR-2020-117, IRS reminder: Deadline postponed to July 15 for those who pay estimated taxes
- IR-2020-115, IRS warns against COVID-19 fraud; other financial schemes
- IR-2020-114, IRS provides answers about Coronavirus related tax relief for Qualified Opportunity Funds and investors
- IR-2020-111, 159 million Economic Impact Payments processed; Low-income people and others who aren’t required to file tax returns can quickly register for payment with IRS Non-Filers tool
- IR-2020-110, IRS provides relief to retirement plan participants to sign elections remotely
- IR-2020-109, IRS reminder: June 15 tax deadline postponed to July 15 for taxpayers who live and work abroad
- IR-2020-106, Treasury, IRS provide safe harbor for taxpayers that develop renewable energy projects
- IR-2020-105, Economic Impact Payments being sent by prepaid debit cards, arrive in plain envelope; IRS.gov answers frequently asked questions
- IR-2020-101, Treasury, IRS release latest state-by-state Economic Impact Payment figures for May 22, 2020
- IR-2020-99, IRS.gov helps taxpayers get tax information they need; find tools for filing, paying, checking accounts and answering questions
- Treasury News Release: Treasury is Delivering Millions of Economic Impact Payments by Prepaid Debit Card
- IR-2020-97, IRS adds phone operators to answer Economic Impact Payment questions
- IR-2020-96, IRS expands partner materials for Economic Impact Payments; continues sweeping effort to share details in multiple languages
- IR-2020-95, IRS provides tax relief through increased flexibility for taxpayers in section 125 cafeteria plans
- IR-2020-93, Why the Economic Impact Payment amount could be different than anticipated
- IR-2020-92, Act by Wednesday for chance to get quicker Economic Impact Payment; timeline for payments continues to accelerate
- IR-2020-91, Treasury, IRS release latest state-by-state Economic Impact Payment figures
- IR-2020-89, IRS: Three new credits are available to many businesses hit by COVID-19
- IR-2020-87, IRS retools Settlement Days program in response to COVID-19 pandemic; allows unrepresented taxpayers to settle their cases virtually and reach finality
- IR-2020-86, VA, SSI recipients with eligible children need to act by Tuesday, May 5 to quickly add money to their automatic Economic Impact Payment; ‘Plus $500 Push’ continues
- IR-2020-85, Economic Impact Payments continue to be sent, check IRS.gov for answers to common questions
- IR-2020-83, Use IRS Non-Filers: Enter Payment Info Here tool to get Economic Impact Payment; many low-income, homeless qualify
- IR-2020-82, IRS enhances Get My Payment online application to help taxpayers
- IR-2020-81, VA, SSI recipients with eligible children need to act by May 5 to quickly add money to their automatic Economic Impact Payment; ‘Plus $500 Push’ continues
- IR-2020-80, Treasury, IRS deliver 89.5 million Economic Impact Payments in first three weeks, release state-by-state Economic Impact Payment figures (Updated: April 28, 2020)
- IR-2020-77, Treasury, IRS announce cross-border tax guidance related to travel disruptions arising from the COVID-19 emergency
- IR-2020-76, SSA, RRB recipients with eligible children need to act by Wednesday to quickly add money to their automatic Economic Impact Payment; IRS asks for help in the “Plus $500 Push”
- IR-2020-75, Veterans Affairs recipients will receive automatic Economic Impact Payments; Step follows work between Treasury, IRS, VA
- IR-2020-74, IRS: Free File use soars; taxpayers still have time to do their taxes for free
- IR-2020-73, Supplemental Security Income recipients will receive automatic Economic Impact Payments; step follows work between Treasury, IRS, Social Security Administration
- IR-2020-72, Treasury, IRS unveil online application to help with Economic Impact Payments
- IR-2020-71, IRS, Security Summit partners warn tax professionals on scams, urge additional security measures to protect taxpayer data
- IR-2020-70, REMINDER: Schedule and pay federal taxes electronically due by July 15; only a few hours remaining for taxpayers to reschedule payments set for April 15
- IR-2020-69, Treasury, IRS launch new tool to help non-filers register for Economic Impact Payments
- IR-2020-68, IRS urges taxpayers to use electronic options; outlines online assistance
- IR-2020-67, IRS provides guidance under the CARES Act to taxpayers with net operating losses
- IR-2020-66, To help taxpayers, the Department of Treasury and the Internal Revenue Service announced today that Notice 2020-23 extends additional key tax deadlines for individuals and businesses
- IR-2020-65, Follow IRS on social media, sign up for e-news subscriptions for urgent updates on COVID-19, scams and economic impact payment information
- IR-2020-64, IRS issues warning about coronavirus-related scams; watch out for schemes tied to economic impact payments
- Treasury News Release: Social Security recipients will automatically receive Economic Impact Payments
- IR 2020-62, IRS: Employee Retention Credit available for many businesses financially impacted by COVID-19
- IR 2020-61, Economic impact payments: What you need to know
- IR-2020-59, IRS unveils new People First Initiative; COVID-19 effort temporarily adjusts, suspends key compliance program
- IR-2020-58, Tax Day now July 15: Treasury, IRS extend filing deadline and federal tax payments regardless of amount
- IR-2020-57, Treasury, IRS and Labor announce plan to implement coronavirus-related paid leave for workers and tax credits for small and midsize businesses to swiftly recover the cost of providing Coronavirus-related leave
- Treasury News Release: Treasury and IRS issue guidance on deferring tax payments due to COVID-19 outbreak
- IR-2020-54, IRS: High-deductible health plans can cover coronavirus costs
Along with these tax rules, businesses and their employees also may be impacted by a broad range of special federal and state labor and employment and other rules adopted in response to the continuing COVID-19 health care emergency and its fallout. Businesses and their leaders should carefully review and monitor these and other COVID-19 specific rules to ensure that their businesses don’t trigger unanticipated liability by failing to meet critical requirements or to ensure that they take full advantage of all available relief.
More Information
We hope this update is helpful. For more information about the these or other health or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years legal and operational management work, coaching, public policy and regulatory affairs leadership and advocacy, training and public speaking and publications. As a significant part of her work, Ms. Stamer has worked extensively domestically and internationally on an demand, special project and ongoing basis with health industry, health plan and insurance and other businesses of all types, government and community organizations and their leaders, spoken and published extensively on workforce and other services, compensation and benefits, and related tax; insurance; workers’ compensation and occupational disease; business reengineering, disaster and distress; and many other management concerns.
Board Certified in Labor and Employment Law By the Texas Board of Legal Specialization, Scribe for the ABA JCEB Annual Agency Meeting with OCR, Vice Chair of the ABA International Section Life Sciences Committee, and the ABA RPTE Employee Benefits & Other Compensation Group and a former Council Representative, Past Chair of the ABA Managed Care & Insurance Interest Group, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, and a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer has extensive experience advising, representing, defending and training health care providers, health plans and insurers, employers, community organizations and others about HIPAA and other privacy concerns and has published and spoken extensively on these concerns.
Her involvement with HIPAA and other privacy and data concerns has taken place as part of her more than 30 years involvement working with with public and private health industry, health insurance and other employers and organizations of all sizes, employee benefit plans, insurance and financial services, health industry and a broad range of public and private domestic and international business, community and government organizations and leaders on pandemic and other health and safety, workforce and performance preparedness, risks and change management, disaster preparedness and response and other operational and tactical concerns throughout her adult life. A former lead advisor to the Government of Bolivia on its pension project, Ms. Stamer also has worked internationally and domestically as an advisor to business, community and government leaders on crisis preparedness and response, privacy and data security, workforce, health care and other policy and enforcement, as well as regularly advises and defends organizations about the design, administration and defense of their organizations workforce, employee benefit and compensation, safety, discipline and other management practices and actions.
Ms. Stamer also serves in leadership of a broad range of professional and civic organizations and shares insights and thought leadership through her extensive publications and public speaking. For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here. ©2020 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.
Comments Off on Businesses Should Confirm Using Benefits, Meeting Mandates Of Special COVID-19 Tax Rules |
401(k), Accommodation, ADA, adea, Association Health Plan, board of directors, Brokers, Child Safety, Civil Rights, Claims, Corporate Compliance, COVID, Data Breach, defined benefit plan, Defined Benefit Plans, defined contribution plan, Defined Contribution Plans, Disability, Disability Discrimination, Disability Leave, Disability Plans, Disaster, Discrimination, Disease Management, EBSA, Electronic Medical Record, Emergency, employee, Employee Benefits, Employer, Employment, Employment Discrimination, family leave, Fiduciary Responsibility, FMLA, Government Contractors, government employer, government plan, health benefit, Health Benefits, health Care, health plan, Health Plans, HIPAA, HR, Human Resources, Insurance, insurers, Internal Controls, Internal Investigations, Leave, Managed Care, Management, OFCCP, OSHA, Privacy, Rehabilitation Act, retirement plan, Retirement Plans, Retirements, Unemployment Benefits, Unemployment Insurance |
Permalink
Posted by Cynthia Marcotte Stamer
June 16, 2020
While most COVID-19 test results won’t draw the widespread coverage and public interest that Elliott’s diagnosis did, businesses generally and health care providers, health plans, health care clearinghouses specifically need to recognize that coverage of the Elliott outrage will heighten awareness and therefore their need to properly handle and protect COVID-19 or other infectious disease and other testing, diagnosis, treatment and other medical and disability information collected or encountered in the course of their operation through the current COVID-19 health care emergency and otherwise in their own organizations.
ADA Responsibilities of Employers In Handling Medical Information
Protecting COVID-19 testing and other medical information isn’t just a concern for covered entities and their business associates, however. Businesses that are not covered entities also generally should use care in their collection, use, protection and disclosure of COVID-19 testing and other medical information to mitigate their potential liability under the disability discrimination requirements of the ADA, the Rehabilitation Act and other laws. For instance, along with prohibiting employers covered by the ADA from discriminating against qualified individuals with disabilities and requiring those employers to provide reasonable accommodations to such employees, the ADA also regulates the ability of covered employers to perform or require medical testing and imposes specific medical confidentiality requirements on all covered employers. See e.g., What You Should Know About COVID-19 and the ADA, the Rehabilitation Act, and Other EEO Laws.
The ADA’s medical confidentiality requirements dictate that covered employers maintain medical information and records about employees and applicants in separate, confidential files. Covered employers are responsible for maintaining the confidentiality of medical information and records and cannot disclose it without authorization from the subject employee except under the specific conditions allowed by the ADA.
EEOC guidance provided in its publication entitled Pandemic Preparedness in the Workplace and the Americans With Disabilities Act as updated as of March 19, 2020 emphasizes that covered employers remain accountable for complying with the requirements of the ADA and Rehabilitation Act during the current COVID-19 health care emergency and other pandemics.
While the EEOC Technical Assistance Questions and Answers in its publication What You Should Know About COVID-19 and the ADA, the Rehabilitation Act, and Other EEO Laws
Technical Assistance Questions and Answers as updated on June 11, 2020 recognizes temperature checks and certain other COVID-19 inquiries to screen for COVID-19 exposure or infection might be permitted under the safety exception to the ADA during the current COVID-19 health care emergency, that and other EEOC guidance makes clear that covered employers remain responsible for ensuring that the ADA medical confidentiality requirements are met with regarding to testing and related medical information. As a result, all ADA-covered employers generally and health care employers specifically are urged to use care both in the administration and collection of information regarding COVID-19 testing and diagnosis, and the protection of the confidentiality of COVID-19 and other medical information and records collected in the course of administering employment, safety, medical leave or other absence or other operations throughout the COVID-19 health care emergency.
Added HIPAA & Texas HIPAA Concerns For Health Plans & Other HIPAA Covered Entities
Assuming that the disclosure of Elliott’s information is traced to a testing provider, laboratory or other health care provider, health plan or insurer, health care clearing house subject to HIPAA (“covered entity”), a service provider acting as a business associate to a covered entity, or a member of their workforce, the unauthorized release of Elliott’s test results, that he underwent the testing, or other medical information, Elliott’s complaint about a possible HIPAA violation could be well-founded as both HIPAA and the somewhat broader provisions of the Texas Medical Privacy Act (“Tex-HIPAA”) (hereafter collectively the “HIPAA Laws”) both generally prohibit unauthorized disclosure of protected medical information such as his COVID-19 test or test results to the media.
The COVID-19 test results and of “individually identifiable personal health information” about Elliott and his encounter created, used, access or disclosed by the testing facility or other health care provider, a health plan, health care clearinghouse (“covered entity”) or a member of its workforce or a subcontractor acting as a business associated qualify as “protected health information subject to HIPAA’s privacy, security, breach and privacy rights protections of HIPAA and Tex-HIPAA.
The HIPAA and Tex-HIPAA prohibition against unauthorized disclosure of protected health information to the media stem from the HIPAA Laws’ broader requirement that covered entities and business associates affirmatively safeguard protected health information against unauthorized use, access or disclosure and sweeping prohibition against their disclosing or allowing the disclosure of protected health information without a HIPAA-compliant authorization except under the narrow and specifically delineated exceptions identified in the rule, none of which appear relevant to the media disclosure objected to by Elliott from the currently available public information.
Both HIPAA Laws expressly prohibit unauthorized disclosure of protected health information by covered entities or their business associates except under the specifically detailed conditions specified in one or more exceptions to this general rule. Assuming all relevant conditions to qualify for the exception are met, HIPAA does allow covered entities and business associates treatment, payment, operations, public health activities or another situation meeting all applicable requirements of an express exception to the HIPAA prohibition against disclosure.
The federal agency primarily responsible for the implementation and enforcement of HIPAA, the Department of Health & Human Services Office of Civil Rights (“OCR”) regulatory guidance and enforcement history clearly communicates OCR’s view that covered entities or business associates violate HIPAA by disclosing protected health information to the media or other third parties without first obtaining a HIPAA-compliant authorization from the subject of the information except under the specific circumstances described in an applicable Privacy Rule exception.
In its May 5, 2020 Guidance on Covered Health Care Providers and Restrictions on Media Access to Protected Health Information about Individuals in Their Facilities (“5/5 Guidance”), for instance, OCR specifically reminded HIPAA covered health care providers that the HIPAA Privacy Rule does not permit them to give media and film crews access to protected health information including access to facilities where patients’ protected health information will be accessible without the patients’ prior authorization. has made clear that testing facilities and other health care providers generally remain accountable for complying with the HIPAA Privacy Rule that prohibits unauthorized use, access or disclosure of test results and other protected health information except as specifically allowed in the applicable HIPAA Law.
The 5/5 Guidance specifically states, “The COVID-19 public health emergency does not alter the HIPAA Privacy Rule’s existing restrictions on disclosures of protected health information (PHI) to the media.’ Additionally, it states confirmed that even during the current COVID-19 public health emergency, covered health care providers remain required to obtain a valid HIPAA authorization from each patient whose PHI will be accessible to the media before the media is given access to that PHI. In this regard, the 5/5 Guidance states, As explained in prior guidance,1 HIPAA does not permit covered health care providers to give the media, including film crews, access to any areas of their facilities where patients’ PHI will be accessible in any form (e.g., written, electronic, oral, or other visual or audio form), without first obtaining a written HIPAA authorization from each patient whose PHI would be accessible to the media. 2 Additionally, covered health care providers may not require a patient to sign a HIPAA authorization as a condition of receiving treatment. The guidance clarifies that masking or obscuring patients’ faces or identifying information before broadcasting a recording of a patient is not sufficient, as a valid HIPAA authorization is still required before giving the media such access. Additionally, the guidance describes reasonable safeguards that should be used to protect the privacy of patients whenever the media is granted access to facilities.
OCR’s positions on disclosures to the media in the 5/5 Guidance reaffirm OCR’s longstanding interpretation and enforcement of HIPAA as prohibiting disclosures of PHI and media access to areas where patients or their protected health information might be visible or accessible is long standing.
In June, 2013, for instance, OCR sent a clear message to covered entities and business associates not to make unconsented disclosures of protected health information to or allow media access to areas where patients or their protected health information could be accessed or observed when it required Shasta Regional Medical Center (SRMC) to pay $275,000 to resolve OCR HIPAA charges stemming from SRMC’s unauthorized disclosure of protected health information to multiple media outlets as part of a public relations effort to mitigate damage from fraud and misconduct allegations made against it by the patient. See HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce.
OCR subsequently reinforced its warning to covered entities and business associates about unauthorized disclosures of protected health information in a 2016 Frequently Asked Question (Media FAQ) that discussed covered entities HIPAA responsibilities when dealing with the media. The Media FAQ was issued in conjunction with OCR’s collection of its $2.2 million settlement with New York-Presbyterian Hospital and a series of other settlements totaling $999,000 from three other health care providers accused of violating HIPAA by allowing media personnel into treatment or other areas where patients or patient protected health information was accessible without first obtaining a HIPAA compliant written authorization from each patient or other subject present or whose protected health information otherwise would be accessible to the media. See $999K Price Hospitals Pay To Settle HIPAA Privacy Charges From Allowing ABC To Film Patients Without Authorization.
In the Media FAQ, OCR stated HIPAA required covered entities to obtain prior written authorization before disclosing protected health information to the media or allowing media to film or access exam rooms or other areas where patients or protected health information could be observed or accessed. The Media FAQ also stated that masking or blurring the identity of the patient or their specific information was not an adequate substitute for written authorization and that covered entities also were responsible for ensuring that reasonable safeguards were in place to protect against impermissible disclosures or to limit incidental disclosures of other PHI in areas where media is allowed access where prior authorization has not been obtained. While stressing the importance of compliance with these requirements, however, the Media FAQ clarified that the HIPAA Privacy Rule does not require health care providers to prevent members of the media from entering areas of their facilities that are otherwise generally accessible to the public like public waiting areas or areas where the public enters or exits the facility In addition, the Media FAQ states a health care provider or other Covered Entity also highlighted certain other limited circumstances where HIPAA might allow limited disclosure of protected health information to the media in accordance with specific provisions of the Privacy Rule about an incapacitated patient when in the patient’s best interest; or disclose a patient’s location in the facility and condition in general terms that do not communicate specific medical information about the individual to the media or any other person any person where the individual has not objected to his information being included in the facility directory and the media representative or other person asks for the individual by name.
In the intervening years, OCR periodically has issued additional reminders to covered entities about HIPAA’s general prohibition against unconsented disclosures to the media as well as sanctioned harshly various covered entities for violating these prohibitions. In 2017, OCR required the largest not-for-profit health system in Southeast Texas, Memorial Hermann Health System (MHHS), to pay OCR $2.4 million to settle charges it violated HIPAA by issuing a press release to the media that shared the name and other protected health information about a patient suspected of using a fraudulent insurance card to obtain care at a clinic without the patient’s prior HIPAA-compliant authorization. While OCR concluded a report made MHHS made to law enforcement about the patient was allowable under the Privacy Rule, OCR found MHHS violated the Privacy Rule by issuing the press release disclosing the patient’s name and other PHI without authorization from the patient and also by failing to timely document the sanctioning of its workforce members for impermissibly disclosing the patient’s information. See $2.4M HIPAA Settlement Warns Providers About Media Disclosures Of PHI.
While OCR has announced certain temporary enforcement relief from a narrow set of HIPAA requirements during the COVID-19 health care emergency as applied to certain qualifying testing facilities, telemedicine providers and other specific health care providers engaging in certain types of health care during the COVID-19 health care emergency, OCR consistently has made clear that its COVID-19 HIPAA relief is very limited in scope, applicability and duration and in no way waives the prohibition against unauthorized disclosure to the media or other third parties not generally permitted under HIPAA. See e.g., 5/5 Guidance; OCR Issues Guidance on How Health Care Providers Can Contact Former COVID-19 Patients About Blood and Plasma Donation Opportunities; OCR Announces Notification of Enforcement Discretion for Community-Based Testing Sites During the COVID-19 Nationwide Public Health Emergency; OCR Announces Notification of Enforcement Discretion to Allow Uses and Disclosures of Protected Health Information by Business Associates for Public Health and Health Oversight Activities During The COVID-19 Nationwide Public Health Emergency; OCR Issues Bulletin on Civil Rights Laws and HIPAA Flexibilities That Apply During the COVID-19 Emergency; OCR Issues Guidance to Help Ensure First Responders and Others Receive Protected Health Information about Individuals Exposed to COVID-19; OCR Issues Guidance on Telehealth Remote Communications Following Its Notification of Enforcement Discretion; OCR Announces Notification of Enforcement Discretion for Telehealth Remote Communications During the COVID-19 Nationwide Public Health Emergency. To the contrary, OCR’s announcement of the 5/5 guidance quotes OCR Director Roger Severino, as stating “Hospitals and health care providers must get authorization from patients before giving the media access to their medical information; obscuring faces after the fact just doesn’t cut it,” Severino added.
Minimize Exposures By Preventing Unauthorized Media & Other Disclosures
Even without Mr. Elliott’s outrage heightening awareness about HIPAA’s prohibitions against unauthorized disclosures of protected health information to the media, the recent warning about HIPAA’s restrictions on media disclosure and access to protected health information and patient treatment areas in OCR’s 5/5 Guidance alone should serve as a strong incentive for covered entities and business associate promptly to reverify that the adequacy of their current policies, practices and training to prevent inappropriate media disclosures of protected health information and otherwise defend their compliance with OCR’s interpretation of HIPAA’s requirements for dealing with the media. Predictable heightened patient and public awareness and expectations about these and other HIPAA responsibilities fueled by the widespread media coverage of Mr. Elliott’s COVID-19 test results and his outrage about the unauthorized disclosure of his test results makes it more important than ever that health care providers and other covered entities and business associates take steps to prepare to respond to foreseeable complaints and questions by other patients, their families and others.
As part of these efforts, most covered entities and business associates may want to consider, at minimum, reconfirming the adequacy and understanding of their current media and other disclosure policies and practices, as well as sending strategic communications to their business associates and members of their workforce reminding them of the covered entity’s policies regarding media access and disclosures.
As part of these activities, covered entities should consider conducting a well-documented assessment of their current policies, practices and workforce training on disclosure of information to the media and other parties generally, as well as policies on allowing media or other parties to enter, film, photograph or record within their facilities or otherwise disclosing or allowing media access to their facilities. Along with these efforts, most covered entities also may want to consider also reminding workforce members that their patient privacy responsibilities also requires that they not share or discuss patient protected health information, film, photograph, or otherwise record, patients or areas where patients or patient protected health information is or might be present without prior written consent of the patient and the consent of their organization.
Since covered entities and members of their workforce also are likely to be subject to other statutory, ethical, contractual or other privacy or confidentiality requirements beyond those imposed by the HIPAA Laws such as medical confidentiality duties applicable to physicians and other health care providers under medical ethics, professional licensure or other similar rules, contractual responsibilities, as well as common law or statutory privacy, theft of likeness or other statutory or common law tort claims and exposures. Covered entities and business associates generally should consider whether other steps are advisable to manage these exposures along with managing their HIPAA Law compliance.
Given the high incidence of COVID-19 exposure and infection within their workplace, covered entities, business associates and other employers should use care fulfill their HIPAA Law relevant employment law confidentiality responsibilities when dealing with testing or other medical information about employees. In this respect, along with any HIPAA Law obligations that a covered entity or business associate has in handling medical information about a patient who also is an employee or family member of an employee, covered entities also should use care to ensure that medical confidentiality requirements of the Americans With Disabilities Act (“ADA”) and other applicable employment laws are met.
Since this analysis and review in most cases will result in the uncovering or discussion of potentially legally or politically sensitive information, Covered Entities should consider consulting with or engaging experienced legal counsel for assistance in structuring and executing these activities to maximize their ability to claim attorney-client privilege or other evidentiary protections against discovery or disclosure of certain aspects of these activities.
Finally, covered entities should keep in mind that HIPAA and other medical privacy compliance and risk management is an ongoing process requiring constant awareness and diligence. Consequently, covered entities and business associates also should use care both to monitor OCR and other regulatory and enforcement developments as well as exercise ongoing vigilance to monitor and maintain compliance within their organizations.
More Information
We hope this update is helpful. For more information about the these or other health or other legal, management or public policy developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years legal and operational management work, coaching, public policy and regulatory affairs leadership and advocacy, training and public speaking and publications. As a significant part of her work, Ms. Stamer has worked extensively domestically and internationally on an demand, special project and ongoing basis with health industry, health plan and insurance and other business, government and community organizations and their leaders, spoken and published extensively on HIPAA and other privacy and data security concerns, as well as other health care and health benefits; human resources, employee benefits and other workforce and services; insurance; workers’ compensation and occupational disease; business reengineering, disaster and distress; and many other management concerns.
Board Certified in Labor and Employment Law By the Texas Board of Legal Specialization, Scribe for the ABA JCEB Annual Agency Meeting with OCR, Vice Chair of the ABA International Section Life Sciences Committee, and the ABA RPTE Employee Benefits & Other Compensation Group and a former Council Representative, Past Chair of the ABA Managed Care & Insurance Interest Group, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, and a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer has extensive experience advising, representing, defending and training health care providers, health plans and insurers, employers, community organizations and others about HIPAA and other privacy concerns and has published and spoken extensively on these concerns.
Her involvement with HIPAA and other privacy and data concerns has taken place as part of her more than 30 years involvement working with with public and private health industry, health insurance and other employers and organizations of all sizes, employee benefit plans, insurance and financial services, health industry and a broad range of public and private domestic and international business, community and government organizations and leaders on pandemic and other health and safety, workforce and performance preparedness, risks and change management, disaster preparedness and response and other operational and tactical concerns throughout her adult life. A former lead advisor to the Government of Bolivia on its pension project, Ms. Stamer also has worked internationally and domestically as an advisor to business, community and government leaders on crisis preparedness and response, privacy and data security, workforce, health care and other policy and enforcement, as well as regularly advises and defends organizations about the design, administration and defense of their organizations workforce, employee benefit and compensation, safety, discipline and other management practices and actions.
Ms. Stamer also serves in leadership of a broad range of professional and civic organizations and shares insights and thought leadership through her extensive publications and public speaking. For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here. ©2020 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.
Comments Off on Ezekiel Elliott COVID-19 Diagnosis Disclosure Outrage Highlights Need To Handle COVID-19 & Other Medical Information With Care |
Accommodation, ADA, adea, Association Health Plan, board of directors, Brokers, Child Safety, Civil Rights, Claims, Corporate Compliance, COVID, Data Breach, Disability, Disability Discrimination, Disability Leave, Disability Plans, Disaster, Discrimination, Disease Management, EBSA, Electronic Medical Record, Emergency, employee, Employee Benefits, Employer, Employment, Employment Discrimination, family leave, Fiduciary Responsibility, FMLA, Government Contractors, government employer, government plan, health benefit, Health Benefits, health Care, health plan, Health Plans, HIPAA, HR, Human Resources, Insurance, insurers, Internal Controls, Internal Investigations, Leave, Managed Care, Management, OFCCP, OSHA, Privacy, Rehabilitation Act |
Permalink
Posted by Cynthia Marcotte Stamer
January 1, 2020
The $65,000 payment and corrective action plan commitments West Georgia Ambulance, Inc. (“West Georgia”) is making to settle Department of Health & Human Services Office for Civil Rights (“OCR”) charges it recurrently violated the Health Insurance Portability and Accountability Act (“HIPAA”) Security Rule and other 2019 HIPAA enforcement sends a clear warning to other HIPAA-covered health plans, health care providers, health care clearighouses and their business associates (“covered entities”) to maintain and be prepared to defend their own HIPAA compliance.
The Western Georgia Resolution Agreement and Corrective Action Plan (“Resolution Agreement”) OCR announced on December 30, 2019 resolves charges resulting from an OCR investigation initiated in response to a HIPAA breach report the Georgia based ambulance company filed in 2013 in which the company, which provides emergency and non-emergency ambulance services in Carroll County, Georgia, disclosed the loss of an unencrypted laptop containing the protected health information (PHI) of 500 individuals. The breach occurred when an unencrypted laptop fell off the back bumper of an ambulance. The laptop was not recovered. West Georgia reported that exactly 500 individuals were affected by the breach.
In the course of its investigation of the breach report, OCR’s investigation uncovered long-standing noncompliance with the HIPAA Rules, including failures to conduct a risk analysis, provide a security awareness and training program, and implement HIPAA Security Rule policies and procedures. Specifically, the Resolution Agreement states that West Georgia:
- Did not conduct an accurate and thorough risk analysis of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of all of its ePHI. See 45 C.F.R. § 164.308(a)(1)(ii)(A);
- Failed to have a HIPAA security training program, and failed to provide security training to its employees. See 45 C.F.R. § 164.308(a)(5);
- Failed to implement Security Rule policies or procedures. See 45 C.F.R. § 164.316; and
- Despite OCR’s investigation and technical assistance, “did not take meaningful steps to address their systemic failures.”
To resolve its exposure to the substantially higher civil monetary penalties that OCR could impose for violations of this nature, West Georgia agreed to pay a $65,000 resolution payment to OCR and implement and comply with a corrective action plan that in addition to requiring West Georgia to correct the compliance deficiencies, also subjects West Georgia to two years of OCR monitoring and oversight.
The Resolution Agreement and corrective action plan carry a number of important messages for other health care providers and other Covered Entities. First, the OCR enforcement action against West Georgia coming at the end of yet another heavy HIPAA enforcement year by OCR reminds Covered Entities that OCR is serious about HIPAA enforcement on the heels of its 2018 HIPAA record setting collection of $28.7 million in civil monetary penalties and resolution payments including the single largest individual HIPAA settlement in history of $16 million with Anthem, Inc. See OCR Concludes 2018 with All-Time Record Year for HIPAA Enforcement. While not topping this record, OCR during 2019 now has collected civil monetary penalties and resolution payments totaling more than $15 million from HIPAA Covered Entities and their business associates including:
Second, the Resolution Agreement and various other smaller settlements during the year show HIPAA compliance and enforcement is a concern for smaller provideres and other covered entities, not juswt the huge ones. While the $65,000 settlement payment required by the Resolution Agreement is substantially smaller than the amounts of the civil monetary penalties and many of resolution payments OCR collected in its other 2019 enforcement actions, the West Georgia and other 2019 enforcement actions demonstrate the teeth behind the warning in the OCR Press Release announcing the West Georgia Resolution Agreement from OCR Director Roger Severino that“All providers, large and small, need to take their HIPAA obligations seriously.” With OCR promises to keep up its vigorous investigation and enforcement of the HIPAA requirements, every Covered Entity and business associate should take the necessary steps to verify and maintain their HIPAA compliance and to be prepared to defend their compliance under the Privacy, Security, Breach Notification and HIPAA access and other individual rights mandates of HIPAA.
Third, OCR’s statement in the Resolution Agreement about the failure by West Georgia to meaningfully act to correct compliance deficiencies and cooperate in other corrective action during the period following the breach report highlights the importance for covered entities involved in a breach or other dealings with OCR on a potential compliance concern to behave appropriately to express and exhibit the necessary concern OCR expects regarding the compliance issue to position themselves to request and receive the clemency OCR is empowered under HIPAA to extend when deciding the sanctions for any noncompliance.
Of course meeting the requirements of HIPAA is not the only concern that covered entities should consider as they review and tightened their HIPAA and other privacy and data security procedures. Health care providers and other covered entities also should keep in mind their other obligations to protect patient and other confidential information under other federal laws, the requirements of which also are ever-evolving. For instance, on January 1, 2020 Texas providers like other Texas businesses will become subject to a shortened deadline for providing notice of data breaches under a new law enacted by the Texas Legislature in its last session. Arrangements should be designed to fulfill all of these requirements as well as any ethical or contractual.
Covered entities also should keep in mind that violations of HIPAA can have implications well beyond HIPAA.ramifications beyond HIPAA itself. For instance, heath care providers can face disqualification from federal program participation, licensing and ethics discipline and other professional consequences. Health plans and their fiduciaries also may face Department of Labor and other fiduciary claims, while insurers can face licensing and other regulatory consequences. The Labor Department followed up on previous warnings that health plan fiduciaries duties include a fiduciary duty to protect health plan data by adding HIPAA compliance to certain health plan audits. Insurers, third of art administrators and others also can face duties and liabilities under state insurance and data privacy laws from regulator or private litigant actions.
For More Information
We hope this update is helpful. For more information about this or other labor and employment developments, please contact the author Cynthia Marcotte Stamer via e-mail or via telephone at (214) 452 -8297.
Solutions Law Press, Inc. invites you receive future updates by registering on our Solutions Law Press, Inc. Website and participating and contributing to the discussions in our Solutions Law Press, Inc. LinkedIn SLP Health Care Risk Management & Operations Group, HR & Benefits Update Compliance Group, and/or Coalition for Responsible Health Care Policy.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: ERISA & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years of health industry and other management work, public policy leadership and advocacy, coaching, teachings, and publications.
Scribe for the ABA JCEB Annual Agency Meeting with the Department of Health & Human Services Office of Civil Rights, Vice Chair of the ABA International Section Life Sciences Committee, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and the ABA RPTE Employee Benefits & Other Compensation Group, Ms. Stamer has extensive legal, operational, and public policy experience advising and representing health care, health care and other entities about HIPAA and other privacy, data security, confidentiality and other matters.
Ms. Stamer’s work throughout her 30 plus year career has focused heavily on working with health care and managed care, health and other employee benefit plan, insurance and financial services, public and private primary, secondary, and other educational institutions, and other public and private organizations and their technology, data, and other service providers and advisors domestically and internationally with legal and operational compliance and risk management, performance and workforce management, regulatory and public policy and other legal and operational concerns. As a part of this work, she has recurrently worked extensively with public school districts and public and private primary and secondary schools, colleges and universities, academic medical, and other educational institutions, insured and self-insured health plans; domestic and international hospitals, health care systems, clinics, skilled nursing, long term care, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing, utilization management, management services organizations, group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; consultants; investors; EMR, claims, payroll and other technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, employers; and federal and state legislative, regulatory, investigatory and enforcement bodies and agencies on health care, education, and other data privacy, security, use, protection and disclosure; disability and other educational rights; workforce, and a host of other risk management and compliance concerns.
Ms. Stamer is most widely recognized for her decades-long leading edge work, scholarship and thought leadership on health and other privacy and data security and other health industry legal, public policy and operational concerns. This involvement encompasses helping health care systems and organizations, group and individual health care providers, health plans and insurers, health IT, life sciences and other health industry clients prevent, investigate, manage and resolve sexual assault, abuse, harassment and other organizational, provider and employee misconduct and other performance and behavior; manage Section 1557, Civil Rights Act and other discrimination and accommodation, and other regulatory, contractual and other compliance; vendors and suppliers; contracting and other terms of participation, medical billing, reimbursement, claims administration and coordination, Medicare, Medicaid, CHIP, Medicare/Medicaid Advantage, ERISA and other payers and other provider-payer relations, contracting, compliance and enforcement; Form 990 and other nonprofit and tax-exemption; fundraising, investors, joint venture, and other business partners; quality and other performance measurement, management, discipline and reporting; physician and other workforce recruiting, performance management, peer review and other investigations and discipline, wage and hour, payroll, gain-sharing and other pay-for performance and other compensation, training, outsourcing and other human resources and workforce matters; board, medical staff and other governance; strategic planning, process and quality improvement; meaningful use, EMR, HIPAA and other technology, data security and breach and other health IT and data; STARK, ant kickback, insurance, and other fraud prevention, investigation, defense and enforcement; audits, investigations, and enforcement actions; trade secrets and other intellectual property; crisis preparedness and response; internal, government and third-party licensure, credentialing, accreditation, HCQIA and other peer review and quality reporting, audits, investigations, enforcement and defense; patient relations and care; internal controls and regulatory compliance; payer-provider, provider-provider, vendor, patient, governmental and community relations; facilities, practice, products and other sales, mergers, acquisitions and other business and commercial transactions; government procurement and contracting; grants; tax-exemption and not-for-profit; privacy and data security; training; risk and change management; regulatory affairs and public policy; process, product and service improvement, development and innovation, and other legal and operational compliance and risk management, government and regulatory affairs and operations concerns. to establish, administer and defend workforce and staffing, quality, and other compliance, risk management and operational practices, policies and actions; comply with requirements; investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; JCHO and other accreditation and quality organizations; private litigation and other federal and state health care industry actions: regulatory and public policy advocacy; training and discipline; enforcement; and other strategic and operational concerns.
Author of leading works on HIPAA and a multitude of other health care, health plan and other health industry matters, the American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting and a former Council Representative, Past Chair of the ABA Managed Care & Insurance Interest Group, former Vice President and Executive Director of the North Texas Health Care Compliance Professionals Association, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, and a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her extensive publications and thought leadership as well as leadership involvement in a broad range of other professional and civic organizations. For more information about Ms. Stamer or her health industry and other experience and involvements, see www.cynthiastamer.com or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources available here such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advice or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The author and Solutions Law Press, Inc. disclaim, and have no responsibility to provide any update or otherwise notify anyone any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2019 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on 2019 OCR Enforcement Shows Getting Defensibly HIPAA Compliant Necessary In 2020! |
Claims Administration, Corporate Compliance, Disease Management, employee, Employee Benefits, Employer, Employers, Employment, EMR, ERISA, Fiduciary Responsibility, health benefit, Health Benefits, health Care, health insurance, Health IT, health plan, Health Plans, HIPAA, Identity Theft, insurance fraud, insurers, Internal Controls, Internal Investigations, Internet, Managed Care, Mental Health Parity, Physician, Plan Admistrator, PPO, prescription drugs, Privacy, Professional Liability, Protected Health Information, Provider, provider contracting, Risk Management, Security, Technology, tpa |
Permalink
Posted by Cynthia Marcotte Stamer
April 30, 2019
Health plans must deliver electronic protected health information (“ePHI”) to electronic applications or software (“apps”) used by plan members, and are responsible under the Health Insurance Portability & Accountability Act (“HIPAA”) Privacy and Security Rules for the security of electronic protected health information (“ePHI”) on apps they sponsor or provide, according to new guidance from the Department of Health & Human Services (“HHS”) Office of Civil Rights (“OCR”).
With health plans and their sponsors and insurers increasingly offering or promoting the use of apps to plan members members to access, maintain and use their health information, health plans, health care providers, health care clearinghouses and their business associates (“covered entities”) covered by HIPAA must understand and be prepared meet their HIPAA responsibilities to provide and protect ePHI to and on these apps, but may want to rethink sponsoring or providing a particular app for that purpose.
New HIPAA FAQ guidance (the “FAQs”) from OCR that addresses the implications of HIPAA on covered entities responsibility when asked to share or for ePHI shared or stored on apps or application programming interfaces (“APIs”) systems, covered entities have a legal obligation to disclose ePHI to an app when subjects of the ePHI or their personal representatives request such disclosures. However, the FAQs also state a covered entity or its business associates won’t be responsible for the security of the data shared to the app unless it sponsors or provides it.
pends upon whether the AP or API interface provider is a business associate of the covered entity versus just a third-party provider whose involvement and receipt of the PHI is requested and arranged by the subject of the PHI.
Covered Entities Obligated To Disclose ePHI to Apps Chosen By Individuals
The FAQs make crystal clear that covered entities do not have the option of refusing to share ePHI to an app when requested to do so by the subject of the ePHI or its personal representative. The FAQs states that covered entities cannot refuse to disclose ePHI to an app chosen by an individual because of concerns about how the app will use or disclose the ePHI it receives. In this regard, the FAQs state that the HIPAA Privacy Rule generally prohibits a covered entity from refusing to disclose ePHI to a third-party app designated by the individual if the ePHI is readily producible in the form and format used by the app. See 45 CFR 164.524(a)(1), (c)(2)(ii), (c)(3)(ii).According to the FAQ, the HIPAA Rules do not impose any restrictions on how an individual or the individual’s designee, such as an app, may use the health information that has been disclosed pursuant to the individual’s right of access. For instance, a covered entity is not permitted to deny an individual’s right of access to their ePHI where the individual directs the information to a third-party app because the app will share the individual’s ePHI for research or because the app does not encrypt the individual’s data when at rest.According to the FAQs, the liability a covered entity or business associate bears for sharing ePHI to an App under the HIPAA Privacy, Security, or Breach Notification Rules (HIPAA Rules) depends on the relationship between the covered entity and the app.
Breaches of Health Information Disclosed To An App
If an app that is neither a covered entity nor a business associate of the covered entity under HIPAA receives ePHI at the request of the subject or its personal representative, the FAQ states that the shared ePHI is no longer subject to the protections of the HIPAA Rules. Thus if the individual’s app – chosen by an individual to receive the individual’s requested ePHI – was not provided by or on behalf of the covered entity (and, thus, does not create, receive, transmit, or maintain ePHI on its behalf), the covered entity would not be liable under the HIPAA Rules for any subsequent use or disclosure of the requested ePHI received by the app. For example, the covered entity would have no HIPAA responsibilities or liability if such an app that the individual designated to receive their ePHI later experiences a breach. See also, See also OCR FAQ 2039, “What is the liability of a covered entity in responding to an individual’s access request to send the individual’s PHI to a third party.In contrast, however, the FAQ states that if the app was developed for, or provided by or on behalf of the covered entity – and, thus, creates, receives, maintains, or transmits ePHI on behalf of the covered entity – the covered entity could be liable under the HIPAA Rules for a subsequent impermissible disclosure because of the business associate relationship between the covered entity and the app developer. For example, if the individual selects an app that the covered health care provider uses to provide services to individuals involving ePHI, the FAQs state that the health care provider may be subject to liability under the HIPAA Rules if the app impermissibly discloses the ePHI received.
Transmission of ePHI to App Using Unsecured Method
The FAQs also address the potential exposures of covered entities and their business associates arising from the transmission of ePHI to an App using an unsecure method. According to the FAQs, the access rights HIPAA guarantees to individuals allows an individual to request that a covered entity to direct their ePHI to a third-party app in an unsecure manner or through an unsecure channel. See 45 CFR 164.524(a)(1), (c)(2)(ii), (c)(3)(ii). For instance, an individual may request that their unencrypted ePHI be transmitted to an app as a matter of convenience. The FAQ states that a covered entity that transmits ePHI through an unsecured means under such circumstances would not be responsible for unauthorized access to the individual’s ePHI while in transmission to the app. With respect to such apps, however, the FAQs also suggest that the covered entity may want to consider informing the individual of the potential risks involved the first time that the individual makes the request.
Post Transmission Exposure of Covered Entity’s EHR Systems Developer
The FAQ also discusses the potential exposure of a covered entity’s electronic health record (EHR) system developer under HIPAA after completing the transmission on behalf of a covered entity of ePHI to an app designated by the subject of the ePHI. According to the FAQs, the exposure of the HER system developer depends on the relationship, if any, between the covered entity, the EHR system developer, and the app chosen by the individual to receive the individual’s ePHI. A business associate relationship exists if an entity creates, receives, maintains, or transmits ePHI on behalf of a covered entity (directly or through another business associate) to carry out the covered functions of the covered entity. A business associate relationship exists between an EHR system developer and a covered entity. If the EHR system developer does not own the app, or if it owns the app but does not provide the app to, through, or on behalf of, the covered entity – e.g., if it creates the app and makes it available in an app store as part of a different line of business (and not as part of its business associate relationship with any covered entity) – the EHR system developer would not be liable under the HIPAA Rules for any subsequent use or disclosure of the requested ePHI received by the app.If the EHR system developer owns the app or has a business associate relationship with the app developer, and provides the app to, through or on behalf of, the covered entity (directly or through another business associate), however, the FAQs state the EHR system developer then potentially could face HIPAA liability (as a business associate of a HIPAA covered entity) for any impermissible uses and disclosures of the health information received by the app. For example, if an EHR system developer contracts with the app developer to create the app on behalf of a covered entity and the individual later identifies that app to receive ePHI, then the EHR system developer could be subject to HIPAA liability if the app impermissibly uses or discloses the ePHI received.
Covered Entity’s Duty To Enter Into Business Associate Agreement Depends Upon Relationship
Likewise, the FAQs also state that whether HIPAA requires a a covered entity or its EHR system developer to enter into a business associate agreement with an app designated by the individual in order to transmit ePHI to the app depends upon the relationship between the app developer and the covered entity and/or its EHR system developer. A business associate is a person or entity who creates, receives, maintains or transmits PHI on behalf of (or for the benefit of) a covered entity (directly or through another business associate) to carry out covered functions of the covered entity. An app’s facilitation of access to the individual’s ePHI at the individual’s request alone does not create a business associate relationship. Such facilitation may include API terms of use agreed to by the third-party app (i.e., interoperability arrangements).HIPAA does not require a covered entity or its business associate (e.g., EHR system developer) to enter into a business associate agreement with an app developer that does not create, receive, maintain, or transmit ePHI on behalf of or for the benefit of the covered entity (whether directly or through another business associate). However if the app was developed to create, receive, maintain, or transmit ePHI on behalf of the covered entity, or was provided by or on behalf of the covered entity (directly or through its EHR system developer as the covered entity’s business associate), then a business associate agreement would be required.
Health Plan & Other Covered Entity Take Aways
The new FAQ raises several action items for health plans, their sponsoring employers or unions, fiduciaries, administrators, brokers and insurers as well as other covered entities. Among other things, health plans and other covered entities must recognize and be prepared currently to provide PHI to subjects of that information on the apps of the requesting individual’s preference within the time frames dictated by HIPAA. Health plans and other covered entities need to recognize that the FAQs reflect this is a current, not future responsibility.
Second, health plans, health care providers and others that have or are considering providing apps or other tools to health plan members or patients for use in accessing or using PHI also generally need to recognize that the health plan or health care provider generally will bear responsibility under HIPAA for the adequacy of the security of the apps provided by or on behalf of the health plan or health care provider. Given the general responsibility to provide PHI to any apps designated by a subject of PHI, many health plans and health care providers may wish to reconsider whether providing or endorsing a particular app continues to make sense taking into account the HIPAA data privacy and security responsibilities and risks attendent to maintaining the security of PHI stored and accessed using those tools. Those electing to provide apps or other tools need to take steps to ensure the current and future adequacy of the data security of the app and its associated storage and other components including any future modifications to those tools.
Furthermore, health plans and other covered entities also should consider the advisability of revising existing notices and authorizations in response to the new FAQs. For instance, health plans, health care providers and others supplying PHI to an app designated by the requesting individual may want to consider revising forms to document the direction and consent of the requestor to the electronic delivery of the PHI to the designated app to better position themselves to claim the protection against liability for breaches on these subject designate apps described in the FAQs. Meanwhile, health plans or other covered entities providing apps also may wish to weigh options for supplementing disclosures to mitigate potential risks from use or failure to upgrade apps that might be viewed as covered entity provided or sponsored.
Certainly, before sponsoring or allowing a business associate to offer or provide an app or other similar solution, health care providers and other covered entities must ensure that the business associate agreement requirements of HIPAA are met from the app developer and others providing services or the app as business associates to the covered entity. Covered entities also should take steps to ensure that the interfaces between the apps and other systems are properly secured at the point of implementation and during any subsequent upgrades keeping in mind that OCR guidance expects covered entities to reconfirm security for any system, software or app upgrades. Meeting this expectation for apps within the possession of patients or plan members can present special challenges requiring careful planning.
Have questions about the new FAQs or other health care regulatory developments or their implications on your organization, contact the author. You also are invited to stay abreast of these and other health care developments by participating in our Solutions Law Press, Inc. Linkedin HR & Benefits Update LinkedIn Group or COPE: Coalition On Patient Empowerment Group or Project COPE: Coalition on Patient Empowerment Facebook Page.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years of health industry, health and other benefit and insurance, workforce and other management work, public policy leadership and advocacy, coaching, teachings, and publications.
Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer’s clients include employers and other workforce management organizations; employer, union, association, government and other insured and self-insured health and other employee benefit plan sponsors, benefit plans, fiduciaries, administrators, and other plan vendors; managed care organizations, insurers, self-insured health plans and other payers and their management; public and private, domestic and international hospitals, health care systems, clinics, skilled nursing, long term care, rehabilitation and other health care providers and facilities; medical staff, health care accreditation, peer review and quality committees and organizations; managed care organizations, insurers, third party administrative services organizations and other payer organizations; billing, utilization management, management services organizations; group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; claims, billing and other health care and insurance technology and data service organizations; other health, employee benefit, insurance and financial services product and solutions consultants, developers and vendors; and other health, employee benefit, insurance, technology, government and other management clients.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in pensions, healthcare, workforce, immigration, tax, education and other areas, Ms. Stamer has been extensively involved in U.S. federal, state and local health care and other legislative and regulatory reform impacting these concerns throughout her career. Her public policy and regulatory affairs experience encompassess advising and representing domestic and multinational private sector health, insurance, employee benefit, employer, staffing and other outsourced service providers, and other clients in dealings with Congress, state legislatures, and federal, state and local regulators and government entities, as well as providing advice and input to U.S. and foreign government leaders on these and other policy concerns.
Beyond her public policy and regulatory affairs involvement, Ms. Stamer also has extensive experience helping these and other clients to design, implement, document, administer and defend workforce, employee benefit, insurance and risk management, health and safety, and other programs, products and solutions, and practices; establish and administer compliance and risk management policies; comply with requirements, investigate and respond to government; accreditation and quality organizations; private litigation and other federal and state health care industry investigations and enforcement actions; evaluate and influence legislative and regulatory reforms and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns. Ms. Stamer’s experience in these matters includes supporting these organizations and their leaders on both a real-time, “on demand” basis with crisis preparedness, intervention and response as well as consulting and representing clients on ongoing compliance and risk management; plan and program design; vendor and employee credentialing, selection, contracting, performance management and other dealings; strategic planning; policy, program, product and services development and innovation; mergers, acquisitions, and change management; workforce and operations management, and other opportunities and challenges arising in the course of their operations.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, heavily involved in health benefit, health care, health, financial and other information technology, data and related process and systems development, policy and operations throughout her career, and scribe of the ABA JCEB annual Office of Civil Rights agency meeting, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues. She regularly helps employer and other health benefit plan sponsors and vendors, health industry, insurers, health IT, life sciences and other health and insurance industry clients design, document and enforce plans, practices, policies, systems and solutions; manage regulatory, contractual and other legal and operational compliance; vendors and suppliers; deal with Medicare, Medicaid, CHIP, Medicare/Medicaid Advantage, ERISA, state insurance law and other private payer rules and requirements; contracting; licensing; terms of participation; medical billing, reimbursement, claims administration and coordination, and other provider-payer relations; reporting and disclosure, government investigations and enforcement, privacy and data security; and other compliance and enforcement; Form 990 and other nonprofit and tax-exemption; fundraising, investors, joint venture, and other business partners; quality and other performance measurement, management, discipline and reporting; physician and other workforce recruiting, performance management, peer review and other investigations and discipline, wage and hour, payroll, gain-sharing and other pay-for performance and other compensation, training, outsourcing and other human resources and workforce matters; board, medical staff and other governance; strategic planning, process and quality improvement; HIPAA administrative simplification, meaningful use, EMR, HIPAA and other technology, data security and breach and other health IT and data; STARK, antikickback, insurance, and other fraud prevention, investigation, defense and enforcement; audits, investigations, and enforcement actions; trade secrets and other intellectual property; crisis preparedness and response; internal, government and third-party licensure, credentialing, accreditation, HCQIA, HEDIS and other peer review and quality reporting, audits, investigations, enforcement and defense; patient relations and care; internal controls and regulatory compliance; payer-provider, provider-provider, vendor, patient, governmental and community relations; facilities, practice, products and other sales, mergers, acquisitions and other business and commercial transactions; government procurement and contracting; grants; tax-exemption and not-for-profit; 1557 and other Civil Rights; privacy and data security; training; risk and change management; regulatory affairs and public policy; process, product and service improvement, development and innovation, and other legal and operational compliance and risk management, government and regulatory affairs and operations concerns.
Ms. Stamer has extensive health care reimbursement and insurance experience advising and defending plan sponsors, administrators, insurance and managed care organizations, health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and employer and association group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other nonpar insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions. Scribe for the ABA JCEB annual agency meeting with HHS OCR, she also has worked extensively on health and health benefit coding, billing and claims, meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical, workforce, consumer financial and other data confidentiality and privacy, federal and state data security, data breach and mitigation, and other information privacy and data security concerns.
Author of leading works on a multitude of health care, health plan and other health industry matters, the American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative and CLE and Marketing Committee Chair, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer’s health industry clients include public health organizations; public and private hospitals, healthcare systems, clinics and other health care facilities; physicians, physician practices, medical staff, and other provider organizations; skilled nursing, long term care, assisted living, home health, ambulatory surgery, dialysis, telemedicine, DME, Pharma, clinics, and other health care providers; billing, management and other administrative services organizations; insured, self-insured, association and other health plans; PPOs, HMOs and other managed care organizations, insurance, claims administration, utilization management, and other health care payers; public and private peer review, quality assurance, accreditation and licensing; technology and other outsourcing; healthcare clearinghouse and other data; research; public and private social and community organizations; real estate, technology, clinical pathways, and other developers; investors, banks and financial institutions; audit, accounting, law firm; consulting; document management and recordkeeping, business associates, vendors, and service providers and other professional and other health industry organizations; academic medicine; trade associations; legislative and other law making bodies and others.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; a ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advise or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2019 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Health Plans Must Share PHI To Apps When Members Request, Responsible For Security On Plan-Sponsored Apps |
Brokers, Cafeteria Plans, Civil Monetary Penalties, Civil Rights, Claims, COBRA, Consumer Protection, Corporate Compliance, Cybercrime, Data Breach, Data Security, Drug & Alcohol, employee, Employee Benefits, Employer, Employers, Employment, ERISA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, Health IT, health plan, Health Plans, HIPAA, HR, Identity Theft, Insurance, Internal Investigations, Managed Care, Mental Health, Mental Health Parity, Privacy, Uncategorized | Tagged: APPs, Data Privacy, Data Security, Health Plan, HIPAA, Inc. publisher/author Cynthia Marcotte Stamer and Society of Professional Benefits Administrators Director of Public Relations & Legal Affairs Elizabeth Leight will lead a conference call discussi, Security |
Permalink
Posted by Cynthia Marcotte Stamer
January 8, 2019
Interoperability will be a key priority for the Office of the National Coordinator for Health Information Technology (“ONC”) going forward.
That’s the message in the just released 2018 Report to Congress: Annual Update on the Adoption of a Nationwide System for the Electronic Use and Exchange of Health Information (“Report”).
The planned shift to demand greater interoperability promises to create new demands for employer-sponsored health plans, health insurers and others involved in the healthcare delivery and payment processes. Health plans and their insurers and sponsors should begin preparing for these new demands, as well as to leverage the new opportunities and manage the new risks they will create.
The Report describes barriers, actions taken, and recommendations as well as ONC’s path forward to implement the 21st Century Cures Act.
Under the 21st Century Cures Act, Congress gave HHS authority to enhance innovation, scientific discovery, and expand the access and use of health information through provisions related to:
- The development and use of upgraded health IT capabilities;
- Transparent expectations for data sharing, including through open application programming interfaces (APIs); and
- Improvement of the health IT end user experience, including by reducing administrative burden.
These priorities seek to increase nationwide interoperability of health information and reduce clinician burden..
Current Status
The Report says increases in the adoption of health IT means most Americans receiving health care services now have their health data recorded electronically. However, this information is not always accessible across systems and by all end users—such as patients, health care providers, and payers—in the market in productive ways. For example:
- Despite the individual right to access health information about themselves established by the HIPAA Privacy Rule, patients often lack access to their own health information, which hinders their ability to manage their health and shop for medical care at lower prices;
- Health care providers often lack access to patient data at the point of care, particularly when multiple health care providers maintain different pieces of data, own different systems, or use health IT solutions purchased from different developers; and
- Payers often lack access to clinical data on groups of covered individuals to assess the value of services provided to their customers.
The Report says these limitations create several problems, including:
Patients should be able to easily and securely access their medical data through their smartphones. Currently, patients electronically access their health information through patient portals that prevent them from easily pulling from multiple sources or health care providers. Patient access to their electronic health information also requires repeated use of logins and manual data updates.
- For health care providers and payers, interoperable access and exchange of health records is focused on accessing one record at a time.
- Payers cannot effectively represent their members if they lack computational visibility into which health care providers offer the highest quality care at the lowest cost. Without the capability to access multiple records across a population of patients, health care providers and payers will not benefit from the value of using modern computing solutions—such as machine learning and artificial intelligence—to inform care decisions and identify trends.
- Payers and employer group health plans which purchase health care have little information on health outcomes. Often, health care providers and payers negotiate contracts based on the health care provider’s reputation rather than on the quality of care that health care provider offers to patients. Health care providers should instead compete based on the entire scope of the quality and value of care they provide, not on how exclusively they can craft their networks. Outcome data will allow payers to apply machine learning and artificial intelligence to have better insight into the value of the care they purchase.
Current Barriers
According to the Report, HHS heard from stakeholders over the past year that barriers to interoperable access to health information remain, including technical, financial, trust, and business practice barriers. These barriers impede the movement of health information to where it is needed across the care continuum. In addition, burden arising from quality reporting, documentation, administrative, and billing requirements that prescribe how health IT systems are designed also hamper the innovative usability of health IT.
Current and Upcoming Actions
The Report states HHS has many efforts to help ensure that electronic health information can be shared safely and securely where appropriate to improve the health and care of all Americans.
ONC also reports Federal agencies, states, and industry have taken steps to address technical, trust, and financial challenges to interoperable health information access, exchange, and use for patients, health care providers, and payers (including insurers). HHS aims to build on these successes through the ONC Health IT Certification Program, HHS rulemaking, health IT innovation projects, and health IT coordination.
In accordance with the Cures Act, HHS is actively leading and coordinating a number of key programs and projects. These include continued work to deter and penalize poor business practices and that HHS conducted multiple outreach efforts to engage the clinical community and health IT stakeholders to better understand these barriers, challenges, and health care provider burden.
Recommendations
The Report makes the following overarching recommendations for future actions HHS plans to support through its policies and that the health IT community as a whole can take to accelerate progress:
Focus on improving interoperability and upgrading technical capabilities of health IT, so patients can securely access, aggregate, and move their health information using their smartphones (or other devices) and health care providers can easily send, receive, and analyze patient data.
Increase transparency in data sharing practices and strengthen technical capabilities of health IT so payers can access population-level clinical data to promote economic transparency and operational efficiency to lower the cost of care and administrative costs.
Prioritize improving health IT and reducing documentation burden, time inefficiencies, and hassle for health care providers, so they can focus on their patients rather than their computers.
The Report also says interoperable access underpins HHS’s efforts to pursue a health care system where data are available when and where needed.
ONC intends to particularly focus on promoting open APIs. Open APIs are technology that allow one software program to access the services provided by another software program and can improve access and exchange of health information. ONC says APIs can:
- Support patients’ ability to have more access to information electronically through, for example, smartphones and mobile applications. HHS applauds the emergence of patient-facing applications that allow patients to access, aggregate, and act on their health information; and
- Allow payers to receive necessary and appropriate information on a group of members without having to access one record at a time.
- Increase institutional accountability, support value- based care models, and lead to competitive medical care pricing that benefits patients.
The Report claims patients, health care providers, and payers with appropriate access to health information can use modern computing solutions to generate value from the data. Improved interoperability can strengthen market competition, result in greater quality, safety, and value for the healthcare system, and enable patients, health care providers, and payers to experience the benefits of health IT.
Prepare For Enhanced Operability Requirements
ONC’s plan to achieve greater interoperability presents new business and compliance planning opportunities and challenges for health care providers, health insurers and other payers, health data and information technology (IT) providers and others. Among other things, participants in the healthcare system and their suppliers will need to prepare to comply with new expectations and mandates for interoperability. Meeting these demands will require financial expenditures as well as present technological challenges.The increased availability and access to electronica medical records and information resulting from these changes also a can be expected to drive new challenges and demands. Among other things, businesses relying on control of health information or records to influence or control patience, reimbursement, or other business value need to reevaluate and adjust their business models accordingly.
Improve accessibility and interoperability also is likely to create new expectations and demands by patients, payers, other providers and perhaps most significantly for providers and payers, regulators. Participants in the system will need to understand these applications and prepare to both defend their business performance as well as their compliance taking into account these new demands.
Amid all of this, of course, providers, pears, and their business associates can anticipate continued if not enhanced demands for enhanced data security and privacy protections and accompanying enforcement of these standards.
As ONC move forward on its plans to enhance interoperability, all concerned stakeholders will want to monitor developments and provide thoughtful and timely input. The time to get started is now. ONC and it’s sister agency, the Office of Civil Rights currently are inviting public comments about how to achieve these and other health IT and privacy improvements. Those interested in providing input should make sure their comments are submitted by the applicable deadlines next month.
ONC and it’s sister agency, the Office of Civil Rights currently are inviting public comments about how to achieve these and other health IT and privacy improvements. Read the full Report here and share your input by the specified deadlines.
About the Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for 30+ years of managed care and other health industry, health and other benefit and insurance, workforce and other management work, public policy leadership and advocacy, coaching, teachings, and publications.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer has been continuously involved the design, regulation, administration and defense of managed care and other health and employee benefit, health care, human resources and other staffing and workforce arrangements, contracts, systems, and processes. As a continuous component of this work, Ms. Stamer has worked closely with these and other clients on the design, development, administration, defense, and breach and data recovery of health care, workforce, insurance and financial services, trade secret and other information technology, data and related process and systems development, policy and operations throughout her career.
Scribe of the ABA JCEB annual Office of Civil Rights agency meeting, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues.
Ms. Stamer’s clients include employers and other workforce management organizations; employer, union, association, government and other insured and self-insured health and other employee benefit plan sponsors, benefit plans, fiduciaries, administrators, and other plan vendors; managed care organizations, insurers, self-insured health plans and other payers and their management; public and private, domestic and international hospitals, health care systems, clinics, skilled nursing, long-term care, rehabilitation and other health care providers and facilities; medical staff, health care accreditation, peer review and quality committees and organizations; managed care organizations, insurers, third-party administrative services organizations and other payer organizations; billing, utilization management, management services organizations; group purchasing organizations; pharmaceutical, pharmacy, and prescription benefit management and organizations; claims, billing and other health care and insurance technology and data service organizations; other health, employee benefit, insurance and financial services product and solutions consultants, developers and vendors; and other health, employee benefit, insurance, technology, government and other management clients.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in pensions, healthcare, workforce, immigration, tax, education and other areas, Ms. Stamer has been extensively involved in U.S. federal, state and local health care and other legislative and regulatory reform impacting these concerns throughout her career. Her public policy and regulatory affairs experience encompasses advising and representing domestic and multinational private sector health, insurance, employee benefit, employer, staffing and other outsourced service providers, and other clients in dealings with Congress, state legislatures, and federal, state and local regulators and government entities, as well as providing advice and input to U.S. and foreign government leaders on these and other policy concerns.
Beyond her public policy and regulatory affairs involvement, Ms. Stamer also has extensive experience helping these and other clients to design, implement, document, administer and defend workforce, employee benefit, insurance and risk management, health and safety, and other programs, products and solutions, and practices; establish and administer compliance and risk management policies; comply with requirements, investigate and respond to government; accreditation and quality organizations; private litigation and other federal and state health care industry investigations and enforcement actions; evaluate and influence legislative and regulatory reforms and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns. Ms. Stamer’s experience in these matters includes supporting these organizations and their leaders on both a real-time, “on demand” basis with crisis preparedness, intervention and response as well as consulting and representing clients on ongoing compliance and risk management; plan and program design; vendor and employee credentialing, selection, contracting, performance management and other dealings; strategic planning; policy, program, product and services development and innovation; mergers, acquisitions, and change management; workforce and operations management, and other opportunities and challenges arising in the course of their operations.
Ms. Stamer also has extensive health care reimbursement and insurance experience advising and defending plan sponsors, administrators, insurance and managed care organizations, health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and employer and association group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other nonpar insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions. Scribe for the ABA JCEB annual agency meeting with HHS OCR, she also has worked extensively on health and health benefit coding, billing and claims, meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical, workforce, consumer financial and other data confidentiality and privacy, federal and state data security, data breach and mitigation, and other information privacy and data security concerns.
Author of leading works on a multitude of health care, health plan and other health industry matters, the American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative and CLE and Marketing Committee Chair, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer’s health industry clients include public health organizations; public and private hospitals, healthcare systems, clinics and other health care facilities; physicians, physician practices, medical staff, and other provider organizations; skilled nursing, long-term care, assisted living, home health, ambulatory surgery, dialysis, telemedicine, DME, Pharma, clinics, and other health care providers; billing, management and other administrative services organizations; insured, self-insured, association and other health plans; PPOs, HMOs and other managed care organizations, insurance, claims administration, utilization management, and other health care payers; public and private peer review, quality assurance, accreditation and licensing; technology and other outsourcing; healthcare clearinghouse and other data; research; public and private social and community organizations; real estate, technology, clinical pathways, and other developers; investors, banks and financial institutions; audit, accounting, law firm; consulting; document management and recordkeeping, business associates, vendors, and service providers and other professional and other health industry organizations; academic medicine; trade associations; legislative and other law making bodies and others.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about contracting, credentialing and quality assurance, compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Author of works on Payer and Provider Contracting and many other managed care concerns, Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; an ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (214) 452-8297 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice or an offer or commitment to provide legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as legal advise or an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2019. Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on ONC New Emphasis On Health IT Interoperability Promises New Demands & Opportunities |
21st Century Cures Act, Association Health Plan, Civil Monetary Penalties, Civil Rights, Claims Administration, compliance, Consumer Protection, Corporate Compliance, Cybercrime, Data Breach, Data Security, Electronic Medical Record, Employers, EMR, ERISA, fiduciary duty, Fiduciary Responsibility, FINRA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, Health IT, health plan, Health Plans, HIPAA, Human Resources, Identity Theft, insurers, Managed Care, ONC, Patient Empowerment, PPO, Privacy, Protected Health Information, Provider, provider contracting, Technology, third party administrators, Trade secret, Uncategorized | Tagged: Corporate Compliance, Employee Benefits, Enron, Health Care, Health Care Reform, Health Insurance, Health IT, Health Plans, HIPAA, Insurance, medical records, ONC, Physicians |
Permalink
Posted by Cynthia Marcotte Stamer
October 16, 2018
Health plans, their employer and other sponsors and fiduciaries, health insurers, health care providers, health care clearinghouses and their business associates should study and learn from the just announced, record-setting $16 million resolution agreement between health insurance giant, Anthem, Inc., to resolve Department of Health & Human Services Office of Civil Rights (OCR) charges that Anthem, Inc.’s violations of the Health Insurance Portability & Accountability Act (HIPAA) Privacy and Security Rules exposed the electronic protected health information (ePHI) of almost 79 million people. In addition to reviewing the adequacy of their own HIPAA privacy and security practices, health plans, their employer and union sponsors and fiduciaries also should consider assessing the advisability of tightening their business associate and other agreements with health insurers, third party administrative services providers and other vendors in light of the resolution agreement and experiences arising out of the Anthem breach to better position themselves to assess and enforce HIPAA compliance, receive notice and respond in the event of an insurer or other vendor breach and mitigate financial costs and liabilities resulting from breaches or other compliance deficiencies.
Anthem’s Record Setting HIPAA Breach & Resolution Agreement
The settlement agreement announced October 15, 2018 by OCR requires Anthem, Inc. to pay a $16 million resolution payment to OCR and take a series of corrective actions to resolve HIPAA liabilities to OCR for allowing the largest known U.S. health data breach in history in 2015. The record $16 million resolution payment eclipses the prior record resolution payment of $5.55 million Memorial Healthcare System (MHS) paid OCR to settle HIPAA charges in 2016. Moreover, the $16 million resolution payment it’s just a small portion of the amount that Anthem has been required to shell out as a consequence of the breach. In addition to the $16 million paid under the OCR resolution agreement, anthem already has paid more than $115 million to settle lawsuits arising out of the breach under other laws.
An independent licensee of the Blue Cross and Blue Shield Association and one of the nation’s largest health benefits companies, Anthem provides medical care coverage to one in eight Americans through its affiliated health plans. The breach that resulted in the settlement agreement affected ePHI Anthem maintained for its affiliated health plans including many employer or union sponsored self-insured and insured group health plans and other HIPAA-covered entity health plans.
On March 13, 2015, Anthem filed a breach report with the HHS Office for Civil Rights that disclosed that Anthem discovered on January 29, 2015 that cyber-attackers had gained access to and engaged in continuous and targeted cyberattack on Anthem’s IT system for the apparent purpose of extracting data, otherwise known as an advanced persistent threat attack. After filing its breach report, Anthem discovered cyber-attackers had infiltrated their system through spear phishing emails sent to an Anthem subsidiary after at least one employee responded to the malicious email and opened the door to further attacks. OCR’s investigation revealed that between December 2, 2014 and January 27, 2015, the cyber-attackers stole the ePHI of almost 79 million individuals, including names, social security numbers, medical identification numbers, addresses, dates of birth, email addresses, and employment information.
In addition to the impermissible disclosure of ePHI, OCR’s investigation revealed that Anthem failed to conduct an enterprise-wide risk analysis, had insufficient procedures to regularly review information system activity, failed to identify and respond to suspected or known security incidents, and failed to implement adequate minimum access controls to prevent the cyber-attackers from accessing sensitive ePHI, beginning as early as February 18, 2014.
In addition to the consequences for the millions of individuals whose ePHI was disclosed through the breach, the breach also triggered responsibilities and concerns for fiduciaries and sponsors of the employer and union-sponsored group health plans administered or insured by Anthem. Sponsors and fiduciaries of private sector employer or union sponsored plans struggled to obtain information and cooperation from Anthem necessary to evaluate and fulfill their health plans’ HIPAA obligations as well as the fiduciary responsibility requirements of the Employee Retirement Income Security Act (ERISA).
In addition to the $16 million settlement that Anthem is paying to resolve OCR’s HIPAA charges stemming from the breach, the OCR settlement agreement also requires Anthem to undertake a robust corrective action plan to comply with the HIPAA Rules.
Health Plans, Sponsors, Fiduciaries & Vendors Should Act To Manage Compliance & Risks
Unquestionably, other health insurers, employer, union and association sponsored group health plans, and their vendors and business associates should evaluate the adequacy and defensibility of their own health plan privacy and security practices in light of the Anthem breach and resolution agreement. In addition, employer, union or association health plan sponsors, administrative service providers and fiduciaries also should consider the advisability of strengthening their business associate agreements with insurers, third party administrators and other health plan service providers to incorporate safeguards, audit, oversight or other provisions and practices to help prudently monitor potential risks and improve their ability to receive timely notice, respond to, and preserve rights of recourse against insurers or other vendors in the event of a breach or other deficiency.
About The Author
A practicing attorney and Managing Shareholder of Cynthia Marcotte Stamer, P.C, Cynthia Marcotte Stamer’s more than 30 years’ of leading edge work as an practicing attorney, author, lecturer and industry and policy thought leader have resulted in her recognition as a “Top” attorney in employee benefits, labor and employment and health care law.
Board certified in labor and employment law by the Texas Board of Legal Specialization, a Fellow in the American College of Employee Benefit Counsel, Scribe for the American Bar Association (ABA) Joint Committee on Employee Benefits (JCEB) Annual Agency Meeting with the Office of Civil Rights and a former JCEB Council Representative; former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group; and past Chair, former Welfare Benefit Committee Co-Chair and current Fiduciary Responsibility Committee Co-Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, former Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, Ms. Stamer is recognized nationally and internationally for her practical and creative insights and leadership on HIPAA and other health care, managed care and insurance, and other employee benefit, human resources, and related antitrust, corporate, privacy and data security, tax and other internal controls, regulatory affairs and public policy concerns.
Ms. Stamer’s legal and management consulting work throughout her career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international health, insurance and financial security, and other businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
In this respect, Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, regulatory compliance and operational and performance management. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well known for her extensive work with health care, insurance and other highly regulated entities on corporate compliance, internal controls and risk management, her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes.
As a key part of this work, Ms. Stamer uses her deep and highly specialized health, insurance, labor and employment and other knowledge and experience to help health industry, insurance and financial services and other employers and other employee benefit plan sponsors; health, pension and other employee benefit plans, their fiduciaries, administrators and service providers, insurers, and others design legally compliant, effective compliance and internal controls, risk management, human resources and other workforce performance, discipline, compensation, employee benefits and related programs, products and arrangements.
In the course of this work, Ms. Stamer has accumulated an impressive resume of experience advising and representing clients on HIPAA and other privacy and data security concerns. The scribe for the American Bar Association (ABA) Joint Committee on Employee Benefits annual agency meeting with the Department of Health & Human Services Office of Civil Rights for several years, Ms. Stamer has worked extensively with health plans, health care providers, health care clearinghouses, their business associates, employer and other sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA and other information privacy and data security rules, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health plans, health insurers, health care providers, banking, technology and other vendors, and others. Beyond advising these and other clients on privacy and data security compliance, risk management, investigations and data breach response and remediation, Ms. Stamer also advises and represents clients on OCR and other HHS, Department of Labor, IRS, FTC, DOD and other health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She also is the author of numerous highly acclaimed publications, workshops and tools for HIPAA or other compliance including training programs on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
Ms. Stamer also is deeply involved in helping to influence the health care, workforce, insurance and financial services, employee benefit, privacy and data security and other federal, state and local laws, regulations and enforcement actions. She both helps her clients respond to and resolve emerging regulations and laws, government investigations and enforcement actions and helps them shape the rules through dealings with Congress and other legislatures, regulators and government officials domestically and internationally. A former lead consultant to the Government of Bolivia on its Social Security reform law and most recognized for her leadership on U.S. health and pension, wage and hour, tax, education and immigration policy reform, Ms. Stamer works with U.S. and foreign businesses, governments, trade associations, and others on workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment and a Fellow in the American Bar Foundation and State Bar of Texas. She also works as a policy advisor and advocate to health, insurance and financial services, employee benefits and other business, professional and civic organizations.
Author of the thousands of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer also is a highly sought out speaker and industry thought leader known for empowering audiences and readers. Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications. Ms. Stamer also regularly serves on the faculty and planning committees for symposia of LexisNexis, the American Bar Association, ALIABA, the Society of Employee Benefits Administrators, the American Law Institute, ISSA, HIMMs, and many other prominent educational and training organizations and conducts training and speaks on these and other management, compliance and public policy concerns.
Ms. Stamer also has a lifelong history of involvement with and service with a diverse range of professional, community and charitable organizations and causes including as founder and Executive Director of the Coalition for Responsible Health Care Policy and its PROJECT COPE: Coalition for Patient Empowerment; technical advisor to the National Physicians’ Council for Health Care Policy; a founding Board Member and President of the Alliance for Healthcare Excellence and its Patient Empowerment and Health Care Heroes Projects; a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; a member of the Dallas United Way Long Range Planning Committee; as well as leadership involvement in the ABA Joint Committee on Employee Benefits Council, the North Texas Healthcare Compliance Professionals Association; the ABA RPTE Employee Benefits & Other Compensation Committee, the ABA Health Law Section, the ABA International Section Life Sciences Committee, and the ABA TIPS Employee Benefit Committee; TEGE Coordinator of the Gulf Coast TEGE Council TE Division; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association; Dallas, Regional and State BACPAC Chair of the Texas Association of Business; SHRM Regional Chair and National Advisory Board Chair; WEB Network of Benefits Professionals National and Dallas Boards; as a contributing author and the Advisory Board member of the BNA EBCD CD, InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications and as chair or planning faculty of a multitude of symposia.. For additional information about Ms. Stamer, see www.cynthiastamer.com, or contact Ms. Stamer via email here or via telephone to (214) 452.8297.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also may be interested reviewing other Solutions Law Press, Inc.™ resources at www.solutionslawpress.com such as:
- OCR Issues HIPAA Privacy Rule Relief About Sharing Medical Information, Shares Guidance to Help Ensure Equal Access to Emergency Services During Hurricane Florence
- House Passes Medical Device Tax Repeal, Other Health Bills; Will Senate Follow Its Lead?
- Key House Committee Votes To Advance HSA & Other Health Choice Reforms; Plans
- Senate Confirms Charles Rettig As Next IRS Commissioner
- House W&M Committee To Markup Retirement and Other “Tax Reform 2.0” Bills Thursday
- Markup Tomorrow On Retirement & Other Republican‘s TCJA Tax Reform 2.0 Bills
- Free Poster for Upcoming October National Disability Employment Awareness Month 2018 Available
- Employer’s Employment Tax Fraud Indictment Warns Employers To Properly Pay Withheld Employment Taxes
- Flurry of Reform Activity Sign Employers, Health Plans Should Prepare To Respond To Last Minute Health Reforms This Fall
- Relationships Matter
- OFCCP Extends TRICARE Affirmative Action Morotorium
- Trump Blue Print To Reduce Drug Costs Announced
- 2018 Family HSA Deductible Contribution Limit Restored To $6,900
- Remind Employees To Update Withholding
- John F. Ring Sworn in as NLRB Chairman
- High Enforcement, New Tip Pool Rules Require Restaurants Reassess & Manage FLSA Risks
- Employers Should Weigh New DOL PAID Program, Other Options To Manage Rising FLSA Minimum Wage & Overtime Risks
- HIPAA Lessons Every Health Plan, Health Care Provider & Business Associate Should Learn From Bankrupt FileFax’s HIPAA Settlement
- Fresenius Medical Care Pays $3.5 Million HIPAA Settlement
- HHS Proposes “Conscience Rule” Expanding Abortion And Other Religious Choice
- Bankrupt Oncology Provider’s $2.3M Settlement Payment & Other HIPAA Breach Consequences Shows Why To Prioritize HIPAA Compliance In 2018
- Bill Allowing FDA Emergency Use Authorizations To Protect Military From Biological Warfare Threats Sent to President
- North Memorial Hit With $3.9M HIPAA Fine For HIPAA Violations
- Brace For OCR HIPAA Audits & Enforcement
- North Memorial Health Care Pays $1.5M Plus HIPAA Settlement For Business Associate Agreement Deficiencies
- New CDC Guidance on Opioid Prescribing
- Update Privacy Practices For New OCR HIPAA Enforcement, Security & Records Access Guidance
- OCR’s 2nd-Ever HIPAA CMP Nails Lincare For $239,000
- Redesigned OCR Website Launched
- Providers Get More Flexibility To Report Mental Health Patients To Gun Data Base Under New Privacy Rule
- OIG Modifies Past Ruling, Blesses Two New Medicare Co-Pay Financial Programs
- Obama Administration Proposal Would Extend FLSA Minimum Wage & Overtime Requirements To 5 Million+ Workers
- Businesses Must Confirm & Clean Up Health Plan ACA & Other Compliance Following Supreme Court’s King v. Burwell Decision
- Obama Administration Devoting $1.25 Million To Find Ways To Encourage States To Force Employers To Give Paid Leave
- IRS FAQ Addresses Determination Letter Program As Applied To Multiple Employer Plans
- $1.4M FLSA Back Pay Award Demonstrates Worker Misclassification Risks
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here.
©2018 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on Record $16M Anthem HIPAA Settlement Signals Need to Tighten Your Health Plan HIPAA Compliance & Risk Management |
Association Health Plan, Employer, Employers, health plan, Health Plans, HIPAA, Privacy, Uncategorized | Tagged: Health Insurance, Health Insurer, Health Plan, media, news, OCR, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
December 5, 2017
The Justice Department’s report Tuesday that the Justice Department spent $3.2 million on Special counsel Robert Mueller’s Russia probe its first four-and-a-half months highlights the importance for leaders accountable for their organizations’s Federal Sentencing Guideline, sexual harassment and other corporate compliance programs to appropriately plan and budget for potential investigation and defense costs as part of their compliance and risk management planning.
Conducting an internal investigation or defending a government or other allegation of wrongdoing often proves surprisingly expensive. While how much an internal investigation costs can vary widely depending on the issue, its potential civil and criminal liability and public relations implications on the organization and its management, it’s timing, the adequacy of the pre-event compliance management and record keeping relating to the issue, and a host of other concerns, investigation and defense costs often become largely irrelevant when an organization is required to investigate or defend against charges of legal or other business misconduct that expose the organization or its leadership to potentially devastating legal or business consequences. When these events happen, organizations and their leaders often see little option to spend whatever is necessary to defend their organization and its reputation.
Compared to the reported internal investigation and defense expenditures of private sector organizations that have faced these these make or break investigations, the Justice Department’s reported expenditures to date on the Russian probe look small.
For instance, Twenty-First Century Fox in March, 2017 Securities and Exchange Commission (SEC) filings disclosed spending $45 million tied to litigation related to harassment allegations in the 9 first three quarters of 2017 and $10 million “related to settlements of pending and potential litigations” during its fiscal third quarter as well as having received investigative inquiries and stockholder demands to inspect the books and records of the company which could lead to future litigation in the aftermath of sexual harassment allegations at Fox News.
In contrast, Avon Products spent nearly $500 million conducting its internal investigation before paying a $135m fine to the US government to settle charges it violated the Foreign Corrupt Practices Act by giving Chinese authorities $8 million in gifts and cash while it sought to obtain the first “direct sell” license in China.
These and other publicly disclosed expenditures make clear that corporate officers and directors need to reassess their investment in compliance both to strengthen the effectiveness of their efforts and to plan to deal with the financial, legal, operational and other costs of investigating and defending potential charges.
Aboaut The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for management work, coaching, teachings, and publications.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. Her day-to-day work encompasses both labor and employment issues, as well as independent contractor, outsourcing, employee leasing, management services and other nontraditional service relationships. She supports her clients both on a real-time, “on demand” basis and with longer term basis to deal with all aspects for workforce and human resources management, including, recruitment, hiring, firing, compensation and benefits, promotion, discipline, compliance, trade secret and confidentiality, noncompetition, privacy and data security, safety, daily performance and operations management, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well-known for her extensive work with health, insurance, financial services, technology, energy, manufacturing, retail, hospitality, governmental and other highly regulated employers, her nearly 30 years’ of experience encompasses domestic and international businesses of all types and sizes.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other concerns by her service as a management consultant, business coach and consultant and policy strategist as well through her leadership participation in professional and civic organizations such her involvement as the Vice Chair of the North Texas Healthcare Compliance Association; Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Gulf Coast TEGE Council Exempt Organization Coordinator; a founding Board Member and past President of the Alliance for Healthcare Excellence; former board member and Vice President of the Managed Care Association; past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; a member and policy adviser to the National Physicians’ Council for Healthcare Policy; current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section; Past Chair of the ABA Health Law Section Managed Care & Insurance Section; ABA Real Property Probate and Trust (RPTE) Section former Employee Benefits Group Chair, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative, and Defined Contribution Committee Co-Chair, past Welfare Benefit Committee Chair and current Employee Benefits Group Fiduciary Responsibility Committee Co-Chair, Substantive and Group Committee member, Membership Committee member and RPTE Representative to the ABA Health Law Coordinating Council; past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former member of the Board of Directors, Treasurer, Member and Continuing Education Chair of the Southwest Benefits Association and others.
Ms. Stamer also is a widely published author, highly popular lecturer, and serial symposia chair, who publishes and speaks extensively on human resources, labor and employment, employee benefits, compensation, occupational safety and health, and other leadership, performance, regulatory and operational risk management, public policy and community service concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications.
Want to know more? See here for details about the author of this update, attorney Cynthia Marcotte Stamer, e-mail her here or telephone Ms. Stamer at (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at SolutionsLawPress.com such as the following:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please provide your current contact information and preferences including your preferred e-mail by creating or updating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Consider Internal Investigation & Defense Costs When Administering Compliance Programs |
ADA, Affirmative Action, board of directors, Brokers, Child Labor, Civil Monetary Penalties, Civil Rights, Claims Administration, compliance, conflict of interest, Corporate Compliance, corporate governance, Data Breach, Data Security, directors, E-Verify, EEOC, Employers, Employment, Employment Discrimination, Employment Policies, Employment Tax, English As A Second Language, ERISA, Executive Compensation, Fair Credit Reporting Act, Fair Labor Standards Act, FICA, fiduciary duty, Fiduciary Responsibility, Financial Security, FINRA, FLSA, GINA, Government Contractors, h-2A Visa, health benefit, health plan, HIPAA, Human Resources, I-9, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Labor Management Relations, Leadership, LEP, LGBT, Management, Managment, Military Leave, Non-Compete, Nonresident aliens, occupational safety, OFCCP, officers, OSHA, Overtime, Pay, Plan Admistrator, Privacy, Professional Liability, Rehabilitation Act, Retaliation, Safety, Uncategorized, USERRA, VEVRRA, visas, Wage & Hour, Whistleblower, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
October 21, 2017
This month’s annual October Stop Bullying Month observances are a great time for employers to deter sexual, racial, religious, national Origin, disability discrimination and harassment, retaliation and other illegal or otherwise counterproductive bullying in their workplaces.
Aside from obvious legal exposures that often attend from many versions of workplaces bullying, unfair or heavy handed tactics of workplace bullies often pervasively disrupt workplace productivity and operations by undermining performance, feedback, initiative, employee retention and a host of other ways.
Seize the opportunity to boost your organization’s legal and operational exposures non discrimination, anti-harassment, and other workplace bullying policies by leveraging the visibility and resources of this month’s anti-bullying activities.
Checkout StopBullying.gov for more information and free resources.
About The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for management work, coaching, teachings, and publications.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. Her day-to-day work encompasses both labor and employment issues, as well as independent contractor, outsourcing, employee leasing, management services and other nontraditional service relationships. She supports her clients both on a real-time, “on demand” basis and with longer term basis to deal with all aspects for workforce and human resources management, including, recruitment, hiring, firing, compensation and benefits, promotion, discipline, compliance, trade secret and confidentiality, noncompetition, privacy and data security, safety, daily performance and operations management, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well-known for her extensive work with health, insurance, financial services, technology, energy, manufacturing, retail, hospitality, governmental and other highly regulated employers, her nearly 30 years’ of experience encompasses domestic and international businesses of all types and sizes.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other concerns by her service as a management consultant, business coach and consultant and policy strategist as well through her leadership participation in professional and civic organizations such her involvement as the Vice Chair of the North Texas Healthcare Compliance Association; Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Gulf Coast TEGE Council Exempt Organization Coordinator; a founding Board Member and past President of the Alliance for Healthcare Excellence; former board member and Vice President of the Managed Care Association; past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; a member and policy adviser to the National Physicians’ Council for Healthcare Policy; current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section; Past Chair of the ABA Health Law Section Managed Care & Insurance Section; ABA Real Property Probate and Trust (RPTE) Section former Employee Benefits Group Chair, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative, and Defined Contribution Committee Co-Chair, past Welfare Benefit Committee Chair and current Employee Benefits Group Fiduciary Responsibility Committee Co-Chair, Substantive and Group Committee member, Membership Committee member and RPTE Representative to the ABA Health Law Coordinating Council; past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former member of the Board of Directors, Treasurer, Member and Continuing Education Chair of the Southwest Benefits Association and others.
Ms. Stamer also is a widely published author, highly popular lecturer, and serial symposia chair, who publishes and speaks extensively on human resources, labor and employment, employee benefits, compensation, occupational safety and health, and other leadership, performance, regulatory and operational risk management, public policy and community service concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications.
Want to know more? See here for details about the author of this update, attorney Cynthia Marcotte Stamer, e-mail her here or telephone Ms. Stamer at (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at SolutionsLawPress.com such as the following:
▪ RAISE Act Immigration Reforms Touted As “Giving Americans A Raise”
▪ Health Clinic At Houston Convention Center, Other HHS Help For Hurricane Harvey Victims
▪ IRS Updates Amounts Used To Calculate 2017 Obamacare Individual Individual Shares Responsibility Tax Penalties
▪ DB Plan Sponsors Check Out New Bifurcated Distribution Model Amendmentsy
▪ U.S. News Names 2017-2018 “Best” Hospitals; Patient Usefulness Starts With Metholodogy Understanding
▪ Use Lessons Of Past Mistakes or Injustice To Build Better Future
▪ Prepare For Turnover, Other Challenges From Rising Workforce Competition
▪ Employers, Health Plans Should Brace For Tightened Federal Mental Health Coverage Mandate Disclosure And Enforcement
▪ Withholding Calculator Tool Helps Workers Figure Withholding
▪ Better Preparing U.S. Workers To Fill Your Jobs
▪ SCOTUS Ruling Bars Many State Arbitration Agreement Restrictions
▪ $2.4M HIPAA Settlement Message Warns Health Plans & Providers Against Sharing Medical Info With Media, Others
If you or someone else you know would like to receive future updates about developments on these and other concerns, please provide your current contact information and preferences including your preferred e-mail by creating or updating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Address Workplace Harassment During October Stop Bullying Month |
Absenteeism, ADA, Affirmative Action, board of directors, Child Safety, Civil Rights, compliance, conflict of interest, Corporate Compliance, corporate governance, directors, Disability, Disability Discrimination, Discrimination, Drug & Alcohol, EEOC, employee, Employee Handbook, Employer, Employers, Employment, Employment Discrimination, Employment Policies, English As A Second Language, Gaming, HR, Human Resources, Immigration, Internal Controls, Internal Investigations, Leadership, LEP, LGBT, Management, Managment, Patient Empowerment, Privacy, Retaliation, Risk Management, Schools, Security, Sexual Harassment, Union, USERRA, veterans, VEVRAA, VEVRRA, Whistleblower, Worker, Workforce | Tagged: ADA, Corporate Compliance, Employer, Employers, Employment, employment law, Human Resources, Insurance, Insurer, Labor Department, Risk Management, Wage & Hour |
Permalink
Posted by Cynthia Marcotte Stamer
October 6, 2017
As businesses continue to struggle to comply with the growing plethora of federal and state laws mandating data security, the identity theft and cyber security epidemic keeps growing.
As human resources and other business leaders work to guard their own data and respond to employee demands for assistance in responding to breaches of their personal financial and other data, this weeks’ announcement that embattled credit monitoring giant Equifax has been awarded the exclusive contract to provide taxpayer identification and fraud prevention services to the Internal Revenue Service has many questioning whether these investments are futile.
The IRS’ announcement comes despite the September 7, 2017 announcement by Equifax of a data breach of its records impacting sensitive personal information of millions of consumers including:
- The names, Social Security numbers, birth dates, addresses and, in some instances, driver’s license numbers of an estimated 143 million U.S. consumers;
- Credit card numbers for approximately 209,000 U.S. consumers,
- Certain dispute documents with personal identifying information for approximately 182,000 U.S. consumers,and
- Personal information for certain U.K. and Canadian consumers.
The huge breach already was creating many headaches for many businesses and their human resources departments before the IRS announced the award of the contract to Equifax. Due to the massive size of the breach, mist companies have been required to respond to concerns of workers impacted directly by the breach as well as requests of employees and identity theft protection companies that the business consider offering cybersecurity protection for employees or customers.
Beyond helping their workforce understand and cope with the news, many businesses and employee benefit plans also face the added headache of needing to investigate and respond to concerns about their own potential responsibilities to provide breach notification or take other actions. This added headache arises due to their or their plans’ use of Equifax or vendors utilizing Equifax to run employee or vendor background checks or carry out internal employee or employee benefit plan, customer or other business activities. These involvements often give rise to duties to conduct investigations and potentially provide notification or other responses to employees, applicants, benefit plan members, contractors or customers whose data may have been impacted under the Fair and Accurate Credit Transactions Act (FACTA), the Health Insurance Portability and Accountability Act (HIPAA), the Employee Retirement Income Security Act (ERISA) Fiduciary Responsibility rules or various other federal and state laws and regulations, vendor contracts or their own data privacy or security policies.
When notification is recommended or required, human resources and other business leaders also have to consider if modifications should be considered to standard protocols recommended to data breach victims. Notification and registration as an identity theft victim with Equifax long has been a standard part of the federal and state government recommended protocol for recommended to consumers impacted by identity theft or other data breaches. See,e.g., IRS Taxpayer Guide To Identity Theft. Although government agencies as of yet have not changed this recommendation to remove Equifax reporting, many consumers and others view reporting to Equifax as akin to the fox watching the hen house. Consequently, employers and other parties helping consumers respond to the breach often receive push back or questions from consumers about the appropriateness and security reporting to Equifax in light of its breach.
Beyond evaluating and handling their own legal responsibilities to investigate and deal with any breach impacting their data, employers and other business leaders also likely are or should consider what claims against Equifax, other vendors and business partners involved with Equifax and their own liability insurers are available and warranted to help cover the costs and potential liabilities for the business arising from the breach and it’s fall out.
As employers and other businesses work through these issues, They should keep in mind that the fallout is likely to continue for years and be further complicated by past and subsequent breaches impacting other governmental and private organizations. Human resources, employee benefits and other businesses and their leaders can expect to experience challenges dealing with fraudulent uses of misappropriated information as well as demands that they tighten up their background check, data security and usage and other practices and documentation to mitigate risks from the compromised data.
Human resources, employee benefits and other business leaders need to secure the assistance of counsel experienced in guiding their organizations through these and other challenges.
About The Author
Recognized by her peers as a Martindale-Hubble “AV-Preeminent” (Top 1%) and “Top Rated Lawyer” with special recognition LexisNexis® Martindale-Hubbell® as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, Cynthia Marcotte Stamer is a practicing attorney board certified in labor and employment law by the Texas Board of Legal Specialization and management consultant, author, public policy advocate and lecturer widely known for management work, coaching, teachings, and publications.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. Her day-to-day work encompasses both labor and employment issues, as well as independent contractor, outsourcing, employee leasing, management services and other nontraditional service relationships. She supports her clients both on a real-time, “on demand” basis and with longer term basis to deal with all aspects for workforce and human resources management, including, recruitment, hiring, firing, compensation and benefits, promotion, discipline, compliance, trade secret and confidentiality, noncompetition, privacy and data security, safety, daily performance and operations management, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well-known for her extensive work with health, insurance, financial services, technology, energy, manufacturing, retail, hospitality, governmental and other highly regulated employers, her nearly 30 years’ of experience encompasses domestic and international businesses of all types and sizes. Author of numerous works on privacy and data security, Ms. Stamer‘s experience includes involvement in cyber security and other data privacy and security matters for more than 20 years.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other concerns by her service as a management consultant, business coach and consultant and policy strategist as well through her leadership participation in professional and civic organizations such her involvement as the Vice Chair of the North Texas Healthcare Compliance Association; Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Gulf Coast TEGE Council Exempt Organization Coordinator; a founding Board Member and past President of the Alliance for Healthcare Excellence; former board member and Vice President of the Managed Care Association; past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; a member and policy adviser to the National Physicians’ Council for Healthcare Policy; current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section; Past Chair of the ABA Health Law Section Managed Care & Insurance Section; ABA Real Property Probate and Trust (RPTE) Section former Employee Benefits Group Chair, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative, and Defined Contribution Committee Co-Chair, past Welfare Benefit Committee Chair and current Employee Benefits Group Fiduciary Responsibility Committee Co-Chair, Substantive and Group Committee member, Membership Committee member and RPTE Representative to the ABA Health Law Coordinating Council; past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former member of the Board of Directors, Treasurer, Member and Continuing Education Chair of the Southwest Benefits Association and others.
Ms. Stamer also is a widely published author, highly popular lecturer, and serial symposia chair, who publishes and speaks extensively on human resources, labor and employment, employee benefits, compensation, occupational safety and health, and other leadership, performance, regulatory and operational risk management, public policy and community service concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications.
Want to know more? See here for details about the author of this update, attorney Cynthia Marcotte Stamer, e-mail her here or telephone Ms. Stamer at (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at SolutionsLawPress.com such as the following:
▪RAISE Act Immigration Reforms Touted As “Giving Americans A Raise”
▪Health Clinic At Houston Convention Center, Other HHS Help For Hurricane Harvey Victims
▪IRS Updates Amounts Used To Calculate 2017 Obamacare Individual Individual Shares Responsibility Tax Penalties
▪DB Plan Sponsors Check Out New Bifurcated Distribution Model Amendmentsy
▪U.S. News Names 2017-2018 “Best” Hospitals; Patient Usefulness Starts With Metholodogy Understanding
▪Use Lessons Of Past Mistakes or Injustice To Build Better Future
▪Prepare For Turnover, Other Challenges From Rising Workforce Competition
▪Employers, Health Plans Should Brace For Tightened Federal Mental Health Coverage Mandate Disclosure And Enforcement
▪Withholding Calculator Tool Helps Workers Figure Withholding
▪Better Preparing U.S. Workers To Fill Your Jobs
▪SCOTUS Ruling Bars Many State Arbitration Agreement Restrictions
▪$2.4M HIPAA Settlement Message Warns Health Plans & Providers Against Sharing Medical Info With Media, Others
If you or someone else you know would like to receive future updates about developments on these and other concerns, please provide your current contact information and preferences including your preferred e-mail by creating or updating your profile here.
NOTICE: These statements and materials are for general informational and purposes only. They do not establish an attorney-client relationship, are not legal advice, and do not serve as a substitute for legal advice. Readers are urged to engage competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The presenter and the program sponsor disclaim, and have no responsibility to provide any update or otherwise notify any participant of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
Circular 230 Compliance. The following disclaimer is included to ensure that we comply with U.S. Treasury Department Regulations. Any statements contained herein are not intended or written by the writer to be used, and nothing contained herein can be used by you or any other person, for the purpose of (1) avoiding penalties that may be imposed under federal tax law, or (2) promoting, marketing or recommending to another party any tax-related transaction or matter addressed herein.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ For information about republication, please contact the author directly. All other rights reserved.
Comments Off on Dealing With HR, Benefits & Other Headaches From Equifax and Other Data Breach |
Banking, board of directors, Brokers, Civil Monetary Penalties, Claims, Claims Administration, compliance, conflict of interest, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, defined benefit plan, Defined Benefit Plans, defined contribution plan, Defined Contribution Plans, directors, E-Verify, EBSA, Educational Privacy, employee, Employee Benefits, Employer, Employers, Employment, Employment Policies, Employment Tax, ERISA, ESOP, Excise Tax, FACTA, Fair Credit Reporting Act, FICA, fiduciary duty, Fiduciary Responsibility, Financial Security, Form 5500, GINA, Government Contractors, health benefit, Health Benefits, health Care, health insurance, health plan, Health Plans, HIPAA, Hiring, HR, Human Resources, I-9, Identity Theft, Income Tax, Insurance, insurers, Internal Controls, Internal Investigations, Internal Revenue Code, Internet, IRC, Labor Management Relations, Leadership, Management, Managment, Patient Empowerment, Payroll Tax, pension plan, Physician, Plan Admistrator, Privacy, Professional Liability, Protected Health Information, Provider, Reporting & Disclosure, retirement plan, Retirement Plans, Retirements, Risk Management, Security, Tax, Tax Credit, Tax Qualification, Technology, third party administrators, visas, Workforce | Tagged: ADA, Corporate Compliance, Data Breach, Employee Benefits, Employer, Employers, employment law, Equifax, ERISA, Health Care, Health Insurance, HIPAA, Human Resources, Insurance, Insurer, Labor Department, Privacy, Retirement Plans, Risk Management, Tax, Technology, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
June 22, 2017
Register Now To Participate In
“2017 Federal Group Health Plan Mental Health Rules Update”
Solutions Law Press, Inc™ Health Plan Update WebEx Briefing
Tuesday, June 27, 2017
10:30 A.M.-11:30 P.M. Eastern | 11:30 A.M.-12:30 P.M. Central
EXPANDING REGULATORY REQUIREMENTS & ENFORCEMENT SPELL TROUBLE FOR HEALTH PLANS AND THEIR SPONSORING EMPLOYERS.
Solutions Law Press, Inc.™ invites employer and other group health plan sponsors, fiduciaries, insurers, administrative service providers, plan brokers and consultants are invited learn critical information about their expanding risks and responsibilities arising from existing and proposed changes to rules and enforcement of federal group health plan mental health and substance abuse (MH/SUB) coverage and privacy rules under the Mental Health Parity and Addiction Equity Act of 2008 (MHPAEA), as supplemented by the Patient Protection and Affordable Care Act (ACA) and the 21st Century Cures Act (Cures Act) and the Privacy Rules of the Health Insurance Portability & Accountability Act (HIPAA) conducted by attorney Cynthia Marcotte Stamer, a Fellow in the American College of Employee Benefits recognized as among the “Best Lawyers” in employee benefits for her health and other benefit knowledge, experience, policy advocacy and thought leadership. Register here now!
Tightening Health Plan Mental Health & Substance Abuse Rules & Enforcement Make Group Health Plan Compliance Critical
New and proposed guidance jointly published June 16, 2017 by the Departments of Labor (DOL), Health & Human Services (HHS) and Treasury is the latest in a series of regulatory and enforcement developments over the past year alerting group health plans and their employer and other group health plan sponsors, fiduciaries, insurers, administrative services providers, plan brokers and consultants involved in health plan design, funding, or administration to get serious about their group health plans’ compliance with the MHPAEA federal group health plan mental health and substance abuse coverage and benefit requirements, as supplemented by the ACA and the Cures Act without running afoul of the Privacy Rules of HIPAA.
Building upon federal group health plan mental health parity mandates originally implemented under the Mental Health Parity Act, the MHPAEA generally requires that any financial requirements or treatment limitations group health plans impose on mental health and substance use disorder (MH/SUD) benefits not be restrictive than the predominant financial requirements and treatment limitations that apply to substantially all medical and surgical benefits. MHPAEA also imposes several disclosure requirements on group health plans and health insurance issuers. Not satisfied with the MHPAEA coverage and disclosure protections, however, Congress subsequently broadened federal MH/SUD benefit rights under group health plans through the enactment of the ACA and the Cures Act. Congress also has imposed special requirements and protections for mental health treatment records adds additional responsibilities for group health plans and their service providers when dealing with information and records in connection with the administration of MH/SUD benefits.
After a long period of lax oversight and enforcement of these federal group health plan mental health rules, the Departments of Labor (DOL), Health and Human Services (HHS), and the Treasury (collectively, the Departments) since October, 2016 have begun both tightening the rules and acting to increase oversight and enforcement. The Departments have issued a series of joint guidance clarifying and broadening their interpretations of these MH/SUD benefit and disclosure mandates while simultaneously taking steps to increase awareness and enforcement of these rights. As part of these ongoing efforts, Departments’ on June 16, 2017 expanded this guidance with their publication of new Mental Health Parity Implementation FAQs Part 38 discussing their joint interpretation of the broadening effect of the enactment of the ACA and the Cure Act on these plan requirements. Concurrently, the Departments signaled their intention to add additional responsibilities for group health plans and insurers by publishing along with FAQ Part 38 a Draft MHPAEA Disclosure Template and request for comments. This latest guidance package reaffirms that the Departments are continuing efforts to increase oversight of and enforcement of MH/SUD compliance against group health plans, their sponsors, fiduciaries, insurers, and their administrative and other service providers. In the face of these developments and the reported initiation of enforcement actions by the Departments, the group health plans, their employer and other sponsors, fiduciaries, insurers, and their administrative and other service providers should move quickly to understand and update their plans and practices to comply with these recent developments while bracing for the likely need to deal with further expanded disclosure and other additional responsibilities under the MHPAEA jointly proposed by the Departments on June 16, 2017.
Beyond fulfilling these expanding MHPAEA responsibilities, health plan fiduciaries, administrators, insurers and sponsors also must ensure their health plan and its business associates comply with special rules concerning the protection, use and disclosure of mental health treatment records and information that may impact certain mental health treatment and other records received, used, retained or disclosed in the course of administering mental health, substance abuse or other provisions of their group health plans under the HIPAA Privacy Rules. Keeping in mind that HHS audit and enforcement of compliance by health plans and other HIPAA covered entities with HIPAA’s medical privacy and data security rules, health plan sponsors, fiduciaries, insurers and administrative and other service providers also should take the opportunity to verify that their plans and practices comply with special HIPAA rules impacting authorizations and other dealings with certain mental health and substance abuse health information and records and other HIPAA medical privacy and security requirements.
Given these developments, group health plans, their sponsors, fiduciaries, insurers and administrator must take steps to verify and maintain compliance with these federal MH/SUD requirements. Ensuring proper compliance with these federal rules is particularly important to avoid triggering the substantial liability that health plans, their employer and other sponsors, insurers, and administrators can incur if their health plan violates these mandates. Obviously, plans and their sponsors, insurers and fiduciaries can expect to pay additional plan expenses necessary to pay wrongfully denied benefits and other expenditures these plan or its fiduciaries expend to investigate, defend and resolve claims or compliance audits, investigations, litigation or actions brought by the Departments, state insurance regulators with respect to state governments or insurers, or private litigation by participants or beneficiaries. Many employer or other plan sponsors may be unaware that these violations also generally expose employers and other health plan sponsors to liability to self identify, self-report on Internal Revenue Service Form 8928 and self-pay and excise tax of up to $100 per participant per day per uncorrected violation by the due date for filing of their annual corporate tax return.
With oversight and enforcement already rising and the Departments proposing to expand further both disclosure duties and enforcement, group health plans, their employer and other sponsors, insurers, fiduciaries and administrators clearly need to take prompt action to verify their existing health plan provisions and administrative practices are up-to-date and administered to withstand challenge from the Departments, participants, beneficiaries, health care providers and others. Consequently, employer and other group health plan sponsors, fiduciaries, insurers, administrative services providers, plan brokers and consultants involved in health plan design, funding, or administration should act quickly to verify their plan terms and practices are updated to comply with existing rules and share their input in response to the Departments June 16, 2017 requests for comments.
ABOUT CYNTHIA MARCOTTE STAMER
Recognized as “Legal Leader™ Texas Top Rated Lawyer” in both Health Care Law and Labor and Employment Law, a “Texas Top Lawyer,” and an “AV-Preeminent” and “Top Rated Lawyer” by Martindale-Hubble, singled out as among the “Best Lawyers In Dallas” in employee benefits by D Magazine; Cynthia Marcotte Stamer is a practicing attorney and management consultant, author, public policy advocate and lecturer widely recognized for her nearly 30 years’ of work and pragmatic thought leadership, publications and training on health coverage and health care, health plan and employee benefits, workforce and related regulatory and other compliance, performance management, risk management, product and process development, public policy, operations and other concerns.
Throughout her legal and consulting career, Ms. Stamer has drawn recognition for combining extensive knowledge and experience with her talents as an insightful innovator and problem solver when advising, representing and defending employer and other plan sponsors, insurers, fiduciaries, insurers, electronic and other technology, plan administrators and other service providers, governments and others about health coverage, benefit program design, funding, documentation, administration, data security and use, contracting, plan, public and regulatory reforms and enforcement, and other risk management and operations matters as well as for her work and thought leadership on a broad range of other health, employee benefits, human resources and other workforce, insurance, tax, compliance and other matters. Her experience encompasses leading and supporting the development and defense of innovative new programs, practices and solutions; advising and representing clients on routine plan establishment, plan documentation and contract drafting and review, administration, change and other compliance and operations crisis prevention and response, compliance and risk management audits and investigations, enforcement actions and other dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, Federal Trade Commission, Justice, state legislatures, attorneys general, insurance, labor, worker’s compensation, and other agencies and regulators, She also provides strategic and other supports clients in defending litigation as lead strategy counsel, special counsel and as an expert witness.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares shared her thought leadership, experience and advocacy on these and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE; Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Past Group Chair, current Defined Contribution Plan Committee Co-Chair, former Welfare Committee Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Counsel, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposia chair and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, the Society of Professional Benefits Administrators, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients, serves on the faculty and planning committee of many workshops, seminars, and symposia, and on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. For additional information about Ms. Stamer, see CynthiaStamer.com or contact Ms. Stamer via email to here or via telephone to (469) 767-8872.
About Solutions Law Press
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at www.SolutionsLawPress.com.
If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press™ events, please be sure that we have your current contact information – including your preferred e-mail by creating or updating your profile here. For important information concerning this communication, see here.
NOTICE: Any party accessing or using any content obtained from or through Solutions Law Press, Inc.™ acknowledges and agrees that any and all programs, publications, statements and materials presented or published by Solutions Law Press, Inc.™ and any statements or other contents made or contained therein are for general informational and educational purposes only. They are generic in nature and not tailored or intended to be relied upon by any person, business, entity or other party for purposes for determining the legal, financial or other appropriateness, defensibility, suitability, outcome or consequences of any strategy, action, course of action, or any other facts, circumstances, event or conduct. Users of these resources are responsible at all times for independently evluating the suitability of any content, materials, tools or other materials or information accessed from or through Solutions Law Press, Inc. directly or indirectly.
Solutions Law Press, Inc.™ and its authors and contributors do not represent or warrant in any form or manner, and expressly disclaim and deny the appropriateness of the use or reliance of any person or entity on any content, tools or resources accessed or obtained from or through Solutions Law Press, Inc.™ for any general or particular use or purpose by any party under any circumstances.
Likewise, they do not establish an attorney-client relationship or other fiduciary, contractual or other relationship between Solutions Law Press, Inc. and/or any of its authors or contributors and any other party. They are not, and do not serve as a substitute for legal, accounting, tax or other advice. They don’t create or otherwise give rise to any duty, obligation, responsibility on behalf of Solutions Law Press, Inc™ or any provider or offeree of content, tools or services to any party.
Parties accessing or using any of Solutions Law Press, Inc.™ competent legal counsel for consultation and representation in light of the specific facts and circumstances presented in their unique circumstance at any particular time. No comment or statement in this publication is to be construed as an admission. The author reserves the right to qualify or retract any of these statements at any time. Likewise, the content is not tailored to any particular situation and does not necessarily address all relevant issues. Because the law is rapidly evolving and rapidly evolving rules makes it highly likely that subsequent developments could impact the currency and completeness of this discussion. The publisher and the author expressly disclaim all liability for this content and any responsibility to provide any update or otherwise notify anyone of any such change, limitation, or other condition that might affect the suitability of reliance upon these materials or information otherwise conveyed in connection with this program. Readers may not rely upon, are solely responsible for, and assume the risk and all liabilities resulting from their use of this publication.
©2017 Solutions Law Press. All rights reserved.
Comments Off on Learn About Rising Group Health Plan Mental Health Mandate Risks From 6/27 “2017 Federal Group Health Plan Mental Health Rules Update” |
4980D, 6039D, ACA, Affordable Care Act, Appeals, Attorney-Client Privilege, board of directors, Brokers, Cafeteria Plans, church plan, Civil Monetary Penalties, Civil Rights, Claims, Claims Administration, compensation, compliance, conflict of interest, Corporate Compliance, corporate governance, Data Breach, Data Security, EBSA, employee, Employee Benefits, Employer, Employers, Employment, Employment Tax, ERISA, Excepted Benefits, exchange, Excise Tax, Excise Taxes, Exempt, fiduciary duty, Fiduciary Responsibility, H.R. 4872, health reform, HIPAA, HR, Human Resources, Identity Theft, Income Tax, Insurance, insurers, Internal Revenue Code, IRC, Labor Management Relations, Management, Mental Health, Mental Health Parity, MEWA, Obamacare, Patient Protection & Affordable Care Act, Pay, Physician, Plan Admistrator, preventive care, Privacy, Professional Liability, Protected Health Information, Provider, Risk Management, SBC, Tax Credit, Uncategorized, Union | Tagged: ACA, Brokers, CCIIO, Corporate Compliance, EBSA, Employers, enforcement, Essential health benefits, Fiduciary, Fiduciary Duties, Health Benefits, health coverage, Health Plans, health reform, HHS, Mental Health, Mental Health Parity, mental health records, substance abuse, Third party Administrators |
Permalink
Posted by Cynthia Marcotte Stamer
May 12, 2017
Solutions Law Press, Inc. editor and attorney Cynthia Marcotte Stamer will speak and moderate two key panel programs on health care privacy and data security scheduled at the Healthcare Privacy & Security Form hosted on May 19, 2017 by the Information Security Systems Association of Los Angeles County (ISSA-LA) as a component of its 9th Annual ISSA-LA Information Security Summit. The presentations of Ms. Stamer and others at the conference are particularly timely coming on the heels of the May 12 Cyber alerts to U.S. health industry and other businesses about the urgent need to defend against the spread of an epidemic international malware threat targeting U.S. healthcare and other businesses. See Urgent WannaCry Ransomware Cyber Warning Issued; Alert: Guard Health E-Mail, Other IT Against WannaCry Malware Attack.
The Medical Privacy & Security Summit is part of the 9th Annual ISSA-LA Information Security Summit scheduled for May 18-19, 2017 at the Universal City Hilton in Los Angeles. Recognized as a premier information security education and networking event, the Summit is expected to bring together 1000 or more health industry and other IT and InfoSec executives, leaders, analysts, and practitioners to learn from the experts, exchange ideas with their peers, and enjoy conversations with the community.
The Healthcare Privacy & Security Forum offered for the 5th year as a component of the annual Summit on May 19 specifically focuses on leading challenges, issues and opportunities confronted by health industry privacy and security professionals and their organizations. Ms. Stamer has served on the steering committee, moderator and popular faculty member for the 2017 Forum for the 5th consecutive year. During the 2017 Forum, she will moderate and speak on two panels:
- “Finding & Negotiating The Mine Fields: CISO, CIO & Privacy Officer’s Playbook for Promoting Compliance & Security Without Getting Fired,” a luncheon interactive panel discussion with the audience exploring the challenging mission CISOs, CIOs and Privacy Officers face to ensure their healthcare, financial and other critical information, data and systems continue to support the patient care and operating functions of their organizations, while at the same time defending these systems, operations and their sensitive, but mission critical data against malicious or innocent misappropriation, use, access or destruction; and
- The closing panel on “What Initiatives Are on the Horizon in Healthcare, and How Can We Secure Them?”, which will explore likely future emerging privacy and security threats and technologies, regulatory challenges and enforcement, and other trends that Privacy and Security professionals are likely to face and tips and strategies for preparing to leverage these likely new opportunities and manage new challenges.
Register or get the full schedule of programs and other events scheduled at the Healthcare Privacy & Security Forum specifically along with the overall Information Security Summit here.
About Ms. Stamer
Cynthia Marcotte Stamer is a Martindale-Hubble “AV-Preeminent (Top 1%) rated practicing attorney and management consultant, health industry public policy advocate, widely published author and lecturer, recognized for her nearly 30 years’ of work on health industry and other privacy and data security and other health care, health benefit, health policy and regulatory affairs and other health industry legal and operational as a LexisNexis® Martindale-Hubbell® “LEGAL LEADER™ and “Top Rated Lawyer,” in Health Care Law and Labor and Employment Law; a D Magazine “Best Lawyers In Dallas” in the fields of “Health Care,” “Labor & Employment,” “Tax: Erisa & Employee Benefits” and “Business and Commercial Law,” a Fellow in the American Bar Foundation, the Texas Bar Foundation and the American College of Employee Benefit Counsel.
Scribe for ABA JCEB annual agency meeting with OCR for many years, Ms. Stamer is well-known for her extensive work and leadership throughout her career on HIPAA, FACTA, PCI, IRC and other tax, Social Security, GLB, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and concerns. Ms. Stamer has worked extensively throughout her career with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks, insurers and other financial institutions, and others on trade secret confidentiality, privacy, data security and other risk management and compliance including design, establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, drafting and negotiation of business associate, chain of custody, confidentiality, and other contracting; risk assessments, audits and other risk prevention and mitigation; investigation, reporting, mitigation and resolution of known or suspected breaches, violations or other incidents; and defending investigations or other actions by plaintiffs, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others; reporting known or suspected violations; commenting or obtaining other clarification of guidance and other regulatory affairs, training and enforcement, and a host of other related concerns.
Her clients include public and private health care providers, health insurers, health plans, employers, payroll, staffing, recruitment, insurance and financial services, health and other technology and other vendors, and others.
Author of a multitude of highly-regarded works and training programs on HIPAA and other data security, privacy and use published by BNA, the ABA and other premier legal industry publishers In addition to representing and advising these organizations, she also speaks extensively and conducts training on health care and other privacy and data security and many other matters Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
Beyond these involvements, Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. Through these and other involvements, she helps develop and build solutions, build consensus, garner funding and other resources, manage compliance and other operations, and take other actions to identify promote tangible improvements in health care and other policy and operational areas.
For additional information about Ms. Stamer, see here or contact Ms. Stamer directly by e-mail here or by telephone at (469) 767-8872. ©2017 Cynthia Marcotte Stamer. Limited, non-exclusive right to republish granted to Solutions Law Press, Inc. All other rights reserved.
Comments Off on Stamer To Moderate, Talk Medical CyberSecurity At 5/19 ISSA-LA IT Security Meedical Privacy Forum |
ADA, ARRA, board of directors, Brokers, Child Safety, Civil Monetary Penalties, compliance, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, EBSA, Educational Privacy, Electronic Medical Record, employee, Employee Benefits, Employer, Employers, EMR, ERISA, FACTA, Fair Credit Reporting Act, FICA, fiduciary duty, FINRA, Government Contractors, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Internet, Management, Mental Health, officers, Physician, Plan Admistrator, Privacy, Professional Liability, Protected Health Information, Provider, Public Policy, Security, Technology, third party administrators, Uncategorized | Tagged: Cyber Security, Cybercrime, Data Security, Information Security, IT, medical data, Medical Privacy, medical security, Protected Health Information, speech |
Permalink
Posted by Cynthia Marcotte Stamer
May 10, 2017
Healthcare providers, health plans, healthcare clearinghouses and their business associates (Covered Entities) can’t disclose the name or other protected health care information about a patient in press releases or other announcements without prior authorization from the patient. That’s the clear lesson Covered Entities should learn from the $2.4 million payment to the U.S. Department of Health and Human Services (HHS) that the largest not-for-profit health system in Southeast Texas, Memorial Hermann Health System (MHHS) is paying to settle charges it violated the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule by issuing a press release with the name and other protected health information (PHI) about a patient without the patient’s prior HIPAA-compliant authorization under a Resolution Agreement and Corrective Action Plan (Resolution Agreement) announced May 10, 2017 by HHS Office of Civil Rights (OCR).
The Resolution Agreement resolves OCR charges the operator of 13 hospitals, eight Cancer Centers, three Heart & Vascular Institutes, and 27 sports medicine and rehabilitation centers violated the Privacy Rule that resulted from an OCR compliance review of MHHS triggered by multiple media reports suggesting that MHHS improperly disclosed the name and other details about a patient arrested and charged with presenting an allegedly fraudulent identification card to office staff at an MHHS’s clinic after MHHS clinic staff alerted law enforcement of suspicions the patient was presenting false identification to the clinic. According to OCR, after law enforcement investigated and arrested the patient, MHHS published a press release concerning the incident in which MHHS senior management approved the impermissible disclosure of the patient’s PHI by adding the patient’s name in the title of the press release without securing prior authorization of the patient.
While OCR concluded the report to law enforcement allowable under the Privacy Rule, OCR found MHHS violated the Privacy Rule by issuing the press release disclosing the patient’s name and other PHI without authorization from the patient and also by failing to timely document the sanctioning of its workforce members for impermissibly disclosing the patient’s information.
To resolve and avoid the potential Civil Monetary Penalties that HIPAA could authorize OCR to impose for the alleged Privacy Rule violation, MHHS agrees in the Resolution Agreement to pay OCR a $2.4 million monetary settlement and implement a corrective action plan that obligates MHHS to update and train its workforce on its policies and procedures on safeguarding PHI from impermissible uses and disclosures including specific instructions and procedures to:
- Address (a) Uses and disclosures for which an authorization is required, including to the media, to public officials, and on the internet; (b) Disclosures for law enforcement purposes; and (c) Uses and disclosures for health oversight activities;
- Identify MHHS personnel or representatives whom workforce members, agents, or business associates may contact in the event of any inquiry or concern regarding compliance with HIPAA in relation to these activities;
- Internal reporting procedures requiring all workforce members to report to the designated person or office at the earliest possible time any potential violations of the Privacy, Security or Breach Notification Rules or of MHHS’ privacy and security policies and procedures and MHHS promptly to investigate and address all received reports in a timely manner; and
- Application and documentation of appropriate sanctions (which may include retraining or other instructive corrective action, depending on the circumstances) against members of MHHS’ workforce, including senior level management, who fail to comply with the Privacy, Security or Breach Notification Rules or MHHS’ privacy and security policies and procedures, including a description of the sanctions; a timeframe in which MHHS will apply and document sanctions for violations of the HIPAA Rules or of MHHS’ privacy, security or breach policies or procedures; the manner in which MHHS will document the sanctions; and where MHHS will store or retain such documentation (e.g., personnel file).
The corrective action plan in the Resolution Agreement also requires all MHHS facilities to attest to their understanding of permissible uses and disclosures of PHI, including disclosures to the media and others.
Covered entities should keep in mind the MHHS Resolution Agreement is the latest in a series of OCR enforcement actions and resolution agreements highlighting the need for Covered Entities to adopt and use appropriate policies and procedures to prevent wrongful disclosures of PHI to the media or public. For instance, in June, 2013, OCR required Shasta Regional Medical Center (SRMC) to pay a $275,000 settlement payment and implement a comprehensive corrective action plan to resolve OCR charges stemming from SRMC’s disclosure of PHI about a patient to members of the media and its workforce in an effort to respond to accusations the patient made that SRMC engaged in fraud and other misconduct. See HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce. In contrast, the $2.2 million resolution agreement that OCR required New York Presbyterian Hospital for improperly allowing a film crew to film hospital patients in violation of HIPAA was almost 10 times greater than the SRMC penalty and was accompanied by OCR’s publication OCR of specific additional guidance warning Covered Entities against improper disclosures to the media. See $2 Million+ HIPAA Settlement, FAQ Warn Providers Protect PHI From Media, Other Recording Or Use.
Following on the heels of this previous guidance and prior enforcement actions warning Covered Entities against wrongful disclosure to the media, the MHHS Resolution Agreement sends a strong message to Covered Entities that they should expect little sympathy if their organizations improperly share PHI with the media. OCR’s announcement of the MHHS Resolution Agreement, for instance quotes OCR Director Roger Severino with stating that “Senior management should have known that disclosing a patient’s name on the title of a press release was a clear HIPAA Privacy violation that would induce a swift OCR response.” The announcement goes on to quote Director Severino further as stating, “This case reminds us that organizations can readily cooperate with law enforcement without violating HIPAA, but that they must nevertheless continue to protect patient privacy when making statements to the public and elsewhere.”
Conduct Entity-Wide Risk Assessment & Review & Tighten Media Relations Policies, Processes & Training ASAP
Covered entities should heed the warning by conducting a risk assessment of their organization’s susceptibility to potential improper disclosures to media or others and reviewing and implementing necessary written policies, procedures and training to prevent the improper disclosure of patient PHI to media or others unless the Covered Entity either secures prior HIPAA-compliant authorization from the patient or can prove the disclosure falls squarely under an exception to the Privacy Rule’s prohibition against disclosure of PHI without authorization except as allowed by the Privacy Rule.
Taking these and other needed steps to evaluate, and strengthen and enforce as needed, risk assessments, policies, procedures, and training to prevent wrongful use, access or disclosure of PHI to the media or others is particularly critical in light of the ongoing tightening of expectations, and rising enforcement and sanctions for HIPAA violations since Congress amended HIPAA in 2009. See OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website.
Based on experiences reported in the MHHS and other similar resolution agreements, Covered Entities also generally will want to ensure that their policies, procedures and training extend to all potential sources of communications that could involve patient information and make clear that the Privacy Rule restrictions must be followed even if the circumstances involve allegations of misconduct, special performance by healthcare providers or others that it would benefit the organization or certain individuals to have known to the public, or other circumstances likely to be of interest to the media or other parties.
As part of this process, covered entities should ensure they look outside the four corners of their Privacy Policies to ensure that appropriate training and clarification is provided to address media, practice transition, workforce communication and other policies and practices that may be covered by pre-existing or other policies of other departments or operational elements not typically under the direct oversight and management of the Privacy Officer such as media relations. Media relations, physician and patients affairs, outside legal counsel, media relations, marketing and other internal and external departments and consultants dealing with the media, the public or other inquiries or disputes should carefully include and coordinate with the privacy officer both to ensure appropriate policies and procedures are followed and proper documentation created and retained to show authorization, account, or meet other requirements.
In conducting this analysis and risk assessment, it will be important that Covered Entities include, but also look beyond the four corners of their Privacy Policies to ensure that their review and risk assessment identifies and assesses and addresses compliance risks on an entity wide basis. This entity-wide assessment should include both communications and requests for information normally addressed to the Privacy Officer as well as requests and communications that could arise in the course of media or other public relations, practice transition, workforce communication and other operations not typically under the direct oversight and management of the Privacy Officer. For this reason, Covered Entities also generally will not only to adopt and implement specific policies, processes and training in these other departments to prohibit and prevent inappropriate disclosures of PHI in the course of those departments operations. It also may be advisable to pre-established processes for reviewing media or other communications for potential PHI content and require prior review of any proposed public relations and other internal or external communications containing patient PHI or other information by the privacy officer, legal counsel or another suitably qualified party.
Because of the high risk that the preparation or review of media or other public communications reports will involve the use and disclosure of PHI, Covered Entities also generally should verify that all outside media or public relations, legal, or other outside service providers participating in the investigation, response or preparation or review of communications to the media or others both are covered by signed business associate agreements that fulfill the Privacy Rule and other requirements of HIPAA as well as possess detailed knowledge and understanding of the Privacy and Security Rules suitable to participate in and help safeguard the Covered Entity against violations of these and other Privacy Rules. See e.g., Latest HIPAA Resolution Agreement Drives Home Importance Of Maintaining Current, Signed Business Associate Agreements.
About The Author
Recognized by LexisNexis® Martindale-Hubbell® as a “AV-Preeminent” (Top 1%/ the highest) and “Top Rated Lawyer,” with special recognition as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Health Care,” “Labor & Employment,” “Tax: Erisa & Employee Benefits” and “Business and Commercial Law” by D Magazine, the author of this update is widely known for her 29 plus years’ of work in health care, health benefit, health policy and regulatory affairs and other health industry concerns as a practicing attorney and management consultant, thought leader, author, public policy advocate and lecturer.
Throughout her adult life and nearly 30-year legal career, Ms. Stamer’s legal, management and governmental affairs work has focused on helping health industry, health benefit and other organizations and their management use the law, performance and risk management tools and process to manage people, performance, quality, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer supports these organizations and their leaders on both a real-time, “on demand” basis as well as outsourced operations or special counsel on an interim, special project, or ongoing basis with strategic planning and product and services development and innovation; workforce and operations management, crisis preparedness and response as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans and insurers, managed care organizations, health care clearinghouses, their business associates, employers, banks and other financial institutions, management services organizations, professional associations, medical staffs, accreditation agencies, auditors, technology and other vendors and service providers, and others on legal and operational compliance, risk management and compliance, public policies and regulatory affairs, contracting, payer-provider, provider-provider, vendor, patient, governmental and community relations and matters including extensive involvement advising, representing and defending public and private hospitals and health care systems; physicians, physician organizations and medical staffs; specialty clinics and pharmacies; skilled nursing, home health, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing and management services organizations; consultants; investors; technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, insurers, self-insured health plans and other payers; and other health industry clients to manage and defend compliance, public policy, regulatory, staffing and other operations and risk management concerns. A core focus of this work includes work to establish and administer compliance and risk management policies; comply with requirements, investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; dealings with JCHO and other accreditation and quality organizations; investigation and defense of private litigation and other federal and state health care industry investigations and enforcement; insurance or other liability management and allocation; process and product development; managed care, physician and other staffing, business associate and other contracting; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
Author of leading works on HIPAA and other privacy and data security works and the scribe leading the American Bar Association Joint Committee on Employee Benefits Annual Agency Meeting with OCR, her experience includes extensive compliance, risk management and data breach and other crisis event investigation, response and remediation under HIPAA and other data security, privacy and breach laws. Heavily involved in health care and health information technology, data and related process and systems development, policy and operations innovation and a Scribe for ABA JCEB annual agency meeting with OCR for many years who has authored numerous highly regarded works and training programs on trade secret, HIPAA and other medical, consumer, insurance, tax, and other privacy and data security, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues including meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and many other concerns.
In connection with this work, Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.
Her work includes both regulatory and public policy advocacy and thought leadership, as well as advising and representing a broad range of health industry and other clients about policy design, drafting, administration, business associate and other contracting, risk assessments, audits and other risk prevention and mitigation, investigation, reporting, mitigation and resolution of known or suspected violations or other incidents and responding to and defending investigations or other actions by plaintiffs, DOJ, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others.
In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, MGMA, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in Pensions, healthcare, workforce, immigration, tax, education and other areas.
The American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has worked closely with a diverse range of physicians, hospitals and healthcare systems, DME, Pharma, clinics, health care providers, managed care, insurance and other health care payers, quality assurance, credentialing, technical, research, public and private social and community organizations, and other health industry organizations and their management deal with governance; credentialing, patient relations and care; staffing, peer review, human resources and workforce performance management; outsourcing; internal controls and regulatory compliance; billing and reimbursement; physician, employment, vendor, managed care, government and other contracting; business transactions; grants; tax-exemption and not-for-profit; licensure and accreditation; vendor selection and management; privacy and data security; training; risk and change management; regulatory affairs and public policy and other concerns.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also has extensive health care reimbursement and insurance experience advising and defending health plans, health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other “nonpar,” insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; an ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposium and chair, faculty member and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, Insurance Thought Leadership and many other prominent publications and speaks and conducts training for a broad range of professional organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved. For information about republication or other use, please contact Ms. Stamer here.
Comments Off on $2.4M HIPAA Settlement Message Warns Health Plans & Providers Against Sharing Medical Info With Media, Others |
ADA, board of directors, Brokers, Cafeteria Plans, Civil Monetary Penalties, Civil Rights, compliance, conflict of interest, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, directors, Disability Discrimination, Electronic Medical Record, employee, Employee Benefits, Employer, Employers, Employment, EMR, ERISA, Fair Credit Reporting Act, fiduciary duty, GINA, HIPAA, HIPAA, Hiring, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Internal Revenue Code, IRC, Leadership, LGBT, Management, Medicare Part D, Mental Health, Mental Health Parity, MEWA, Physician, Prescription Drugs, Privacy, Professional Liability, Protected Health Information, Provider, Risk Management, Technology, third party administrators, Uncategorized | Tagged: Health Care Provider, Health Plans, HIPAA, Medical Privacy, PHI, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
April 26, 2017
A new Department of Health and Human Services Office of Civil Rights (OCR) CardioNet Resolution Agreement and Corrective Action Plan (Resolution Agreement) settling OCR charges of violations of the Privacy and Security Rules of the Health Insurance Portability & Accountability Act against remote cardiac monitoring provider CardioNet provides important lessons for all health plans, health insurers, telemedicine and other healthcare providers, healthcare clearinghouses (Covered Entities) and their business associates about steps to take to reduce their risk of getting hit with big OCR penalty like the $2.5 million settlement payment CardioNet must pay under the Resolution Agreement.
OCR announced the first OCR HIPAA settlement involving a wireless health services provider Monday, April 24. Under the Resolution Agreement, CardioNet agrees to pay OCR $2.5 million and to implement a corrective action plan to settle potential OCR charges it violated the HIPAA Privacy and Security Rules based on the impermissible disclosure of unsecured electronic protected health information (ePHI).
CardioNet Charges & Settlement
As has become increasingly common in recent years, the CardioNet settlement arose from concerns initially brought to OCR’s attention in connection with a HIPAA breach notification report. On January 10, 2012, OCR received notification from the provider of remote mobile monitoring of and rapid response to patients at risk for cardiac arrhythmias that a workforce member’s laptop with the ePHI of 1,391 individuals was stolen from a parked vehicle outside of the employee’s home. CardioNet subsequently notified OCR of a second breach of ePHI 2,219 individuals, respectively.
Likewise, the HIPAA breaches uncovered by OCR in the course of investigating these CardioNet breaches occur in the operations of many other covered entities. According to the OCR’s investigation in response to these breach reports revealed a series of continuing compliance concerns, including:
- CardioNet failed to conduct an accurate and thorough risk analysis to assess the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI and failed to plan for and implement security measures sufficient to reduce those risks and vulnerabilities;
- CardioNet’s policies and procedures implementing the standards of the HIPAA Security Rule were in draft form and had not been implemented;
- CardioNet was unable to produce any final policies or procedures regarding the implementation of safeguards for ePHI, including those for mobile devices;
- CardioNet failed to implement policies and procedures that govern the receipt and removal of hardware and electronic media that contain electronic protected health information into and out of its facilities, the encryption of such media, and the movement of these items within its facilities until March 2015; and
- CardioNet failed to safeguard against the impermissible disclosure of protected health information by its employees, thereby permitting access to that information by an unauthorized individual, and failed to take sufficient steps to immediately correct the disclosure.
To resolve these OCR charges, CardioNet agrees in the Resolution Agreement to pay $2.5 million to OCR and implement a corrective action plan. Among other things, the corrective action plan requires CardioNet to complete the following actions to the satisfaction of OCR:
- Prepare a current, comprehensive and thorough Risk Analysis of security risks and vulnerabilities that incorporates its current facility or facilities and the electronic equipment, data systems, and applications controlled, currently administered or owned by CardioNet, that contain, store, transmit, or receive electronic protected health information (“ePHI”) and update that Risk Analysis annually or more frequently, if appropriate in response to environmental or operational changes affecting the security of ePHI.
- Assess whether its existing security measures are sufficient to protect its ePHI and revise its Risk Management Plan, Policies and Procedures, and training materials and implement additional security measures, as needed.
- Develop and implement an organization-wide Risk Management Plan to address and mitigate any security risks and vulnerabilities found in the Risk Analysis as required by the Risk Management Plan.
- Review and, to the extent necessary, revise, its current Security Rule Policies and Procedures (“Policies and Procedures”) based on the findings of the Risk Analysis and the implementation of the Risk Management Plan to comply with the HIPAA Security Rule.
- Provide certification to OCR that all laptops, flashdrives, SD cards, and other portable media devices are encrypted, together with a description of the encryption methods used (“Certification”).
- Review, revise its HIPAA Security training to include a focus on security, encryption, and handling of mobile devices and out-of-office transmissions and other policies and practices require to address the issues identified in the Risk Assessment and otherwise comply with the Risk Management Plan and HIPAA train its workforce on these policies and practices.
- Investigate all potential violations of its HIPAA policies and procedures and notify OCR in writing within 30 days of any violation.
- Submit annual reports to OCR, which must be signed by an owner or officer of CardioNet attesting that he or she has reviewed the annual report, has made a reasonable inquiry regarding its content and believes that, upon such inquiry, the information is accurate and truthful.
- Maintain for inspection and copying, and provide to OCR, upon request, all documents and records relating to compliance with the corrective action plan for six years.
Implications For Covered Entities & Business Associates
The latest in a rapidly-growing list of high dollar HIPAA enforcement actions by OCR, the CardioNet Resolution Agreement contains numerous lessons for other Covered entities and their business associates about the importance of appropriate HIPAA privacy and security compliance, including but not limited to the following:
- Like many previous resolution agreements announced by OCR, the Resolution Agreement reiterates the responsibility of covered entities and business associates to properly secure their ePHI and that as part of this process, OCR expects all laptop computers and other mobile devices containing or with access to ePHI be properly encrypted and secured.
- It also reminds covered entities and their business associates to be prepared for, and expect an audit from OCR when OCR receives a report that their organization experienced a large breach of unsecured ePHI.
- The Resolution Agreement’s highlighting of the draft status of CardioNet’s privacy and security policies also reflects OCR expects covered entities to actually final policies, procedures and training in place for maintaining compliance with HIPAA.
- The discussion and requirements in the Corrective Action Plan relating to requirements to conduct comprehensive risk assessments at least annually and in response to other events, and to update policies and procedures in response to findings of these risk assessments also drives home the importance of conducting timely, documented risk analyses of the security of their ePHI, taking prompt action to address known risks and periodically updating the risk assessment and the associated privacy and security policies and procedures in response to the findings of the risk assessment and other changing events.
- The requirement in the Resolution Agreement of leadership attestation and certification on the required annual report reflects OCR’s expectation that leadership within covered entities and business associates will make HIPAA compliance a priority and will take appropriate action to oversee compliance.
- Finally, the $2.5 million settlement payment required by the Resolution Agreement and its implementation against CardioNet makes clear that OCR remains serious about HIPAA enforcement.
Clearly, covered entities, business associates and their management should take steps to promptly review the adequacy of their organizations’ HIPAA compliance policies, practices and documentation in light of the deficiencies listed in the CardioNet and other HIPAA OCR settlements and civil monetary penalty assessments. See e.g., Latest HIPAA Resolution Agreement Drives Home Importance Of Maintaining Current, Signed Business Associate Agreements; $400K HIPAA Penalty Teaches Risk Assessment Importance; $3.2 Children’s HIPAA CMP Teaches Key Lessons.
Of course, covered entities and business associates need to keep in mind that acts, omissions and events that create HIPAA liability risks also carry many other potential legal and business risks. For instance, since PHI records and data involved in such breaches usually incorporates Social Security Numbers, credit card or other debt or payment records or other personal consumer information, and other legally sensitive data, covered entities and business associates generally also may face investigation, notification and other responsibilities and liabilities under confidentiality, privacy or data security rules of the Fair and Accurate Credit Transaction Act (FACTA), the Internal Revenue Code, the Social Security Act, state identity theft, data security, medical confidentiality, privacy and ethics, insurance, consumer privacy, common law or other state privacy claims and a host of other federal or state laws. Depending on the nature of the covered entity or its business associates, the breach or other privacy event also may trigger fiduciary liability exposures for health plan fiduciaries in the case of a health plan, professional ethics or licensing investigations or actions against health care providers, insurance companies, administrative service providers or brokers, shareholder or other investor actions, employment or vendor termination or disputes and a host of other indirect legal consequences.
Beyond, and regardless of if, a covered entity or business ultimately succeeds in defending its actions against a charge of violating any of these or other standards, however, covered entities, business associates and their leaders should keep in mind that the most material and often most intractable consequences of a HIPAA or other data or other privacy breach report or public accusation, investigation, admission also typically are the most inevitable:
- The intangible, but critical loss of trust and reputation covered entities and business associates inevitably incur among their patients, participants, business partners, investors and the community; and
- The substantial financial expenses and administrative and operational disruptions of investigating, defending the actions of the organization and implementation of post-event corrective actions following a data or other privacy breach, audit, investigation, or charge.
In light of these risks, covered entities business associates and their management should use the experiences of CardioNet and other covered entities or business associates caught violating HIPAA or other privacy and security standards to reduce their HIPAA and other privacy and data security exposures. Management of covered entities and their business associates should take steps to ensure that their organizations policies, practices and procedures currently are up-to-date, appropriately administered and monitored, and properly documented. Management should ensure that their organizations carefully evaluate and strengthen as necessary their current HIPAA risk assessments, policies, practices, record keeping and retention and training in light of these and other reports as they are announced in a well-documented manner. The focus of these activities should be both to maintain compliance and position their organizations efficiently and effectively to respond to and defend their actions against a data breach, investigation, audit or accusation of a HIPAA or other privacy or security rule violation with a minimum of liability, cost and reputational and operational damages.
As the conduct of these activities generally will involve the collection and analysis of legally sensitive matters, most covered entities and business associates will want to involve legal counsel experienced with these matters and utilize appropriate procedures to be able to use and assert attorney-client privilege and other evidentiary privileges to mitigate risks associated with these processes. To help plan for and mitigate foreseeable expenses of investigating, responding to or mitigating a known, suspected or asserted breech or other privacy event, most covered entities and business associates also will want to consider the advisability of tightening privacy and data security standards, notification, cooperation and indemnification protections in contracts between covered entities and business associates, acquiring or expanding data breach or other liability coverage, or other options for mitigating the financial costs of responding to a breach notification, investigation or enforcement action.
About The Author
Recognized by LexisNexis® Martindale-Hubbell® as a “AV-Preeminent” (Top 1%/ the highest) and “Top Rated Lawyer,” with special recognition as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Health Care,” “Labor & Employment,” “Tax: Erisa & Employee Benefits” and “Business and Commercial Law” by D Magazine, the author of this update is widely known for her 29 plus years’ of work in health care, health benefit, health policy and regulatory affairs and other health industry concerns as a practicing attorney and management consultant, thought leader, author, public policy advocate and lecturer.
Throughout her adult life and nearly 30-year legal career, Ms. Stamer’s legal, management and governmental affairs work has focused on helping health industry, health benefit and other organizations and their management use the law, performance and risk management tools and process to manage people, performance, quality, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer supports these organizations and their leaders on both a real-time, “on demand” basis as well as outsourced operations or special counsel on an interim, special project, or ongoing basis with strategic planning and product and services development and innovation; workforce and operations management, crisis preparedness and response as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans and insurers, managed care organizations, health care clearinghouses, their business associates, employers, banks and other financial institutions, management services organizations, professional associations, medical staffs, accreditation agencies, auditors, technology and other vendors and service providers, and others on legal and operational compliance, risk management and compliance, public policies and regulatory affairs, contracting, payer-provider, provider-provider, vendor, patient, governmental and community relations and matters including extensive involvement advising, representing and defending public and private hospitals and health care systems; physicians, physician organizations and medical staffs; specialty clinics and pharmacies; skilled nursing, home health, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing and management services organizations; consultants; investors; technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, insurers, self-insured health plans and other payers; and other health industry clients to manage and defend compliance, public policy, regulatory, staffing and other operations and risk management concerns. A core focus of this work includes work to establish and administer compliance and risk management policies; comply with requirements, investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; dealings with JCHO and other accreditation and quality organizations; investigation and defense of private litigation and other federal and state health care industry investigations and enforcement; insurance or other liability management and allocation; process and product development; managed care, physician and other staffing, business associate and other contracting; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
In the course of this work, Ms. Stamer has accumulated extensive experience helping health industry clients manage workforce, medical staff, vendors and suppliers, medical billing, reimbursement, claims and other provider-payer relations, business partners, and their recruitment, performance, discipline, compliance, safety, compensation, benefits, and training, board, medical staff and other governance; compliance and internal controls; strategic planning, process and quality improvement; change management; assess, deter, investigate and address staffing, quality, compliance and other performance; meaningful use, EMR, HIPAA and other data security and breach and other health IT and data; crisis preparedness and response; internal, government and third-party reporting, audits, investigations and enforcement; government affairs and public policy; and other compliance and risk management, government and regulatory affairs and operations concerns.
Author of leading works on HIPAA and other privacy and data security works and the scribe leading the American Bar Association Joint Committee on Employee Benefits Annual Agency Meeting with OCR, her experience includes extensive compliance, risk management and data breach and other crisis event investigation, response and remediation under HIPAA and other data security, privacy and breach laws. Heavily involved in health care and health information technology, data and related process and systems development, policy and operations innovation and a Scribe for ABA JCEB annual agency meeting with OCR for many years who has authored numerous highly regarded works and training programs on HIPAA and other data security, privacy and use, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues including meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and many other concerns.
In connection with this work, Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.
Her work includes both regulatory and public policy advocacy and thought leadership, as well as advising and representing a broad range of health industry and other clients about policy design, drafting, administration, business associate and other contracting, risk assessments, audits and other risk prevention and mitigation, investigation, reporting, mitigation and resolution of known or suspected violations or other incidents and responding to and defending investigations or other actions by plaintiffs, DOJ, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others.
In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, MGMA, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in Pensions, healthcare, workforce, immigration, tax, education and other areas.
The American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has worked closely with a diverse range of physicians, hospitals and healthcare systems, DME, Pharma, clinics, health care providers, managed care, insurance and other health care payers, quality assurance, credentialing, technical, research, public and private social and community organizations, and other health industry organizations and their management deal with governance; credentialing, patient relations and care; staffing, peer review, human resources and workforce performance management; outsourcing; internal controls and regulatory compliance; billing and reimbursement; physician, employment, vendor, managed care, government and other contracting; business transactions; grants; tax-exemption and not-for-profit; licensure and accreditation; vendor selection and management; privacy and data security; training; risk and change management; regulatory affairs and public policy and other concerns.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also has extensive health care reimbursement and insurance experience advising and defending health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other “nonpar,” insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; an ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposium and chair, faculty member and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, Insurance Thought Leadership and many other prominent publications and speaks and conducts training for a broad range of professional organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved. For information about republication or other use, please contact Ms. Stamer here.
Comments Off on Latest $2.5M HIPAA Settlement Warning To Health Plans, Providers: Get HIPAA Compliant |
ARRA, Attorney-Client Privilege, board of directors, Brokers, Civil Monetary Penalties, Civil Rights, compliance, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, directors, Electronic Medical Record, Employee Benefits, Employer, fiduciary duty, Fiduciary Responsibility, FINRA, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Physician, Plan Admistrator, Privacy, Professional Liability, Protected Health Information, Provider, Risk Management, Technology, Telecommuting, Uncategorized | Tagged: Breach, Breach Notification, Business Associate, Covered Entity, Health Insurance, Health Plan, HIPAA, HIPAA Privacy, HIPAA Security, Medical Privacy, OCR, Office of Civil Rights, REmote Care, Technology, Telemedicine |
Permalink
Posted by Cynthia Marcotte Stamer
April 24, 2017
Health plans, their fiduciaries and sponsors, health insurers, health care providers, health care clearinghouses (“covered entities”) and their business associates must get and keep your business associate (BA) agreements (BAAs) in place, up-to-date, and readily available for inspection in accordance with the Health Insurance Portability & Accountability Act (HIPAA) Privacy Rule, 45 C.F.R. Part 160 and Subparts A and E of Part 164 (Privacy Rule). That’s the clear message to covered entities and their business associates in the April 17, 2017 HIPAA Resolution Agreement just announced by the Department of Health & Human Services (HHS) Office of Civil Rights (OCR) with the Center for Children’s Digestive Health (CCDH).
While the Resolution Agreement relates to breaches of the BAA requirements of a small pediatric practice, all health plans, health care providers and other covered entities and business associates should focus on the adequacy of their BAAs and their BAA record keeping. HIPAA compliance surveys reflect deficiencies with the BAA rules are common throughout the industry. These findings and the involvement of BAs in data breaches or other OCR enforcement activities suggest a high probability that many other covered entities and business associates may be sitting ducks for similar sanctions. See e.g., HIPAA Compliance Survey Churns Up Many Business Associate Problems (January 3, 2017). Consequently, all covered entities and business associates generally should treat the CCDH Resolution Agreement as a message to review and correct as necessary their organizations’ compliance and recordkeeping to minimize their exposure to potential sanctions from violations of the HIPAA business associate rules.
The HIPAA Business Associate Agreement Requirements
OCR’s announcement of the CCDH Resolution Agreement is the latest in a growing series of HIPAA enforcement actions showing the growing risk covered entities and their business associates face for failing to take appropriate steps to comply with the BAA and other Privacy Rule requirements of HIPAA.
As compliance audits and surveys of covered entities and business associates suggest a high level of noncompliance with the business associate agreement requirements among covered entities and business associates, While the ever-growing list of Resolution Agreements and Civil Monetary Penalties announced by OCR cover a variety of categories of HIPAA violations, the CCDH Resolution Agreement highlights the importance of covered entities and their business associates ensuring that before the BA creates, accesses, receives, discloses, retains or destroys any PHI for the covered entity, a BAA meeting the Privacy Rule requirements is signed and retained for at least the six-year period the Privacy Rule requires in a manner easily producible when and if OCR or another agency asks for a copy as part of an investigation or other compliance audit. See Privacy Rule §§ 164.502(e), 164.504(e), 164.532(d) and (e).
The Privacy Rule requires that covered entities and business associates enter into a written and signed business associate agreement that contains the elements specified in Privacy Rule § 164.504(e) before the business associate creates, uses, accesses or discloses PHI of the covered entity. Meanwhile, the Privacy Rule recordkeeping requirements require that covered entities and BAs maintain copies of these BAAs for a minimum of six years.
Violations of the Privacy Rule can carry stiff civil or even criminal penalties Pursuant to amendments to HIPAA enacted as part of the HITECH Act, civil penalties typically do not apply to violations punished under the criminal penalty rules of HIPAA set forth in Social Security Act , 42 U.S.C § 1320d-6 (Section 1177).
Under Section 1177, the criminal enforcement provisions of HIPAA authorize the Justice Department to prosecute a person who knowingly in violation of the Privacy Rule (1) uses or causes to be used a unique health identifier; (2) obtains individually identifiable health information relating to an individual; or (3) discloses individually identifiable health information to another person, punishable by the following criminal sanctions and penalties:
- A fine of up to $50,000, imprisoned not more than 1 year, or both;
- If the offense is committed under false pretenses, a fine of up to $100,000, imprisonment of not more than 5 years, or both; and
- If the offense is committed with intent to sell, transfer, or use individually identifiable health information for commercial advantage, personal gain, or malicious harm, a fine of up to $250,000, imprisoned not more than 10 years, or both.
In contrast, as amended by the HITECH Act, the civil enforcement provisions of HIPAA empower OCR to impose Civil Monetary Penalties on both covered entities and BAs for violations of any of the requirements of the Privacy or Security Rules. The penalty ranges for civil violations depends upon the circumstances associated with the violations and are subject to upward adjustment for inflation. As most recently adjusted here effective September 6, 2016, the following currently are the progressively increasing Civil Monetary Penalty tiers:
- A minimum penalty of $100 and a maximum penalty of $50,000 per violation, for violations which the CE or BA “did not know, and by exercising reasonable diligence would not have known” about using “the business care and prudence expected from a person seeking to satisfy a legal requirement under similar circumstances;”
- A minimum penalty of $1,000 and a maximum penalty of $50,000 per violation, for violations for “reasonable cause” which do not rise to the level of “willful neglect” where “reasonable cause” means the “circumstances that would make it unreasonable for the covered entity, despite the exercise of ordinary business care and prudence, to comply with the violated Privacy Rule requirement;”
- A minimum penalty of $10,000 and a maximum penalty of $50,000 per violation, for violations attributed to “willful neglect,” defined as “the conscious, intentional failure or reckless indifference to the obligation to comply” with the requirement or prohibition; and
- A minimum penalty of $50,000 and a maximum penalty of $1.5 million per violation, for violations attributed to “willful neglect” not remedied within 30 days of the date that the covered entity or BA knew or should have known of the violation.
For continuing violations such as failing to implement a required BAA, OCR can treat each day of noncompliance as a separate violation. However, sanctions under each of these tiers generally are subject to a maximum penalty of $1,500,000 for violations of identical requirements or prohibitions during a calendar year. For violations such as the failure to implement and maintain a required BAA where more than one covered entity bears responsibility for the violation, OCR an impose Civil Monetary Penalties against each culpable party. OCR considers a variety of mitigating and aggravating facts and circumstances when arriving at the amount of the penalty within each of these applicable tiers to impose.
While criminal enforcement of HIPAA remains relatively rare, a review of the OCR enforcement record in recent years makes clear that civil enforcement of HIPAA and the sanctions imposed is growing. See e.g., $400K HIPAA Settlement Shows Need To Conduct Timely & Appropriate Risk Assessments; $5.5M Memorial HIPAA Resolution Agreement Shows Need To Audit. For more examples, also see here.
CCDH Sanctions For Violation Of HIPAA Business Associate Agreement Rules
The CCDH Resolution Agreement arises from violations of this requirement that OCR says it discovered as a result of a compliance review conducted in response to an OCR investigation of a CCDH business associate, FileFax, Inc. According to OCR, OCR found from the compliance review of CCDH triggered by OCR’s investigation of FileFax that while CCDH began disclosing PHI to Filefax in 2003 and that Filefax stored records containing protected health information (PHI) for CCDH, neither CCDH nor Filefax could produce a signed Business Associate Agreement (BAA) covering their relationship for any period before October 12, 2015.
Based on the resulting investigation, OCR concluded:
- CCDH failed to obtain a BAA providing written assurances from Filefax that it would appropriately safeguard the PHI in Filefax’s possession or control satisfactory assurances as required by Privacy Rule §164.502(e); and
- Because CCDH failed to secure the required BAA, it violated the Privacy Rule by impermissibly disclosing the PHI of at least 10,728 individuals to Filefax when CCDH transferred the PHI to Filefax without obtaining the requisite BAA from Filefax (Covered Conduct).
In the Resolution Agreement, CCDH agrees to pay HHS $31,000.00 (Resolution Amount) and enter into and comply with a Corrective Action Plan (CAP) in return for OCR’s release of CCDH from liability for “any actions it may have against CCDH under the HIPAA Rules” for the Covered Conduct. The Resolution Agreement only settles the civil monetary penalty and other OCR enforcement liabilities of CCDH with respect to the Covered Conduct. Its provisions expressly state the Resolution Agreement does not affect any exposures of CCDH to CCDH to OCR civil monetary penalties or other enforcement for any HIPAA violations other than the Covered Conduct.
Perhaps even more noteworthy given the HITECH Act’s provisions coordinating the civil and criminal sanctions of HIPAA, while the Resolution Agreement provides no clear indication that the Justice Department might be considering criminally prosecuting CCDH or any other party in relation to the Covered Conduct, the Resolution Agreement also expressly states that its provisions do not affect CCDH’s potential exposure, if any, to criminal prosecution by the Justice Department for a criminal violation of the Privacy Rules under Section 1177 of the Social Security Act.
Implications For Covered Entities & Business Associates
Covered entities and their business associates should heed the CCDH Resolution Agreement as a strong message from OCR to ensure their organizations are complying with HIPAA’s BAA and other requirements. The Resolution Agreement makes clear that the starting point of this compliance effort must be obtaining and maintaining the requisite BAAs for each BA relationship.
To position their organizations to withstand potential investigation by OCR, covered entities and BAs should start by conducting a well-documented audit within the scope of attorney-client privilege both to verify that an appropriate, signed BAA is in place for each BA relationship as well as adequacy of processes for identifying business associate relationships, ensuring that signed BAAs are in effect before BAs access any PHI, and for investigating, reporting and resolving any breaches of the HIPAA Privacy or Security Rules that may arise in the course of operations.
Conducting this audit as soon as possible is particularly important in light of reported findings of widespread compliance concerns. See HIPAA Compliance Survey Churns Up Many Business Associate Problems (January 3, 2017). As the audit process could identify potential violations or other legally sensitive concerns, covered entities and business associates generally will want to arrange for this audit and evaluation to be conducted under the supervision of legal counsel experienced with HIPAA within or pursuant to processes structured with the assistance of legal counsel within the scope of attorney-client privilege.
Beyond confirming all necessary BAAs are in place, covered entities and business associates also generally will want to evaluate the adequacy of BAs’ processes and procedures for maintaining compliance with the Privacy and Security Rules as well as processes and procedures for responding to audits, investigations and complaints, reporting and addressing breaches of electronic and other PHI and other possible compliance concerns under HIPAA and other related laws. In many instances, parties may n wish to revise and strengthen existing BAAs to more specifically define these policies and procedures more specifically as well as indemnification, cyber or other liability coverage requirements and other contractual provisions for allocating potential costs and liabilities arising from breaches, audits, investigations and other expenses associated with the administration of these provisions.
About The Author
Recognized by LexisNexis® Martindale-Hubbell® as a “AV-Preeminent” (Top 1%/ the highest) and “Top Rated Lawyer,” with special recognition as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Health Care,” “Labor & Employment,” “Tax: Erisa & Employee Benefits” and “Business and Commercial Law” by D Magazine, the author of this update is widely known for her 29 plus years’ of work in health care, health benefit, health policy and regulatory affairs and other health industry concerns as a practicing attorney and management consultant, thought leader, author, public policy advocate and lecturer.
Throughout her adult life and nearly 30-year legal career, Ms. Stamer’s legal, management and governmental affairs work has focused on helping health industry, health benefit and other organizations and their management use the law, performance and risk management tools and process to manage people, performance, quality, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer supports these organizations and their leaders on both a real-time, “on demand” basis as well as outsourced operations or special counsel on an interim, special project, or ongoing basis with strategic planning and product and services development and innovation; workforce and operations management, crisis preparedness and response as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans and insurers, managed care organizations, health care clearinghouses, their business associates, employers, banks and other financial institutions, management services organizations, professional associations, medical staffs, accreditation agencies, auditors, technology and other vendors and service providers, and others on legal and operational compliance, risk management and compliance, public policies and regulatory affairs, contracting, payer-provider, provider-provider, vendor, patient, governmental and community relations and matters including extensive involvement advising, representing and defending public and private hospitals and health care systems; physicians, physician organizations and medical staffs; specialty clinics and pharmacies; skilled nursing, home health, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing and management services organizations; consultants; investors; technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, insurers, self-insured health plans and other payers; and other health industry clients to manage and defend compliance, public policy, regulatory, staffing and other operations and risk management concerns. A core focus of this work includes work to establish and administer compliance and risk management policies; comply with requirements, investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; dealings with JCHO and other accreditation and quality organizations; investigation and defense of private litigation and other federal and state health care industry investigations and enforcement; insurance or other liability management and allocation; process and product development; managed care, physician and other staffing, business associate and other contracting; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
In the course of this work, Ms. Stamer has accumulated extensive experience helping health industry clients manage workforce, medical staff, vendors and suppliers, medical billing, reimbursement, claims and other provider-payer relations, business partners, and their recruitment, performance, discipline, compliance, safety, compensation, benefits, and training, board, medical staff and other governance; compliance and internal controls; strategic planning, process and quality improvement; change management; assess, deter, investigate and address staffing, quality, compliance and other performance; meaningful use, EMR, HIPAA and other data security and breach and other health IT and data; crisis preparedness and response; internal, government and third-party reporting, audits, investigations and enforcement; government affairs and public policy; and other compliance and risk management, government and regulatory affairs and operations concerns.
Author of leading works on HIPAA and other privacy and data security works and the scribe leading the American Bar Association Joint Committee on Employee Benefits Annual Agency Meeting with OCR, her experience includes extensive compliance, risk management and data breach and other crisis event investigation, response and remediation under HIPAA and other laws.
The American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, a Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Member and Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has worked closely with a diverse range of physicians, hospitals and healthcare systems, DME, Pharma, clinics, health care providers, managed care, insurance and other health care payers, quality assurance, credentialing, technical, research, public and private social and community organizations, and other health industry organizations and their management deal with governance; credentialing, patient relations and care; staffing, peer review, human resources and workforce performance management; outsourcing; internal controls and regulatory compliance; billing and reimbursement; physician, employment, vendor, managed care, government and other contracting; business transactions; grants; tax-exemption and not-for-profit; licensure and accreditation; vendor selection and management; privacy and data security; training; risk and change management; regulatory affairs and public policy and other concerns.
Past Chair of the ABA Managed Care & Insurance Interest Group and, a Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also has extensive health care reimbursement and insurance experience advising and defending health care providers, payers, and others about Medicare, Medicaid, Medicare and Medicaid Advantage, Tri-Care, self-insured group, association, individual and group and other health benefit programs and coverages including but not limited to advising public and private payers about coverage and program design and documentation, advising and defending providers, payers and systems and billing services entities about systems and process design, audits, and other processes; provider credentialing, and contracting; providers and payer billing, reimbursement, claims audits, denials and appeals, coverage coordination, reporting, direct contracting, False Claims Act, Medicare & Medicaid, ERISA, state Prompt Pay, out-of-network and other nonpar, insured, and other health care claims, prepayment, post-payment and other coverage, claims denials, appeals, billing and fraud investigations and actions and other reimbursement and payment related investigation, enforcement, litigation and actions.
Heavily involved in health care and health information technology, data and related process and systems development, policy and operations innovation and a Scribe for ABA JCEB annual agency meeting with OCR for many years who has authored numerous highly-regarded works and training programs on HIPAA and other data security, privacy and use, Ms. Stamer also is widely recognized for her extensive work and leadership on leading edge health care and benefit policy and operational issues including meaningful use and EMR, billing and reimbursement, quality measurement and reimbursement, HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and many other concerns.
In connection with this work, Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others.
Her work includes both regulatory and public policy advocacy and thought leadership, as well as advising and representing a broad range of health industry and other clients about policy design, drafting, administration, business associate and other contracting, risk assessments, audits and other risk prevention and mitigation, investigation, reporting, mitigation and resolution of known or suspected violations or other incidents and responding to and defending investigations or other actions by plaintiffs, DOJ, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others.
In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, MGMA, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy concerns in Pensions, healthcare, workforce, immigration, tax, education and other areas.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on these and other related concerns by her service in the leadership of the Solutions Law Press, Inc. Coalition for Responsible Health Policy, its PROJECT COPE: Coalition on Patient Empowerment, and a broad range of other professional and civic organizations including North Texas Healthcare Compliance Association, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children (now Warren Center For Children); current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, past Representative and chair of various committees of ABA Joint Committee on Employee Benefits; a ABA Health Law Coordinating Council representative, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposium and chair, faculty member and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, Insurance Thought Leadership and many other prominent publications and speaks and conducts training for a broad range of professional organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating your profile here.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved. For information about republication or other use, please contact Ms. Stamer here.
Comments Off on Latest HIPAA Resolution Agreement Drives Home Importance Of Maintaining Current, Signed Business Associate Agreements |
ARRA, Attorney-Client Privilege, Cafeteria Plans, church plan, Civil Monetary Penalties, Civil Rights, Claims, Consumer Protection, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, employee, Employee Benefits, Employer, Employers, Employment, HIPAA, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Internal Investigations, Patient Empowerment, Physician, Plan Admistrator, Privacy, Professional Liability, Protected Health Information, Provider, Risk Management, Uncategorized | Tagged: Business Associate, Health Care, Health Insurer, Health Plans, HIPAA, HIPAA OCR, HIPAA Privacy, HITECH, Insurer, Technology, tpa |
Permalink
Posted by Cynthia Marcotte Stamer
February 2, 2017
A just-announced $3.2 million Health Insurance Portability & Accountability Act (HIPAA) Civil Monetary Penalty (CMP) paid by Children’s Medical Center of Dallas (Children’s) for failing to adequately secure electronic protected health information (ePHI) and correct other HIPAA compliance deficiencies teaches many key lessons for employer and other health plans and insurers, healthcare clearinghouses, healthcare providers and their business associates (“Covered Entities”) about mistakes to avoid in managing not only ePHI on laptops and mobile devices, as well as their overall HIPAA compliance and risk management.
The Department of Health & Human Services (HHS) Office of Civil Rights (OCR) imposed the $3,217,000.00 Civil Monetary Penalty (CMP) under a January 18, 2017 Final Determination based upon findings that Children’s for years knowingly violated HIPAA by failing to encrypt or otherwise properly secure ePHI on laptops and other mobile devices and failing to comply with many other HIPAA requirements. OCR originally notified Children’s of its intention to impose the CMP based on findings of widespread violations by Children’s of HIPAA in a September 30, 2016 Notice of Proposed Determination (Proposed Determination) that OCR sent to Children’s President of System Clinical Operations, David Berry. Although the Proposed Determination included instructions for requesting a hearing on the Proposed Determination, Children’s paid the CMP rather than exercising these hearing rights.
Evidence Children’s Ignored Repeated Notices of Violations For Years
According to the Proposed Determination, OCR uncovered widespread HIPAA violations by Children’s while investigating the HIPAA compliance of the Dallas-based pediatric health and hospital system in response to two separate notices of large breaches of ePHI that Children’s filed with OCR in response to the HIPAA Breach Notification Rule. Under the Breach Notification Rule, Covered Entities generally must provide notice of any breach of unsecured ePHI involving more than 500 individuals with OCR, subjects of the breached ePHI and the media within 60 days of receiving notice of the breach. In contrast, for breaches of unsecured ePHI involving fewer than 500 individuals, Covered Entities generally must notify subjects of the breached ePHI within 60 days, but can delay notification to OCR until filing a consolidated annual report of small breaches of ePHI.
The two breach notifications that triggered the OCR investigation leading to the CMP both involved losses of mobile devices containing ePHI that Children’s filed with OCR.
The first breach report, filed on January 18, 2010, notified OCR of the loss at the Dallas/Fort Worth International Airport on November 19, 2009 of an unencrypted, non-password protected BlackBerry device containing the ePHI of approximately 3,800 individuals.
The second reported breach report filed on July 5, 2013, reported the theft of an unencrypted laptop with the ePHI of 2,462 individuals from its premises sometime between April 4 and April 9, 2013. The OCR investigation found that although Children’s implemented some physical safeguards to the operating room storage area (e.g., badge access was required, and a security camera was present at one of the entrances), it also provided access to the area to staff who were not authorized to access ePHI. Children’s janitorial staff had unrestricted access to the area where the laptop was stored but did not provide encryption to protect the ePHI on the laptop from access by such unauthorized persons. Children’s internal investigation concluded that the laptop was probably stolen by a member of the janitorial staff.
In the course of investigating these two reported breaches, OCR took note that Children’s previously reported a small breach of unsecured ePHI on an unencrypted mobile device. In a letter dated August 22, 2011, from Children’s Vice President of Compliance and Internal Audit and Chief Compliance Officer Ron Skillens to OCR Equal Opportunity Specialist Jamie Sorley, Mr. Skillens stated that a Children’s workforce member (an unidentified medical resident) lost an iPod device in December 2010. The iPod had been synched to the resident’s Children’s email account, which resulted in the ePHI of at least 22 individuals being placed on the device. The ePHI on the iPod was not encrypted. The loss of the iPod resulted in the impermissible disclosure of ePHI by the medical resident. OCR concluded the ePHI of 22 individuals was impermissibly disclosed, because the workforce member and agent of Children’s provided access to any unauthorized person who discovered the device.
- OCR found that the breaches resulted from Children’s violation of the HIPAA Security Rule by failing to encrypt laptops and other mobile devices or and implement other appropriate safeguards for the protection of ePHI on mobile devices;
- Failing to appropriately document its decision to not implement encryption on mobile devices and any applicable rationale behind a decision to use alternative security measures to encryption; and
- Failing to implement security measures that were an equivalent alternative to the security protection available from encryption solutions.
The Proposed Determination also reports that the OCR ’s investigation revealed that Children repeatedly over several years knowingly failed to implement and administer proper encryption and other safeguards on laptops and other mobile devices containing ePHI despite actual knowledge of the unaddressed risks to unencrypted ePHI in violation of the HIPAA Security Rule dating back to at least 2007. The Proposed Determination notes, for instance, that:
- A Security Gap Analysis and Assessment conducted for Children’s December 2006-February 2007 by Strategic Management Systems, Inc. (SMS) (SMS Gap Analysis) identified the absence of risk management as a major finding and recommended that Children’s implement encryption to avoid loss of PHI on stolen or lost laptops.
- A separate PricewaterhouseCoopers (PwC) analysis of threats and vulnerabilities to certain ePHI (PwC Analysis) conducted in August, 2008 for Children’s determined that encryption was necessary and appropriate. The PwC Analysis also determined that a mechanism was not in place to protect data on a laptop, workstation, mobile device, or USB thumb drive if the device was lost or stolen and identified the loss of data at rest through unsecured mobile devices as being “high” risk. PwC identified data encryption as a “high priority” item and recommended that Children’s implement data encryption in the fourth quarter of 2008.
- Furthermore, in September 2012, the HHS Office of the Inspector General (OIG) issued the findings from its audit of Children’s that focused on information technology controls for devices such as smartphones and USB drives. Among other things, the report, entitled “Universal Serial Bus Control Weaknesses Found at Children’s Medical Center,” found that Children’s had insufficient controls to prevent data from being written onto unauthorized and unencrypted USB devices and that “without sufficient USB controls, there was a risk that ePHI could have been written onto an unauthorized/unencrypted USB device and taken out of the hospital, resulting in a data breach.” A copy of this report was provided to Mr. Skillens.
- Despite the prior breach notifications and warnings from the SMS Gap Analysis, the PwC Analysis and the OIG audit report, Children’s failed to take the necessary steps to encrypt and otherwise safeguard its ePHI on mobile devices. Children’s still had not implemented encryption on all devices as of April 9, 2013 even though appropriate commercial encryption products were available to achieve encryption of laptops, workstations, mobile devices, and USB thumb drives in use by Children’s staff by, at least, the time of the PwC Analysis in 2008. Furthermore, while leaving these deficiencies unresolved, the Proposed Determination notes that Children’s issued unencrypted BlackBerry devices to nurses beginning in 2007 and allowed its workforce members to continue using unencrypted laptops and other mobile devices until at least April 9, 2013 despite the findings of SMS and PwC and Children’s actual knowledge about the risk of maintaining unencrypted ePHI on its devices.
Based on this evidence, OCR concluded that Children’s had “actual knowledge” of the unaddressed threats to ePHI as early as March 2007 and at least one year prior to the reported security incidents. Furthermore, OCR also found that Children’s additionally violated HIPAA by failing to implement sufficient policies and procedures governing the receipt and removal of hardware and electronic media that contain ePHI into and out of its facility, and the movement of these items within the facility prior to at least November 9, 2012. Prior to November 2012, Children’s information technology (IT) assets were inventoried and managed separately from the inventory of devices used within its Biomedical Department. Children’s IT asset policies did not apply to devices that accessed or stored ePHI that were managed by the Biomedical Department. Consequently, Children’s was unable to identify all devices to which the device and media control policy should apply prior to completing a full-scope inventory to identify all information systems containing ePHI in November 9, 2012. As Children’s did not conduct a complete inventory to identify all devices to which its IT asset policies apply to ensure that all devices were covered by its device and media control policies, the Proposed Determination concluded Children’s was out of compliance with the Security Rule at 45 C.P.R. § 164.310(d)(l).
After OCR’s investigation indicated widespread Privacy and Security Rule noncompliance by Children’s, the Proposed Determination states that OCR attempted to negotiate a resolution with Children’s through its informal resolution agreement process from approximately November 6, 2015, to August 30, 2016. When these efforts failed, OCR issued a May 10,2016 Letter of Opportunity that formally informed Children’s that since OCR had been unable to resolve its findings that Children’s violated the Privacy and Security Rules by informal means, OCR was informing Children’s of the preliminary indications of non-compliance and providing Children’s with an opportunity to submit written evidence of mitigating factors under 45 C.F.R. § 160.408 or affirmative defenses under 45 C.F.R. § 160.410 for OCR’s consideration in making a determination of a CMP pursuant to 45 C.F.R. § 160.404. The letter stated that Children’s could also submit written evidence to support a waiver of a CMP for the indicated areas of non-compliance. Each of Children’s indicated acts of noncompliance and the potential CMP for them were described in the letter. The letter was delivered to Children’s and received by Children’s agent on May 12, 2016.
Children’s responded to OCR’s letter on or about June 9, 2016. The Proposed Determination states that OCR determined that the information and arguments submitted by Children’s in its June 9, 2016 letter did not support an affirmative defense pursuant to 45 C.F.R. § 160.410 or a waiver of the CMP pursuant to 45 C.F.R. § 160.412. Accordingly, OCR notified Children’s in its September 30, 2016 Proposed Determination of OCR’s intent to implement the $3,217,000.00 CMP and procedures for appealing this planned CMP assessment. When Children’s did not file an appeal, OCR issued the Final Determination assessing the CMP. OCR reports that Children now has paid the $3,217,000.00 CMP.
Important Lessons For Other Covered Entities
The Children’s CMP and underlying circumstances provide many key lessons for other Covered Entities. Obviously, the Final Decision drives home the importance of:
- Proper encryption and other security and access controls of devices and systems containing ePHI; and
- Proper documentation of risk assessments, audits, breach investigations and other events, compliance analysis and conclusions taken in response, and corrective actions selected and implemented in response to these events.
Beyond the importance of documented compliance with encryption and other requirements, the Children’s CMP and its associated Proposed Determination and Final Determinations also illustrate the importance of proper behavior in response to a known or suspected breach. The Proposed Determination and Final Determination make clear that beyond the breaches uncovered in the course of the investigation, OCR’s decision to implement the CMP was influenced by, among other things:
- OCR investigates all large breach reports;
- Small breach reports can count too;
- The recurrent disregard and failure by Children to act to address the HIPAA security violations over a period of years despite both repeated notifications of its noncompliance and actual breaches resulting from these compliance deficiencies; and
- The failure of Children’s to cooperate with OCR to reach a voluntary resolution agreement which might have allowed Children to resolve its liability for the breaches OCR found by paying a potentially smaller settlement payment and implementing corrective actions to OCR’s satisfaction.
About The Author
Recognized by LexisNexis® Martindale-Hubbell® as a “AV-Preeminent” (Top 1%/ the highest) and “Top Rated Lawyer,” with special recognition as “LEGAL LEADER™ Texas Top Rated Lawyer” in Health Care Law and Labor and Employment Law; as among the “Best Lawyers In Dallas” for her work in the fields of “Labor & Employment,” “Tax: Erisa & Employee Benefits,” “Health Care” and “Business and Commercial Law” by D Magazine, the author of this update is widely known for her 28 plus years’ of work in health care, health benefit, health policy and regulatory affairs and other health industry concerns as a practicing attorney and management consultant, thought leader, author, public policy advocate and lecturer.
Throughout her adult life and nearly 30-year legal career, Ms. Stamer’s legal, management and governmental affairs work has focused on helping health industry, health benefit and other organizations and their management use the law, performance and risk management tools and process to manage people, performance, quality, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps these and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup legal and operational crises large and small that arise in the course of operations.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, current American Bar Association (ABA) International Section Life Sciences Committee Vice Chair, Scribe for the ABA Joint Committee on Employee Benefits (JCEB) Annual OCR Agency Meeting, former Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Section, past ABA JCEB Council Representative, past Board President of Richardson Development Center (now Warren Center) for Children Early Childhood Intervention Agency, past North Texas United Way Long Range Planning Committee Member, and past Board Compliance Chair of the National Kidney Foundation of North Texas, and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer’s includes nearly 30 years’ of work with a diverse range of health industry clients on an extensive range of matters.
Ms. Stamer has worked closely with health industry, managed care and insurance and other businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of staffing, human resources and workforce performance management, internal controls and regulatory compliance, change management and other performance and operations management and compliance. She supports her clients both on a real-time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
As a core component of her work, Ms. Stamer has worked extensively throughout her career with health care providers, health plans and insurers, managed care organizations, health care clearinghouses, their business associates, employers, banks and other financial institutions, management services organizations, professional associations, medical staffs, accreditation agencies, auditors, technology and other vendors and service providers, and others on legal and operational compliance, risk management and compliance, public policies and regulatory affairs, contracting, payer-provider, provider-provider, vendor, patient, governmental and community relations and matters including extensive involvement advising, representing and defending public and private hospitals and health care systems; physicians, physician organizations and medical staffs; specialty clinics and pharmacies; skilled nursing, home health, rehabilitation and other health care providers and facilities; medical staff, accreditation, peer review and quality committees and organizations; billing and management services organizations; consultants; investors; technology, billing and reimbursement and other services and product vendors; products and solutions consultants and developers; investors; managed care organizations, insurers, self-insured health plans and other payers; and other health industry clients to establish and administer compliance and risk management policies; comply with requirements, investigate and respond to Board of Medicine, Health, Nursing, Pharmacy, Chiropractic, and other licensing agencies, Department of Aging & Disability, FDA, Drug Enforcement Agency, OCR Privacy and Civil Rights, Department of Labor, IRS, HHS, DOD, FTC, SEC, CDC and other public health, Department of Justice and state attorneys’ general and other federal and state agencies; JCHO and other accreditation and quality organizations; private litigation and other federal and state health care industry investigation, enforcement including insurance or other liability management and allocation; process and product development, contracting, deployment and defense; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others, and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns.
Heavily involved in health care and health information technology, data and related process and systems development, policy and operations innovation and a Scribe for ABA JCEB annual agency meeting with OCR for many years who has authored numerous highly-regarded works and training programs on HIPAA and other data security, privacy and use, Ms. Stamer also is widely recognized for her extensive work and leadership on HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and concerns including policy design, drafting, administration and training; business associate and other contracting; risk assessments, audits and other risk prevention and mitigation; investigation, reporting, mitigation and resolution of known or suspected breaches, violations or other incidents; and defending investigations or other actions by plaintiffs, OCR, FTC, state attorneys’ general and other federal or state agencies, other business partners, patients and others. Ms. Stamer has worked extensively with health care providers, health plans, health care clearinghouses, their business associates, employers and other plan sponsors, banks and other financial institutions, and others on risk management and compliance with HIPAA, FACTA, trade secret and other information privacy and data security rules, including the establishment, documentation, implementation, audit and enforcement of policies, procedures, systems and safeguards, investigating and responding to known or suspected breaches, defending investigations or other actions by plaintiffs, OCR and other federal or state agencies, reporting known or suspected violations, business associate and other contracting, commenting or obtaining other clarification of guidance, training and enforcement, and a host of other related concerns. Her clients include public and private health care providers, health insurers, health plans, technology and other vendors, and others. In addition to representing and advising these organizations, she also has conducted training on Privacy & The Pandemic for the Association of State & Territorial Health Plans, as well as HIPAA, FACTA, PCI, medical confidentiality, insurance confidentiality and other privacy and data security compliance and risk management for Los Angeles County Health Department, ISSA, HIMMS, the ABA, SHRM, schools, medical societies, government and private health care and health plan organizations, their business associates, trade associations and others.
A former lead consultant to the Government of Bolivia on its Pension Privatization Project with extensive domestic and international public policy and governmental and regulatory affairs experience, Ms. Stamer also is widely recognized for regulatory and policy work, advocacy and outreach on healthcare, education, aging, disability, savings and retirement, workforce, ethics, and other policies. Throughout her adult life and career, Ms. Stamer has provided thought leadership; policy and program design, statutory and regulatory development design and analysis; drafted legislation, proposed regulations and other guidance, position statements and briefs, comments and other critical policy documents; advised, assisted and represented health care providers, health plans and insurers, employers, professional. and trade associations, community and government leaders and others on health care, health, pension and retirement, workers’ compensation, Social Security and other benefit, insurance and financial services, tax, workforce, aging and disability, immigration, privacy and data security and a host of other international and domestic federal, state and local public policy and regulatory reforms through her involvement and participation in numerous client engagements, founder and Executive Director of the Coalition for Responsible Health Policy and its PROJECT COPE: the Coalition on Patient Empowerment, adviser to the National Physicians Congress for Healthcare Policy, leadership involvement with the US-Mexico Chamber of Commerce, the Texas Association of Business, the ABA JCEB, Health Law, RPTE, Tax, Labor, TIPS, International Life Sciences, and other Sections and Committees, SHRM Governmental Affairs Committee and a host of other involvements and activities.
A popular lecturer and widely published author on health industry concerns, Ms. Stamer continuously advises health industry clients about compliance and internal controls, workforce and medical staff performance, quality, governance, reimbursement, privacy and data security, and other risk management and operational matters. Ms. Stamer also publishes and speaks extensively on health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her insights on these and other related matters appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications.
Beyond her extensive involvement advising and representing clients on privacy and data security concerns and other health industry matters, Ms. Stamer also has served for several years as a scrivener for the ABA JCEB’s meeting with OCR, the Chair of the Southern California ISSA Health Care Privacy & Security Summit, and an editorial advisory board member, author, program chair or steering committee member, and faculties for a multitude of other programs and publications regarding privacy, data security, technology and other compliance, risk management and operational concerns in the health care, health and other insurance, employee benefits and human resources, retail, financial services and other arenas.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares her thought leadership, experience and advocacy on HIPAA and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as the Vice Chair of the North Texas Healthcare Compliance Association, Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE: Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Board Compliance Chair and Board member of the National Kidney Foundation of North Texas, current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Council, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposium and chair, faculty member and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, Insurance Thought Leadership and many other prominent publications and speaks and conducts training for a broad range of professional organizations.
For more information about Ms. Stamer or her health industry and other experience and involvements, see here or contact Ms. Stamer via telephone at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources here such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or your profile here.
©2017 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Learn Key Lessons From $3.2M+ Children’s HIPAA CMP |
compliance, Corporate Compliance, Employer, Employers, health plan, Health Plans, Privacy, Protected Health Information, Uncategorized, Union | Tagged: Children's MEdical Center, civil monetary penalty, CMP, Data Privacy, Data Security, Health Data Privacy, Health Plans, HIPAA, Mobile Device, PHI, Privacy, Protected Health Information, Security, Technology |
Permalink
Posted by Cynthia Marcotte Stamer
May 31, 2016
Self-insured employer or union sponsored health plans (Plans), their fiduciaries, third party administrative or other service providers, and sponsors should consult legal counsel for advice about whether their Plans might violate the Privacy Rule of the Health Insurance Portability & Accountability Act (HIPAA) by disclosing individually identifiable claims or other Plan records or data to a state “all payer” claims or other data base in response to a state law or regulation mandating those disclosures in light of the Supreme Court’s recent ruling in Gobeille v. Liberty Mutual, 136 S. Ct. 936 (2016).
Gobeille involved a challenge to a Vermont “all payer” law similar to laws enacted by at least 20 other states, that requires health plan payers, their administrators or both to disclose individually identifiable health claims and other claims data about Plan members to a state created all payer data base. The Vermont law challenged in Gobeille required health insurers and other payers to disclose treatment information about Plan members as well as other certain health care claim payment and other data to an all payer claims database, which under the law is made “available as a resource for insurers, employers, providers, purchasers of health care, and State agencies to continuously review health care utilization, expenditures, and performance in Vermont. See Gobeille at 941. Vermont’s law requires third party administrators of self-insured Plans and other payers to disclose the information regardless of whether the member resides or received the treatment in Vermont.
In Gobeille, the Supreme Court ruled that the preemption provisions of Section 514 of the Employee Retirement Income Security Act (ERISA) bar Vermont from requiring self-insured ERISA Plans
In addition to excusing self-insured Plans from the trouble and expense of complying with Vermont’s disclosure law, the Supreme Court’s ruling in Gobeille that Vermont cannot enforce the law against self-insured ERISA Plans raises a concern that the Privacy Rules of HIPAA may prohibit Plans from disclosing certain individually identifiable claims information. The HIPAA compliance concern arises because the claims information and other data that the Vermont and most other similar laws require Plans and other payers to disclose generally is or include information that qualifies as “protected health information” within the meaning of the HIPAA Privacy Rule. These laws generally are structured either to directly require self-insured Plans to disclose the claims data directly, indirectly compel the disclosure by requiring third party administrators of such Plans to disclose the claims information for Plans they administer, or both.
Under the HIPAA Privacy Rule, Plans and other HIPAA-covered entities and service providers acting as business associates of the Plans are prohibited from using or disclosing individually identifiable protected health information unless the use or disclosure is expressly authorized by the Privacy Rule. Since violations of the Privacy Rule trigger substantial civil or even criminal penalties under HIPAA, Plans, their fiduciaries, service providers acting as business associates and other members of their workforce need to verify that the disclosure meets all of the requirements to fall within an exception to the Privacy Rule’s prohibition against disclosure before allowing such a disclosure
Before Gobeille, many self-insured Plans and their administrators treated the disclosures of individually identifiable claims data of the Plans as permitted as a disclosure “required by law” Privacy § 164.512(a), which provides in relevant part:
- a) Standard: Uses and disclosures required by law.
(1) A covered entity may use or disclose protected health information to the extent that such use or disclosure is required by law and the use or disclosure complies with and is limited to the relevant requirements of such law.
(2) A covered entity must meet the requirements described in paragraph (c), (e), or (f) of this section for uses or disclosures required by law.
The Gobeille ruling that that the Vermont law is unenforceable against self-insured Plans appears to eliminate the availability of this exception as a basis for allowing disclosures in response to the Vermont law as well as calls into question the ability of Plans to rely upon the “required by law” exception to the Privacy Rule to justify disclosures of protected health information to state all payer data bases in response to similar requirements enacted in the other 20 states that have enacted similar mandates. Plans that previously disclose or intend in the future to disclose protected health information to a state all payer data base in Vermont or another state generally will want to carefully document their justification, if any for making that disclosure under the Privacy Rule.
Unless the disclosure otherwise falls within another exception to the HIPAA Privacy Rule against disclosures without authorization, Plans, their sponsors, fiduciaries, third party administrators and other service providers and other members of the Plan workforce at minimum should be concerned that the HIPAA risks of disclosing protected health information in response to these state mandates after Gobeille. Plans that decide not to disclose information otherwise required by such state law requirements in light of the Gobeille ruling or HIPAA concerns may want to consult with qualified legal counsel about the steps, if any, that the Plan might want to take to document its ERISA preemption or other justifications for not providing the otherwise required disclosures.
Beyond evaluating the advisability of future disclosures in response to the Vermont or another similar all payer statute, Plans whose data previously was disclosed by the Plan or its administrator to an all payer data base under the belief that the disclosure was required by law also may want to seek the advice of qualified legal counsel about whether these prior disclosures triggered breach notification responsibilities under the Breach Notification rules of HIPAA with respect to any disclosures previously made. When electronic protected health information is used or disclosed in violation of HIPAA, the Breach Notification Rules of HIPAA generally require Plans and their business associates timely notify impacted individuals and the Department of Health & Human Services Office of Civil Rights (OCR) in accordance with the detailed requirements set forth in OCR’s implementing regulations. Furthermore, where a breach involves 500 or more individuals, the timetable for providing notification to OCR is accelerated and the Plan also is required to provide notification to the media and others.
About The Author
Cynthia Marcotte Stamer is a noted Texas-based management lawyer and consultant, author, lecturer and policy advocate, recognized for her nearly 30-years of cutting edge management work as among the “Top Rated Labor & Employment Lawyers in Texas” by LexisNexis® Martindale-Hubbell® and as among the “Best Lawyers In Dallas” for her work in the field of “Tax: Erisa & Employee Benefits” and “Health Care” by D Magazine.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a Fellow in the American College of Employee Benefit Counsel, past Chair and current committee Co-Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, a former ABA Joint Committee on Employee Benefits Council Representative and , Ms. Stamer helps management manage.
Ms. Stamer’s legal and management consulting work throughout her nearly 30-year career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce and other legal and operational crises large and small that arise in the course of operations.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce, internal controls and regulatory compliance, change management and other performance and operations management and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Well known for her extensive work with health care, insurance and other highly regulated entities on corporate compliance, internal controls and risk management, her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes. Common engagements include internal and external workforce hiring, management, training, performance management, compliance and administration, discipline and termination, and other aspects of workforce management including employment and outsourced services contracting and enforcement, sentencing guidelines and other compliance plan, policy and program development, administration, and defense, performance management, wage and hour and other compensation and benefits, reengineering and other change management, internal controls, compliance and risk management, communications and training, worker classification, tax and payroll, investigations, crisis preparedness and response, government relations, safety, government contracting and audits, litigation and other enforcement, and other concerns.
Ms. Stamer uses her deep and highly specialized health, insurance, labor and employment and other knowledge and experience to help employers and other employee benefit plan sponsors; health, pension and other employee benefit plans, their fiduciaries, administrators and service providers, insurers, and others design legally compliant, effective compensation, health and other welfare benefit and insurance, severance, pension and deferred compensation, private exchanges, cafeteria plan and other employee benefit, fringe benefit, salary and hourly compensation, bonus and other incentive compensation and related programs, products and arrangements. She is particularly recognized for her leading edge work, thought leadership and knowledgeable advice and representation on the design, documentation, administration, regulation and defense of a diverse range of self-insured and insured health and welfare benefit plans including private exchange and other health benefit choices, health care reimbursement and other “defined contribution” limited benefit, 24-hour and other occupational and non-occupational injury and accident, expat and medical tourism, onsite medical, wellness and other medical plans and insurance benefit programs as well as a diverse range of other qualified and nonqualified retirement and deferred compensation, severance and other employee benefits and compensation, insurance and savings plans, programs, products, services and activities. As a key element of this work, Ms. Stamer works closely with employer and other plan sponsors, insurance and financial services companies, plan fiduciaries, administrators, and vendors and others to design, administer and defend effective legally defensible employee benefits and compensation practices, programs, products and technology. She also continuously helps employers, insurers, administrative and other service providers, their officers, directors and others to manage fiduciary and other risks of sponsorship or involvement with these and other benefit and compensation arrangements and to defend and mitigate liability and other risks from benefit and liability claims including fiduciary, benefit and other claims, audits, and litigation brought by the Labor Department, IRS, HHS, participants and beneficiaries, service providers, and others. She also assists debtors, creditors, bankruptcy trustees and others assess, manage and resolve labor and employment, employee benefits and insurance, payroll and other compensation related concerns arising from reductions in force or other terminations, mergers, acquisitions, bankruptcies and other business transactions including extensive experience with multiple, high-profile large scale bankruptcies resulting in ERISA, tax, corporate and securities and other litigation or enforcement actions.
Ms. Stamer also is deeply involved in helping to influence the Affordable Care Act and other health care, pension, social security, workforce, insurance and other policies critical to the workforce, benefits, and compensation practices and other key aspects of a broad range of businesses and their operations. She both helps her clients respond to and resolve emerging regulations and laws, government investigations and enforcement actions and helps them shape the rules through dealings with Congress and other legislatures, regulators and government officials domestically and internationally. A former lead consultant to the Government of Bolivia on its Social Security reform law and most recognized for her leadership on U.S. health and pension, wage and hour, tax, education and immigration policy reform, Ms. Stamer works with U.S. and foreign businesses, governments, trade associations, and others on workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment and a Fellow in the American Bar Foundation and State Bar of Texas, Ms. Stamer annually leads the Joint Committee on Employee Benefits (JCEB) HHS Office of Civil Rights agency meeting and other JCEB agency meetings. She also works as a policy advisor and advocate to many business, professional and civic organizations.
Author of the thousands of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer also is a highly sought out speaker and industry thought leader known for empowering audiences and readers. Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications. Ms. Stamer also regularly serves on the faculty and planning committees for symposia of LexisNexis, the American Bar Association, ALIABA, the Society of Employee Benefits Administrators, the American Law Institute, ISSA, HIMMs, and many other prominent educational and training organizations and conducts training and speaks on these and other management, compliance and public policy concerns.
Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer serves on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and as an editorial advisor and contributing author of many other publications. Her leadership involvements with the American Bar Association (ABA) include year’s serving many years as a Joint Committee on Employee Benefits Council representative; ABA RPTE Section current Practice Management Vice Chair and Substantive Groups & Committees Committee Member, RPTE Employee Benefits & Other Compensation Committee Past Group Chair and Diversity Award Recipient, current Defined Contribution Plans Committee Co-Chair, and past Welfare Benefit Plans Committee Chair Co-Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; International Section Life Sciences Committee Policy Vice Chair; and a speaker, contributing author, comment chair and contributor to numerous Labor, Tax, RPTE, Health Law, TIPS, International and other Section publications, programs and task forces. Other selected service involvements of note include Vice President of the North Texas Healthcare Compliance Professionals Association; past EO Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a former Southwest Benefits Association Board of Directors member, Continuing Education Chair and Treasurer; former Texas Association of Business BACPAC Committee Member, Executive Committee member, Regional Chair and Dallas Chapter Chair; former Society of Human Resources Region 4 Chair and Consultants Forum Board Member and Dallas HR Public Policy Committee Chair; former National Board Member and Dallas Chapter President of Web Network of Benefit Professionals; former Dallas Business League President and others. For additional information about Ms. Stamer, see CynthiaStamer.com or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal control and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at Solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. ©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc. ™. All other rights reserved.
Comments Off on Health Plans Disclosing Data To State All Payer Data Banks Face HIPAA Risks |
Brokers, Civil Rights, Claims, Claims Administration, Corporate Compliance, Cybercrime, Data Breach, Data Security, EBSA, employee, Employee Benefits, Employer, Employers, Employment, ERISA, fiduciary duty, Fiduciary Responsibility, health benefit, Health Benefits, health Care, health insurance, health plan, Health Plans, health reform, HIPAA, HIPAA, HR, Human Resources, insurers, Internal Controls, Internal Investigations, Patient Empowerment, Preemption, Privacy, Reporting & Disclosure, Uncategorized |
Permalink
Posted by Cynthia Marcotte Stamer
March 22, 2016

Employer and union sponsored health plans, their sponsors, fiduciaries, and business associates should brace for audits and enforcement of the Privacy, Security, and Breach Notification rules by the Department of Health & Human Service Office of Civil Rights (OCR) follow OCR’s 2016 audit program on the heels of its announcement last week of two large HIPAA settlements last week.
OCR confirmed today it is sending emails notifying health plans, healthcare providers, healthcare clearing houses (Covered Entities) and their business associates identified as part of the kickoff of its next phase of audits of Covered Entities. In light of the HIPAA verification rules and the notorious spread of opportunistic identity theft and other fraud by opportunistic Cybercriminals following these types of announcements, Covered Entities and business associates should carefully verify the requests validity and manage the response to avoid violating HIPAA in responding and position for defensibility against potential penalties.
Even if health plans or other Covered Entities reviewed their practices in the last 12-months, most will want to update this review in response to new OCR guidance and enforcement actions, including new guidance on obligations to provide plan members or other subjects of protected health information with access to or copies of their records and other guidance, as well as the ever-expanding list of enforcement actions by OCR.
To catch up on this latest guidance, Solutions Law Press, Inc. ™ invites you to register to participate in a special WebEx briefing on “HIPAA Update: The Latest On Security, Patient Access & Other HIPAA Developments” on Wednesday, March 30, 2016 beginning at Noon Central Time on Wednesday, March 30, 2016.
2016 Audit Program
In its 2016 Phase 2 HIPAA Audit Program, OCR will review the policies and procedures adopted and employed by Covered Entities and their business associates to meet selected standards and implementation specifications of the Privacy, Security, and Breach Notification Rules. OCR says it will primarily conduct these audits as desk audits, although some on-site audits will be conducted.
According to today’s announcement, the 2016 audit process begins with verification of an entity’s address and contact information. OCR is sending emails to Covered Entities and business associates requesting that contact information be provided to OCR on time. OCR will then send a pre-audit questionnaire to gather data about the size, type, and operations of potential audit targets. OCR says this data will be used with other information to create potential audit subject pools. Recipients should contact qualified legal counsel immediately for advice and assistance about proper procedures to verify the email is in fact from OCR and for assistance in responding.
If an entity does not respond to OCR’s request to verify its contact information or pre-audit questionnaire, OCR will use publicly available information about the entity to create its audit subject pool. Therefore an entity that does not respond to OCR may still be selected for an audit or subject to a compliance review. Communications from OCR will be sent via email and may be incorrectly classified as spam. If your entity’s spam filtering and virus protection are automatically enabled, OCR expects entities to check their junk or spam email folder for emails from OCR.
The announcement also reflects that OCR is still developing other aspects of the audit program. OCR will post updated audit protocols on its website closer to conducting the 2016 audits. The audit protocol will be updated to reflect the HIPAA Omnibus Rulemaking and can be used as a tool by organizations to conduct their own internal self-audits as part of their HIPAA compliance activities.
OCR says its audits will enhance industry awareness of compliance obligations and enable OCR to better target technical assistance regarding problems identified through the audits. Through the information gleaned from the audits, OCR will develop tools and guidance to aid the industry in compliance self-evaluation and in preventing breaches. OCR plans to use results and procedures used in the phase 2 audits to develop its permanent HIPAA audit program.
OCR Settlements Show Enforcement Risk
The audit program announcement comes less than a week after OCR announced millions of dollars of new penalties under settlements with two Covered Entities:
- A $1,555,000 settlement with North Memorial Health Care of Minnesota;
- A $3.9 million settlement with Feinstein Institute for Medical Research.
The two settlements drive home again the substantial liability that health care providers, health plans, health care clearinghouses and their business associates risk for violating HIPAA.
Feinstein Settlement
Feinstein is a biomedical research institute organized as a New York not-for-profit corporation sponsored by Northwell Health, Inc., formerly known as North Shore Long Island Jewish Health System, a large health system headquartered in Manhasset, New York comprised of 21 hospitals and over 450 patient facilities and physician practices.
OCR’s investigation began after Feinstein filed a breach report indicating that on September 2, 2012, a laptop computer containing the electronic protected health information (ePHI) of approximately 13,000 patients and research participants was stolen from an employee’s car. The ePHI stored in the laptop included the names of research participants, dates of birth, addresses, social security numbers, diagnoses, laboratory results, medications, and medical information about potential participation in a research study.
OCR’s investigation discovered that Feinstein’s security management process was limited in scope, incomplete, and insufficient to address potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI held by the entity. Further, Feinstein lacked policies and procedures for authorizing access to ePHI by its workforce members, failed to implement safeguards to restrict access to unauthorized users, and lacked policies and procedures to govern the receipt and removal of laptops that contained ePHI into and out of its facilities. For electronic equipment procured outside of Feinstein’s standard acquisition process, Feinstein failed to implement proper mechanisms for safeguarding ePHI as required by the Security Rule.
“Research institutions subject to HIPAA must be held to the same compliance standards as all other HIPAA-covered entities,” said OCR Director Jocelyn Samuels. “For individuals to trust in the research process and for patients to trust in those institutions, they must have some assurance that their information is kept private and secure.”
The resolution agreement and corrective action plan may be found on the OCR website at http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/Feinstein/index.html.
North Memorial
The Feinstein settlement announcement follows yesterday’s announcement of a $1.5 million plus settlement with North Memorial to resolve HIPAA charges that it failed to implement a business associate agreement with a major contractor and failed to institute an organization-wide risk analysis to address the risks and vulnerabilities to its patient information. North Memorial is a comprehensive, not-for-profit health care system in Minnesota that serves the Twin Cities and surrounding communities.
The settlement highlights the importance for healthcare providers, health plans, healthcare clearinghouses and their business associates to comply with HIPAA’s business associate agreement and other HIPAA organizational, risk assessment, privacy and security, and other requirements.
OCR’s announcement emphasizes the importance of meeting these requirements. “Two major cornerstones of the HIPAA Rules were overlooked by this entity,” said Director Samuels. “Organizations must have in place compliant business associate agreements as well as an accurate and thorough risk analysis that addresses their enterprise-wide IT infrastructure.”
The settlement comes from charges filed after OCR initiated its investigation of North Memorial following receipt of a breach report on September 27, 2011, which indicated that an unencrypted, password-protected laptop was stolen from a business associate’s workforce member’s locked vehicle, impacting the ePHI of 9,497 individuals.
OCR’s investigation indicated that North Memorial failed to have in place a business associate agreement, as required under the HIPAA Privacy and Security Rules, so that its business associate could perform certain payment and health care operations activities on its behalf. North Memorial gave its business associate, Accretive, access to North Memorial’s hospital database, which stored the ePHI of 289,904 patients. Accretive also received access to non-electronic protected health information as it performed services on-site at North Memorial.
The investigation further determined that North Memorial failed to complete a risk analysis to address all of the potential risks and vulnerabilities to the ePHI that it maintained, accessed, or transmitted across its entire IT infrastructure — including but not limited to all applications, software, databases, servers, workstations, mobile devices and electronic media, network administration and security devices, and associated business processes.
In addition to the $1,550,000 payment, North Memorial is required to develop an organization-wide risk analysis and risk management plan, as required under the Security Rule. North Memorial will also train appropriate workforce members on all policies and procedures newly developed or revised pursuant to this corrective action plan.
The Resolution Agreement and Corrective Action Plan can be found on the HHS website at: http://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/north-memorial-health-care/index.html.
Settlement Latest Reminder To Manage HIPAA Risks.
Following up on OCR’s imposition of its second-ever HIPAA Civil Monetary Penalty (CMP) and the latest in an ever-growing list of settlements by Covered Entities under HIPAA, these latest settlements illustrate the substantial liability that Covered Entities face for violating HIPAA. To avoid these liabilities, Covered Entities must constantly be diligent to comply with the latest guidance of OCR about their obligations under HIPAA.
As OCR continues to issue additional guidance as well as supplement this guidance through information shared in settlement agreements like the North Memorial settlement, even if Covered Entities reviewed their practices in the last 12-months, most will want to update this review in response to new OCR guidance and enforcement actions, including new guidance on obligations to provide plan members or other subjects of protected health information with access to or copies of their records and other guidance, as well as the ever-expanding list of enforcement actions by OCR.
Since the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH) amended HIPAA, Covered Entities face growing responsibilities and liability for maintaining the security of ePHI.
In response to HITECH, OCR continues to use a carrot and stick approach to encouraging and enforcing compliance. As demonstrated by OCR’s imposition of the second-ever HIPAA Civil Monetary Penalty (CMP) of $239,000 against Lincare and the ever-growing list of Resolution Agreements OCR announces with other Covered Entities, OCR continues to step up enforcement against Covered Entities that breach the Privacy and Security Rules. See OCR’s 2nd-Ever HIPAA CMP Nails Lincare For $239,000.
On the other hand, OCR also continues to encourage voluntary compliance by Covered Entities by sharing guidance and tools to aid Covered Entities to understand fulfill their HIPAA responsibilities such as the HIPAA Security Rule Crosswalk to NIST Cybersecurity Framework (Crosswalk) unveiled by OCR on February 24, 2016.The crosswalk that maps the HIPAA Security Rule to the standards of the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity (the Cybersecurity Framework) as well as mappings to certain other commonly used security frameworks.
While stating that the HIPAA Security Rule does not require use of the NIST Cybersecurity Framework, OCR says it hopes the Crosswalk will provide “a helpful roadmap” for HIPAA Covered Entities and their business associates to understand the overlap between the NIST Cybersecurity Framework, the HIPAA Security Rule, and other security frameworks that can help Covered Entities safeguard health data in a time of increasing risks and help them to identify potential gaps in their programs.
At the same time, OCR’s announcement of its release of the Crosswalk also cautions users that “use of the Framework does not guarantee HIPAA compliance.” Rather, OCR says “the crosswalk provides an informative tool for entities to use to help them more comprehensively manage security risks in their environments.
With a USA Today report attributing more than 40 percent of data breaches to the healthcare industry over the last three years 91 percent of all health organizations having reporting breaches over the last two years, OCR has made clear that it intends to zealously investigate and enforce the Security Rules against Covered Entities that violate the Security Rules against Covered Entities that fail to take suitable steps to safeguard the security of PHI as required by the HIPAA Security Rule.
To meet these requirements, the HIPAA Security Rule requires that Covered Entities conduct and be prepared to product documentation of their audit and other efforts to comply with the Security Rule Most Covered Entities will want to consider including an assessment of the adequacy of their existing practices under the Crosswalk and other requirements disclosed by OCR in these assessments to help position the Covered Entity to defend or mitigate HIPAA CMP and other liabilities in the event of a HIPAA breech or audit.
Changing Rules Complicate Compliance
In addition to maintaining adequate security, HIPAA also requires Covered Entities to provide individuals with the right to access and receive a copy of their health information from their providers, hospitals, and health insurance plans in accordance with the HIPAA Privacy Rule. In response to recurrent difficulties experienced by individuals in exercising these rights, OCR recently published supplemental guidance to clarify and promote better understanding and compliance with these rules by Covered Entities. OCR started this process in January, 2015 by releasing a comprehensive fact sheet (Access fact sheet) and the first in a series of topical frequently asked questions (FAQs) addressing patients’ right to access their medical records, which set forth requirements providers must follow in sharing medical records with patients, including that they must do so in a timely manner and in a format that works for the patient.
Earlier this month, OCR followed up by publishing on March 1, 2016 a second set of FAQs addresses additional issues, including the fees individuals may be charged for copies of their health information and the right of individuals to have their health information sent directly to a third party if they so choose.
Covered entities and their business associates should expect OCR to ask about use of these tools in audits and investigations. Accordingly, they should move quickly to review and update their business associate agreements and other practices to comply with this new guidance as well as watch for further guidance and enforcement about these practices from OCR.
Other Key HIPAA Regulatory & Enforcement Changes Raise Responsibilities & Risks
OCR’s new guidance on access to PHI follows a host of other regulatory and enforcement activities. While the particulars of each of these new actions and guidance vary, all send a very clear message: OCR expects Covered Entities and their business associates to comply with HIPAA and is offering tools and other guidance to aid them in that process. In the event of a breach or audit, Covered Entities and their business associates need to be prepared to demonstrate their efforts to comply.
Those that cannot show adequate compliance efforts should be prepared for potentially substantial CMP or Resolution Agreement payments and other sanctions.
Register For 3/30 Webex Briefing
Solutions Law Press, Inc.™ invites to catch up on the latest guidance on the Covered Entities’ responsibility under HIPAA to provide access to patients to PHI by registering here to participate in the “HIPAA Update: The Latest On Security, Patient Access & Other HIPAA Developments” Webex briefing by attorney Cynthia Marcotte Stamer that Solutions Law Press, Inc.™ will host beginning at Noon Central Time on Wednesday, March 30, 2016.
About The Author
Cynthia Marcotte Stamer is a practicing attorney and management consultant, author, public policy advocate and lecturer widely recognized for her extensive work and pragmatic thought leadership, experience, publications and training on HIPAA and other privacy, medical records and data and other health care and health plan concerns.
Recognized as “LEGAL LEADER™ Texas Top Rated Lawyer” in both Health Care Law and Labor and Employment Law, a “Texas Top Lawyer,” an “AV-Preeminent” and “Top Rated Lawyer” by Martindale-Hubble and as among the “Best Lawyers In Dallas” in employee benefits 2015 by D Magazine; Ms. Stamer has more than 28 years of extensive proven, pragmatic knowledge and experience representing and advising health industry clients and others on operational, regulatory and other compliance, risk management, product and process development, public policy and other key concerns.
As a core component of her work as the Managing Shareholder of Cynthia Marcotte Stamer, PC, the Co-Managing Member of Stamer Chadwick Soefje PLLC, Ms. Stamer has worked extensively throughout her nearly 30 year career with health care providers, health plans, health care clearinghouses, their business associates, employers, banks and other financial institutions, their technology and other vendors and service providers, and others on legal and operational risk management and compliance with HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and concerns; prevention, investigation, response, mitigation and resolution of known or suspected data or privacy breaches or other incidents; defending investigations or other actions by plaintiffs, OCR, FTC, state attorneys’ general and other federal or state agencies; reporting and redressing known or suspected breaches or other violations; business associate and other contracting; insurance or other liability management and allocation; process and product development, contracting, deployment and defense; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others.
Beyond her extensive involvement advising and defending clients on these matters, Ms. Stamer also has served for several years as the scrivener for the ABA JCEB’s meeting with OCR for many years. She returns as Chair of the Southern California ISSA Health Care Privacy & Security Summit for the third year in 2016, as well as speaks and serves on the steering committee of a multitude of other programs.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares shared her thought leadership, experience and advocacy on HIPAA and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as the Vice Chair of the North Texas Healthcare Compliance Association, Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE; Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Board Compliance Chair and Board member of the National Kidney Foundation of North Texas, current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Counsel, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposia chair and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clientson the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. For additional information about Ms. Stamer, see CynthiaStamer.com or the Stamer│Chadwick │Soefje PLLC or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at www.solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here. ©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Brace For Health Plan OCR HIPAA Audits |
Brokers, Civil Rights, compensation, compliance, Corporate Compliance, Cybercrime, Data Breach, Data Security, employee, Employee Benefits, FACTA, fiduciary duty, Fiduciary Responsibility, Financial Security, GINA, health benefit, Health Benefits, health Care, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HIPAA, Hospitality, HR, Human Resources, Identity Theft, Insurance, insurers, Internal Controls, Management, Medicare Part D, Mental Health, Mental Health Parity, MEWA, Obamacare, Patient Empowerment, Prescription Drugs, Privacy, Professional Liability, Risk Management, third party administrators, Uncategorized, Wellness, Wellness Programs, Workforce | Tagged: Data Breach, Data Security, Employee Benefits, ERISA, Fiduciary Liability, financial privacy, Health Insurance, Health Plan, Health Plans, HIPAA, Medical Privacy, OCR, Office of Civil Rights, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
March 9, 2016
Solutions Law Press, Inc. ™ Invites You To A Special WebEx Briefing
HIPAA Update: The Latest On Security, Patient Access & Other HIPAA Developments
Wednesday, March 30, 2016
1:00 P.M.-2:00 P.M. Eastern | 12:00 P.M.-1:00 P.M. Central 11:00 A.M-12:00 P.M. Mountain | 10:00 A.M-11:00 A.M. Pacific
Health care providers, health plans, health care clearinghouses and their business associates (Covered Entities) face new imperatives to review and tighten their practices to ensure their practices comply with recently released guidance from the U.S. Department of Health & Human Services Office of Civil Rights (OCR)) emphasizing and clarifying the responsibilities of health care providers, health plans and the healthcare clearinghouses under the Health Insurance Portability & Accountability Act of 1996 (HIPAA) to provide access to individuals that are the subject of protected health information or “PHI” to access or copies of their PHI in accordance with HIPAA’s rules and other recent HIPAA guidance and enforcement. With OCR’s recent release of added guidance and OCR enforcement statistics continuing to show HIPAA access rule violations among the most common HIPAA violations and OCR stepping up HIPAA enforcement, health care providers, health plans, healthcare clearinghouses can expect heightened scrutiny and enforcement of these requirements. Additionally, Covered Entities also should evaluate the adequacy of their other practices in light of other recent OCR guidance and enforcement actions.
Solutions Law Press, Inc.™ invites to catch up on the latest guidance on HIPAA’s requirements to provide access to patients to PHI by registering here to participate in the Solutions Law Press, Inc.™ “HIPAA Update: The Latest On Security, Patient Access & Other HIPAA Developments” WebEx briefing from Cynthia Marcotte Stamer on Friday, March 18, 2016. During the Briefing, Ms. Stamer will provide participants with:
√ An update on OCR enforcement actiions and guidance over past 12 months
√ A detailed discussion of OCR’s new guidance about when Covered Entities must provide PHI access or copies to patients
√ Discuss rules and best practices for verifying the identity and credentials of an individual requesting PHI as a patient or personal representative of a patient
√ Share tips for contracting and dealing with business associates to facilitate administration of patient PHI access and security compliance activities
√ Share other practical considerations & best practices for compliance and risk management
√ Respond to participant questions on a time permitting basis
√ More
ABOUT THE SPEAKER
Recognized as “Legal Leader™ Texas Top Rated Lawyer” in both Health Care Law and Labor and Employment Law, a “Texas Top Lawyer,” and an “AV-Preeminent” and “Top Rated Lawyer” by Martindale-Hubble, singled out as among the “Best Lawyers In Dallas” in employee benefits 2015 by D Magazine;, Cynthia Marcotte Stamer is a practicing attorney and management consultant, author, public policy advocate and lecturer widely recognized for her more than 28 years extensive work and pragmatic thought leadership, experience, publications and training on HIPAA and other privacy, medical records and data and other health care, health plan and employee benefits, workforce and related regulatory and other compliance, performance management, risk management, product and process development, public policy and other key operational concerns.
As a core component of her work as the Managing Shareholder of Cynthia Marcotte Stamer, PC, the Co-Managing Member of Stamer Chadwick Soefje PLLC, Ms. Stamer has worked extensively throughout her nearly 30 year career with health care providers, health plans, health care clearinghouses, their business associates, employers, banks and other financial institutions, their technology and other vendors and service providers, and others on legal and operational risk management and compliance including extensive involvement with HIPAA, FACTA, PCI, trade secret, physician and other medical confidentiality and privacy, federal and state data security and data breach and other information privacy and data security rules and concerns; prevention, investigation, response, mitigation and resolution of known or suspected data or privacy breaches or other incidents; defending investigations or other actions by plaintiffs, OCR, FTC, state attorneys’ general and other federal or state agencies; reporting and redressing known or suspected breaches or other violations; business associate and other contracting; insurance or other liability management and allocation; process and product development, contracting, deployment and defense; evaluation, commenting or seeking modification of regulatory guidance, and other regulatory and public policy advocacy; training and discipline; enforcement, and a host of other related concerns for public and private health care providers, health insurers, health plans, technology and other vendors, employers, and others. Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on HIPAA and other privacy and data security risks and requirements as well as a broad range of other health, employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, Federal Trade Commission, HUD and Justice, as well as a state legislatures attorneys general, insurance, labor, worker’s compensation, and other agencies and regulators as well supports clients in defending litigation as lead strategy counsel, special counsel and as an expert witness.
Beyond her extensive involvement advising and defending clients on these matters, Ms. Stamer also has served as the scrivener for the ABA JCEB’s meeting with OCR on HIPAA for many years. She returns as Chair of the Southern California ISSA Health Care Privacy & Security Summit for the third year in 2016, as well as speaks and serves on the steering committee of a multitude of other programs.
A Fellow in the American College of Employee Benefit Counsel, the American Bar Foundation and the Texas Bar Foundation, Ms. Stamer also shares shared her thought leadership, experience and advocacy on HIPAA and other concerns by her service in the leadership of a broad range of other professional and civic organization including her involvement as the Vice Chair of the North Texas Healthcare Compliance Association, Executive Director of the Coalition on Responsible Health Policy and its PROJECT COPE; Coalition on Patient Empowerment, a founding Board Member and past President of the Alliance for Healthcare Excellence, past Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; former Board President of the early childhood development intervention agency, The Richardson Development Center for Children; former Board Compliance Chair and Board member of the National Kidney Foundation of North Texas, current Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, current Vice Chair of Policy for the Life Sciences Committee of the ABA International Section, Past Chair of the ABA Health Law Section Managed Care & Insurance Section, a current Defined Contribution Plan Committee Co-Chair, former Group Chair and Co-Chair of the ABA RPTE Section Employee Benefits Group, immediate past RPTE Representative to ABA Joint Committee on Employee Benefits Council Representative and current RPTE Representative to the ABA Health Law Coordinating Counsel, former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division, past Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee, a former member of the Board of Directors of the Southwest Benefits Association and others.
Ms. Stamer also is a highly popular lecturer, symposia chair and author, who publishes and speaks extensively on health and managed care industry, human resources, employment and other privacy, data security and other technology, regulatory and operational risk management. Examples of her many highly regarded publications on these matters include “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security: Beyond HIPAA,” as well as thousands of other publications, programs and workshops these and other concerns for the American Bar Association, ALI-ABA, American Health Lawyers, Society of Human Resources Professionals, the Southwest Benefits Association, the Society of Employee Benefits Administrators, the American Law Institute, Lexis-Nexis, Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, the HCCA, ISSA, HIMSS, Modern Healthcare, Managed Healthcare, Institute of Internal Auditors, Society of CPAs, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other symposia and publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications and speaks and conducts training for a broad range of professional organizations and for clients, serves on the faculty and planning committee of many workshops, seminars, and symposia, and on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. For additional information about Ms. Stamer, see CynthiaStamer.com or the Stamer│Chadwick │Soefje PLLC or contact Ms. Stamer via email to here or via telephone to (469) 767-8872.
REGISTRATION & PROGRAM DETAILS
Registration Fee per course is $75.00 per person. Registration Fee Discounts available for groups of three or more participants from the same organization. Limited opportunities for participation. Registration accommodated on a first come basis. Completed registration and payment required via website registration 48 hours in advance of the program. No checks or cash accepted. Persons not registered with completed payment at least 48 hours in advance will only participate subject to availability and completed registration and payment. Payment only accepted via website PayPal. Register Here!
The Webex will be conducted over the internet. Participants will receive access code and instructions for sign on to participate in the Webex and/or dial in to participate in the program via telephone after processing of completed registration. Participants must have access to a computer with internet access and to telephone access to dial in via telephone to participate in the program. Solutions Law Press, Inc. is not responsible for any interruption or interference in participation resulting from limitations in the internet connectivity, computer, telephone or other equipment used by the participant to access and participate in the program.
ABOUT SOLUTIONS LAW PRESS, INC.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders better anticipate legal and operational issues impacting their organization’s performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to inquire about becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com. These programs, publications and other resources are provided only for general informational and educational purposes, the applicability of which to any particular circumstances may be impacted by legal changes, the specific facts and circumstances or other factors. Consequently, neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are not intended to or shall not be construed as establishing an attorney-client relationship, to constitute legal advice or a substitute for legal advice, or otherwise provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties that any participant or any other party can rely upon the information or any statements presented herein. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. If you would prefer not to receive communications from Solutions Law Press, Inc. send an e-mail with “Solutions Law Press Unsubscribe” in the Subject to support@solutionslawyer.net. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know at the time of your registration so that we may consider your request. ©2016 Solutions Law Press, Inc.
Comments Off on Learn Latest HIPAA Health Plan Rules In 3/30 SLP Webex |
Employee Benefits, Employer, Employers, health benefit, Health Benefits, health Care, Health Care Reform, health insurance, health insurance marketplace, health plan, Health Plans, HIPAA, HIPAA, Privacy, Protected Health Information, Uncategorized | Tagged: Business Associate, Health Insurance, Health Plan, HIPAA, Medical Privacy, PHI, Protected Health Information, third party administrator, tpa |
Permalink
Posted by Cynthia Marcotte Stamer
March 9, 2016
By: Cynthia Marcotte Stamer
Employers, health plans and individual taxpayers should be concerned about reports of deficiencies in the eligibility and enrollment tracking procedures of some health insurance exchanges or “marketplaces” created under the Patient Protection and Affordable Care Act (ACA) that are likely to identify individuals enrolling in health insurance coverage offered through the Healthcare.gov and certain state health insurance exchanges or “marketplaces” as eligible for subsidies who in fact are ineligible for subsidies.
As the Internal Revenue Service (IRS) and Department of Health & Human Services (HHS) rely upon Marketplaces’ eligibility and enrollment records to enroll Americans in health insurance coverage through the ACA created marketplaces, to help determine in individual Americans and employers are complying with the ACA shared responsibility rules, and to determine which individuals enrolling in coverage through marketplaces qualify for ACA subsidies, deficiencies in these practices and resulting errors in eligibility and enrollment records are likely to mean headaches for employer, health plans and individual Americans.
Marketplace Eligibility & Enrollment Data Critical To Administer ACA Reforms
Accurate eligibility and enrollment determination by marketplaces is critical to the administration of the ACA’s complicated web of reforms, including the determination the determination of whether the employee of a large employer who enrolls in coverage qualifies for a subsidy so as to trigger an obligation for the employer to pay an employer shared responsibility payment under IRC Section 4980H if the employee is not enrolled in group health coverage offered by the employer meeting ACA’s requirements.
As part of ACA’s massive restructuring of the health care payment system enacted by President Obama and the then Democrat-led Congress, most Americans now must pay an “individual shared responsibility payment” unless enrolled in “minimum essential coverage” one of the ACA-approved health coverage options. Along with this individual mandate, the ACA:
- Dictates that all group and individual health insurance policies other than a narrow list of “excluded” plans include the rich and generally expensive package of ACA-mandated “essential health benefits,” pay a host of ACA-imposed taxes and assessments, and comply with a host of tight ACA market reforms;
- Penalizes employers with 50 or more full-time employees (large employers) that fail to offer all full-time employees group health coverage for the employee and each of his dependent children (hereafter “dependent coverage”) through an employer-sponsored arrangement that provides minimum essential benefits at a cost not greater than 9.5 percent of the federal poverty level by providing that any large employer with at least 1 employee enrolled in subsidized health coverage offered through an ACA-established health insurance marketplace, to pay a monthly “employer shared responsibility payment” under Internal Revenue Code Section 4980H of:
- For any large employer not offering any group health plan employee and dependent coverage providing minimum essential coverage to each full-time employee, $150 per full-time employee per month; or
- For any other large employer, $250 per month for each full-time employee earning less than 400 percent of the federal poverty level enrolled in subsidized health insurance coverage through an ACA-established health insurance marketplace unless the employer shows the employer offered the employee the opportunity to enroll in employee and dependent coverage under a group health plan that provided the ACA-required minimum essential coverage at a cost not exceeding 9.5 percent of the employee’s adjusted gross income; and
- Seeks to incentivize small employers (generally with fewer than 25 full-time and full-time equivalent employees) tax credits for offering minimum essential coverage under an employer-sponsored plan that meets the ACA requirements; and
- Created a system of one federal and various state health care exchanges or “marketplaces” through which individual Americans and small employers can purchase an expensive package of “essential health benefits” from private health insurers offering “qualified health plans” (QHPs) through the their state “marketplace,” if any, or for Americans living in a state with that elected not to establish a state marketplace, the federal Healthcare.gov marketplace;
- Uses federal tax dollars to subsidize a portion of the premiums paid by certain Americans earning less than 400% of the federal poverty level that enroll in coverage under a QHP through the marketplace applicable in their states unless the individual had the option to enroll in an employer-sponsored group health plan meeting the ACA’s “minimum essential coverage,” “minimum value” and “affordability” standards; and
- Requires all employers, health plans and insurers and each Marketplace accurately and reliably to collect, maintain and report certain key data needed to coordinate and administer ACA’s individual coverage mandates, employer mandates and subsidy rules.
For proper administration and coordination with other plans and employers and the administration by the Internal Revenue Service of ACA tax subsidies payable to qualifying individuals obtaining coverage in a QHP through an exchange, HHS regulations require each marketplace to implement and administer reliably an application and enrollment process for enrollment in QHPs through the exchange.
To enroll in a QHP, an applicant must complete an application and meet eligibility requirements defined by the ACA. An applicant can enroll in a QHP through the Federal or a State marketplace, depending on the applicant’s State of residence. Applicants can enroll through a Web site, by phone, by mail, in person, or directly with a broker or an agent of a health insurance company. For online and phone applications, the marketplace verifies the applicant’s identity through an identity-proofing process. For paper applications, the marketplace requires the applicant’s signature before the marketplace processes the application. When completing any type of application, the applicant attests that answers to all questions are true and that the applicant is subject to the penalty of perjury.
After reviewing the applicant’s information, HHS expects the marketplace to determine whether the applicant is eligible for a QHP and, when applicable, eligible for insurance affordability programs. To verify the information submitted by the applicant, the marketplace is expected to use multiple electronic data sources, including those available through the Federal Data Services Hub (Data Hub). Data sources available through the Data Hub are the U.S. Department of Health and Human Services, Social Security Administration (SSA), U.S. Department of Homeland Security, and Internal Revenue Service, among others. The marketplace can verify an applicant’s eligibility for ESI through Federal employment by obtaining information from the U.S. Office of Personnel Management through the Data Hub.
Generally, when a marketplace cannot verify information that the applicant submitted or the information is inconsistent with information available through the Data Hub or other sources, HHS regulations require the marketplace to attempt to resolve the inconsistency in accordance with HHS regulations before treating the individual as ineligible. Because of the presumption of eligibility built into the system, individual’s who care not verified as ineligible are treated as eligible. As a result, inadequate verification practices by marketplaces are likely to result in the inappropriate characterization of individuals as eligible for enrollment with subsidies.
Audits Show Marketplace Eligibility & Enrollment Practices Deficient
Unfortunately, recent OIG reports raising concerns about the adequacy of the eligibility and enrollment verification procedures of various marketplaces are raising concerns about the reliability and adequacy of the eligibility and enrollment verification procedures and resulting data of various marketplaces. For instance, in its recently released report, Not All of the District of Columbia Marketplace’s Internal Controls Were Effective in Ensuring That Individuals Were Enrolled in Qualified Health Plans According to Federal Requirements, HHS OIG Report A-03-14-03301 (the ”D.C. Report”), OIG reports that OIG’s audit of 45 sample applicants from the enrollment period for insurance coverage in the District of Colombia’s exchange for calendar year 2014 revealed that District of Colombia’s health insurance marketplace had ineffective internal processes and controls for:
- Verifying an applicant’s eligibility for minimum essential coverage (both employer-sponsored insurance and non-employer-sponsored insurance;
- Maintaining application and eligibility verification data;
- Maintain identity-proofing documentation for applicants who apply for QHPs;
- Verifying annual household income in accordance with Federal requirements;
- Maintaining documentation demonstrating that it verified whether an applicant was eligible for minimum essential coverage under an employment based health plan; and
- Ensuring that its enrollment system maintains application, eligibility, and documentation, including all electronic eligibility verifications from the Data Hub.
Deficiencies Create Likely Headaches For Employers, Plans & Individual Taxpayers
Given the importance of accurate subsidy eligibility and other marketplace enrollment information, marketplace audit results recently reported by the OIG finding certain federal and state health insurance marketplaces are not using effective internal controls to verify and administer eligibility and enrollment processes raises concerns not only concerns for taxpayers generally, but also could signal added headaches for employers and health plans.
Large employers and individual Americans receiving subsidies are likely to experience the greatest impact because of the reliance upon the IRS on marketplace data to determine employer and individual shared responsibility payment liability. However, all employers and health plans also could experience some fallout.
Large employers should be prepared to receive and defend against IRS assertions that the employer is liable for paying employer shared responsibility payment under IRC Section 4980H when an employee of the employer is one of those individuals that a marketplace improperly classifies as eligible to receive subsidies because of deficient marketplace eligibility or enrollment data collection and verification practices. In addition, all employers should be prepared to receive and respond to inquiries from marketplaces, the IRS or HHS seeking to investigate, verify and reconcile data relevant to the administration of the ACA market, subsidy, shared responsibility and other reforms of the ACA.
Meanwhile, employers, health plans and individual Americans alike should brace to receive inquiries from the IRS, HHS, marketplaces, health plans and others seeking to verify and reconcile marketplace data with data reported by health plans, employers and individual Americans. While timely and appropriate response to legitimate requests from the IRS, HHS, a marketplace or other appropriate party is important, all parties should be careful to verify the legitimacy of the request and the identity and credentials of the party making the request in light of the IRS and other agencies’ reports of the identity theft and other scams by opportunist criminals using the pretext of acting for the IRS or other legitimate purposes illegally to trick businesses or individuals into sharing sensitive tax, financial or other information. While all parties need to use care in responding to these requests, employers, health plans and their service providers also need to ensure that these procedures are appropriately conducted and documented to minimize their exposure to liability for violations of the confidentiality, privacy or data security requirements that may apply to the employer, health plan or other party under the IRC, the Health Insurance Portability & Accountability Act (HIPAA) or various other federal or state laws.
To help prepare for these potential inquiries, employers, health plans and other parties should ensure that their recordkeeping, enrollment and reporting practices under ACA are clean and ready to respond to these and other government or employee inquiries.
Employers and others concerned about the impact of these deficiencies on the liabilities of large employers, taxpayers or both may wish express concern to their elected representatives in Congress.
About The Author
Recognized as a “Top” attorney in employee benefits, labor and employment and health care law extensively involved in health and other employee benefit and human resources policy and program design and administration representation and advocacy throughout her career, Cynthia Marcotte Stamer is a practicing attorney and Managing Shareholder of Cynthia Marcotte Stamer, P.C., a member of Stamer│Chadwick│Soefje PLLC, author, pubic speaker, management policy advocate and industry thought leader with more than 28 years’ experience practicing at the forefront of employee benefits and human resources law.
A Fellow in the American College of Employee Benefit Counsel, past Chair and current Welfare Benefit Committee Co-Chair of the American Bar Association (ABA) RPTE Section Employee Benefits Group, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, an ABA Joint Committee on Employee Benefits Council Representative and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer is recognized nationally and internationally for her practical and creative insights and leadership on health and other employee benefit, human resources and insurance matters and policy.
Ms. Stamer helps management manage. Ms. Stamer’s legal and management consulting work throughout her career has focused on helping organizations and their management use the law and process to manage people, process, compliance, operations and risk. Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce and other legal and operational crises large and small that arise in the course of operations.
Ms. Stamer works with businesses and their management, employee benefit plans, governments and other organizations deal with all aspects of human resources and workforce management operations and compliance. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy. Well known for her extensive work with health care, insurance and other highly regulated entities on corporate compliance, internal controls and risk management, her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes. Common engagements include internal and external workforce hiring, management, training, performance management, compliance and administration, discipline and termination, and other aspects of workforce management including employment and outsourced services contracting and enforcement, sentencing guidelines and other compliance plan, policy and program development, administration, and defense, performance management, wage and hour and other compensation and benefits, reengineering and other change management, internal controls, compliance and risk management, communications and training, worker classification, tax and payroll, investigations, crisis preparedness and response, government relations, safety, government contracting and audits, litigation and other enforcement, and other concerns.
Ms. Stamer uses her deep and highly specialized health, insurance, labor and employment and other knowledge and experience to help employers and other employee benefit plan sponsors; health, pension and other employee benefit plans, their fiduciaries, administrators and service providers, insurers, and others design legally compliant, effective compensation, health and other welfare benefit and insurance, severance, pension and deferred compensation, private exchanges, cafeteria plan and other employee benefit, fringe benefit, salary and hourly compensation, bonus and other incentive compensation and related programs, products and arrangements. She is particularly recognized for her leading edge work, thought leadership and knowledgeable advice and representation on the design, documentation, administration, regulation and defense of a diverse range of self-insured and insured health and welfare benefit plans including private exchange and other health benefit choices, health care reimbursement and other “defined contribution” limited benefit, 24-hour and other occupational and non-occupational injury and accident, ex-patriate and medical tourism, onsite medical, wellness and other medical plans and insurance benefit programs as well as a diverse range of other qualified and nonqualified retirement and deferred compensation, severance and other employee benefits and compensation, insurance and savings plans, programs, products, services and activities. As a key element of this work, Ms. Stamer works closely with employer and other plan sponsors, insurance and financial services companies, plan fiduciaries, administrators, and vendors and others to design, administer and defend effective legally defensible employee benefits and compensation practices, programs, products and technology. She also continuously helps employers, insurers, administrative and other service providers, their officers, directors and others to manage fiduciary and other risks of sponsorship or involvement with these and other benefit and compensation arrangements and to defend and mitigate liability and other risks from benefit and liability claims including fiduciary, benefit and other claims, audits, and litigation brought by the Labor Department, IRS, HHS, participants and beneficiaries, service providers, and others. She also assists debtors, creditors, bankruptcy trustees and others assess, manage and resolve labor and employment, employee benefits and insurance, payroll and other compensation related concerns arising from reductions in force or other terminations, mergers, acquisitions, bankruptcies and other business transactions including extensive experience with multiple, high-profile large scale bankruptcies resulting in ERISA, tax, corporate and securities and other litigation or enforcement actions.
Ms. Stamer also is deeply involved in helping to influence the Affordable Care Act and other health care, pension, social security, workforce, insurance and other policies critical to the workforce, benefits, and compensation practices and other key aspects of a broad range of businesses and their operations. She both helps her clients respond to and resolve emerging regulations and laws, government investigations and enforcement actions and helps them shape the rules through dealings with Congress and other legislatures, regulators and government officials domestically and internationally. A former lead consultant to the Government of Bolivia on its Social Security reform law and most recognized for her leadership on U.S. health and pension, wage and hour, tax, education and immigration policy reform, Ms. Stamer works with U.S. and foreign businesses, governments, trade associations, and others on workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment and a Fellow in the American Bar Foundation and State Bar of Texas, Ms. Stamer annually leads the Joint Committee on Employee Benefits (JCEB) HHS Office of Civil Rights agency meeting and other JCEB agency meetings. She also works as a policy advisor and advocate to many business, professional and civic organizations.
Author of the thousands of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer also is a highly sought out speaker and industry thought leader known for empowering audiences and readers. Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs (BNA), InsuranceThoughtLeaders.com, Benefits Magazine, Employee Benefit News, Texas CEO Magazine, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. She also has served as an Editorial Advisory Board Member for human resources, employee benefit and other management focused publications of BNA, HR.com, Employee Benefit News, InsuranceThoughtLeadership.com and many other prominent publications. Ms. Stamer also regularly serves on the faculty and planning committees for symposia of LexisNexis, the American Bar Association, ALIABA, the Society of Employee Benefits Administrators, the American Law Institute, ISSA, HIMMs, and many other prominent educational and training organizations and conducts training and speaks on these and other management, compliance and public policy concerns.
Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer presently serves on an American Bar Association (ABA) Joint Committee on Employee Benefits Council representative; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, its current Welfare Benefit Plans Committee Co-Chair, on its Substantive Groups & Committee and its incoming Defined Contribution Plan Committee Chair and Practice Management Vice Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; the former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. She also previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association. For additional information about Ms. Stamer, see CynthiaStamer.com or the Stamer│Chadwick │Soefje PLLC or contact Ms. Stamer via email here or via telephone to (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at http://www.solutionslawpress.com such as:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here.
©2016 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Marketplace Data Deficiencies Signal Employer ACA Headaches |
105(h), 4980D, 4980H, 6039D, ACA, Corporate Compliance, corporate governance, Cybercrime, Data Breach, Data Security, EBSA, employee, Employee Benefits, Employer, Employers, Employment, Employment Tax, ERISA, exchange, Excise Tax, Excise Taxes, fiduciary duty, health benefit, Health Benefits, health Care, Health Care Reform, health insurance, health insurance marketplace, health plan, Health Plans, health reform, HIPAA, HIPAA, Hiring, HR, Identity Theft, Income Tax, Insurance, insurers, Internal Controls, Internal Revenue Code, IRC, Obamacare, Patient Protection & Affordable Care Act, Patient Protection and Affordable Care Act, Pay, Premium Subsidies, Privacy, Protected Health Information, Reporting & Disclosure, Risk Management, third party administrators, Worker Classification, Workforce | Tagged: 4980H, ACA, group health plan, Health Care Reform, health insurance marketplace, Health Plans, Insurer, marketplace, Obama Care, shared responsibility payment |
Permalink
Posted by Cynthia Marcotte Stamer
October 25, 2015
Halloween’s annual celebration of spooks and goblins peak is a perfect time to promote awareness and help American businesses and citizens build their skills to guard against the real and growing menace of identity thieves and other cybercriminals by getting involved with the 12th annual National Cyber Security Awareness Month (NCSAM) in October, begin preparing to participate in the next annual “Data Privacy Day” on January 28, 2016 and joining in other activities highlighted through NCSAM and Data Privacy Day to help deter Cybercrime and identity theft threats. Even if your organization or family choose not to participate in any official or public way, checking out and using the many free resources provides an invaluable, free opportunity to raise your defenses against this rising risk.
With virtually every American business and citizen now connected to and using the Internet to conduct key personal and business transactions and the constant drive by government and business to digitize regular business transactions, no one agency, business or individual alone can truly know where and who has their sensitive data, much less reliably can defend this data against the identity and other theft and other cybercriminals lurking in the digital world’s virtual streets waiting to strike, then disappear in “Jack The Ripper” style into the darkness of the Internet. That’s why every American and American business should take time to participate and urge others to Get Involved in the 12th Annual NCSAM activities this month and use the supportive resources offered through that involvement throughout the year.
Celebrated annually in October, NCSAM was created to provide resources to help Americans stay safer and more secure online through public-private collaboration between the U.S. Department of Homeland Security and industry led by the National Cyber Security Alliance (NCSA). NCSAM and its associated activities outreach to consumers, small and medium-sized businesses, corporations, educational institutions and young people across the nation. NCSAM 2015 particularly focuses on the consumer and his/her needs regarding cybersecurity and safety continuing the overall message of STOP. THINK. CONNECT. Campaign founded in 2010 and its capstone concepts: “Keep a Clean Machine,” “Protect Your Personal Information,” “Connect with Care,” “Be Web Wise” and “Be a Good Online Citizen.” NCSAM seeks to remind Americans to incorporate “STOP. THINK. CONNECT.” into their online routines and offers resources to help individuals understand and put these principles into practice into their online routine at the home, the office and elsewhere.
Designed to be accessible and understandable by consumers, many business and government organizations may want to support and promote their Cyber Security employee and customer training and awareness efforts by participating annually in NCSAM in October, signing up your organization to Data Privacy Day Champion and/or participating in Data Privacy Day on January 28, 2016, or otherwise using and sharing tips, tools and other resources in the Privacy Library such as:
General Privacy & Cyber Security Awareness
Keep a Clean Machine/Cookies & Behavioral Tracking
- Malware & Botnets
- A video about cookies and why they matter created by the Wall Street Journal.
- Information about the Network Advertising Initiative (NAI) offering opt-out of online behavior advertising and provides factual information about online behavioral advertising, privacy, cookies.
Health Privacy
Identity Theft Prevention & Clean Up
Mobile App Privacy & Security
Student & Educational Privacy & Security
- I want to each online safety for Grades K-2, Grades 3-5 Middle and High School Higher Education and CSave Volunteer Lesson Plans & Materials
- The Protecting Privacy in Connected Learning toolkit is an in-depth, step-by-step guide to navigating the Family Education Rights and Privacy Act (FERPA), the Children’s Online Privacy Protection Act (COPPA) and related privacy issues.
- Securing Your Home Network
- The Family Educational Rights and Privacy Act, or FERPA, is the main federal law that deals with education privacy, but there are a host of other laws, best practices, and guidelines that are essential to understanding education privacy. FERPA|SHERPA aims to provide service providers, parents, school officials, and policymakers with easy access to those materials to help guide responsible uses of student’s data.
- General guidance for parents provided by the department of education Family Educational Rights and Privacy Act (FERPA)
- Student Privacy 101: FERPA for parents and students – Ever have questions about your rights regarding education records? This short video highlights the key points of the family education rights and privacy act (FERPA).
Other Resources
About the Author
Cynthia Marcotte Stamer is a practicing attorney and Managing Shareholder of Cynthia Marcotte Stamer, P.C., a member of Stamer│Chadwick │Soefje PLLC, author, pubic speaker, management policy advocate and industry thought leader with more than years’ experience helping business and government organizations and their leaders manage. Ms. Stamer’s legal and management consulting work throughout her 28 plus year career has focused on helping organizations and their management understand and use the law and process to manage people, process, compliance, operations and risk including significant work in the prevention, investigation and remediation of data breach and other Cybercrime events.
Scribe responsible for leading the American Bar Association (ABA) Joint Committee on Employee Benefits (JCEB) annual agency meeting with the Department of Health & Human Services Office of Civil Rights,Scribe responsible for leading the American Bar Association (ABA) Joint Committee on Employee Benefits (JCEB) annual agency meeting with the Department of Health & Human Services Cynthia Marcotte Stamer’s practice has focused on advising and representing government and private technology, security, health care providers, health plans, health, schools and other educational organizations, insurance, banking and financial services, retail, employer and other organizations about privacy and data security compliance and risk management, breach and other investigations and enforcement, workforce and performance management and other risk management, compliance, public policy, regulatory, staffing, and other operations and risk management concerns.
With data and technology use, protection and management imbedded in virtually every aspect of her client’s operations, data and other confidential information and systems use, protection, breach or other abuse investigation and response, enforcement and liability mitigation and defense and other Cybercrime and Cyber Security challenges are a continuous component of Ms. Stamer’s management work. Ms. Stamer helps public and private, domestic and international businesses, governments, and other organizations and their leaders manage their employees, vendors and suppliers, and other workforce members, customers and other’ performance, compliance, compensation and benefits, operations, risks and liabilities, as well as to prevent, stabilize and cleanup workforce, data breach and Cybercrime, and other legal and operational crises large and small that arise in the course of operations. Ms. Stamer regularly helps clients design, administer and defend HIPAA, FACTA, data breach, identity theft and other risk management, compliance and other privacy, data security, confidential information and other data security, technology and management policies and practices affecting their operations. She also helps clients prevent, investigate and mitigate HIPAA, FACTA, PHI and other data breach hacking, identity theft, data breach, data loss or destruction, theft of trade secrets or other sensitive data, spoofing, industrial espionage, insider and other parties misuse of data or technology and other cybercrime and technology use concerns. Best-known for her extensive work helping health care, insurance and other highly regulated entities manage both general employment and management concerns and their highly complicated, industry specific corporate compliance, internal controls and risk management requirements, Ms. Stamer’s clients and experience also includes a broad range of other businesses. Her clients range from highly regulated entities like employers, contractors and their employee benefit plans, their sponsors, management, administrators, insurers, fiduciaries and advisors, technology and data service providers, health care, managed care and insurance, financial services, government contractors and government entities, as well as retail, manufacturing, construction, consulting and a host of other domestic and international businesses of all types and sizes. Common engagements include internal and external privacy and data security compliance, risk management, investigation and remediation, workforce hiring, management, training, performance management, compliance and administration, discipline and termination, and other aspects of workforce management including employment and outsourced services contracting and enforcement, sentencing guidelines and other compliance plan, policy and program development, administration, and defense, performance management, wage and hour and other compensation and benefits, reengineering and other change management, internal controls, compliance and risk management, communications and training, worker classification, tax and payroll, investigations, crisis preparedness and response, government relations, safety, government contracting and audits, litigation and other enforcement, and other legal and operational compliance, risk management, disaster preparedness and response, and liability defense and mitigation concerns arising out of organization’s operations.
Cindy also is widely recognized for her regulatory and public policy advocacy, publications, and public speaking on privacy and other compliance, risk management concerns. Among others, she is the author of “Privacy & Securities Standards-A Brief Nutshell,” “Privacy Invasions of Medical Care-An Emerging Perspective,” the E-Health Business and Transactional Law Chapter on Other Liability-Tort and Regulatory;” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA;” “Personal Identity Management Legal Demands and Technology Solutions;” “Tailoring A Records Management Plan And Process To Meet Your Legal And Operational Needs;” “Brokers & Insurers Identity Theft and Privacy Perils;” “HR’s Role In Personal Identity Theft & Cyber Crime Prevention;” “Protecting & Using Patient Data In Disease Management Opportunities, Liabilities And Prescriptions;” “Why Your Business Needs A Cybercrime Prevention and Compliance Program;” “Leveraging Your Enterprise Digital Identity Management Investments and Breaking though the Identity Management Buzz;” “When Your Employee’s Private Life Becomes Your Business;” and hundreds of other works. Her insights on privacy, data security, and other matters have appeared in The Wall Street Journal, Business Insurance, the Dallas Morning News, Spencer Publications, and a host of other publications. She speaks and has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.
Highly valued for her rare ability to find pragmatic client-centric solutions by combining her detailed legal and operational knowledge and experience with her talent for creative problem-solving, Ms. Stamer works with businesses and government organizations and their management, employee benefit plans, schools, financial institutions, retail, hospitality, and other organizations deal with all aspects of these and other operations performance and compliance management. She supports her clients both on a real time, “on demand” basis and with longer term basis to deal with daily performance management and operations, emerging crises, strategic planning, process improvement and change management, investigations, defending litigation, audits, investigations or other enforcement challenges, government affairs and public policy.
Ms. Stamer also is active in the leadership of a broad range of other professional and civic organizations. For instance, Ms. Stamer presently serves on an American Bar Association (ABA) Joint Committee on Employee Benefits Council representative; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, its current Welfare Benefit Plans Committee Co-Chair, on its Substantive Groups & Committee and its incoming Defined Contribution Plan Committee Chair and Practice Management Vice Chair; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; current Vice Chair of the ABA TIPS Employee Benefit Committee; the former Coordinator and a Vice-Chair of the Gulf Coast TEGE Council TE Division; on the Advisory Boards of InsuranceThoughtLeadership.com, HR.com, Employee Benefit News, and many other publications. She also previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early childhood development intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association. For additional information about Ms. Stamer, see here, or the Stamer Chadwick Soefje PLLC website here. To contact Ms. Stamer, e-mail her at here or telephone (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides human resources and employee benefit and other business risk management, legal compliance, management effectiveness and other coaching, tools and other resources, training and education on leadership, governance, human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press, Inc.™ resources at http://www.solutionslawpress.com including:
- Ranching Employers: Labor Department Tightening H-2A VISA Rules For Employing Range Workers
- NLRB 29 Unfair Labor Practice Charges Against Community Health Systems, Inc. Shows Industry Labor Risks
- DOL Schools Halliburton With $18M+ Overtime Settlement; Other Employers & Executives Should Take Note
- Evolving Rules Mean Execs & Employers Should Review Executive Comp
- OCR’s Proposed Sex & Other Discrimination Rules Spell Headaches & New Risks For Health Care Providers, Insurers & Others
- Feds Charges 8 For Alleged $50M In Bogus Student Substance Abuse Counseling Claims
- Check Out & Comment By 10/13 On FDA Proposed Food Labeling Rule Changes
- 10 Practical Pointers To Use Law To Better Strengthen The Legal Defensibility Of Your Business & Its Leaders
- Check Defensibility Of Policies & Practices Given New HHS/DOJ Joint Disability Law Technical Assistance
- New HIPAA Settlement Highlights Internet Applications Safeguards, Whistleblower & Management Oversight Compliance Risks
- McGraw Appointed New OCR Deputy Director
- Tex Docs Urged To Support Medical Board Reforms
- CMS Proposes New Quality Measures, Reporting, Other Changes For FY 2016 Psych Facilities Prospective Payment SYstem Updates
- Great Time To Remind Patients, Employees To Check Their Immunizations Are Up To Date
- CMS Issues Last Call For Comments, Questions On Proposed Medicare Home Health Billing Templates
- CMS Announces ACA 2015 Reinsurance Contribution Training For Self-insured Group Health Plans, Health Insurers
- CMS Updates For Health Insurance Issuers On ACA Enrollment & Payment Data Reporting
- U.S. Businesses & Their Leaders Face Rising FLSA Collective Action Liability Risks
- Hone Workforce Management By Making Your HR The “Performance Department”
- Health Plan Sponsoring Employers, Insurers & Administrators Confirm Out-Of-Pocket Limits & Practices Up-To-Date
- Improve HR Value To Company By Making HR A Performance Rather Than People Department
- Sponsoring Employers Face Excise Taxes, Other Liabilities Unless Health Plans Comply With ACA Out-Of-Pocket & Other Federal Rules
- Legal Review Of Health Plan Documents, Processes Needed To Mitigate Employer’s Excise Tax & Other Health Plan Risks
- Comment On Proposed Changes To FDA Food Labeling Rules Due October 13
- EEOC ADA Suit Against Magnolia Health Highlights US Employer’s Growing Disability Discrimination Risks
- Proposed OSHA Regs Will Clarify Employer’s Continuing Duty To Ensure OSHA 300 Log Completeness
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information including your preferred e-mail by creating or updating your profile here.
©2015 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press, Inc.. All other rights reserved.
33.019843
-96.698886
Comments Off on Strengthen Your Cyber Security By Sharing National Cyber Security Awareness Month Resources This Week |
Banking, Child Safety, Cybercrime, Data Breach, Education, Educational Privacy, Employer, FACTA, Fair Credit Reporting Act, Financial Security, FINRA, Gaming, health Care, HIPAA, Hospitality, HR, Human Resources, Identity Theft, Insurance, Internet, Managment, NCSAM, Privacy, Retail, Risk Management, Safety, Schools, Security, Technology | Tagged: Cyber Security, Cybercrime, Data Breach, Data Security, FACTA, FERPA, Health Care, HIPAA, Identity Theft, Internet Security, On-line Dating Safety, On-line Security, Privacy, Schools, Security, Teen Safety, Teens |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2015
The EEOC has declared war on many employer sponsored wellness programs. The Senate Health, Education, Labor, and Pensions Committee will hold a hearing about how to improve employer wellness programs on Thursday, January 29. Employers and others should urge the Committee and other Congressional leaders to overrule the EEOC’s attacks on wellness programs as illegal disability discrimination under the Americans with Disabilities Act.
1 Comment |
ADA, Affordable Care Act, Disability, Discrimination, EEOC, EEOC, Employee Benefits, Employers, ERISA, GINA, Health Care Reform, Health Plans, Human Resources, Insurance, Internal Controls, MEWA, Patient Empowerment, Patient Protection and Affordable Care Act, Privacy, Rehabilitation Act, Wellness, Wellness Programs |
Permalink
Posted by Cynthia Marcotte Stamer
November 10, 2014
Human resources and other management leaders are watching Washington to see if the change in Congressional control resulting from the November 4, 2014 mid-term election ushers in a more management friendly federal legal environment. Since President Obama took office, the Democrats aggressive pursuit of health care, minimum wage and other federal pro-labor legislation, regulations and enforcement has increased management responsibilities, costs and liabilities.
Nationally recognized management attorney, public policy advisor and advocate, author and lecturer Cynthia Marcotte Stamer will help human resources and other management leaders prepare for 2015 when she speaks on “2015 Federal Legislative, Regulatory & Enforcement Update: What HR & Benefit Leaders Should Expect & Do Now” at the 2015 Dallas HR monthly luncheon series kickoff meeting on January 13, 2014.
About The Program
While November 4, 2014 Republican election victories gave Republicans a narrow majority in both the House and Senate when the new Congress takes office January 3, 2015, the new Republican Majority may face significant challenges delivering on their promises to move quickly to enact more business-friendly health care, guest worker, tax and other key reforms Republicans say will boost the employment and the economy.
While President Obama and Democrat Congressional leaders say they plan to work with the new majority, President Obama already is threatening to use vetoes, regulations and executive orders to block Republicans from obstructing or rolling back his pro-labor policy and enforcement agenda. When the new Congress takes office, the narrowness of the Republican Majority in the Senate means Republicans can’t block a Democratic filibuster or override a Presidential veto without recruiting some Democratic support.
As the Democrats and Republicans head into battle again, Board Certified Labor & Employment attorney and public policy advocate Cynthia Marcotte Stamer will help human resources and other management leaders get oriented for the year ahead by sharing her insights and predictions on the legislative, regulatory and enforcement agendas that HR, benefit and other business leaders need to plan for and watch in 2015. Among other things, Ms. Stamer will:
- Discuss how management can benefit from monitoring and working to influence potential legislative, regulatory and enforcement developments when planning and administering HR and related workforce policies;
- Discuss the key workforce and other legislative, regulatory and enforcement priorities and proposals Democrats and Republicans plan to pursue during 2015;
- Share her insights and predictions about how the narrow Republican majority, Mr. Obama’s lame duck presidency and other factors could impact each Party’s ability to pursue its agenda
- Share tips management leaders can use to help monitor developments and to help shape legislation, regulation and enforcement through Dallas HR, SHRM and other organizations as well as individually;
- Learn tips for anticipating and maintaining flexibility to respond to legislative, regulatory and enforcement developments; and
- More
To register or get more details about the program, DallasHR, or both, see http://www.dallashr.org.
About Ms. Stamer
Board certified labor and employment attorney, public policy leader, author, speaker Cynthia Marcotte Stamer is nationally and internationally recognized and valued for her more than 25 years of work advising and representing employers, insurers, employee benefit plans, their fiduciaries and advisors, business and community leaders and governments about workforce, employee benefits, social security and pension, health and insurance, immigration and other performance and risk management, public policy and related regulatory and public policy, management and other operational concerns.
Throughout her career, Ms. Stamer continuously both has helped businesses and their management to monitor and respond to federal and state legislative, regulatory and enforcement concerns and to anticipate and shape federal, state and other laws, regulations, and enforcement in the United States and internationally.
Well known for her leadership on workforce, health and pension policy through her extensive work with clients as well as through her high profile involvements as the Founder and Executive Director of the Coalition for Responsible Healthcare Policy and its PROJECT COPE: the Coalition on Patient Empowerment, a founding Board member of the Alliance for Health Care Excellence, a Fellow in the American College of Employee Benefit Counsel, the American Bar Association (ABA), and the State Bar of Texas leadership and other involvements with the ABA including her annual service leading the annual agency meeting of Joint Committee on Employee Benefits (JCEB) representatives with the HHS Office of Civil Rights and participation in other JCEB agency meetings, past involvements with legislative affairs for the Texas Association of Business and Dallas HR and others, and many speeches, publications, and other educational outreach efforts, Ms. Stamer has worked closely with Congress and federal and state regulators on the Patient Protection & Affordable Care Act and other health care, pension, immigration, tax and other workforce-related legislative and regulatory reforms for more than 30 years. One of the primary drafters of the Bolivian Social Security reform law and a highly involved leader on U.S. workforce, benefits, immigration and health care policy reform, Ms. Stamer’s experience also includes working with U.S. and foreign government, trade association, private business and other organizations to help reform other countries’ and U.S. workforce, social security and severance, health care, immigration, privacy and data security, tax, ethics and other laws and regulations. Ms. Stamer also contributes her policy, regulatory and other leadership to many professional and civic organizations including as Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Committee and its current Welfare Benefit Plans Committee Co-Chair, a Substantive Groups & Committee Member; a member of the leadership council of the ABA Joint Committee on Employee Benefits; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; the current Vice Chair of the ABA TIPS Employee Benefit Committee, and the past Coordinator of the Gulf Coast TEGE Council TE Division.
The publisher and editor of Solutions Law Press, Inc. who serves on the Editorial Advisory Boards of Employee Benefit News, HR.com, InsuranceThoughtLeadership.com and many other publications, Ms. Stamer also is a prolific and highly respected author and speaker, National Public Radio, CBS, NBC, and other national and regional news organization, Atlantic Information Services, The Bureau of National Affairs, HealthLeaders, Telemundo, Modern Healthcare, Business Insurance, Employee Benefit News, the Employee Benefits News, World At Work, Benefits Magazine, InsuranceThoughtLeadership.com, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, CEO Magazine, CFO Magazine, CIO Magazine, the Houston Business Journal, and many other prominent news and publications. She also serves as a planning faculty member and regularly conducts training and speaks on these and other management, compliance and public policy concerns for these and a diverse range of other organizations. For additional information about Ms. Stamer, see www.cynthiastamer.com.
For Added Information and Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For Help Or More Information
If you need assistance in auditing or assessing, updating or defending your organization’s compliance, risk manage or other internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 24 years of work helping employers and other management; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend union-management relations, wage and hour, discrimination and other labor and employment laws, privacy and data security, internal investigation and discipline and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on management, reengineering, investigations, human resources and workforce, employee benefits, compensation, internal controls and risk management, federal sentencing guideline and other enforcement resolution actions, and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters.Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see hereor contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources at www.solutionslawpress.com.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2014 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Stamer Kicks Off Dallas HR 2015 Monthly Lunch Series With 2015 Federal Legislative, Regulatory & Enforcement Update |
105(h), ACA, ADA, Affirmative Action, Affordable Care Act, Bankruptcy, Cafeteria Plans, Child Labor, CHIP, Civil Rights, Claims Administration, COBRA, compensation transparency, Corporate Compliance, Defined Benefit Plans, Defined Contribution Plans, Disability, Disability, Disability Plans, Discrimination, Disease Management, Drug & Alcohol, E-Verify, EEOC, EEOC, Employee Benefits, Employers, Employment Agreement, Employment Tax, ERISA, ESOP, Excise Tax, Executive Compensation, family leave, Fiduciary Responsibility, FMLA, GINA, Government Contractors, Health Care Reform, Health Plans, HIPAA, Human Resources, I-9, Immigration, Income Tax, Insurance, Internal Controls, Internal Investigations, Labor Management Relations, Leave, medical leave, Mental Health, Mental Health Parity, MEWA, Military Leave, Non-Compete, Non-Competition Agreement, Nonresident aliens, OFCCP, OSHA, Patient Protection and Affordable Care Act, Payroll Tax, Preemption, Premium Subsidies, Prescription Drugs, Privacy, Professional Liability, Protected Health Information, Public Policy, Rehabilitation Act, Reporting & Disclosure, Restructuring, Retaliation, Retirement Plans, Risk Management, Safety, Sexual Harassment, Tax, Tax Credit, Telecommuting, Unemployment Benefits, Unemployment Insurance, Union, USERRA, VEVRRA, Wage & Hour, Wellness, Wellness Programs | Tagged: Administrative Simplification, CMS, Health Benefits, Health Insurance, Health insurers, Health Plans, HHS, HPID, HPOES, out-of-pocket maximum, TPAs |
Permalink
Posted by Cynthia Marcotte Stamer
July 22, 2013
While large employers are getting an additional year to collect data and make other preparations to comply with the “pay-or-play” rules in the shared responsibility provisions of new Internal Revenue Code Section 4980H under the extension announced by the Administration in early July, all employers still have much to do stay on top of the developing rules and make the arrangements necessary to prepare to comply with the current and 2014 federal health plan mandates of the Patient Protection & Affordable Care Act (ACA) and other federal laws.
As the Departments of Health & Human Services, Labor and Treasury continue to refine and roll out guidance implementing these rules, the agencies recently released various updated resources discussing these evolving rules. Among others, Publication 5093, Healthcare Law Online Resources, lists ACA resources from the IRS, the Departments of Health & Human Services and Labor, and the Small Business Administration. Meanwhile, IRS.gov and HealthCare.gov also have new ACA webpages.
While these updated resources are intended by the agencies to help acquaint businesses with ACA’s requirements, businesses and the insurers and administrators that offer health benefit services need to keep in mind that these resources have risk and limitations. As the agencies are continuing to refine the rules, these resources often do not reflect the most current or emerging guidance or status of rules. Additionally, government provided explanations, model forms and resources often incorporate provisions or interpretations that are biased against the interests of the businesses, or contain other provisions that may not fully inform the business to all of its options. Furthermore, because of limitations in jurisdiction and other constraints, guidance issued by an agency or agency that reflects that certain approaches may satisfy the requirements of the rules specifically addressed by the guidance often do not disclose or adequately communicate potential concerns with certain types of actions under other applicable requirements.
For instance, model exchange notices published by the Department of Labor this Spring to assist employers to provide the notifications about federal exchange coverage options that ACA requires employers distribute by October 1 contain many provisions beyond the content actually required to meet the notice requirements. The Labor Department in announcing the model notices indicated that its model language includes discretionary provisions which the Department thought some employers might want to include to minimize questions from employees about employer provided benefits that employees interested in pursuing subsidized coverage could be expected to need to apply for subsidies. While as of now, exchanges and subsidies still are scheduled to come on line January 1, 2014, the Obama Administration extended the employer “pay-or-play” mandate of Code Section 4980 and its associated employer reporting requirements, as well as has established that it does not plan to verify eligibility for subsidies requested by individuals enrolling in exchanges in 2014. Given this, most employers will want to consider carefully the specific content that they wish to include in the exchange notice as they prepare the notice in anticipation of its distribution in October.Accordingly, all businesses dealing with these issues are encouraged to arrange for comprehensive advice from qualified legal counsel familiar with these requirements and other related human resources, health care, insurance and employee benefit issues.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
“Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Use New Government Health Care Reform Resources With Care |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
July 12, 2013
WellPoint $1.7 M HIPAA Settlement Expensive Lesson On HIPAA Risks Of Leaving PHI Too Accessible In Web-Based Applications
As health plans and health care organizations increasingly jump on the Web-based application bandwagon, managed care company WellPoint Inc. (WellPoint) is learning a $1.7 million lesson about the importance of ensuring Web-based applications and portals that allow access to members or other consumers protected health information (PHI) have the administrative, technical and other security safeguards required by the Health Insurance Portability & Accountability Act (HIPAA) Privacy and Security rules.
The U.S. Department of Health and Human Services (HHS) Office of Civil Rights (OCR) announced late yesterday (July 11, 2013) that WellPoint has agreed to pay $1.7 million to settle OCR charges that WellPoint violated the HIPAA Security Rule and left the electronic protected health information (ePHI) of 612,402 individuals accessible to unauthorized individuals over the Internet by failing to implement appropriate administrative and technical safeguards in its Web-based applications. See WellPoint HIPAA Settlement Press Release.
Web-based application use is increasingly popular among health plans and their wellness programs, as well as health care providers. Employers and health plans use them both in plan administration and offer them to members to use as member tools. Health care providers use them for health care operations, as well as patient engagement and communication tools. The WellPoint settlement illustrates that managed care and other health insurers, health plans and their employer or other sponsors, health care providers, health care clearinghouses (Covered Entities) and their business associates can’t let their enthusiasm for the ease of use of these products to compromise the security of PHI.
Rather, health plans and other Covered Entities, employer and other health plan sponsors, their business associates, and the Web and other technology developers, providers and consultants marketing products, services or other solutions should learn from WellPoint’s hard lesson by ensuring that current and future Web-based applications, portals and other information system components that are or could be used to provide access to PHI incorporate the Security Rule safeguards both when originally implemented and with each subsequent upgrade.
HIPAA Privacy, Security & Breach Notification Rules Require PHI Safeguards & Other Protections
The Breach Notification Rule added to HIPAA under the Health Information Technology for Economic and Clinical Health, or HITECH Act requires HIPAA-covered entities to notify OCR, affected individuals and the media promptly of a breach of “unsecured protected health information” (UPHI) impacting more than 500 individuals. For smaller breaches, the Breach Notification Rule still requires prompt notice to affected individuals, but allows Covered Entities to disclose the breach to OCR as part of an annual breach report and to forego notification to the media. UPHI generally includes any PHI, whether or not ePHI that is not either secured or destroyed in the way described by the Breach Notification Rules.
In addition to the Breach Notification Rule, most Covered Entities and their business associates also are subject to state laws or regulations that impose similar or additional breach notification and other standards and responsibilities on the protection of personal health or other data including required notification and other responses following a breach of the security of UPHI or other PHI.
WellPoint’s $1.7 HIPAA Security Mistake
WellPoint’s $1.7 million settlement lesson resulted from an OCR investigation started in response to a breach report WellPoint submitted to comply with the Breach Notification Rules.
According to OCR, the Breach Report indicated that security weaknesses in an online application database left the electronic protected health information (ePHI) of 612,402 individuals accessible to unauthorized individuals over the Internet.
OCR says its investigation indicated that WellPoint did not implement appropriate administrative and technical safeguards as required under the HIPAA Security Rule. According to OCR, WellPoint did not:
- Adequately implement policies and procedures for authorizing access to the on-line application database;
- Perform an appropriate technical evaluation in response to a software upgrade to its information systems; or
- Have technical safeguards in place to verify the person or entity seeking access to electronic protected health information maintained in its application database.
As a result, OCR concluded that from October 23, 2009 until March 7, 2010, WellPoint impermissibly disclosed the ePHI of 612,402 individuals by allowing access to their ePHI maintained in the application database. This data included names, dates of birth, addresses, Social Security numbers, telephone numbers and health information.
Under the resulting WellPoint HIPAA Resolution Agreement, WellPoint must pay OCR a $1.7 million settlement payment as well as take a series of corrective actions to correct the deficiencies in its policies and practices that resulted in the reported breach to minimize future risks of breaches resulting from these deficient.
OCR Warns Learn From WellPoint’s Experience
All Covered Entities and their business associates and leaders should heed the lesson sent to them by OCR in announcing the WellPoint settlement and take appropriate steps other to ensure that appropriate policies and safeguards are adopted and applied in selecting and implementing future application or system upgrades, as well as review existing systems to ensure that the security of existing systems and applications have incorporated and apply the requisite safeguards.
OCR made clear that the WellPoint settlement is intended to send a message to Covered Entities and their business associates to ensure that these steps are appropriately taken. The settlement announcement states:
This case sends an important message to HIPAA-covered entities to take caution when implementing changes to their information systems, especially when those changes involve updates to Web-based applications or portals that are used to provide access to consumers’ health data using the Internet. Whether systems upgrades are conducted by covered entities or their business associates, HHS expects organizations to have in place reasonable and appropriate technical, administrative and physical safeguards to protect the confidentiality, integrity and availability of electronic protected health information – especially information that is accessible over the Internet.
The settlement announcement also reminds business associates that OCR will begin holding them directly accountable along with their Covered Entity clients for complying with many HIPAA requirements beginning in September, stating:
Beginning Sept. 23, 2013, liability for many of HIPAA’s requirements will extend directly to business associates that receive or store protected health information, such as contractors and subcontractors.
Take Documented Steps To Show You Hear OCR’s Messages
Covered entities and their business associates and leaders, and vendors and consultants offering services or products to them should take care to conduct careful and well-documented reviews and implement corrective actions necessary to show their applications and systems, policies and practices reflect their strong commitment and action to appropriately protect PHI in accordance with the expectations shown by the WellPoint HIPAA Resolution Agreement and other OCR settlements, OCR’s updated HIPAA regulations, and other OCR and industry information.
In addition to the guidance set forth in OCR’s Resolution Agreements with WellPoint and other Covered Entities, revisions to OCR’s Privacy and Security Rules in OCR’s 2013 restatement of its regulations here cause all Covered Entities and their business associates conduct a well-documented reassessment of the adequacy of their existing policies, systems and practices and steps taken to redress any uncovered gaps.
Among other things, the 2013 Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the manner required by the 2013 Regulations;
- Update OCR’s rules about the individual rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Covered Entities were required to begin complying with most of these rule changes earlier this year. However, delayed compliance dates in the 2013 Regulations allowed Covered Entities and Business Associates to delay updates to pre-existing business associate agreements and the date that OCR would begin enforcing many of the HIPAA Rules directly against business associates to September 23, 2013.
Even without the necessity Settlements like that involving WellPoint, these 2013 Regulations make it imperative that Covered Entities to take the necessary steps to conduct an appropriate and well-documented review and update as needed their systems, policies and practices, business associate agreements, training and documentation.
With self-disclosures of breaches mandated by the Breach Notification Rules and OCR audits and enforcement rising, careful documentation of these activities and its analysis is necessary so that Covered Entities can be in a position to show OCR that the risk assessments required by the Security Rules was conducted as well as the efforts and commitment of the Covered Entity or business associate in the event of a breach investigation or audit. Yesterday’s WellPoint HIPAA announcement is just the latest in an ever-growing list of examples of the expensive consequences that can result if a Covered Entity or business associate cannot produce this documentation in response to an OCR audit or investigation. See, e.g. OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards. In contrast, the OCR website also provides a multitude of examples showing how the ability to produce documentation and other evidence showing diligent efforts to comply has helped other covered entities that fall under OCR investigation to avoid or mitigate serious sanctions.
Coupled with statements by OCR about its intolerance, the WellPoint and other settlements provide a strong warning to covered entities of the need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
In response to the 2013 Regulations and these expanding exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions against WellPoint and others, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. Covered Entities and business associates should document this review in a manner that both reflects the scope and diligence of their activities including relevant considerations and decision-making about identified potential susceptibilities and reasoning about the adequacy of safeguards and other solutions.
Because this review is likely to uncover existing or past deficiencies or breaches, most covered entities and business associates will want to discuss with qualified legal counsel the planned assessment within the scope of attorney-client privilege to understand when and how to conduct the assessment to preserve options to claim attorney-client privilege to protect sensitive work product or discussions that may result in the course of the investigation within the attorney-client communication, work product or other evidentiary privileges, evaluation of the adequacy and appropriateness of the audit and resulting investigations and its documentation, and other assistance in strengthening the defensibility of compliance and risk management activities.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
“Pay Or Play” Reprieve Still Leaves Employers Facing Challenging 2014 Health Care Reform Deadlines
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
1 Comment |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
June 14, 2013
Health plans, health care providers, health care clearinghouses (covered entities) and their business associates should confirm their existing policies, practices and training for communicating with the media and others comply with the Privacy Rule requirements of the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule in light of a Resolution Agreement with Shasta Regional Medical Center (SRMC) announced by the U.S. Department of Health and Human Services (HHS) Office of Civil Rights today (June 14, 2013).
Under the Resolution Agreement, SRMC agrees to pay $275,000 and implement a comprehensive corrective action plan (CAP) to settle an investigation that resulted when SRMC used and disclosed protected health information (PHI) of a patient to members of the media and its workforce while trying to do damage control against fraud or other allegations of misconduct involving individual patient information or circumstances. The Resolution Agreement shows how efforts to respond to press or media reports, patient or other complaints, physician or employee disputes, high profile accidents, or other events that may involve communications not typically run by privacy officers can create big exposures. While the Resolution Agreement targets a health care provider, the lessons are equally applicable to health plans and health care clearinghouses, who increasingly face their own pressure to communicate with the media and others about enforcement actions, workforce claims and other matters.
Talking Out Of Turn To Media & Others Violated HIPAA
OCR investigated SRMC after a January 4, 2012 Los Angeles Times article reported two SRMC senior leaders had met with media to discuss medical services provided to a patient. OCR’s investigation indicated that SRMC failed to safeguard the patient’s protected health information (PHI) from impermissible disclosure by intentionally disclosing PHI to multiple media outlets on at least three separate occasions, without a valid written authorization. OCR’s review also revealed senior management at SRMC impermissibly shared details about the patient’s medical condition, diagnosis and treatment in an email to the entire workforce. Further, SRMC failed to sanction its workforce members for impermissibly disclosing the patient’s records pursuant to its internal sanctions policy.
Among other things, the specific misconduct uncovered by HHS’s investigation indicated that from December 13 – 20, 2011, SRMC failed to safeguard the patient’s PHI from any impermissible intentional or unintentional disclosure on multiple occasions in connection with its response to media coverage arising from a Medicare fraud story including:
- On December 13, 2011, for instance, OCR reports SRMC’s parent company sent a letter to California Watch, responding to a story about Medicare fraud. The letter described the patient’s medical treatment and provided specifics about her lab results even though SRMC did not have a written authorization from the patient to disclose this information to this news outlet.
- On December 16, 2011, two of SRMC’s senior leaders also met with The Record Searchlight’s editor to discuss the patient’s medical record in detail even though SRMC did not have a written authorization from the patient to disclose this information to this newspaper.
- On December 20, 2011, SRMC sent a letter to The Los Angeles Times, which contained detailed information about the treatment the patient received when, again, SRMC did not have a written authorization from the patient to disclose this information to this newspaper.
In addition, OCR found SRMC impermissibly used the affected party’s PHI when on December 20, 2011, SRMC sent an email to its entire workforce and medical staff, approximately 785-900 individuals, describing, in detail, the patient’s medical condition, diagnosis and treatment. SRMC did not have a written authorization from the patient to share this information with SRMC’s entire workforce and medical staff.
SRMC Must Correct & Pay $$275K Penalty
Under the Resolution Agreement, SRMC pays a $275,000 monetary settlement and agrees to comply with a CAP for the next year.
The CAP requires SRMC to update its policies and procedures on safeguarding PHI from impermissible uses and disclosures and to train its workforce members. The CAP also requires fifteen other hospitals or medical centers under the same ownership or operational control as SRMC to attest to their understanding of permissible uses and disclosures of PHI, including disclosures to the media.
The Resolution Agreement specifically requires that Shasta Regional Medical Center, among other things:
- To update policies to include specific policies about sharing PHI with the media, members of the workforce not involved in an individual patient’s care and others to comply with HIPAA;.
- To provide updated policies to OCR for approval;
- To provide training documented with certification of all workforce members before allowing them to get access to PHI;
SRMC is one of several Prime Healthcare Services facilities under common ownership and control. The Resolution Agreement also requires corrective action at these commonly owned facilities including California-based Alvarado Hospital Medical Center in San Diego, Centinela Hospital Medical Center in Inglewood, Chino Valley Medical Center in Chino, Desert Valley Hospital in Victorville, Garden Grove Hospital Medical Center in Garden Grove, La Palma Intercommunity Hospital in La Palma, Paradise Valley Hospital in National City, San Dimas Community Hospital in San Dimas, Shasta Regional Medical Center in Redding, and West Anaheim Medical Center in Anaheim; Saint Mary’s Regional Medical Center in Reno, Nevada; Pennsylvania based Lower Bucks Hospital in Bristol and Roxborough Memorial Hospital in Philadelphia;and Texas-based Dallas Medical Center in Dallas, Harlingen Medical Center in Harlingen, Pampa Regional Medical Center in Pampa. Among other things, the Resolution Agreement requires that for each of these related facilities:
- The CEO and Privacy Officer of each facility must give OCR a signed affidavit stating that they understand that the Privacy Rule protects an individual’s PHI is protected by Privacy Rule even if such information is already in the public domain or even though it has been disclosed by the individual; and that disclosures of PHI in response to media inquiries are only permissible pursuant to a signed HIPAA authorization; and
- Ensure all members of their respective workforce are informed of this policy.
The Resolution Agreement highlights the difficulty that health care providers and other covered entities often face in properly recognizing and handling PHI in the case of fraud or other disputes. While health care providers have an understandable wish to defend themselves in the media and elsewhere in response to charges of misconduct, today’s settlement shows that improperly sharing PHI of each patient in the process will make matters much worse. It’s important to keep in mind that just omitting to mention the name or other common identifying information may not overcome this concern because information about a patient can be considered individually identifiable and to enjoy protection under HIPAA where the facts and circumstances would allow another person to know or determine who the individual is, even if the specific name, address or more common identifying information is not shared.
Furthermore, the settlement also makes clear that merely because the patient or some other party has shared the same information with the media or others does not excuse the health care provider or other covered entity or business associate from the obligation to keep confidential the PHI unless it gets proper consent or otherwise can show that an exception to HIPAA applies.
Finally, the Resolution Agreement also makes clear that OCR expects covered entities to connect their HIPAA compliance with other policies and operations and will hold covered entities and associates accountable for properly integrating, training workforce and enforcing compliance with these policies. While this means that covered entities and business associates may find themselves in the uncomfortable situation of facing unsavory reports and rumors without the ability to respond, the significant civil and even criminal penalties that can arise from violation of HIPAA make it critical that covered entities exercise discipline in responding to avoid sharing PHI improperly.
The 2013 Regulations Overview
Adding a review and update of HIPAA and other policies for communicating with the media and internally on matters that may involve use or discussions of PHI in unusual contexts outside the purview of typically HIPAA policies is a good idea while health plans and other covered entities and business associates are updating their existing policies and practices for compliance with updated Omnibus HIPAA Rules (2013 Regulations) implementing HITECH Act amendments to the Privacy and Security Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Rulemaking announced January 17, 2013 may be viewed here.
Since 2003, HIPAA generally has required that health care providers, health plans, health care clearinghouses and their business associates (“Covered Entities”) restrict and safeguard individually identifiable health care information (“PHI”) of individuals and afford other protections to individuals that are the subject of that information. The 2013 Regulations published today complete the implementation of changes to HIPAA that Congress enacted when it passed the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009 as well as make other changes to the prior regulations that OCR found desirable based on its experience administering and enforcing the law over the past decade.
Since passage of the HITECH Act, OCR officials have warned Covered Entities to expect an omnibus restatement of its original regulations. While OCR had issued certain regulations implementing some of the HITECH Act changes, it waited to publish certain regulations necessary to implement other HITECH Act changes until it could complete a more comprehensive restatement of its previously published HIPAA regulations to reflect both the HITECH Act amendments and other refinements to its HIPAA Rules. The 2013 Regulations published today fulfill that promise by restating OCR’s HIPAA Regulations to reflect the HITECH Act Amendments and other changes and clarifications to OCR’s interpretation and enforcement of HIPAA.
Among other things, the 2013 Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the way required by the 2013 Regulations;
- Update OCR’s rules about the rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Liability & Enforcement Risks Heighten Need To Act To Review & Update Policies & Practices
The new Resolution Agreement and the growing list of others like it, as well as restated rules in the 2013 Regulations make it imperative that Covered Entities review the revised rules carefully and updated their policies, practices, business associate agreements, training and documentation to comply with the updated requirements and other enforcement and liability risks. OCR even prior to the regulations has aggressively investigated and enforced the HIPAA requirements.
OCR increasingly is imposing sanctions against a covered entity for data breaches to show the potential risks of HIPAA violations are significant and growing. OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards.
In response to the 2013 Regulations and these expanding exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
Enforcement Actions Highlight Growing HIPAA Exposures For Covered Entities
The SRMC Resolution Agreement again shows the growing risk of enforcement that health care providers, health plans, health care clearinghouses and their business associates face as OCR continues its audits and enforcement, new Omnibus HIPAA Regulations implementing the HITECH Act amendments to HIPAA and state and federal liability grows.. See e.g., $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website.
In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to determine if additional steps are necessary or advisable.
As part of this process, covered entities should ensure they look outside the four corners of their Privacy Policies to ensure that appropriate training and clarification is provided to address media, practice transition, workforce communication and other policies and practices that may be covered by pre-existing or other policies of other departments or operational elements not typically under the direct oversight and management of the Privacy Officer such as media relations. Media relations, physician and patients affairs, outside legal counsel, media relations, marketing and other internal and external departments and consultants dealing with the media, the public or other inquiries or disputes should carefully include and coordinate with the privacy officer both to ensure appropriate policies and procedures are followed and proper documentation created and retained to show authorization, account, or meet other requirements.
For more information about HIPAA compliance and risk management tips, see here.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Makes Technical Corrections To HIPAA Omnibus Final Rule; September 2013 Enforcement Deadline Looming;
- OCR Gives HIPAA Guidance On Safety Disclosures
- OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach
- OCR Audit Program Kickoff Further Heats HIPAA Privacy RisksProvidence To Pay $100000 & Implement Other Safeguards
- Former White House Cybersecurity Coordinator Schmidt, Stamer & Others Share Key HIPAA & Other Privacy & Data Security Insights 5/21 In LA
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on HIPAA Sanctions Triggered From Covered Entity Statements To Media, Workforce |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Employer, Employment, Health Care, Health Plans, HIPAA, Hospitals, OCR, Office of Civil Rights, PHI, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
June 6, 2013
The Department of Health & Human Services Office of Civil Rights (OCR) on June 6, 2013 released an advance copy of to Technical Corrections (Technical Corrections) to the Modifications to the HIPAA Privacy, Security, Enforcement, and Breach Notifications Rules Under the Health Information Technology for Economic and Clinical Health Act and the Genetic Information Nondiscrimination Act; Other Modifications to the HIPAA Rules; Final Rule (Omnibus Rule) previously published on January 25, 2013. Health plans, health care clearinghouses, health care providers and their business associates will want to be sure to take into account the Technical Corrections as they rush to update business associate agreements, policies, practices, training and other HIPAA compliance to comply with the Omnibus Rule changes by the September 2013 deadline.
Technical Corrections To Omnibus Rule Released
OCR published the Omnibus Rule to implement changes to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules (“the HIPAA Rules”) enacted by the Health Information Technology for Economic and Clinical Health Act (“the HITECH Act”) and section 105 of Title I of the Genetic Information Nondiscrimination Act of 2008, as well as to address public comment received on the interim final Breach Notification Rule and to other changes to the HIPAA Rules. The Technical Corrections are scheduled for publication in the Federal Register on June 7, 2013.
The Technical Corrections correct various typographical errors and other oversights in the Omnibus Regulations as originally published. While many of these corrections have limited material impact, certain corrections do have substantive implications. For instance, by correcting errors in references to other provisions of the Omnibus Regulations, the Technical Corrections clarify that the authority of OCR to grant an extension of time pursuant to § 160.508(c)(5) for violations before February 18, 2009 also applies to violations occurring on or after February 18, 2009, as there is for violations occurring prior to February 18, 2009.
Health plans, health care clearinghouses and their business associates will need to review and take into account the Technical Corrections as they work to review and update their policies and practices for handling and disclosing personally identifiable health care information (“PHI”) in response to the Omnibus Rule.
Get Moving To Update HIPAA Compliance For New Omnibus Rule Requirements As Amended By Technical Corrections
Covered entities and their business associates have a lot to accomplish between now and September to update their business associates and comply with other changes made by the Omnibus Rule by its September 2013 deadline. Among other things, the Omnibus Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the way required by the Omnibus Regulations;
- Update OCR’s rules about the individual rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Liability & Enforcement Risks Heighten Need To Act To Review & Update Policies & Practices
The restated rules in the Omnibus Rule make it imperative that Covered Entities review the revised rules carefully and updated their policies, practices, business associate agreements, training and documentation to comply with the updated requirements and other enforcement and liability risks. OCR even prior to the regulations has aggressively investigated and enforced the HIPAA requirements. See, e.g., OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards.
Coupled with statements by OCR about its intolerance, the HONI and other settlements provide a strong warning to covered entities of the need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
All Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Gives HIPAA Guidance On Safety Disclosures
- Id & Manage Hidden Employee Benefit Exposures In Business Insolvency Or Other Transactions
- Final Regulations Update HIPAA Health Plan Wellness Program Rules
- Beware: Not All Products Marketed As “Fixed Indemnity Coverage” Products Are HIPAA/ACA Exempt
- Updated Kaiser Family Foundation Tool May Help Project Which Employees Will Get Exchange Subsidies
- New IRS Guidance On ESOP Investment Diversification Reminder To Tighten Compliance, Risk Management
- EBSA Releases Model ACA Notices Discussing Coverage Options
- Group Health Plans &No-Fault & Worker’s Comp Ruled Primary Plans When Coordinating With Medicare Advantage Plans
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Former White House Cybersecurity Coordinator Schmidt, Stamer & Others Share Key HIPAA & Other Privacy & Data Security Insights 5/21 In LA
- Strengthen Health Plan Privacy Compliance & Risk Management Using Lessons From New OCR Provider & Consumer Tools
- Changing Plan Years Won’t Extend Health Plan’s Affordable Care Act Annual Limit Waiver Eligibility
- Deadline To Send ACA Summary of Benefits & Coverage Adds Pressure To Finalize 2014 Plan Designs As Agencies Add MEC & MV Disclosures To SBC
- Study Finds Down Economy, Not Health Care Reform Accounts For Slower Health Care Cost Increases; Projects Renewed Costs When Economy Improves
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Consider OCR Technical Corrections When Updating Privacy Practices & Agreements For Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
March 5, 2013
Even as small and other businesses are struggling to cope with rising rates and impending new rules under the Patient Protection and Affordable Care Act (ACA), small businesses now must deal with being sideswiped by sequester.
Sequester will hurt certain small employers that were counting on the Small Business Health Care Tax Credit (SBHCTC) to afford health care coverage for their employees.
Under the sequester requirements of the Balanced Budget and Emergency Deficit Control Act of 1985, as amended, certain automatic budget cuts went into effect on March 1, 2013. These required cuts include an 8.7% reduction to the refundable part of the SBHCTC for otherwise qualifying small employers under Internal Revenue Code § 45R. As a result, employers qualifying for the SBHCTC should expect to see an 8.7% percent reduction in the amount of reimbursement received for health premiums under the SBHCTC. The sequestration reduction rate will apply until the end of the fiscal year on September 30, 2013 or intervening Congressional action, at which time the sequestration rate is subject to change.
Aside from the effects of sequester, small and other businesses health care costs and responsibilities continue to be shaped by a deluge of new rules rolling out under ACA, the Health Insurance Portability & Accountability Act (HIPAA), the Family & Medical Leave Act, and a host of other laws. Stay tuned here for more updates.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized as a knowledgable and innovative health benefit thought leader by business and government leaders for her extensive work, publications and leadership on health benefit and insurance and other related employee benefits, insurance, human resources and health care matters, Ms. Stamer has advised and defended employer and other health plan sponsors, administrators and fiduciaries, insurers, and others about benefit design, compliance, administration and defense for more than 25 years. Her work includes highly pragmatic, leading edge work helping clients to design, deploy, administer and defend catastrophic, mini-med, expatriate and medical tourism, occupational injury and 24-hour coverage, HRA, HSA HFSA and other defined contribution, Medicare Advantage, and other health plans, policies and practices to comply with the Affordable Care Act, HIPAA, ERISA, COBRA, Mental Health Parity, Internal Revenue Code, labor and employment, privacy, managed care and insurance and other federal and state laws and regulations.
In addition to her extensive legal resume, Ms. Stamer also is a highly regarded industry thought leader and author with extensive involvement in the leadership of a broad range of professional and civic organizations. For instance, Ms. Stamer is the founder and executive director of the Coalition for Responsible Health Care Policy and its PROJECT COPE; The Coalition on Patient Empowerment; a Fellow in the American College of Employee Benefits Counsel, the American Bar Association and the State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group; the Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee and the current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair; a Council Member of the ABA Joint Committee on Employee Benefits; Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; Immediate Past Gulf States Area TEGE Council Exempt Organization Coordinator; a current or former Editorial Advisory Board Member of Insurance Thought Leadership, HR.com, Employee Benefit News, the BNA Employee Benefits CD-Rolm and various other BNA HR and Employee Benefits publications; a former national board member and Dallas Chapter President of WEB, Network of Benefits Professionals; a former Southwest Benefits Association Board Member; the past Dallas HR Government Relations Committee Chair; a former SHRM Region IV Board Member and National Consultants Forum Board Member,; past Dallas Bar Association Employee Benefits & Compensation Committee Chair, and a former Texas Association of Business State Board and Regional and Dallas Chapter Chair.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications
- 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues
- Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C.
- IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February
- IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Sequester Will Cut ACA Small Businesses Health Care Tax Credits |
Corporate Compliance, Employers, Excise Tax, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Payroll Tax, Privacy, Risk Management, Tax, Tax Credit | Tagged: ACA, Employer, Employers, Employment, Health Care Reform, Health Plans, Labor Department, PPACA, Small Business Health Care Tax Credit, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
March 1, 2013
The U.S. Department of Labor’s Occupational Safety and Health Administration (OSHA) citation of the Battle Creek Veterans Administration Medical Center, following a safety inspection conducted in July as part of OSHA’s Federal Agency Targeting Inspection Program for seven notices of unsafe or unhealthful working conditions reminds employers that OSHA expects employers to maintain safe workplaces.
Under the Occupational Safety and Health Act, federal agencies must comply with the same safety standards as private-sector employers. According to OSHA, its inspection uncovered several repeat safety violations, as well as certain other serious safety violations.
OSHA reports that three repeat safety violations involved failing to evaluate the workplace to identify if permit-required confined spaces were present and label such spaces with danger signs; failing to adequately guard automated laundry equipment to prevent employees from entering the work area, and failing to fully guard the belt and pulley of an air compressor. To issue notices for repeat violations, OSHA must have issued at least one other notice for the same violation at one of the agency’s establishments within the same standard industrial classification code, commonly known as the SIC code. OSHA previously has cited U.S. Department of Veterans Affairs facilities in Danville and North Chicago, Illinois, and Minneapolis, Minnesota for the same safety and health violations.
The serious safety violations found included three serious safety violations for unguarded floor openings in the general repair shop; failing to inspect powered industrial trucks prior to placing them in service, and failing to remove trucks from service in need of repair. Additionally, OSHA found a circuit breaker panel was not mounted correctly. OSHA issues a serious notice when it finds a substantial probability that death or serious physical harm could result from a hazard about which the employer knew or should have known.
Beyond the repeated and serious violations, OSHA reports it also found one other-than-serious violation for failing to close unused openings on electrical cabinets and junction boxes. An other-than-serious violation is one that has a direct relationship to job safety and health, but probably would not cause death or serious physical harm.
The medical center has 15 business days from receipt of the notices to comply, request an informal conference with OSHA’s area director or appeal the notices by submitting a summary of the agency’s position on the unresolved issues to OSHA’s regional administrator.
While the medical center and other federal agencies are required to comply with the same OSHA rules as private sector employers, the VA and other federal agencies don’t face the same liabilities when cited. OSHA cannot propose monetary penalties against another federal agency for failure to comply with OSHA standards.
The risks for private sector employers is illustrated by another recent OSHA. OSHA recently cited Riddell All-American Sports Co. with eight serious violations following an OSHA investigation, which found that the company exposed workers to multiple safety and health hazards at its San Antonio facility. The violations include failing to ensure electrical equipment was free from recognized hazards, provide adequate machine guarding while employees operate industrial sewing machines and provide a fall protection program to prevent falls from the basket of a powered industrial truck. The Elyria, Ohio-based company, which employs about 25 workers in San Antonio, paints helmets for various sports. Proposed penalties total $44,000. Read the News Release.
Since private sector employers that don’t enjoy the VA’s immunity liability run much greater risks for failing to maintain workplace safety, including significant civil and in the case of a workplace death, potentially even criminal penalties, private sector hospitals and other organizations should exercise special care to ensure appropriate safety in their workplaces. “The Battle Creek Veterans Administration Medical Center failed to properly ensure the facility was in compliance with established safety and health procedures,” said Robert Bonack, director of OSHA’s Lansing Area Office. “All employers, including federal employers, are responsible for knowing what hazards exist in their facilities and taking appropriate precautions by following OSHA standards so workers are not exposed to such hazards.”
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help in conducting a risk assessment of or responding to an IRS, DOL, Justice Department, or other federal or state agencies or other private plaintiff or other legal challenges to your organization’s existing workforce classification or other labor and employment, compliance, employee benefit or compensation practices, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469) 767-8872 .
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications
- 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues
- Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C.
- IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February
- IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on OSHA Citation Of Michigan VA Reminder To Manage Workplace Safety |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, Health, Hospital, IT, Labor Department, Medical Center, Minimum Wage, OSHA, Safety, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 25, 2013
The U.S. Department of Health and Human Services (HHS) on February 22, 2013 released its Final Rule implementing many of the key market reform provisions of the Patient Protection and Affordable Care Act, as amended by the Health Care and Education Reconciliation Act of 2010 (the “Affordable Care Act”) applicable to non-grandfathered health plans and health insurance issuers.
The 145 page regulations and associated guidance package scheduled for official publication in the Federal Register on February 27, 2013 clarifies and implements the Affordable Care Act’s provisions relating to Guaranteed Availability and Renewability; Health Insurance Premiums; Single Risk Pool; Catastrophic Plans, Utilization Data Collection and Reporting under the Federal Rate Review Program and certain other matters.
Among other thing, the Final Regulations:
- Clarify the approach HHS will use to enforce the applicable requirements of the Affordable Care Act with respect to health insurance issuers and group health plans that are nonfederal governmental plans
- Amend the standards for health insurance issuers and states on reporting, utilization, and collection of data under the federal rate review program
- Revise the timeline for states to propose state-specific thresholds for review and approval by the Centers for Medicare & Medicaid Services (CMS)
- Allow health insurance issuers to vary the premium rate for health insurance coverage in the individual and small group markets only based on family size, geography, and age and tobacco use within limits
- Direct health insurance issuers to offer coverage to and accept every employer or individual who applies for coverage in the group and individual market, subject to certain exceptions including how these requirements inter-relate with the Affordable Care Act’s restrictions on pre-existing condition limitations and exclusions
- Direct health insurance issuers to renew or continue in force coverage in the group and individual market, subject to certain exceptions
- Codify the requirement that issuers maintain a single risk pool for the individual market and a single risk pool for the small group market (unless a state decides to merge the markets into a single risk pool)
- Outline standards for enrollment in catastrophic plans for young adults and people who cannot otherwise afford health insurance
- Amend the standards under the rate review program in 45 CFR part 154 by among other things, changing the timeline for states to propose state-specific thresholds for review and approval by CMS, requiring health insurance issuers to submit data relating to proposed rate increases in a standardized format specified by the Secretary of HHS and modifying criteria and factors for states to have an effective rate review program
Along with responding to these regulations, health insurers, group health plans and their insurers and others need to stay tuned. These regulations are just one of a deluge of regulations and other interpretations that HHS and other agencies are rolling out in the rush to meet the impending deadlines for the implementaton of the Affordable Care Act. For instance, along with this guidance, HHS along with the Internal Revenue Service and Employee Benefit Security Administration also last week issued FAQ XII, which discusses the co-pay, deductible and certain other aspects of the cost sharing limits of the Affordable Care Act. In previous weeks, the agencies also have issued or proposed regulations about waiting period, employer shared responsibility, essential health benefits, and various other elements of the rules. Additional guidance is impending.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized as a knowledgable and innovative health benefit thought leader by business and government leaders for her extensive work, publications and leadership on health benefit and insurance and other related employee benefits, insurance, human resources and health care matters, Ms. Stamer has advised and defended employer and other health plan sponsors, administrators and fiduciaries, insurers, and others about benefit design, compliance, administration and defense for more than 25 years. Her work includes highly pragmatic, leading edge work helping clients to design, deploy, administer and defend catastrophic, mini-med, expatriate and medical tourism, occupational injury and 24-hour coverage, HRA, HSA HFSA and other defined contribution, Medicare Advantage, and other health plans, policies and practices to comply with the Affordable Care Act, HIPAA, ERISA, COBRA, Mental Health Parity, Internal Revenue Code, labor and employment, privacy, managed care and insurance and other federal and state laws and regulations.
In addition to her extensive legal resume, Ms. Stamer also is a highly regarded industry thought leader and author with extensive involvement in the leadership of a broad range of professional and civic organizations. For instance, Ms. Stamer is the founder and executive director of the Coalition for Responsible Health Care Policy and its PROJECT COPE; The Coalition on Patient Empowerment; a Fellow in the American College of Employee Benefits Counsel, the American Bar Association and the State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group; the Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee and the current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair; a Council Member of the ABA Joint Committee on Employee Benefits; Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee; Immediate Past Gulf States Area TEGE Council Exempt Organization Coordinator; a current or former Editorial Advisory Board Member of Insurance Thought Leadership, HR.com, Employee Benefit News, the BNA Employee Benefits CD-Rolm and various other BNA HR and Employee Benefits publications; a former national board member and Dallas Chapter President of WEB, Network of Benefits Professionals; a former Southwest Benefits Association Board Member; the past Dallas HR Government Relations Committee Chair; a former SHRM Region IV Board Member and National Consultants Forum Board Member,; past Dallas Bar Association Employee Benefits & Compensation Committee Chair, and a former Texas Association of Business State Board and Regional and Dallas Chapter Chair.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications
- 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues
- Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C.
- IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February
- IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on HHS Releases Final Rule on Health Insurance Market, Rate Review, Pre-Existing Conditions & Other ACA Market Reform Rules |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 23, 2013
Thinking about or using mobile devices and applications in your heath care, health plan, workforce or related operations or struggling to meet the demands of employees, plan members or others to allow use of these tools? Be sure that you’ve taken appropriate steps to design, implement and manage legal responsibilities and risks associated with the development and use of these tools.
While the popularity, accessibility and cost-effectiveness of mobile devices and applications provides a strong incentive for health and other employee benefit plans, employers, their business associates, workforce members and customers to use mobile devices and applications, the use of these technologies and applications to collect, access, or use personal health care, financial, or other sensitive information presents special challenges and risks. Unfortunately, as the use of these tools proliferates, federal officials are increasingly concerned that the data security protections afforded by many of the devices and applications in use on these highly popular smart phone, tablet and other mobile devices and applications is highly lacking. See FTC Settlement With Mobile Device & App Developer Shows Developers & Businesses Need To Manage Mobile App & Data Security.
As federal regulators and law enforcement responds to growing concerns about cyber security and other risks, heath care, health plan and other businesses, their employees, customers, and other business partners jumping on the mobile device and application bandwagon, health, application bandwagon, and the device and application developers developing and offering these tools must take appropriate steps to manage the personal health, financial, and other sensitive information and data that these tools use, create, access or disclose.
Of course, most health plan sponsors, fiduciaries, administrators and service providers already recognize the need to use care when dealing with health plan data. The Health Insurance Portability & Accountability Act (HIPAA) generally requires that health care providers, health plans, health care clearinghouses and their businesses associates safeguard personal health care information or “PHI” and restrict its use, access and disclosure in accordance with the extensive and highly detailed requirements of the Privacy, Security and Breach Notification Regulations of the Department of Health & Human Services Office of Civil Rights (OCR).
OCR’s collection of several multi-million dollar settlements as well as its statements in its recent restated HIPAA regulations and other OCR guidance make clear that OCR views HIPAA as imposing significant responsibilities upon covered entities and their business associates to safeguard and restrict access to PHI on mobile devices and applications. OCR’s Long-Anticipated Omnibus HIPAA Privacy, Security, Breach Notification & Enforcement Rule Tightens Privacy Requirements, Require Action; Breaches resulting from the loss or theft of unencrypted ePHI on mobile or other computer devices or systems has been a common basis of investigation and sanctions since that time, particularly since the Breach Notification rules took effect. OCR Pops Idaho Hospice In 1st HIPAA Breach Settlement Affecting < 500 Patients; Providence To Pay $100000 & Implement Other Safeguards; OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website. These actions and statements of OCR provide a clear warning to HIPAA-covered entities and their business associates to expect significant consequences for failing to properly encrypt and safeguard ePHI used, accessed or disclosed on mobile devices and applications.
Of course, HIPAA isn’t the only law and health plans should not be the only area of concern when employers or their health or other employee benefit plan fiduciaries and service providers are considering mobile device and application use. In addition to HIPAA’s health plan requirements concerning PHI, mobile devices and applications used in connection with employment, benefit plan, and related operations also can trigger a host of privacy, data security and other rules requiring data security and other safeguards. Federal laws like the Internal Revenue Code, the Fair Credit Reporting Act, Graham-Leech-Biliey, the Fair & Accurate Credit Transactions Act (FACTA) or other Federal Trade Commission (FTC) Rules, state data security, data breach, identity theft or other privacy rules or both are just a few of the many and constantly expanding regulatory requirements that can apply. Depending on the nature of the data and the circumstances of the unanticipated use or disclosure, invasion of privacy or other common or statutory laws also may come into play.
With the use of these applications by consumers and business proliferates, Congress, OCR, the FTC, state regulators and others are upping the responsibilities and the liability of businesses that fail to appropriately consider and implement security in their mobile devices and applications. Following on OCR’s restatement of its HIPAA regulations, the Obama Administration’s announcement of new cyber security initiatives, and a plethora of other federal and state regulatory and enforcement actions against businesses for data security missteps, the FTC recently launched a campaign to ensure that companies secure the software and devices mobile device and application providers provide consumers.
Earlier this month, the FTC introduced Mobile App Developers: Start with Security, a new business guide that encourages app developers to aim for reasonable data security.
On June 4, 2013, the FTC also plans to host a public forum on malware and other mobile security threats in order to examine the security of existing and developing mobile technologies and the roles that various members of the mobile ecosystem can play in protecting consumers.
Along side this educational outreach, the FTC also is moving to punish businesses that fail to act responsibly to protect sensitive data. This trend is illustrated by the FTC’s announcement this week of its first settlement with a mobile device manufacturer.
FTC Charges Against HTC America
This week, the FTC announced that mobile device giant HTC American, Inc. will to settle FTC charges that the company failed to take reasonable steps to secure the software it developed for its smart phones and tablet computers and introduced security flaws that placed sensitive information about millions of consumers at risk.
A leading mobile device manufacturer in the United States, HTC America develops and manufactures mobile devices based on the Android, Windows Mobile, and Windows Phone operating systems. HTC America has customized the software on these devices in order to differentiate itself from competitors and to comply with the requirements of mobile network operators.
In its first-ever complaint against a mobile device or application developer, the FTC charged HTC America failed to incorporate and administer appropriate safeguards for personal financial and other sensitive data accessed and used in these applications when designing or customizing the software on its mobile devices. Among other things, the complaint alleged that HTC America failed to provide its engineering staff with adequate security training, failed to review or test the software on its mobile devices for potential security vulnerabilities, failed to follow well-known and commonly accepted secure coding practices, and failed to establish a process for receiving and addressing vulnerability reports from third parties.
To illustrate the consequences of these alleged failures, the FTC’s complaint details several vulnerabilities found on HTC America’s devices, including the insecure implementation of two logging applications – Carrier IQ and HTC Loggers – as well as programming flaws that would allow third-party applications to bypass Android’s permission-based security model.
Due to these vulnerabilities, the FTC charged, millions of HTC devices compromised sensitive device functionality, potentially permitting malicious applications to send text messages, record audio, and even install additional malware onto a consumer’s device, all without the user’s knowledge or consent. The FTC alleged that malware placed on consumers’ devices without their permission could be used to record and transmit information entered into or stored on the device, including, for example, financial account numbers and related access codes or medical information such as text messages received from healthcare providers and calendar entries about doctor’s appointments. In addition, malicious applications could exploit the vulnerabilities on HTC devices to gain unauthorized access to a variety of other sensitive information, such as the user’s geolocation information and the contents of the user’s text messages.
Moreover, the FTC complaint alleged that the user manuals for HTC Android-based devices contained deceptive representations, and that the user interface for the company’s Tell HTC application was also deceptive. In both cases, the security vulnerabilities in HTC Android-based devices undermined consent mechanisms that would have otherwise prevented unauthorized access or transmission of sensitive information.
HTC America Settlement
The settlement not only requires the establishment of a comprehensive security program, but also prohibits HTC America from making any false or misleading statements about the security and privacy of consumers’ data on HTC devices. Under the settlement agreement, HTC American must:
- Fix vulnerabilities found in millions of HTC devices;
- Establish a comprehensive security program designed to address security risks during the development of HTC devices; and
- Undergo independent security assessments every other year for the next 20 years.
HTC America and its network operator partners are also in the process of deploying the security patches required by the settlement to consumers’ devices. Many consumers have already received the required security updates. The FTC is encouraging consumers using HTC America applications to apply the updates as soon as possible.
The FTC Commission vote to accept the consent agreement package containing the proposed consent order for public comment was 3-0-2, with Chairman Jon Leibowitz not participating and Commissioner Maureen Ohlhausen recused. The FTC will publish a description of the consent agreement package in the Federal Register shortly.
In accordance with FTC procedures, the settlement agreement will be subject to public comment through March 22, after which the Commission will decide whether to make the proposed consent order final. Interested parties can submit comments electronically or in paper form using instructions in the “Invitation To Comment” part of the “Supplementary Information” section. Comments in paper form should be mailed or delivered to: Federal Trade Commission, Office of the Secretary, Room H-113 (Annex D), 600 Pennsylvania Avenue, N.W., Washington, DC 20580. The FTC is requesting that any comment filed in paper form near the end of the public comment period be sent by courier or overnight service, if possible, because U.S. postal mail in the Washington area and at the Commission is subject to delay due to heightened security precautions.
Act To Manage Mobile Application Device & Security
Given the expanding awareness, expectations and enforcement of OCR, FTC and others, health care, health plan and other industry participants deciding whether and when to use, or allow others to use mobile devices or applications to access data or carry out other activities and the mobile device or other technology developers and providers offering products or services to these organizations must get serious about security.
These and other related activities send a clear message that health care, health insurance mobile device and application users and developers must incorporate and administer appropriate processes and safeguards to protect PHI, personal financial and other sensitive data. In response to these developments, industry mobile device and application developers and the health care, health insurance and other businesses must consider carefully before deploying or allowing others to deploy or use these tools in relation to data within their operations or systems. Before and when using or permitting customers, business partners, employees or others to use tools, these organizations must ensure the adequacy of the design and security safeguards for their devices, software and applications, as well as their disclaimers and associated consumer disclosures and consents. Because of the special legal and operational expectations for these organizations, health care, health insurance and other industry provides must resist pressure to allow the use of these tools unless and until they can verify that these legal and operational requisites are fulfilled.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on FTC, HIPAA Rules Require Health Plans & Employers Strengthen Data Security on Mobile Devices and Applications |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 19, 2013
Cynthia Marcotte Stamer will share her insights on health and welfare benefit challenges for multinational employers as one of the featured panelists on the “Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues” Teleconference hosted by the American Bar Association Joint Committee on Employee Benefits on March 13, 2013 from 10:00-11:30 a.m. Central Time.
- Intended to help broad-based U.S. and European community benefits attorneys and others seeking to understand common and unique issues associated with employee transferees, granting of equity compensation and associated treaty issues, including:
- Basic issues associated with transfers including granting of past service credits, vesting and distribution issues
- Case studies involving employee transfers between the U.S. and the UK.
- Use of international deferred compensation programs.
- Unique health and welfare issues associated with international transfers.
- Interesting/Global equity issues to avoid.
Moderated by Elizabeth Drigotas, PriceWaterhouseCoopers, Washington, DC, the program will feature a diverse and highly experienced group of distinguished government and private speakers including:
- M. Grace Fleeman, Senior Technical Reviewer, Branch 1, (Associate Chief Counsel International)), Internal Revenue Service, U.S. Department of the Treasury, Washington, DC (invited)
- Andrew C. Liazos, McDermott Will & Emery, Boston, MA
- Matthew Preston, Clifford Chance, London, UK
- Cynthia Marcotte Stamer, Cynthia Marcotte Stamer, PC, Addison, TX.
To register or for additional information, see here.
About Ms. Stamer
Sought out nationally and internationally as an industry thought leader and problem solver, attorney, Cynthia Marcotte Stamer has more than 25 years experience helping domestic and foreign private and public businesses, employer and union plan sponsors, health and other employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental and community leaders and others develop, implement, administer and defend creative, legally compliant and operationally effective health and other employee benefit, employment, insurance, pension and retirement, health care, workers’ compensation and workforce plans, practices, and policies.
Recognized in International Who’s Who, the founder and Executive Director of Project COPE: The Coalition on Patient Empowerment and its affiliate, the Coalition on Responsible Health Policy; a Fellow in the American College of Employee Benefits Counsel, American Bar Association, and State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee, current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair and Substantive Groups Committee Member, and a Council Member of the ABA Joint Committee on Employee Benefits, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, and Immediate Past Gulf States Area TEGE Council Exempt Organization Chair, Ms. Stamer helps these and other clients. to design, document, administer and defend managed care and insurance programs, processes, and products; to monitor and manage evolving regulatory, contractual and fiduciary obligations and risks; to draft, negotiate, interpret and enforce managed care and other contracts, plan documents, insurance policies, administrative services agreements, and other agreements, policies, procedures and controls; to credential, monitor and manage fiduciaries, service providers, consultants and others providing services relating to programs; to conduct and defend litigation, audits, and other enforcement actions; to deal with legislators, regulators, auditors and others; and to fulfill legal obligations, mitigate legal risks and improve operational effectiveness.
As a core focus of her practice, Ms. Stamer continuously counsels, represents and defends self-insured and insured managed care and health, disability and welfare, pension, deferred compensation and other employee benefit plans; employer, association, insurer, and other employee benefit and insurance program sponsors; plan fiduciaries, administrators, brokers, consultants and other service providers; Medicare and Medicaid Advantage and other group, individual, stop-loss and other reinsurance, fiduciary liability and other insurers; health and insurance technology and other outsourcing companies; human resources, insurance and employee benefit consulting organizations; and other insurance, employee benefit and human resources industry clients, domestic and foreign governments and others about a diverse range of employee benefit, insurance, employment, tax, regulatory, risk management, public policy and related matters.
Ms. Stamer’s health benefit experience includes extensive and highly-innovative dealings with insured and self-insured managed care, defined contribution, indemnity and other health benefit, disability, life, occupational injury, Medicare and Medicaid Advantage, and other welfare benefit and insurance plans and policies; and a wide range of other employee benefits, compensation, insurance, equity and other related arrangements. Her work includes leading edge development and use of 24-hour coverage and other occupational injury, ex-pat and other medical tourism products, HRA, HSA, HRA and other defined contribution, hi-deductible, deductible reimbursement, min-med and other limited benefit plans, 24-hour and occupational benefit, fraternal benefit and association, and other medical programs as well as a broad range of claims, appeals, audit, and other administrative processes and tools designed to promote defensibility and mitigate risks.
Along side this domestic work, Ms. Stamer also has extensive international experience. A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on design, administration, operations, compliance, public policy and regulatory, and other challenges arising in the administration of multinational workforces and populations. Throughout her career, Ms. Stamer has advised both U.S. based businesses and foreign owned or operated businesses about design and administration of employment, employee benefit, worker’s compensation, employment tax, occupational safety, discipline and promotion, collective bargaining, recruiting, compliance, risk management and other personnel practices for multinational workforces. She has worked extensively on the design and administration of pension, severance, health and other benefit and compensation programs for their multinational workforce. She assists businesses with cross-border and domestic employment, consulting, independent contractor, subcontractor, employee leasing and other staffing and vendor agreements; multinational Foreign Corrupt Practices Act, Federal Sentencing Guidelines, and other compliance programs and practices; design, drafting, interpretation, implementation, and coordination pension, health care, severance, education, insurance, employment, tax, unemployment, disability, and other programs and requirements; represents and advises businesses, associations and government agencies before U.S. and foreign governments in connection with tax, employment, and other compliance matters, trade relationships and missions, public policy advocacy.
A widely published author and highly sought out speaker whose HR & Benefits Update has been recognized as among the “Top 50” HR Blogs To Watch, Ms. Stamer also regularly authors materials and conducts workshops and professional, management and other training on employee benefits, human resources, health care and other compliance and management topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Insurance Thought Leadership, Government Institutes, Inc., Solutions Law Press, Inc., the Society of Professional Benefits Administrators, HealthLeaders, Managed Care Executive, CEO Magazine, Business Insurance and many other industry, professional and business publications. An Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Employee Benefit News, and other publications, Ms. Stamer also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to inquire about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com. Ms. Stamer also is widely recognized for her regulatory and public policy advocacy, publications, and public speaking on privacy and other compliance, risk management concerns. For the past two years, Ms. Stamer has serve as the appointed scribe for the ABA Joint Committee on Employee Benefits annual agency meeting with OCR and has lead numerous programs for the ABA and others on this topic. Her insights on HIPAA risk management and compliance frequently appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on 3/13 JCEB Teleconference Explores Foreign Transferees: Outbound, Inbound, Equity And Treaty Issues |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
February 5, 2013
Solutions Law Press, Inc. (SLP) readers qualify for up to a $400 discount on their registration to learn key insights from on strategies for charting the path forward to drive employee wellness, strengthen the workforce and impact global business competitiveness in the face of the impending health care reforms of the Patient Protection & Affordable Care Act from SLP Editor/Author Cynthia Marcotte Stamer and other leading employer health care decision makers at the 8th Annual Employer Health & Human Capital Strategy Congress that the World Health Congress is hosting on February 21-22, 2013 at The Westin Lake Mary, Orlando North Conference Center in Lake Mary, Florida.
About the Program
Nationally recognized industry thought leader and attorney SLP Editor attorney Cynthia Marcotte Stamer will help kick off the program when she joins a panel of prominent HR leaders discussing “Assessing Alternatives and Opportunities: Defined Contribution and Exchanges-What are the Long-Term Implications on Your Human Capital Strategy” beginning at 9:30 a.m. on February 21, 2013.
Following this keynote panel, attendees also will learn other key ideas and strategies to help their organizations cope with Health Care Reform as they participate in a host of other insightful and timely presentations by dynamic team of prominent HR and other industry experts and network with other management and human resources leaders .including:
- John Rother, National Coalition on Health care
- Shawn Leavitt, Carlson Companies
- Rebecca Mariet Lynn-Crockford, Suntrust Banks, Inc
- Jo-Ann Gastin, Lockton Companies, LLC
- Paul Grundy, M.D., Patient-Centered Primary Care Collaborative
- Roger C. Merring, M.D., Perdue Farm Inc.
- Sam Nussbaum, Wellpoint, Inc.
- Benjamin H. Hoffman, M.D., GE Energy
- Bruce Sherman, MD, Employers Health Coalition
For a full agenda and other details on the program, see here.
SLP Reader Registration Discount
SLP is delighted to announce that the World Health Congress is offering SLP readers the opportunity to claim a $400 discount off the otherwise applicable registration fee when registering for the program. To register and claim this discount, enter registration code “GHH925” at the designated location when registering for the program here.
About Ms. Stamer
Sought out nationally and internationally as an industry thought leader and problem solver, SLP Editor and author attorney, Cynthia Marcotte Stamer has spent more than 25 years helping private and public employers, employer and union plan sponsors, health and other employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental and community leaders and others develop, implement, administer and defend creative, legally compliant and operationally effective health and other employee benefit, employment, insurance, health care and workforce plans, policies, practices, operations and policies.
Recognized in International Who’s Who, the founder and Executive Director of Project COPE: The Coalition on Patient Empowerment and its affiliate, the Coalition on Responsible Health Policy; a Fellow in the American College of Employee Benefits Counsel, American Bar Association, and State Bar of Texas; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Immediate Past Chair of the ABA RPTE Employee Benefit & Other Compensation Committee, current ABA RPTE Employee Benefit & Other Compensation Committee Welfare Benefits Committee Co-Chair and Substantive Groups Committee Member, and a Council Member of the ABA Joint Committee on Employee Benefits, Vice Chair of the ABA Tort & Insurance Practice Section Employee Benefits Committee, and Immediate Past Gulf States Area TEGE Council Exempt Organization Chair, Ms. Stamer helps these and other clients. to design, document, administer and defend managed care and insurance programs, processes, and products; to monitor and manage evolving regulatory, contractual and fiduciary obligations and risks; to draft, negotiate, interpret and enforce managed care and other contracts, plan documents, insurance policies, administrative services agreements, and other agreements, policies, procedures and controls; to credential, monitor and manage fiduciaries, service providers, consultants and others providing services relating to programs; to conduct and defend litigation, audits, and other enforcement actions; to deal with legislators, regulators, auditors and others; and to fulfill legal obligations, mitigate legal risks and improve operational effectiveness.
As a core focus of her practice, Ms. Stamer continuously counsels, represents and defends self-insured and insured managed care and health, disability and welfare, pension, deferred compensation and other employee benefit plans; employer, association, insurer, and other employee benefit and insurance program sponsors; plan fiduciaries, administrators, brokers, consultants and other service providers; Medicare and Medicaid Advantage and other group, individual, stop-loss and other reinsurance, fiduciary liability and other insurers; health and insurance technology and other outsourcing companies; human resources, insurance and employee benefit consulting organizations; and other insurance, employee benefit and human resources industry clients, domestic and foreign governments and others about a diverse range of employee benefit, insurance, employment, tax, regulatory, risk management, public policy and related matters.
Ms. Stamer’s health benefit experience includes extensive and highly-innovative dealings with insured and self-insured managed care, defined contribution, indemnity and other health benefit, disability, life, occupational injury, Medicare and Medicaid Advantage, and other welfare benefit and insurance plans and policies; and a wide range of other employee benefits, compensation, insurance, equity and other related arrangements. Her work includes leading edge development and use of 24-hour coverage and other occupational injury, ex-pat and other medical tourism products, HRA, HSA, HRA and other defined contribution, hi-deductible, deductible reimbursement, min-med and other limited benefit plans, 24-hour and occupational benefit, fraternal benefit and association, and other medical programs as well as a broad range of claims, appeals, audit, and other administrative processes and tools designed to promote defensibility and mitigate risks.
A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on health and other employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, Federal Trade Commission, HUD and Justice, as well as a state legislatures attorneys general, insurance, labor, worker’s compensation, and other agencies and regulators. Her Patient Empowerment Toolkit™, Play4Life Community Program™, and other patient empowerment, health care quality, and other industry thought leadership, advocacy and solutions have drawn the attention of business, government and community leaders for their insightfulness and practicality.
A widely published author and highly sought out speaker whose HR & Benefits Update has been recognized as among the “Top 50” HR Blogs To Watch, Ms. Stamer also regularly authors materials and conducts workshops and professional, management and other training on employee benefits, human resources, health care and other compliance and management topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Insurance Thought Leadership, Government Institutes, Inc., Solutions Law Press, Inc., the Society of Professional Benefits Administrators, HealthLeaders, Managed Care Executive, CEO Magazine, Business Insurance and many other industry, professional and business publications. An Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com), Employee Benefit News, and other publications, Ms. Stamer also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to inquire about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com or contact Ms. Stamer directly via email here or (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on SLP Readers Get $400 Discount To Learn Key Health Care Reform Coping Strategies At 2/21-22 Employer Health & Human Capital Strategy Congress In Lake Mary, FL |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2013
Cynthia Marcotte Stamer will a featured panelists discussing “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” on Thursday, May 2, 2013 at 24th Annual RPTE Spring Symposia at the Capital Hilton in Washington, DC. The Symposia scheduled to take place on May 2–3, 2013 will cover a broad range of timely topics on real estate, trusts and estates and other related concerns. To register, review the full agenda or get additional information about the Symposium, see here.
About Ms. Stamer
A noted Texas-based employee benefits and employment lawyer with extensive involvement in the leadership of the ABA and other professional organizations involved in employee benefits, health care and workforce matters, is nationally and internationally known for her innovative leadership and work as an attorney, consultant, policy advocate, speaker and author helping businesses, governments, and communities on health and other insurance and employee benefits, patient education and empowerment, wellness and disease management, and other programs, policies, and processes. For more than 24 years, Ms. Stamer’s legal practice has focused on advising and representing employers, insurers, health care providers, community leaders and governments about health care and employee benefits policy and process improvement, quality, performance management, education, compliance, communications, risk management, reimbursement and finance, and other related matters. In addition to her legal practice, Stamer also extensively consults and provides leadership to a broad range of clients, professional and civic organizations, and others on strategies for improving the health care system and the ability of health care providers, payers, employers, community organizations, government agencies to promote the ability of patients and their families to access cost-effective, quality, affordable health care and other resource needs. She also has worked extensively with a broad range of business and government clients on health care, pension, social security, workforce, insurance and many other related policy matters.
In addition to her service with the ABA, Ms. Stamer also is active in the leadership of a broad range of other professional and civil organizations. For instance, Ms. Stamer presently serves as Executive Director of Project COPE, the Coalition on Patient Empowerment and the Coalition for Responsible Healthcare Policy; Vice President of the North Texas Healthcare Compliance Professionals Association; Immediate Past Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Committee and its representative to the ABA Joint Committee on Employee Benefits and Vice Chair of its Welfare Benefits Committee; Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and a current member of its Healthcare Coordinating Council; and as the Gulf Coast TEGE Council TE Committee Coordinator. She previously served as a founding Board Member and President of the Alliance for Healthcare Excellence, as a Board Member and Board Compliance Committee Chair for the National Kidney Foundation of North Texas; the Board President of the early retirement intervention agency, The Richardson Development Center for Children; Chair of the Dallas Bar Association Employee Benefits & Executive Compensation Committee; a member of the Board of Directors of the Southwest Benefits Association; on numerous seminar faculties and in many other professional and civic leadership and volunteer roles.
Author of the hundreds of publications and workshops these and other employment, employee benefits, health care, insurance, workforce and other management matters, Ms. Stamer’s insights on employee benefits, insurance, health care and workforce matters in Atlantic Information Services, The Bureau of National Affairs, HealthLeaders, Modern Healthcare, Business Insurance, Employee Benefits News, World At Work, Benefits Magazine, the Wall Street Journal, the Dallas Morning News, the Dallas Business Journal, the Houston Business Journal, and many other publications. Nationally known for her work on health care reform and related matters, Ms. Stamer also regularly conducts training and speaks on these and other management, compliance and public policy concerns. For additional information about Ms. Stamer, upcoming training, publications or other materials or events, see here or contact Ms. Stamer directly via email here or (469) 767-8872.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Stamer Talks on “What the Wind Blew In: Coping with Health Care Reform: 2013 and Beyond” May 2 At 24th Annual RPTE Spring Symposia In Washington, D.C. |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2013
As preparations continue for the Jan. 30 opening of the 2013 filing season for most taxpayers, the Internal Revenue Service has announced that it beginprocessing of tax returns claiming education credits n by the middle of February.
Taxpayers using Form 8863, Education Credits, can begin filing their tax returns after the IRS updates its processing systems. Form 8863 is used to claim two higher education credits — the American Opportunity Tax Credit and the Lifetime Learning Credit.
The IRS emphasized that the delayed start will have no impact on taxpayers claiming other education-related tax benefits, such as the tuition and fees deduction and the student loan interest deduction. People otherwise able to file and claiming these benefits can start filing Jan. 30, 2013
As it does every year, the IRS reviews and tests its systems in advance of the opening of the tax season to protect taxpayers from processing errors and refund delays. The IRS discovered during testing that programming modifications are needed to accurately process Forms 8863. Filers who are otherwise able to file but use the Form 8863 will be able to file by mid-February. No action needs to be taken by the taxpayer or their tax professional. Typically through the mid-February period, about 3 million tax returns include Form 8863, less than a quarter of those filed during the year.
The IRS remains on track to open the tax season on January 30 for most taxpayers. The January 30 opening includes people claiming the student loan interest deduction on the Form 1040 series or the higher education tuition or fees on Form 8917, Tuition and Fees Deduction. Forms that will be able to be filed later are listed on IRS.gov.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Will Begin Accepting Returns Claiming Education Credits By Mid-February |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 28, 2013
The Administrative Taxpayer Relief Act retroactively increased monthly transit benefit limit that employers can provide to employees on a tax-free basis for 2012 from $125 per month to $240 per month. Notice 2013-8 provides a special correction procedure for employers who paid benefits in excess of $125 per month in 2012 and wish to make corrections on their fourth quarter Form 941.
Notice 2013-8 will be published in Internal Revenue Bulletin 2013-7 on February 11, 2013
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Shares Procedures Employers Use To Claim Increased Monthly Transit Benefit Exclusion Allowed By Administrative Taxpayer Relief Act |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Employer, Employment, transit benefit exclusion |
Permalink
Posted by Cynthia Marcotte Stamer
January 27, 2013
Since the enactment of the Patient Protection & Affordable Care Act (ACA), many employers searching for health plan solutions may have been asked to consider replacing or modifying their existing insured or self-insured group health plan with a “health reimbursement arrangement” (HRA) or other arrangement which would reimburse employees for premiums paid for individual health insurance policies. New guidance released on Thursday, January 24, 2013 indicates that such arrangements are prohibited as part of the ACA health care reforms.
“FAQS About Affordable Care Implementation (Part XI)” (FAQ) available here issued by the Departments of Labor, Health and Human Services (HHS), and the Treasury (collectively, the Agencies) on January 24, 2013 sends a clear message to employers that trying to escape ACA or other federal group health plan mandates by replacing their traditional insured or group health plans or policies with health reimbursement arrangements (HRAs) or other arrangements under which the employer agrees to provide a fixed defined contribution to be used to buy or reimburses employees for buying individual health insurance generally won’t pass legal muster. The FAQ also indicates that employers sponsoring HRAs that only reimburse medical expenses, not individual health insurance premiums also need to review their arrangements to verify that those programs also comply with ACA and other applicable rules.
Concerning the use of HRAs to pay for individual health insurance policy premiums, the FAQ states that PHS Act Section 2711 generally prohibits an employer-sponsored HRA cannot be integrated with individual market coverage or with an employer plan that provides coverage through individual policies. Under ACA, employers that improperly offer arrangements that violate PHS Section 2711 or other group health plans risk exposing themselves to liability for significant unanticipated health benefit claims, as well as other penalties and costs. Therefore, employers that have or are contemplating arrangements that provide or reimburse premiums for individual health insurance coverage are urged to contact qualified legal counsel with documented experience with ACA and other group health plan requirements for advice before establishing or continuing such arrangements.
The FAQ’s guidance about the use of individual insurance policies to arrange coverage for employees is one of several issues addressed in the FAQ and part of a wave of new guidance that has and is emerging as the Obama Administration moves to full implementation of the ACA reforms. Employers, plan fiduciaries, insurers, and others involved in the design or administration of health benefit programs need to monitor carefully this emerging guidance as they move quickly to tailor their programs in response to these evolving rules. For help monitoring or responding to these evolving rules, contact the author of this update, Cynthia Marcotte Stamer.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 25, 2013
The Department of Labor has extended the deadline for employers to notify employees about the existence of and their rights under the health exchanges required by new Section 18B of the Fair Labor Standards Act (FLSA), as added by Section 1512 of the Patient Protection & Affordable Care Act (ACA). The extension announced in Frequently Answered Question (FAQ) here provides a welcome temporary reprieve to employers who otherwise would have been required to notify employees by March 1, 2013.
As part of the impending implementation of ACA’s health care reform, FLSA § 18B generally requires each applicable employer provide each employee a written notice (Exchange Notice) in accordance with regulations promulgated by the Secretary of Labor:
- Informing the employee of the existence of Exchanges including a description of the services provided by the Exchanges, and the way the employee may contact Exchanges to request assistance;
- If the employer plan’s share of the total allowed costs of benefits provided under the plan is less than 60 percent of such costs, that the employee may be eligible for a premium tax credit under section 36B of the Internal Revenue Code (the Code) if the employee purchases a qualified health plan through an Exchange; and
- If the employee purchases a qualified health plan through an Exchange, the employee may lose the employer contribution (if any) to any health benefits plan offered by the employer and that all or a portion of such contribution may be excludable from income for Federal income tax purposes. The Department of Labor expects that the timing for distribution of notices will be the late summer or fall of 2013, which will coordinate with the open enrollment period for Exchanges.
Before the Department’s announcement in the FAQ, the deadline for employers to begin giving employees Exchange Notices was the later of March 1, 2013 or at the time of hiring. The FAQ extends this deadline until a date to be set by the Department in future guidance, which the Department expects will require employers to distribute the notices in the late summer or fall of 2013 to coordinate with the open enrollment period for Exchanges.
According to the announcement of the delay, the Department delayed the impending March 1, 2013 deadline to give the (Exchange Notice) to better coordinate with related Health and Human Service and Internal Revenue Service efforts and to allow more time to comply and to distribute the Exchange Notices to employees at a meaningful time.
In addition to providing added time to provide the Exchange Notice, the Department also has announced that it is considering providing model, generic language that employers could use to provide the Exchange Notice. to satisfy the notice requirement. As a compliance alternative, the Department also is considering allowing employers to meet the Exchange Notice requirement by providing employees with information using the employer coverage template as discussed in the preamble to the Proposed Rule on Medicaid, Children’s Health Insurance Programs, and Exchanges: Essential Health Benefits in Alternative Benefit Plans, Eligibility Notices, Fair Hearing and Appeal Processes for Medicaid and Exchange Eligibility Appeals and Other Provisions Related to Eligibility and Enrollment for Exchanges, Medicaid and CHIP, and Medicaid Premiums and Cost Sharing (78 FR 4594, at 4641), which will be available for download at the Exchange web site as part of the streamlined application that will be used by the Exchange, Medicaid, and CHIP.
The Exchange Notice is just one of a multitude of notices and other mandates that ACA requires that employers or their health plans, insurers, or both to meet. Although the Exchange Notice gives employers a little more time to provide the Exchange Notices, employer and other health plan sponsors, fiduciaries, administrators and insurers are urged to continue to diligently move forward to update their plans, communications, processes and other arrangements to comply with existing and impending ACA mandates while keeping a watchful eye on for additional guidance that may require additional tailoring of these arrangements.
Stay tuned for updates about future guidance on complying with the notice requirement under FLSA section 18B and other developments.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- Employers ACA Health Reforms Prohibit Using HRAs To Pay Individual Medical Policy Premiums & Impact Other HRA Arrangements
- ADA May Require Food Allergy Accommodation By Employers, Schools & Businesses
- Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed
- Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Employer Deadline To Give ACA Notice of Exchange Coverage Options Delayed |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 23, 2013
Cynthia Marcotte Stamer will share key information and practical strategies for “Coping with Health Care Reform Now” at the Dallas Chaper ICEBS Valentines Day luncheon meeting on February 14, 2012. The meeting is scheduled from 11:30 a.m. to 1:30 p.m on February 14, 2012 at Haggar Clothing Company at 11511 Luna Road, Dallas, Texas . Interested persons may register or get other details at http://www.dfwiscebs.org.
With the initial debate about the Constitutionality of the Patient Protection & Affordable Care Act (ACA) decided and making a Congressional reprieve highly improbable, employer and other health plan sponsors, insurers, fiduciaries and administrators are scrambling to update plan documents, communications, processes and procedures to meet current ACA and other health plan rules, while bracing to cope with the sweeping health care reforms slated to take effect in 2014. These already daunting tasks are made more challenging by the continuing uncertainty of the constantly evolving regulations, evolving marketplace, increases in health plan costs and ever-shrinking corporate budgets.
To help health plan sponsors, fiduciaries, administrators and insurers deal with the tough business of implementation, attorney Cynthia Marcotte Stamer will discuss practical strategies, legal updates and other information needed for to cope with health care reform now and to prepare to meet future health plan regulations and challenges including:
- The Latest On Key ACA & Other Health Care Reform Regulations Such As ACA’s Requirements On Fees Employers Sponsoring Self-Insured Health Plans & Insurers Must Pay To Fund The Patient-Centered Outcomes Research Institute, Contraceptive and Other Preventive Services, Nondiscrimination, Essential Health Benefits, Internal Claims and Appeals and External Review, Medical Loss Ratios, Large Employer Automatic Enrollment, Summary of Benefits & Coverage, Culturally & Linguistically Appropriateness, Value-Based Insurance Design, Wellness Programs, Exchanges, the Employer Pay-Or-Plan Mandates, Wellness Reporting, Wellness Programs, W-2 Reporting of Employer Provided Health Coverage, Employer Plan Minimum Value & The Premium Tax Credit And Other ACA & Other Federal Health Plan Mandates;
- Key Changes To HIPAA Privacy Regulations & What Health Plans & Employers Should Expect To Be Required To Do To Comply With These Changes By the September, 2013 Deadline;
- What’s Happened, Happening & Likely To Happen With Exchanges;
- A 12-Step Practical Process For Helping Employers Managing ACA & Other Health Plan Compliance Responsibilities & Risks; and
- Tips On What To Watch For And Options For Maintaining Flexibility To Respond To Evolving Rules; and
- Answer Common Questions That Health Plan Sponsors and Administrators Are Struggling With Submitted By Audience Members
Registrants are encouraged to help shape the program to reflect their questions and concerns by e-mailing their proposed questions prior to the program to cstamer@solutionslawyer.net. The program’s educational* discussion will be tailored taking into account this input with significant time set aside to share practical information and possible approaches for addressing questions and concerns of shared concern identified from this audience input.
About Ms. Stamer
A Fellow in the American College of Employee Benefits Counsel, the American Bar Association & the State Bar of Texas, recognized in International Who’s Who, and Board Certified in Labor & Employment Law, Cynthia Marcotte Stamer is nationally and internationally recognized for her extensive and highly practical, solutions-oriented health plan work, advocacy, publications, programs and leadership.
For more than 25 years, Ms. Stamer has advised and represented private and public employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governments and others on health and other employee benefit, employment, insurance and health care compliance, risk management, public policy, administration and defense. Throughout her career, Ms. Stamer has worked extensively with employer and other health plan sponsors, insurers, plan administrators and other service providers, outsourcers and others to develop innovative health benefit programs and solutions and to document, administer and defend those arrangements in the mist of rising costs, evolving regulations and changing markets.
A primary drafter of the Bolivian Social Security privatization law with extensive regulatory and public policy experience, Ms. Stamer has been involved domestically and internationally as an advocate and advisor on health care, pension and Social Security, workforce and insurance reform and regulation. She presently serves as the scribe for the ABA JCEB Annual Agency Meeting with the Office of Civil Rights. She also represents clients in dealings with the US Congress, Departments of Labor, Treasury, Health & Human Services, Federal Trade Commission, HUD and Justice, as well as a state legislatures attorneys general, insurance, labor, worker’s compensation, and other agencies and regulators.
Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and the ABA RPTE Employee Benefits Group, Ms. Stamer presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee; Vice Chair of the ABA TIPS Employee Benefit Committee; as a Council Representative of the ABA Joint Committee on Employee Benefits; an Editorial Advisory Board Member for the Institute of Human Resources (IHR/HR.com), Employee Benefit News and Insurance Thought Leadership; Editor and Publisher of various Solutions Law Press, Inc. publications, and previously served on the Editorial Advisor Board of the the BNA Employee Benefits CD-Rolm.
A popular and prolific author and speaker, Ms. Stamer’s Solutions Law Press, Inc. HR & Benefits Update publication was recognized as one of the Top 50 Human Resources Blogs To Watch in 2012. Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training on employee benefits, human resources and related topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Government Institutes, Inc., the Society of Professional Benefits Administrators and many other organizations. She also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to inquire about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com.
* Registrants are reminded that this discussion is provided for general information and educational purposes. Accordingly, registrants are reminded that the discussion does not constitute legal advice, a substitute for legal advice or establish an attorney-client or other professional relationship.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- BNSF OSHA Whistleblower Settlement Gives Employers Insights About Policies OSHA View As Prohibited
- OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Hear Stamer Speak On “Coping With Health Care Reform Now” At 2/14 Dallas ICEBS Meeting |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 17, 2013
Health plans, their employer or other sponsors, insurers, fiduciaries, administrative service providers and other business associates have a lot of work to do.
Health plans, health care clearinghouses and their business associates will need to review and update their policies and practices for handling and disclosing personally identifiable health care information (“PHI”) in response to the omnibus restatement of the Department of Health & Human Services (“HHS”) Office of Civil Rights (“OCR”) of its of its regulations (the “2013 Regulations”) implementing the Privacy and Security Rules under the Health Insurance Portability and Accountability Act of 1996 (HIPAA). The Rulemaking announced January 17, 2013 may be viewed here.
The 2013 Regulations Overview
Since 2003, HIPAA generally has required that health care providers, health plans, health care clearinghouses and their business associates (“Covered Entities”) restrict and safeguard individually identifiable health care information (“PHI”) of individuals and afford other protections to individuals that are the subject of that information. The 2013 Regulations published today complete the implementation of changes to HIPAA that Congress enacted when it passed the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009 as well as make other changes to the prior regulations that OCR found desirable based on its experience administering and enforcing the law over the past decade.
Since passage of the HITECH Act, OCR officials have warned Covered Entities to expect an omnibus restatement of its original regulations. While OCR had issued certain regulations implementing some of the HITECH Act changes, it waited to publish certain regulations necessary to implement other HITECH Act changes until it could complete a more comprehensive restatement of its previously published HIPAA regulations to reflect both the HITECH Act amendments and other refinements to its HIPAA Rules. The 2013 Regulations published today fulfill that promise by restating OCR’s HIPAA Regulations to reflect the HITECH Act Amendments and other changes and clarifications to OCR’s interpretation and enforcement of HIPAA.
Among other things, the 2013 Regulations:
- Revise OCR’s HIPAA regulations to reflect the HITECH Act’s amendment of HIPAA to add the contractors and subcontractors of health plans, health care providers and health care clearinghouses that qualify as business associates to the parties directly responsible for complying with and subject to HIPAA’s civil and criminal penalties for violating HIPAA’s Privacy, Security, and Breach Notification rules;
- Update previous interim regulations implementing HITECH Act breach notification rules that require Covered Entities including business associates to give specific notifications to individuals whose PHI is breached, HHS and in some cases, the media when a breach of unsecured information happens;
- Update interim enforcement guidance OCR previously published to implement increased penalties and other changes to HIPAA’s civil and criminal sanctions enacted by the HITECH Act;
- Implement HITECH Act amendments to HIPAA that tighten the conditions under which Covered Entities are allowed to use or disclose PHI for marketing and fundraising purposes and prohibit Covered Entities from selling an individual’s health information without getting the individual’s authorization in the manner required by the 2013 Regulations;
- Update OCR’s rules about the individual rights that HIPAA requires that Covered Entities to afford to individuals who are the subject of PHI used or possessed by a Covered Entity to reflect tightened requirements enacted by the HITECH Act that allow individuals to order their health care provider not to share information about their treatment with health plans when the individual pays cash for the care and to clarify that individuals can require Covered Entities to provide electronic PHI in electronic form;
- Revise the regulations to reflect amendments to HIPAA made as part of the Genetic Information Nondiscrimination Act of 2008 (GINA) which added genetic information to the definition of PHI protected under the HIPAA Privacy Rule and prohibits health plans from using or disclosing genetic information for underwriting purposes; and
- Clarifies and revises other provisions to reflect other interpretations and information guidance that OCR has issued since HIPAA was passed and to make certain other changes that OCR found appropriate based on its experience administering and enforcing the rules.
Liability & Enforcement Risks Heighten Need To Act To Review & Update Policies & Practices
The restated rules in the 2013 Regulations make it imperative that Covered Entities review the revised rules carefully and updated their policies, practices, business associate agreements, training and documentation to comply with the updated requirements and other enforcement and liability risks. OCR even prior to the regulations has aggressively investigated and enforced the HIPAA requirements.
The commitment of OCR to enforcement most recently was demonstrated by its recent settlement with Hospice of North Idaho (HONI). On January 2, 2013, OCR announced HONI will pay OCR $50,000 to settle potential HIPAA violations that occurred in connection with the theft of an unencrypted laptop computer containing ePHI. The HONI settlement is the first settlement involving a breach of ePHI affecting fewer than 500 individuals.
While the HONI settlement marks the first settlement on a small breach, this is not the first time OCR has sought sanctions against a covered entity for data breaches involving the loss or theft of unencrypted data on a Laptop, storage device or other computer device. Rather, OCR continues to rollout a growing list of enforcement actions demonstrating the potential risks of HIPAA violations are significant and growing. OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach; OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website; Providence To Pay $100000 & Implement Other Safeguards.
Coupled with statements by OCR about its intolerance, the HONI and other settlements provide a strong warning to covered entities of the need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
In response to the 2013 Regulations and these expanding exposures, all Covered Entities should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses; and other developments to decide if additional steps are necessary or advisable. In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if tightening their policies, practices, documentation or training is necessary or advisable.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
For help with these or other compliance concerns, to ask about compliance audit or training, or for legal representation on these or other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
- OCR Gives HIPAA Guidance On Safety Disclosures
- IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers
- IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments
- Tax-Related ID Theft Growing Problem For IRS, Taxpayers
- Tax Saver’s Credit Helps Low & Moderate Income Workers Save For Retirement; Possible Tool To Help Boost Their Participation In Employer Plans
- Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees
- 1st OCR Small HIPAA Breach Settlement Shows Plans, Other Covered Entities At Risk From Small Breach Reports Too
- Labor Department Targeting Businesses Violating Overtime, Other Wage & Hour Laws
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on OCR Publishes Long-Anticipated Omnibus Restatement of HIPAA Privacy, Security, Breach Notification & Enforcement Rules |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 16, 2013
IRS Says Eligible Home-Based Businesses May Deduct up to $1,500; Saves Taxpayers 1.6 Million Hours A Year
The Internal Revenue Service (IRS) has announced a simplified option that many owners of home-based businesses and some home-based workers may use to figure their deductions for the business use of their homes.
In tax year 2010, the most recent year for which figures are available, nearly 3.4 million taxpayers claimed deductions for business use of a home (commonly referred to as the home office deduction).
The new optional deduction, capped at $1,500 per year based on $5 a square foot for up to 300 square feet, will reduce the paperwork and recordkeeping burden on small businesses by an estimated 1.6 million hours annually.
“This is a common-sense rule to provide taxpayers an easier way to calculate and claim the home office deduction,” said Acting IRS Commissioner Steven T. Miller. “The IRS continues to look for similar ways to combat complexity and encourages people to look at this option as they consider tax planning in 2013.”
The new option provides eligible taxpayers an easier path to claiming the home office deduction. Currently, the IRS generally requires a home-based business to fill out a 43-line form (Form 8829) often with complex calculations of allocated expenses, depreciation and carryovers of unused deductions. Taxpayers claiming the optional deduction will complete a significantly simplified form.
Though homeowners using the new option cannot depreciate the portion of their home used in a trade or business, they can claim allowable mortgage interest, real estate taxes and casualty losses on the home as itemized deductions on Schedule A. These deductions need not be allocated between personal and business use, as is required under the regular method.
Business expenses unrelated to the home, such as advertising, supplies and wages paid to employees are still fully deductible.
Current restrictions on the home office deduction, such as the requirement that a home office must be used regularly and exclusively for business and the limit tied to the income derived from the particular business, still apply under the new option.
The new simplified option is available starting with the 2013 return most taxpayers file early in 2014. Further details on the new option can be found in Revenue Procedure 2013-13, posted on IRS.gov. Revenue Procedure 2013-13 is effective for taxable years beginning on or after January 1, 2013, and the IRS welcomes public comment on this new option to improve it for tax year 2014 and later years. There are three ways to submit comments.
- E-mail to: Notice.Comments@irscounsel.treas.gov. Include “Rev. Proc. 2013-13” in the subject line.
- Mail to: Internal Revenue Service, CC:PA:LPD:PR (Rev. Proc. 2013-13), Room 5203, P.O. Box 7604, Ben Franklin Station, Washington, DC 20044.
- Hand deliver to: CC:PA:LPD:PR (Rev. Proc. 2013-13), Courier’s Desk, Internal Revenue Service, 1111 Constitution Avenue NW, Washington, DC, between 8 a.m. and 4 p.m., Monday through Friday.
The deadline for comment is April 15, 2013.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Offers New Simplified Option For Businesses Claiming Home Office Deductions For Home-Based Business Owners & Workers |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 16, 2013
Revenue Procedure 2013-15 provides the 2013 cost-of-living adjustments for inflation for certain items. The guidance includes adjustments to the tax tables, including items whose values were specified in the American Taxpayer Relief Act of 2012 (ATRA), such as:
- The beginning of the 39.6% income tax brackets;
- The beginning income levels for the limitation on certain itemized deductions; and
- The beginning income levels for the phaseout of the personal exemptions[
In addition Revenue Procedure 2013-5 modifies Revenue Procedure 2011-52 to reflect an amendment to section 132(f)(2) made by ATRA concerning qualified transportation fringe benefits. Specifically, for 2012, the monthly limitation regarding the aggregate fringe benefit exclusion amount for transit passes and transportation in a commuter highway vehicle is $240.
Revenue Procedure 2013-15 will be published in Internal Revenue Bulletin 2013-5 on January 28, 2013.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on IRS Announces Cost of Living & American Taxpayer Relief Act Income Tax Adjustments |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 14, 2013
Employers and others collecting, retaining or reporting employee or other tax identification numbers or other sensitive information for tax withholding or reporting purposes should take appropriate steps to protect that information against possible identity theft or other misuse.
The wealth of sensitive personal identification information and financial records makes tax records a highly attractive source of data for identity thieves. According to the Internal Revenue Service (IRS), tax-related identity theft incidents have risen significantly in recent years. Identity theft case receipts increased by more than 650 percent from FY 2008 to FY 2012. At the end of FY 2012, the IRS had almost 650,000 identity-theft cases in its inventory servicewide. The IRS reports the problem has grown worse as organized criminal actors have found ways to steal the Social Security numbers (SSNs) of taxpayers, file tax returns using those taxpayers’ names and SSNs, and obtain fraudulent tax refunds. Then, when the real taxpayer files a return claiming the refund, that return is rejected. The impact on victims is significant. More than 75 percent of taxpayers filing returns are due refunds, which average some $3,000 and are not paid until the IRS fully resolves a case.
When the IRS Commissioner testified in 2008 about identity theft before a Senate Finance Committee hearing. he stated: “My overall goal as the IRS Commissioner is that when a taxpayer [who is an identity theft victim] contacts us with an issue or concern, we have in place a seamless process that gets the issue resolved promptly.” Later that year, the IRS established an “Identity Protection Specialized Unit” (or “IPSU”), which was designed to provide centralized assistance to victims of identity theft. The National Taxpayer Advocate supported the commitment to centralized and prompt victim assistance.
Since that time, the IRS has created numerous task forces and other teams in recent years in an attempt to improve its identity theft processes, yet victims still face the same “labyrinth of procedures and drawn-out timeframes for resolution” that they faced five years ago. The IRS is instructing its employees to advise identity theft victims that it will take 180 days – half a year – to resolve their cases. Complicated cases inevitably will take longer. Thus, the IRS’s procedural changes are not providing faster relief.
The report also says the IRS has decided to reverse course and decentralize victim assistance. It recently created specialized units within each of 21 individual functions to work on identity theft cases, apparently under the belief that most identity theft cases involve a single issue that the relevant specialized unit can work most efficiently. The report expresses concern about this backtracking from a centralized approach.
The Taxpayer Advocate Service (TAS) itself handled nearly 55,000 identity theft cases in FY 2012, most of which involved multiple issues that required actions by multiple units. The report expresses concern that creation of 21 specialized units will erode the centralized role of the IPSU, require taxpayers to speak with multiple functions, increase the time it takes to resolve cases, and heighten the risk that some issues may not be addressed.
“Taxpayers need ‘one-stop shopping’ – a single point of contact they can work with to resolve all issues in their cases – and the IRS needs a ‘traffic cop’ to make sure that all units complete their actions and that parts of cases do not fall through the cracks,” Olson said. “And six months is an unacceptable period of time to expect taxpayer-victims to wait. The IRS must do more to provide the prompt and seamless assistance to identity theft victims that Commissioner Shulman promised.”
While the IRS continues to work on protecting taxpayer data against theft and investigating and resolving tax-related identity theft cases, businesses that collect, retain and report employee, contractor or other personal financial information for tax related or other purposes are urged to take steps to protect the data that they collect and retain against identity theft. Since identity theft may begin when a worker misrepresents his or her identity at the commencement of employment, many employers find it beneficial to take reasonable steps to verify the identity and veracity of the documentation that a worker presents when commencing employment. Once data is collected, businesses and others that have access to personal financial information or other data collected for tax purposes need to recognize their responsibility to safeguard that information against improper use and disclosure under the Internal Revenue Code as well as other applicable laws. If confronted with a “no-match” letter from the Social Security Administration or a complaint or other indication that a worker may have misrepresented his or her identity, or another indication of a breach of this data, businesses should contact experienced legal counsel to aid in the proper investigation of these concerns and the resolution of concerns resulting from this investigation. Where appropriate, the business may need to report its concerns to the IRS or advise a worker or other party reporting a likely identity theft of taxpayer information to the TAS or other appropriate officials.
Businesses needing assistance with investigation or mitigation of a potential theft of tax or other sensitive data, see www.cynthiastamer.com or contact attorney Cynthia Marcotte Stamer.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Tax-Related ID Theft Growing Problem For IRS, Taxpayers |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 11, 2013
As part of its continuing effort to boost retirement savings among Americans, the Internal Revenue Service is reminding low- and moderate-income workers to take steps now to save for retirement and earn a special tax credit in 2012 and the years ahead. Employers sponsoring retirement plans where low participation by low- and moderate income workers adversely impacts the ability of the plan to meet applicable nondiscrimination tests may want to consider incorporating information about the availability of the saver’s credit into their plan related communications as an added tool for helping these workers recognize the potential benefits of contributing.
The saver’s credit helps qualifying low to moderate income workers offset part of the first $2,000 workers voluntarily contribute to IRAs and to 401(k) plans and similar workplace retirement programs. Also known as the retirement savings contributions credit, the saver’s credit is available in addition to any other tax savings that apply.
The saver’s credit can be claimed by:
- Married couples filing jointly with incomes up to $57,500 in 2012 or $59,000 in 2013;
- Heads of Household with incomes up to $43,125 in 2012 or $44,250 in 2013; and
- Married individuals filing separately and singles with incomes up to $28,750 in 2012 or $29,500 in 2013.
Eligible workers still have until April 15, 2013 to make qualifying retirement contributions and get the saver’s credit on their 2012 tax return by setting up a new individual retirement arrangement or adding money to an existing IRA. However, elective deferrals (contributions) must be made by the end of the year to a 401(k) plan or similar workplace program, such as a 403(b) plan for employees of public schools and certain tax-exempt organizations, a governmental 457 plan for state or local government employees, and the Thrift Savings Plan for federal employees. Employees who are unable to set aside money for this year may want to schedule their 2013 contributions soon so their employer can begin withholding them in January.
Like other tax credits, the saver’s credit can increase a taxpayer’s refund or reduce the tax owed. Though the maximum saver’s credit is $1,000, $2,000 for married couples, the IRS cautioned that it is often much less and, due in part to the impact of other deductions and credits, may, in fact, be zero for some taxpayers.
A taxpayer’s credit amount is based on his or her filing status, adjusted gross income, tax liability and amount contributed to qualifying retirement programs. Form 8880 is used to claim the saver’s credit, and its instructions have details on figuring the credit correctly.
In tax-year 2010, the most recent year for which complete figures are available, saver’s credits totaling just over $1 billion were claimed on more than 6.1 million individual income tax returns. Saver’s credits claimed on these returns averaged $204 for joint filers, $165 for heads of household and $122 for single filers.
The saver’s credit supplements other tax benefits available to people who set money aside for retirement. For example, most workers may deduct their contributions to a traditional IRA. Though Roth IRA contributions are not deductible, qualifying withdrawals, usually after retirement, are tax-free. Normally, contributions to 401(k) and similar workplace plans are not taxed until withdrawn.
Other special rules that apply to the saver’s credit include the following:
- Eligible taxpayers must be at least 18 years of age.
- Anyone claimed as a dependent on someone else’s return cannot take the credit.
- A student cannot take the credit. A person enrolled as a full-time student during any part of 5 calendar months during the year is considered a student.
Certain retirement plan distributions reduce the contribution amount used to figure the credit. For 2012, this rule applies to distributions received after 2009 and before the due date, including extensions, of the 2012 return. Form 8880 and its instructions have details on making this computation.
Begun in 2002 as a temporary provision, the saver’s credit was made a permanent part of the tax code in legislation enacted in 2006. To help preserve the value of the credit, income limits are now adjusted annually to keep pace with inflation. More information about the credit is on IRS.gov.
For Help or More Information
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved
1 Comment |
Corporate Compliance, Employers, GINA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Retirement Plans, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 10, 2013
Employers and other self-insured group health plan sponsors and health insurers, adjust your budgets and prepare to open up your wallets to pay additional fees mandated by the Patient Protection and Affordable Care Act (“PPACA”).
Self-insured employers and health insurers generally must begin paying a new fee imposed as part of PPACA. PPACA generally requires that health insurance policy issuers and plan sponsors of self-insured health plans pay the new fee for policy and plan years ending on or after October 1, 2012, and before October 1, 2019 or policy and plan years ending on or after October 1, 2012, and before October 1, 2019. July 31, 2013 is the deadline for reporting and payment of the first fee payment required by these provisions.
The Internal Revenue Service (IRS) and Department of Treasury published final regulations (“Regulations”) implementing these new rules on December 6, 2012. These Regulations include many provisions that are likely to come as a surprise to many employer and other health plan sponsors. Health insurers, employers and other sponsors of self-insured health plans and others responsible for their funding and administration need to review these regulations and make other arrangements to budget for and timely report and pay this required fee.
New Fees Help Fund New Patient-Centered Outcomes Research Institute
PPACA amended the Internal Revenue Code (“Code”) to require the new fee to help fund the establishment and operation of the new Patient-Centered Outcomes Research Institute (the ‘‘Institute’’) to be created by PPACA. Congress intends that the Institute will be a private, nonprofit corporation charged with conducting research to help assist patients, clinicians, purchasers, and policy-makers in making informed health decisions by advancing the quality and relevance of evidence-based medicine through the synthesis and dissemination of comparative clinical effectiveness research findings.
PPACA added new Sections 4375, 4376, and 4377 to the Code to provide a funding source for the Trust Fund. These new Code Sections impose require issuers of specified health insurance policies and plan sponsors of applicable self-insured health plans to pay the new fee by July 31, 2012 for each plan year beginning after September 30, 2012 and before October 1, 2019 to fund the Patient-Centered Outcomes Research Trust Fund (the “Trust Fund”), which in turn will help pay the costs of the Institute.
Code Section 4377(c) provides that the fees imposed by sections 4375 and 4376 are treated as taxes for purposes of subtitle F of the Code (sections 6001 through 7874 that set forth the rules of federal tax procedure and administration).
Fee Amount Calculation & Payment
As amended by PPACA, the Code requires that employers sponsoring self-insured group health plans and most health insurers file a return and pay a fee equal to $1 multiplied by the average number of lives covered under the plan or policy by July 31, 2012. The amount of this fee will increase to $2 multiplied by the average number of lives for post-September 30, 2013 plan years. For post-September 30, 2014 plan years, the Code provides for further adjustments in the fee based on increases in the projected per capita amount of National Health Expenditures.
To meet this requirement, health insurers and plan sponsors must file a Form 720, Quarterly Federal Excise Tax Return along with the required payment once a year on or before July 31 of the calendar year following the last day of the policy year or plan year for which the fee is required to report and pay the fee.
Overview of ACA Rules Requiring Payment of Fee
The Code now separately assesses a fee on issuers of health insurance policies and on plan sponsors of self-insured health plans for each policy year ending on or after October 1, 2012 and before October 1, 2019. Code Section 4375 requires payment of a fee by “issuers” of “specified health insurance policies.” Code Section 4376 requires “sponsors” of self-insured health plans to pay a fee.
Each of these Code Sections basically uses the same formula to calculate the required fee owing by a health insurance issuer or a self-insured plan sponsor. The amount of the required fee due on July 31, 2013 for plan years beginning on or before October 1, 2013 will be one dollar multiplied by the average number of lives covered by the policy or plan. The fee due on July 31, 2014 for plan years beginning between October 2, 2013 and October 1, 2014 is set to increase to two dollars multiplied by the average number of lives covered under the policy. For policy or plan years ending on or after October 1, 2014, PPACA provides for additional increases in the required fee based on increases in the projected per capita amount of National Health Expenditures. See Treas. Reg. §§ 46.4375–1; Rejecting arguments that Congress only intended to require that either the insurer or the plan sponsor pay a fee annually, the Regulations construe these requirements as obligating both a self-insured health plans sponsor and an insurer to pay a separate fee annually, even if the fee is assessed upon the same lives.
The Preamble to the Regulations states that a self-insured plan sponsor must pay the fee with respect to arrangements where the plan design layers a self-insured portion of the plan with an insured portion, even though the insurer also must pay the fee with respect to the insured portion.
The fee calculation differs slightly for purposes of determining the fee a self-insured plan sponsor owes versus the fee owed by an insurer. Regardless, however, the Regulations state that for purposes of calculating these numbers, retirees and beneficiaries continuing coverage under the group medical coverage continuation rules generally count. The Preamble to the Regulations states that the IRS views retiree-only plans and COBRA coverage subject to the tax imposed under Code § 4375 and plan sponsors may be required to pay the tax under Code § 4376. Concerning retiree-only coverage, the Preamble states:
- Although group health plans that have fewer than two participants who are current employees (such as retiree-only plans) are excluded from the requirements of Code chapter 100 (setting forth requirements applicable to group health plans such as portability, nondiscrimination, and market reform requirements), this exclusion does not apply to Code §§ 4375 and 4376 because these sections are in chapter 34; and
- For self-insured arrangements, Code § 4376(c)(2)(A) states explicitly that an applicable self-insured health plan includes a plan established or maintained by one or more employers for the benefit of their employees or former employees.
Section 4376 Fee For Self-Insured Plan Sponsors
Applicability of Code Section 4376 Fee To Self-Insured Health Plans. The fee under Code Section 4376 applies to the plan sponsor of an applicable self-insured health plan.
Section 4376(c) defines an applicable self-insured health plan as any plan for providing accident or health coverage if any portion of the coverage is provided other than through an insurance policy, and the plan is established or maintained by either:
- One or more employers for the benefit of their employees or former employees;
- One or more employee organizations for the benefit of their members or former members;
- Jointly by one or more employers and one or more employee organizations for the benefit of employees or former employees;
- By a voluntary employees’ beneficiary association described in Code Section 501(c)(9); or
- By any organization described in section 501(c)(6), or (6) if not previously described, by a multiple employer welfare arrangement (as defined in section 3(40) of the Employee Retirement Income Security Act (“ERISA”), a rural electric cooperative under ERISA Section 3(40)(B)(iv), or a rural telephone cooperative association under ERISA Section 3(40)(B)(v). See Code § 4376; Regulation §46.4376–1(a), (b)(1).
Code Section 4376(b)(1) requires that the plan sponsor of a self-insured health plan pay the required fee for self-insured health plans imposed by Section 4376(a). For this purpose, Code Section 4376(b)(2) defines a plan sponsor as:
- The employer in the case of a plan established or maintained by a single employer;
- The employee organization in the case of a plan established or maintained by an employee organization;
- The association, committee, joint board of trustees, or other similar group of representatives of the parties who establish or maintain the plan in the case of: (1) a plan established or maintained by two or more employers or jointly by one or more employers and one or more employee organizations; (2) a multiple employer welfare arrangement; or (3) a voluntary employees’ beneficiary association described in Code Section 501(c)(9); or
- The cooperative or association that establishes the plan in the case of a plan established or maintained by a rural electric cooperative or rural telephone cooperative association within the meaning of ERISA.
Regulation § 46.4376-2(b)(2) defines plan sponsor to mean the following:
- The employer for a self-insured health plan established or maintained by a single employer;
- The employee organization for a self-insured health plan established or maintained by an employee organization;
- The joint board of trustees for a multiemployer plan within the meaning of Code §414(f));
- The committee, in the case of a multiple employer welfare arrangement within the meaning of Section 3(40) of the Employee Retirement Income Security Act (“ERISA”);
- The cooperative or association that establishes or maintains an applicable self-insured health plan established or maintained by a rural electric cooperative under ERISA § 3(40)(B)(iv) or rural cooperative association under ERISA 3(40)(B)(v);
- The trustee, in the case of an applicable self-insured health plan established or maintained by a voluntary employees’ beneficiary association under Code § 501(c)(9) not merely serving as a funding vehicle for a plan that is established or maintained by an employer or other person;
- In the case of an applicable self-insured health plan the plan sponsor of which is not previously described, the person identified by the terms of the document under which the plan is operated as the plan sponsor, or the person designated by the terms of the document under which the plan is operated as the plan sponsor for Code § 4376 purposes, provided that designation is made in writing, and that person has consented to the designation in writing, by no later than the date by which the return paying the fee under section 4376 for that plan year is required to be filed, after which date that designation for that plan year may not be changed or revoked, and provided further that a person may be designated as the plan sponsor only if the person is one of the persons establishing or maintaining the plan (for example, one of the employers that establishes or maintains the plan with one or more other employers or employee organizations); or
- Where an applicable self-insured health plan sponsor is not previously and for which no identification or designation of a plan sponsor has been made under the prior paragraph the plan sponsor means, each employer that establishes or maintains the plan with respect to employees of that employer, each employee organization that establishes or maintains the plan with respect to members of that employee organization, and each board of trustees, cooperative, or association that establishes or maintains the plan.
While the fee will impact most health insurance policies and self-insured plans, the Code does exempt a few arrangements. See Code § 4376. Regulation § 46.4376-1(b)(2) construes these exemptions to include the following categories of programs:
- A plan that provides benefits substantially all of which are excepted benefits for purposes of the HIPAA Portability Rules under Code § 9832(c). Pursuant to this provision, for instance, the Regulations state that a health flexible spending arrangement (health FSA) under Code § 106(c)(2)) that satisfies the requirements to be treated as an excepted benefit under Code § 9832(c) and Regulation § 54.9831–1(c)(3)(v) is not an applicable self-insured health plan. However, a health FSA that is not treated as an excepted benefit under Code § 9832(c) and Regulation § 54.9831–1(c)(3)(v) is an applicable self-insured health plan.
- An employee assistance program, disease management program, or wellness program if the program does not provide significant benefits in the nature of medical care or treatment.
- A plan that, as demonstrated by the facts and circumstances surrounding the adoption and operation of the plan, was designed specifically to cover primarily employees who are working and residing outside the United States (as defined in § 46.4377–1(a)(3)). See Regulation § 46.4376–1(b)(ii).
Where the same plan sponsor maintains multiple self-insured arrangements Regulation § 46.4376(b)(iii) specifies that the employer may treat two or more arrangements established or maintained by the same plan sponsor that provide accident and health coverage other than through an insurance policy and that have the same plan year as a single applicable self-insured health plan for purposes of reporting and calculating the Code § 4376 fee.
Calculation Of Self-Insured Plan Fee Under Code § 4376
Regulation § 46.4376-1 requires that a self-insured plan sponsor determine the number of covered lives for purposes of calculating the fee using on of the following methods:
- The actual count method where the plan sponsor adds the totals of lives covered for each day of the plan year and divides that total by the number of days in the plan year;
- The snapshot method, the plan sponsor adds the totals of lives covered on a date during the first, second, or third month of each quarter of the plan year (or more dates in each quarter if an equal number of dates is used in each quarter), and divides that total by the number of dates on which a count was made in accordance with rules set forth in the Regulations. For instance, Each date used for the second, third and fourth quarter must be within three days of the date in that quarter that corresponds to the date used for the first quarter, and all dates used must fall within the same plan year. If a plan sponsor uses multiple dates for the first quarter, the plan sponsor must use dates in the second, third, and fourth quarters that correspond to each of the dates used for the first quarter or are within three days of such corresponding dates, and all dates used must fall within the same plan year. The 30th and 31st day of a month are treated as the last day of the month for purposes of determining the corresponding date for any month that has fewer than 31 days. The number of lives covered on a designated date using this method may be determined using either the snapshot factor method or the snapshot count method set forth in the Regulations. In the snapshot factor method, the number of lives covered on a date is equal to the sum of: (1) the number of participants with self-only coverage on that date; plus (2) the number of participants with coverage other than self-only coverage on the date multiplied by 2.35. In the snapshot count method, the number of lives covered on a date equals the actual number of lives covered on the designated date. The plan sponsor must use the same method of calculating the average number of lives covered under the plan consistently for the duration of the plan year. However, a plan sponsor may use a different method from one plan year to the next.
- The Form 5500 method, where the plan sponsor determines the average number of lives covered under a plan for a plan year as the result of the sum of the total participants covered at the beginning and the end of the plan year, as reported on the Form 5500 or Form 5500–SF for the applicable self-insured health plan, divided by 2. This method is only available if the Form 5500 is filed by the due date for payment of the fee. This means where a plan administrator extends filing beyond July 31, the plan sponsor cannot use this method.
The Regulations establish a special rule for lives covered solely by the fully-insured options under an applicable self-insured health plan. Under this special rule, when an applicable self-insured health plan provides accident and health coverage through fully insured options and self-insured options, the plan sponsor is permitted to disregard the lives that are covered solely under the fully-insured options in determining the lives covered taken into account for the actual count method, the snapshot method, and the Form 5500 method.
As for insured plans, the Regulations also provide special rules for determining the fee the first year the fee is in effect. Under this rule, for a plan year beginning before July 11, 2012, and ending on or after October 1, 2012, a plan sponsor may determine the average number of lives covered under the plan for the plan year using any reasonable method.
Section 4375 Fee For Insurers
The fee under Code Section 4375 generally applies to issuers of a “specified health insurance policy.” Code Section 4375(c) generally defines a specified health insurance policy as any accident or health insurance policy (including a policy under a group health plan) issued with respect to individuals residing in the United States. Code Section 4377(a)(1) defines accident and health coverage as any coverage that, if provided by an insurance policy, would cause the policy to be a specified health insurance policy under Code Section 4375. See Treas. Reg. § 46.4375–1.
Policies Subject To Fee. Regulation § 46.4377–1(a) defines a “specified health insurance policy” as “any accident and health insurance policy (including a policy under a group health plan) issued with respect to individuals residing in the United States” other than those recognized as exempt by the Regulation. The Regulation makes clear that this includes any policy that provides accident and health coverage to an active employee, former employee, or qualifying beneficiary, as continuation coverage required under the Consolidated Omnibus Budget Reconciliation Act of 1985 (COBRA) or similar continuation coverage under other Federal law or state law.
However Regulation § 46.4377-1(a)(ii) exempts the following arrangements from the definition of a specified health insurance policy.
- Any insurance policy if substantially all of its coverage is of excepted benefits described in Code Section 9832(c);
- Any group policy issued to an employer where the facts and circumstances show that the group policy was designed and issued specifically to cover primarily employees who are working and residing outside of the United States for purposes of Regulation § 46.4377–1(a)(3);
- Any stop loss or indemnity reinsurance policy; or
- Any insurance policy to the extent it provides an employee assistance program, disease management program, or wellness program if the program does not provide significant benefits in the nature of medical care or treatment.
Fee Calculation. The amount of the fee an insurer must pay for a policy for a policy year under Code § 4375 is equal to the product of the average number of lives covered under the policy for the policy year, multiplied by the applicable dollar amount for that policy year.
The applicable dollar amount multiplier is $1 for the fee due on October 1, 2013; $2 for the fee due on October 1, 2014, and the adjusted amount for fees due after October 1, 2014.
Determination Of The Average Number Of Lives Covered. To determine the average number of lives covered under a specified health insurance policy during a policy year, the Regulation requires an issuer to use one of the following methods:
- The actual count method, where the issuer determines the average number of lives covered under a policy for a policy year under the actual count method by adding the total number of lives covered for each day of the policy year and dividing that total by the number of days in the policy year;
- The snapshot method, where the issuer determines the average number of lives covered under a policy for a policy year by adding the totals of lives covered on a date during the first, second, or third month of each quarter (or more dates in each quarter if an equal number of dates is used for each quarter), and dividing that total by the number of dates on which a count is made. Each date used for the second, third and fourth quarters must be within three days of the date in that quarter that corresponds to the date used for the first quarter, and all dates used must be within the same policy year. If an issuer uses multiple dates for the first quarter, the issuer must use dates in the second, third, and fourth quarters that correspond to each of the dates used for the first quarter or are within three days of such corresponding dates, and all dates used must be within the same policy year. The 30th and 31st day of a month are treated as the last day of the month for purposes of determining the corresponding date for any month that has fewer than 31 days (for example, if either March 30 or March 31 is used as a counting date for a calendar year policy, June 30 is the corresponding date for the second quarter);
- The member months method, where the issuer determines the average number of lives covered under all policies in effect for a calendar year based on the member months (an amount that equals the sum of the totals of lives covered on prespecified days in each month of the reporting period) reported on the National Association of Insurance Commissioners (“NAIC”) Supplemental Health Care Exhibit filed for that calendar year. Under this method, the average number of lives covered under the policies in effect for the calendar year equals the member months divided by 12; or
- The state form method, where an insurer not required to file NAIC annual financial statements may determine the number of lives covered under all policies in effect for the calendar year using a form filed with the issuer’s state of domicile and a method similar to the member months method if the form reports the number of lives covered in the same manner as member months are reported on the NAIC Supplemental Health Care Exhibit. See Regulation § 46.4375–1(c)(2)(i).
Issuers must use the same method of calculating the average number of lives covered under a policy consistently for the duration of the year and must use the same method of computing lives for all policies for which a liability is reported on a Form 720, “Quarterly Federal Excise Tax Return,” for a particular year. Regulation § 46.4375–1(c)(2)(ii). However, the Regulation allows an issuer that determines the average number of lives covered by using the actual count method or the snapshot method to change its method of computing the average lives covered to the snapshot method or actual count method, respectively, provided that the issuer uses the same method for computing the average lives covered for all policies for which a liability is reported on the Form 720 for that year. Regulation § 46.4375–1(c)(2).
The Regulations also impose various other special rules. For instance, the Regulations state that if the issuer elects to determine the average number of lives covered for all policies in effect during a calendar year using the member months method or the state form method, the applicable dollar amount with respect to such issuer’s policies for such calendar year is the applicable dollar amount for policy years ending on December 31 of such calendar year, except that the applicable dollar amount with respect to such an issuer’s policies for calendar year 2019 is the applicable dollar amount for policy years ending on September 30, 2019. The Regulations provide various examples of these calculations to illustrate the rules.
The Regulations also provide special rules for the first year and the last year the fee is in effect for an insurer. See Regulation § § 46.4375–1(c).
Plans, Insurers Should Evaluate Options, Plan To Pay Required Fees
The impending obligation provides yet another reason that employers and other self-insured plan sponsors, administrators, insurers, and vendors should re-evaluate their existing health plan designs and costs. Most health insurers and self-insured health plan sponsors will want not only to budget for the impending additional costs associated with these fees, but also evaluate options for mitigating their impact, as well as the costs and administrative burden of tracking and making the required filings. For instance, insurers and plan sponsors of programs subject to these new fees generally will want to evaluate which of the options for collecting the data and calculating the fees will most benefit them. Also, where plan designs used by particular employer or other plan sponsors include both insured and self-insured features, the insurer, plan sponsor and their advisors may want to consider the advisability of restructuring or redesigning plans to mitigate fees or administrative or other expenses. In all cases, parties should audit their programs to ensure that each program and its element is identified and properly taken into account to avoid inadvertent oversights resulting in penalties or other avoidable costs.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help with these or other health benefit or other human resources, employee benefit, insurance, compensation or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, and Past Chair of the ABA Health Law Section Managed Care & Insurance Section, Ms. Stamer is nationally and internationally recognized for her experience and skill aiding clients with a diverse range of employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of leading edge experience helping employers; health and other employee benefit plans and their sponsors, administrators, fiduciaries; TPAs, insurers, governments, employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work representing advising these and other clients, governmental bodies, insurance and financial services organizations, third party administrators and others to develop, design, defend and administer creative health, disability, severance and other employee benefit and compensation arrangements, products and services. She also helps these and other clients monitor, address and respond to federal, state, and international health care and insurance and other regulatory, legislative, audit and enforcement developments. Ms. Stamer has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly. Ms. Stamer regularly works with agencies, publishes and speaks extensively on human resources and employee benefits, medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. You can get more information about her HIPAA and other experience here.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
Comments Off on Self-Insured Health Plan Sponsors, Health Insurers Brace To Pay New ACA-Imposed Fees |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
January 3, 2013
$50K Settlement Shows Small Breach Reports Carry Enforcement Risk
Properly encrypt and protected electronic protected health information (ePHI) on laptops and in other mediums! That’s the clear message of the Department of Health and Human Services (HHS) Office of Civil Rights (OCR) in its announcement of its first settlement under the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule involving a breach of ePHI of fewer than 500 individuals by a HIPAA-covered entity, Hospice of North Idaho (HONI).
In announcing the settlement against HONI, OCR sent a clear message that OCR stands ready to penalize these health care providers, health plans, healthcare clearinghouses and their businesses associates (covered entities) when their failure to properly secure and protect ePHI on laptops or in other systems results in a breach of ePHI even when the breach affects fewer than 500 individuals.
OCR Director Leon Rodriguez reiterated OCR’s expectation that covered entities will properly encrypt ePHI on mobile or other devices in OCR’s announcement of the HONI settlement. “This action sends a strong message to the health care industry that, regardless of size, covered entities must take action and will be held accountable for safeguarding their patients’ health information.” said OCR Director Leon Rodriguez. “Encryption is an easy method for making lost information unusable, unreadable and undecipherable.”
In light of this latest clear warning, health plans and their fiduciaries, sponsors and administrators, health care providers, health care clearinghouses and their business associates should review plans, practices and data security as affecting ePHI and other protected health information on mobile and other devices.
HONI Settlement For Small Breach Notification
On January 2, 2013, OCR announced HONI will pay OCR $50,000 to settle potential HIPAA violations that occurred in connection with the theft of an unencrypted laptop computer containing ePHI. The HONI settlement is the first settlement involving a breach of ePHI affecting fewer than 500 individuals. Read the full HONI Resolution Agreement here.
OCR opened an investigation after HONI reported to HHS that an unencrypted laptop computer containing ePHI of 441 patients had been stolen in June 2010. HONI team members regularly use Laptops containing ePHI their field work. Over the course of the investigation, OCR discovered that HONI had not conducted a risk analysis to safeguard ePHI or have in place policies or procedures to address mobile device security as required by the HIPAA Security Rule. Since the June 2010 theft, HONI has taken extensive additional steps to improve their HIPAA Privacy and Security compliance program.
HIPAA Security & Breach Notification For ePHI
The HONI settlement is notable because it marks the first time OCR has sanctioned a covered entity as a result of an OCR investigation stemming from the covered entity’s report of a breach of unsecured protected health information involving fewer than 500 individuals under new breach notification rules added to HIPAA in 2009.
Under the originally enacted requirements of HIPAA, covered entities and their business associates are required to restrict the use, access and disclosure of protected health information and establish and administer various other policies and safeguards in relation to protected health information. Additionally, the Security Rules require specific encryption and other safeguards when covered entities collect, create, use, access, retain or disclose ePHI.
The Health Information Technology for Economic and Clinical Health (HITECH) Act amended HIPAA, among other things to tighten certain HIPAA requirements, expand its provisions to directly apply to business associates, as well as covered entities and to impose specific breach notification requirements. The HITECH Act Breach Notification Rule requires covered entities to report an impermissible use or disclosure of protected health information, or a “breach,” of 500 individuals or more (Large Breach) to the Secretary of HHS and the media within 60 days after the discovery of the breach. Smaller breaches affecting less than 500 individuals (Small Breach) must be reported to the Secretary on an annual basis. Since the Breach Notification Rule took effect, OCR’s announced policy has been to investigate all Large Breaches and such investigations have resulted in settlements or other corrective action in relation to various Large Breaches. Until now, however, OCR has not made public any resolution agreements requiring settlement payments involving any Small Breaches.
Enforcement Actions Highlight Growing HIPAA Exposures For Covered Entities
While the HONI settlement marks the first settlement on a small breach, this is not the first time OCR has sought sanctions against a covered entity for data breaches involving the loss or theft of unencrypted data on a Laptop, storage device or other computer device. In fact, OCR’s first resolution agreement – reached before Congress added the HIPAA Breach Notification Rules to HIPAA – stemmed from such a breach. Providence To Pay $100000 & Implement Other Safeguards. Breaches resulting from the loss or theft of unencrypted ePHI on mobile or other computer devices or systems has been a common basis of investigation and sanctions since that time, particularly since the Breach Notification rules took effect including breaches of ePHI involving compromised health plan information. See, e.g., OCR Hits Alaska Medicaid For $1.7M+ For HIPAA Security Breach. Coupled with statements by OCR about its intolerance, the HONI and other settlements provide a strong warning to covered entities to properly encrypt ePHI on mobile and other devices.
Furthermore, the HONI settlement also adds to growing evidence of the growing exposures that health care providers, health plans, health care clearinghouses and their business associates need to carefully and appropriately manage their HIPAA encryption and other Privacy and Security responsibilities. See OCR Audit Program Kickoff Further Heats HIPAA Privacy Risks; $1.5 Million HIPAA Settlement Reached To Resolve 1st OCR Enforcement Action Prompted By HITECH Act Breach Report; HIPAA Heats Up: HITECH Act Changes Take Effect & OCR Begins Posting Names, Other Details Of Unsecured PHI Breach Reports On Website. Covered entities are urged to heed these warning by strengthening their HIPAA compliance and adopting other suitable safeguards to minimize HIPAA exposures.
In the face of rising enforcement and fines, OCR’s initiation of HIPAA audits and other recent developments, covered entities and their business associates should tighten privacy policies, breach and other monitoring, training and other practices to reduce potential HIPAA exposures in light of recently tightened requirements and new enforcement risks.
In response to these expanding exposures, all covered entities and their business associates should review critically and carefully the adequacy of their current HIPAA Privacy and Security compliance policies, monitoring, training, breach notification and other practices taking into consideration OCR’s investigation and enforcement actions, emerging litigation and other enforcement data; their own and reports of other security and privacy breaches and near misses, and other developments to decide if additional steps are necessary or advisable.
New OCR HIPAA Mobile Device Educational Tool
While OCR enforcement of HIPAA has significantly increased, compliance and enforcement of the encryption and other Security Rule requirements of HIPAA are a special focus of OCR.
To further promote compliance with the Breach Notification Rule as it relates to ePHI on mobile devices, OCR and the HHS Office of the National Coordinator for Health Information Technology (ONC) recently kicked off a new educational initiative, Mobile Devices: Know the RISKS. Take the STEPS. PROTECT and SECURE Health Information. The program offers health care providers and organizations practical tips on ways to protect their patients’ health information when using mobile devices such as laptops, tablets, and smartphones. For more information, see here. For more information on HIPAA compliance and risk management tips, see here.
For Help With Compliance, Risk Management, Investigations, Policy Updates Or Other Needs
If you need help monitoring HIPAA and other health and health plan related regulatory policy or enforcement developments, or to review or respond to these or other human resources, employee benefit, or other compliance, risk management, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer may be able to help.
Nationally recognized for her extensive work, publications and leadership on HIPAA and other privacy and data security concerns, Ms. Stamer has extensive experience representing, advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical and other privacy and data security, employment, employee benefits, and to handle other compliance and risk management policies and practices; to investigate and respond to OCR and other enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
A Fellow in the American College of Employee Benefit Counsel, State Bar of Texas and American Bar Association, Vice President of the North Texas Health Care Compliance Professionals Association, the Former Chair of the ABA RPTE Employee Benefit & Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Council Representative, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer serves as the scribe for the ABA Joint Committee on Employee Benefits agency meeting with OCR. Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights on HIPAA and other data privacy and security concerns appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, Ms. Stamer for the third year will serve in 2013 as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR. Her insights on HIPAA risk management and compliance often appear in medical privacy related publications of a broad range of health care, health plan and other industry publications Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, SHRM, HIMMS, the American Bar Association, the Health Care Compliance Association, a multitude of health plan, insurance and financial services, education, employer employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here.
In addition to this extensive HIPAA specific experience, Ms. Stamer also is recognized for her experience and skill aiding clients with a diverse range of other employment, employee benefits, health and safety, public policy, and other compliance and risk management concerns.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, a member of the Editorial Advisory Board and expert panels of HR.com, Employee Benefit News, InsuranceThoughtLeadership.com, and Solutions Law Press, Inc., management attorney and consultant Ms. Stamer has 25 years of experience helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Ms. Stamer often has worked, extensively on these and other workforce and performance related matters. In addition to her continuous day-to-day involvement helping businesses to manage employment and employee benefit plan concerns, she also has extensive public policy and regulatory experience with these and other matters domestically and internationally. A former member of the Executive Committee of the Texas Association of Business and past Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Ms. Stamer served as a primary advisor to the Government of Bolivia on its pension privatization law, and has been intimately involved in federal, state, and international workforce, health care, pension and social security, tax, education, immigration, education and other legislative and regulatory reform in the US and abroad. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For more information about Ms. Stamer and her experience or to get access to other publications by Ms. Stamer see here or contact Ms. Stamer directly.
If you need help with these or other compliance concerns, wish to ask about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested in exploring other Solutions Law Press, Inc. ™ tools, products, training and other resources here and reading some of our other Solutions Law Press, Inc.™ human resources news here including the following:
-
- Company President, Officer Can’t Use Bankruptcy To Avoid Liability For Using Plan Money For Company Operations
- Peter Madoff 10 Sentence For Defrauding ERISA Plans Reminder Manage Plan Investment Responsibilities
- IRS Plans To Issue 2013 Withholding Guidance By 12/31
- ESOP, Other Employee Plan Investments In Company Stock Land Plans, Fiduciaries, Sponsors & Others In Hot Water
- Confirm Qualified Plans Updated By Reviewing Against 2012 Required Plan Qualification Requirements Change List
- Catch Up On Health Reform & Other Key Employee Benefits & Insurance Issues Emerging Issues and Litigation Relating to Life, Health, Disability and ERISA Symposium In Ft. Lauderdale
- 2013 Standard Mileage Rates Announced
- IRS Shares Rules Allowing Government Plans To Switch Remedial Amendment Cycles
- Reminder To Amend Health FSA Plan Terms To Include ACA $2500 Contribution Before 2013 Plan Year Begins
- Bank’ $1Million Plus Overtime Settlement Shows Risks of Misapplying FLSA’s Administrative Exemption
- Labor Department Serves The Christmas Light Co. & Its Owner With Holiday Season FLSA Lawsuit
- Boston Hides and Furs Ltd. Sued For $1 Million For Alleged Willful FLSA Wage & Hour Law Violations
- 2013 Maximum Yearly PBGC Guaranteed Pension Benefit Amount To Increase Slightly In 2013
- Rare Court Order Telling Union To Stop Filing Grievances Example Of Employer Risks When Caught Between Competing Unions
- IRS OKs Retirement Plans Allowing Plan Loans & Hardship Withdrawals To Hurricane Sandy Victims
- Agencies Release ACA Wellness, Adult Pre-Existing Condition, Essential Health Benefits Guidance; Briefing Planned
- New Employee Smart Phone App New Tool In Labor Department’s Aggressive Wage & Hour Law Enforcement Campaign Against Restaurant & Other Employers
- 12 Steps Every Employer With A Health Plan Should Do Now No Matter Who Wins the Election
- Boost Employee Recognition of Value Of Employer & Other Retirement Savings Tools & Plans
- Texas Landscaper’s $106,000 In Minimum Wage & Overtime Settlement Reminds Employers To Prepare For FLSA Enforcement
- NLRB’s Nailing of Bel Air Hotel Reminder RIFs, Other Reengineering & Transactions Impacting Workforce Requirement Proper Risk Management
- Tighten Disability Discrimination Defenses As National Disability Employment Awareness Month Promises To Whip Up New Claims & Awareness
- Settlement of OFCCP Employment Discrimination Charge Reminder To ARRA, Other Government Contractors Of Heightened Enforcement Risks
- $1.25M NLRB Backpay Order Highlights Risks of Mismanaging Union Risks In Health Care & Others M&A Deals
- As EEOC Steps Up ADA Accommodation Enforcement, New DOD Apple App, Other Resources Released
- $1.5 M HIPAA Security Breach Resolution Agreement Shows Looming HIPAA Risks
- Labor Risks Rising For Employers Despite NLRB Loss Of Arizona Secret Ballot Challenge
- USI Advisors Will Pay $1.27 Million To Settle Charges It Violated ERISA Fee Disclosure Requirements
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assists businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2013 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press, Inc.™ All other rights reserved.
1 Comment |
Corporate Compliance, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Risk Management, Whistleblower | Tagged: Backpay, Employer, Employment, employment law, Fair Labor Standards Act, FSLA, IT, Labor Department, Minimum Wage, Technology, Wage & Hour, wage and hour, Worker Classification |
Permalink
Posted by Cynthia Marcotte Stamer
November 27, 2012
Get Up To Date On Details of New De-Identification Guidance & Other HIPAA Developments By Participating In 12/12 HIPAA Update Web Workshop
Health care providers, health plans, health care clearinghouses (covered entities) and their business associates and leadership should check and update their policies and practices for the de-identification of protected health information (PHI) in light of newly-released Guidance Regarding Methods for De-identification of Protected Health Information in Accordance With the Health Insurance Portability and Accountablity Act (HIPAA) Privacy Rule (Guidance) released by the Department of Health & Human Services (HHS) Office of Civil Rights yesterday (November 26, 2012).
Solutions Law Press, Inc. will host a one-hour, online HIPAA Update Workshop on the Guidance and other recent regulatory and enforcement developments under HIPAA for covered entities and their business associates on Wednesday, December 12 beginning at Noon Central Time. To register, see here.
PHI collected by health care providers, health plans, their management, sponsors, and vendors often includes a wealth of information valuable for use for functions unrelated to the HIPAA-covered functions and activities that leads covered entities or their business associates to collect or keep this data. While it might be tempting to repurpose this information for business planning and marketing purposes, covered entities and their business partners or associates frequently assume that covered entities and others that they deal with must take proper steps to that no PHI is used, accessed, disclosed or shared unless that action is allowed under the Privacy Rules, properly de-identified, or both.
When planning to rely upon the de-identification of PHI to engage in these activities, parties planning to rely upon HIPAA’s exception for de-identified PHI will want to consult new guidance just released by OCR about the de-identification requirements before moving forward. Existing Privacy Rules and the Guidance recognize two alternative methods that covered entities and their business can use to properly de-identify PHI for purposes of the HIPAA Privacy Rule.
OCR published the Guidance to help covered entities to understand what qualifies as de-identification, the general process by which de-identified information is created, and the options available for performing de-identification for purposes of the HIPAA Privacy Rule. The publication of this guidance was mandated as part of amendments to HIPAA enacted by Health Information Technology for Economic and Clinical Health (HITECH) Act included in the American Recovery and Reinvestment Act of 2009 (ARRA). Section 13424(c) of the HITECH Act requires the HHS to issue guidance on how best to implement the requirements for the de-identification of health information contained in the Privacy Rule.
De-identification & Its Rationale Under Privacy Rule
The Privacy Rule was designed to protect individually identifiable health information through permitting only certain uses and disclosures of PHI provided by the Rule, or as authorized by the individual subject of the information. However, in recognition of the potential utility of health information even when it is not individually identifiable, §164.502(d) of the Privacy Rule permits a covered entity or its business associate to create information that is not individually identifiable by following the de-identification standard and implementation specifications in Privacy Rule §164.514(a)-(b). These provisions allow the entity to use and disclose information that neither identifies nor provides a reasonable basis to identify an individual provided the Covered Entity can show that the PHI has been de-identified in accordance with either the Expert Determination Method or the Safe Harbor Method of the de-identification standard of the Privacy Rule and is not re-identified. Regardless of the method used to de-identify PHI, the Privacy Rule does not restrict the use or disclosure of de-identified health information, as it is no longer considered PHI and is not re-identified.
Privacy Rule De-Identification Implementation Standards Permit Alternative Methods of De-identification
Section 164.514(a) of the HIPAA Privacy Rule provides the standard for de-identification of protected health information. Under this standard, health information is not individually identifiable if it does not identify an individual and if the covered entity has no reasonable basis to believe it can be used to identify an individual. See Privacy Rule § 164.514.
Sections 164.514(b) and (c) of the Privacy Rule contain the implementation specifications that a covered entity must follow to meet the de-identification standard. As summarized in Figure 1, the Privacy Rule provides two methods by which health information can be designated as de-identified:
- The formal determination by a qualified expert in accordance with the Privacy Rule (Expert Determination Method); or
- The removal of specified individual identifiers as well as absence of actual knowledge by the covered entity that the remaining information could be used alone or in combination with other information to identify the individual (Safe Harbor Method).
In order for PHI to qualify as de-identified under the “Expert Determination Method, Privacy Rule § 164.514(b)(1) requires that a person with appropriate knowledge of and experience with generally accepted statistical and scientific principles and methods for rendering information not individually identifiable:
- Applying such principles and methods, determines that the risk is very small that the information could be used, alone or in combination with other reasonably available information, by an anticipated recipient to identify an individual who is a subject of the information; and
- Documents the methods and results of the analysis that justify such determination.
Alternatively, Privacy Rule § 164.514(b)(2) provides that PHI will qualify as de-identified under the Safe Harbor Method if:
- All of an extensive list of identifiers of the individual or of relatives, employers, or household members of the individual, are removed from the data; and
- The covered entity does not have actual knowledge that the information could be used alone or in combination with other information to identify an individual who is a subject of the information.
As long as the data is not re-identified, the Guidance indicates that a covered entity may prove fulfillment of the de-identification standard of Privacy Rule §164.514(a) by showing satisfaction of all applicable requirements of either method. Under the Privacy Rule, de-identified health information created following these methods is no longer protected by the Privacy Rule because it does not fall within the definition of PHI. Of course, de-identification leads to information loss which may limit the usefulness of the resulting health information in certain circumstances. Consequently, covered entities may wish to select de-identification strategies that minimize such loss.
Both alternatives for de-identification under the Privacy Rule require that covered entities and their business associates decide whether and how to keep the option for re-identification of PHI slated for de-identification and where applicable, appropriately manage the re-identification opportunity and data to avoid violation of the Privacy Rule.
According to the Privacy Rule, if a covered entity or business associate successfully undertook an effort to identify the subject of de-identified information it maintained, the health information now related to a specific individual would again be protected by the Privacy Rule, as it would meet the definition of PHI. Disclosure of a code or other means of record identification designed to enable coded or otherwise de-identified information to be re-identified is also considered a disclosure of PHI. In this regard, Privacy Rule §164.514(c) specifies that if the covered entity assigns a code or other means of record identification to allow information de-identified under this section to be re-identified by the covered entity, themeans of record identification is not derived from or related to information about the individual and is not otherwise capable of being translated so as to identify the individual; it can’t use elements of the protected PHI as the re-identification key,must safeguard the key, and can’t use or disclose the key or other re-identification tool for any other purpose.
Preparing For, Guiding & Documenting The De-identification Process For Defensibility
The Guidance stresses that importance of documentation for which values in health data correspond to PHI, as well as the systems that manage PHI and its risk of identification or re-identification in the de-identification process cannot be overstated.
The Guidance provides guidance to help guide covered entities and their business associates through the steps and analysis of using the Expert Determination versus Safe Harbor Method. A review of this Guidance makes clear that the design and administration of the de-identification process under either method requires careful and well-documented planning, analysis and implementation to fulfill and to keep the documentation that a covered entity or business associate might need to defend its decision to treat and use PHI as de-identified under the Privacy Rule against a potential audit or enforcement inquiry. The Guidance also seeks to further illuminate the requirements for effective de-identification through a series of questions and answers, supplemented by work flow and other charts, examples and other illustrations and tips on the proper use of each alternative Method and managing risks and the process associated with that Method. A Glossary of Terms also is shared. The discussion in the Guidance makes clear that covered entities and their businesses associates using either Method to de-identify PHI should be prepared to make a number of judgments about which Method to use, whether and how to make arrangements for re-identification, and how to properly manage the process to meet the requirements of the implementation standard and manage re-identification or other risks.
Register For 12/12 HIPAA Update Web Workshop To Catch Up On De-Identification Guidance & Other HIPAA & Texas HIPAA Regulatory & Enforcement Developments
Training and compliance mandates applicable to covered entities and their business associates under the newly strengthened Texas HIPAA law and HIPAA’s Privacy and Breach Notification Rules make it more important than ever that covered entities and their business associates get the timely training and other assistance needed to properly comply with requirements for the protection of PHI under the new Guidance and other HIPAA and Texas HIPAA mandates.
To aid in this process, Solutions Law Press, Inc. will host a 2012 HIPAA Update Web Workshop covering the new Guidance on de-identification and other regulatory and enforcement developments under HIPAA and the newly amended Texas HIPAA law on December 12, 2012 from 1:00 P.M.-2:00 P.M. Eastern | Noon – 1:00 P.M. Central | 11:00 A.M-Noon Mountain | 10:00A.M-11:00 A.M. Pacific Time.
Expanded health care privacy mandates of the Texas Medical Records Privacy Act that take effect September 1, 2012 and HIPAA regulations require covered entities and their business associates conduct training and take other steps to protect the privacy and security of PHI.
Complete HIPAA Training While You Catch Up On The Latest On HIPAA & Texas Medical Records Privacy Rules & Get Helpful Compliance And Risk Management Tips!
Health care providers, health plans, health care clearinghouses face new imperatives to strengthen their HIPAA and other procedures for handling protected health information and other sensitive information to manage expanding risks and responsibilities arising from evolving rules, expanding enforcement and oversight, and rising penalties and other liabilities.
Expanded health care privacy mandates of the Texas Medical Records Privacy Act that take effect September 1, 2012 and HIPAA regulations require covered entities and their business associates conduct training and take other steps to protect the privacy and security of personal health information (PHI) and certain other information.
The $4.3 million HIPAA Civil Monetary Penalty and growing list of $1 million plus resolution payments announced by the Office of Civil Rights coupled with its commitment to investigate all large breaches reported under the HITECH Act Breach Notification Rule and other stepped up enforcement and newly initiated audit activities send a clear signal that HIPAA-covered entities and their business associates face significant exposures for failing to appropriately manage their HIPAA and other responsibilities when handling protected health information. Meanwhile, Texas House Bill 300 has raised maximum state civil penalties for unlawful disclosures of Protected Health Information under the Texas Medical Records Privacy Act to from $5,000 to $1.5 million per year. Meanwhile HITECH Act amendments to HIPAA require covered entities provide notification of certain breaches while Texas House Bill 300 adds its own specific requirements to provide notice of certain breaches of computerized data containing sensitive personal information.
With Texas House Bill 300 expanding covered entities responsibilities and liabilities and OCR issuing new regulations and other guidance to implement amendments to the HIPAA Privacy & Security Standards and implement and enforce the HITECH Act Breach Notification Rule, health care providers, health plans and insurers, their brokers, third-party administrators, and other covered entities, as well as their business associates and employer and union clients must review and tighten their policies, practices, business associate and other contracts, and enforcement to manage HIPAA and other compliance and manage risks arising from the access, collection, use, protection and disclosure of PHI to meet expanding mandates and to guard against growing liability exposures under HIPAA and other federal and state laws.
Solutions Law Press, Inc. invites you to catch up on the latest on these and other key HIPAA requirements and enforcement and learn tips for managing risks and liabilities by participating in the “HIPAA Update Workshop” on Wednesday, December 12, 2012 via WebEx for a registration fee of $125.00.
Pre-approved for various types of continuing and professional education credit, the December 12, 2012 HIPAA Update Workshop will brief participants on the De-Identification Guidance as well as the latest on other regulatory and enforcement guidance under the HIPAA Privacy, Security and Breach Notification rules and guidance and share compliance and risk management lessons emerging from recent OCR enforcement and audit activities and other selected federal and state litigation and enforcement actions impacting the handling of protected health information. Among other things, the workshop will cover:
- The De-Identification Guidance just released by OCR on November 26, 2012;
- The latest HIPAA Privacy, Security & Breach Notification Guidance, Audits & Enforcement
- Highlights Texas House Bill’s Amendments To Texas Medical Records Privacy Law That Took Effect September 1, 2012
- Post HITECH Act Heightened Liability Risks: Audits, Civil Penalties, Criminal Penalties & State Lawsuits
- Expansion of HIPAA Responsibilities & Liabilities To Business Associates & What Covered Entities & Business Associates Should Do In Response
- HIPAA Data Breach Notification Requirements
- Practical Challenges & Strategies For Managing These Responsibilities
- Tips For Coordinating HIPAA & Other Federal & State Medical Privacy, Financial Information, Identity Theft & Date Security Compliance and Risk Management
- Practical Strategies For Monitoring & Responding To New Requirements & Changing Rules
- Participant Questions
About The Speaker
The workshop will be conducted by attorney Cynthia Marcotte Stamer. A Fellow in the American College of Employee Benefits Counsel, recognized in International Who’s Who, North Texas Health Care Compliance Professionals Association Vice-President and Board Certified in Labor & Employment Law, attorney Cynthia Marcotte Stamer has 25 years experience advising and representing private and public health care providers, employers, employer and union plan sponsors, employee benefit plans, associations, their fiduciaries, administrators, and vendors, group health, Medicare and Medicaid Advantage, and other insurers, governmental leaders and others on privacy and data security, health care, health and other employee benefit. employment, insurance and related matters. A well-known and prolific author and popular speaker, Ms. Stamer has worked extensively with heath care providers, health plans and other payers, health and insurance IT and data systems, and others on HIPAA and other privacy and data security concerns. She served as the scrivener for the ABA JCEB Agency Meetings with the Office of Civil Rights on HIPAA Privacy for the past two years. She presently serves as Co-Chair of the ABA RPTE Section Welfare Plan Committee, Vice Chair of the ABA TIPS Employee Benefit Committee, an ABA Joint Committee on Employee Benefits Representative, an Editorial Advisory Board Member of the Institute of Human Resources (IHR/HR.com) and Employee Benefit News, and various other publications. A primary drafter of the Bolivian Social Security privatization law with extensive domestic and international regulatory and public policy experience, Ms. Stamer also has worked extensively domestically and internationally on public policy and regulatory advocacy on HIPAA and other privacy and data security risks and requirements as well as a broad range of other health, employee benefits, human resources, insurance, tax, compliance and other matters and representing clients in dealings with OCR and other HHS agencies, as well as the Departments of Labor, Treasury, Federal Trade Commission, HUD and Justice, Congress and state legislatures, and various state attorneys general, insurance, labor, worker’s compensation, medical licensure and disciplinary and other agencies and regulators. A prolific author and popular speaker, Ms. Stamer regularly authors materials and conducts workshops and professional, management and other training on HIPAA and other privacy, health care, employee benefits, human resources, insurance and related topics for the ABA, Aspen Publishers, the Bureau of National Affairs (BNA), SHRM, World At Work, Government Institutes, Inc., the Society of Professional Benefits Administrators and many other organizations. Her insights on privacy and other matters are quoted in Modern Healthcare, HealthLeaders, Benefits, Caring for the Elderly, The Wall Street Journal and many other publications. She also regularly serves on the faculty and planning committees of a multitude of symposium and other educational programs. For more details about Ms. Stamer’s services, experience, presentations, publications, and other credentials or to ask about arranging counseling, training or presentations or other services by Ms. Stamer, see www.CynthiaStamer.com.
Registration
The Registration Fee is $125.00 per person. Registration Fee Discounts available for groups of three or more. Pre-payment required via website registration required via website PayPal. No checks or cash accepted. Persons not registered at least 48 hours in advance will only participate subject to system and space availability.
Continuing Education Credit
The HIPAA Update Workshop is approved to be offered for general certification credit by the State Bar of Texas, Texas Department of Insurance, HRCI and WorldAtWork education credit for the time period offered subject to fulfillment all applicable accrediting agency requirements, completion of required procedures. Note that the applicable credentialing agency retain the final authority to determine whether an individual qualifies to receive requested continuing education credit. Neither Solutions Law Press, Inc., the speaker or any of their related parties guarantees the approval of credit for any individual or has any liability for any denial of credit. Special fees or other conditions may apply. CANCELLATION & REFUND POLICY: In order to receive credit, cancellation (either fax or mail) must be received at least 48 hours in advance of the meeting and are subject to a $10.00 refund processing fee. Refunds will be made within 60 days of receipt of written cancellation notice.
About Solutions Law Press, Inc.™
Solutions Law Press, Inc.™ provides business and management information, tools and solutions, training and education, services and support to help organizations and their leaders promote effective management of legal and operational performance, regulatory compliance and risk management, data and information protection and risk management and other key management objectives. Solutions Law Press, Inc.™ also conducts and assist businesses and associations to design, present and conduct customized programs and training targeted to their specific audiences and needs. For additional information about upcoming programs, to explore becoming a presenting sponsor for an upcoming event, e-mail your request to info@Solutionslawpress.com These programs, publications and other resources are provided only for general informational and educational purposes. Neither the distribution or presentation of these programs and materials to any party nor any statement or information provided in or in connection with this communication, the program or associated materials are intended to or shall be construed as establishing an attorney-client relationship, to constitute legal advice or provide any assurance or expectation from Solutions Law Press, Inc., the presenter or any related parties. If you or someone else you know would like to receive future Alerts or other information about developments, publications or programs or other updates, send your request to info@solutionslawpress.com. If you would prefer not to receive communications from Solutions Law Press, Inc. send an e-mail with “Solutions Law Press Unsubscribe” in the Subject to support@solutionslawyer.net. CIRCULAR 230 NOTICE: The following disclaimer is included to comply with and in response to U.S. Treasury Department Circular 230 Regulations. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN. If you are an individual with a disability who requires accommodation to participate, please let us know at the time of your registration so that we may consider your request.
©2012 Solutions Law Press, Inc. All Rights Reserved.
Comments Off on New OCR HIPAA De-Identification Guidance Among Developments Covered In 12/12 HIPAA Update Web Workshop |
ADA, Civil Rights, Consumer Protection, Corporate Compliance, Data Security, Disease Management, Drug & Alcohol, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Medicare Part D, Prescription Drugs, Privacy, Wellness Programs | Tagged: compliance, Health Care, Heatlh Plans, HIPAA, PHI, Texas Medical Records Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
August 13, 2012
Businesses sponsoring employee benefit plans and officers, directors, employees and others acting as fiduciaries with respect to these employee benefit plans should take steps to confirm that all of the appropriate fiduciary bonds required by the Employee Retirement Income Security Act of 1974, as amended (ERISA) are in place, that all employee benefit plans sponsored are appropriately covered, and that all individuals serving in key positions requiring bonding are covered and appropriately qualified to serve in that capacity under ERISA and the terms of the bond. Adequate attention to these concerns not only is a required component of ERISA’s fiduciary compliance, it also may provide invaluable protection if a dishonesty or other fiduciary breach results in a loss or other exposure.
ERISA generally requires that every employee benefit plan fiduciary, as well as every other person who handles funds or other property of a plan (a “plan official”), be bonded if they have some discretionary control over a plan or the assets of a related trust. While some narrow exceptions are available to this bonding requirement, these exceptions are very narrow and apply only if certain narrow criteria are met. Plan sponsors and other plan fiduciaries should take steps to ensure that all of the bonding requirements applicable to their employee benefit plans are met at least annually. Monitoring these compliance obligations is important not only for the 401(k) and other retirement plans typically associated with these requirements, but also for self-insured medical and other ERISA-covered employee benefit plans. This process of credentialing persons involved with the plan and auditing bonding generally should begin with adopting a written policy requiring bonding and verification of credentials and that that appropriate bonds are in place for all internal personnel and outside service providers.
Steps should be taken to ensure that the required fiduciary bonds are secured in sufficient amounts and scope to meet ERISA’s requirements. In addition to confirming the existence and amount of the fiduciary bonds, plan sponsors and fiduciaries should confirm that each employee plan for which bonding is required is listed in the bond and that the bond covers all individuals or organizations that ERISA requires to be bonded. For this purpose, the review should verify the sufficiency and adequacy of bonding in effect for both internal personnel as well as outside service providers. In the case of internal personnel, the adequacy of the bonds should be reviewed annually to ensure that bond amounts are appropriate. Unless a service provider provides a legal opinion that adequately demonstrates that an ERISA bonding exemption applies, plan sponsors and fiduciaries also should require that third party service providers provide proof of appropriate bonding as well as to contract to be bonded in accordance with ERISA and other applicable laws, to provide proof of their bonded status or documentation of their exemption, and to provide notice of events that could impact on their bonded status. When verifying the bonding requirements, it also is a good idea to conduct a criminal background check and other prudent investigation to reconfirm the credentials and suitability of individuals and organizations serving in fiduciary positions or otherwise acting in a capacity covered by ERISA’s bonding requirements. ERISA generally prohibits individuals convicted of certain crimes from serving, and prohibits plan sponsors, fiduciaries or others from knowingly hiring, retaining, employing or otherwise allowing these convicted individuals during or for the 13-year period after the later of the conviction or the end of imprisonment, to serve as:
- An administrator, fiduciary, officer, trustee, custodian, counsel, agent, employee, or
representative in any capacity of any employee benefit plan,
- A consultant or adviser to an employee benefit plan, including but not limited to any entity whose activities are in whole or substantial part devoted to providing goods or services to any employee benefit plan, or
- In any capacity that involves decision-making authority or custody or control of the moneys, funds, assets, or property of any employee benefit plan.
Because ERISA’s bonding and prudent selection of fiduciaries and service provider requirements, breach of its provisions carries all the usual exposures of a fiduciary breach.
Bonding exposures can arise in audit or as part of a broader fiduciary investigation.The likelihood of discovery in an audit or investigation by the Labor Department in the course of an audit is high, as review of bonding is a standard part of audits and investigations. The Employee Benefit Security Administration (EBSA) Enforcement Manual specifies in connection with the conduct of a fiduciary investigation or audit:
… the Investigator/Auditor will ordinarily determine whether a plan is in compliance with the bonding, reporting, and disclosure provisions of ERISA by completing an ERISA Bonding Checklist … These checklists will be filled out in fiduciary cases and retained in the RO workpaper case file unless violations are uncovered, developed, and reported in the ROI.
In the best case scenario, where the bonding noncompliance comes to light in the course of an EBSA audit where no plan loss resulted, the responsible fiduciary generally runs at least a risk that EBSA will assess the 20 percent fiduciary penalty under ERISA Section 502(l). If the bonding lapse comes to light in connection with a fiduciary breach that resulted in damages to the plan by a fiduciary or other party, the bonding insufficiency may be itself a breach of fiduciary duty resulting in injury to the plan and where this breach left the plan unprotected against an act of dishonesty or fiduciary breach by an individual who should have been bonded, may spread liability for the wrongful acts of the wrongdoer to a plan sponsor, member of management or other party serving in a fiduciary role who otherwise would not be liable but for definiciences in the bonding or other credentialing responsibilities.
Under ERISA Section 409, a fiduciary generally is personally liable for injuries to the plan arising from his own breach (such as failure to properly bond) or resulting from breaches of another co-fiduciary who he knew or should have known through prudent exercise of his responsibilities.
Of course, in the most serious cases, such as embezzlement or other criminal acts by a fiduciary of ERISA, the consequences can be quite dire. Knowing or intentional violation of ERISA’s fiduciary responsibilities exposes the guilty fiduciary to fines of up to $10,000, imprisonment for not more than five years, or both. Even where the violation is not knowing or willful, however, allowing disqualified persons to serve in fiduciary roles can have serious consequences such as exposure to Department of Labor penalties and personal liability for breach of fiduciary duty for damages resulting to the plan if it is established that the retention of services was an imprudent engagement of such an individual that caused the loss. When conducting such a background check, care should be taken to comply with the applicable notice and consent requirements for conducting third party conducted background checks under the Fair Credit Reporting Act (FCRA) and otherwise applicable law. As such background investigations generally would be conducted in such a manner as to qualify as a credit check for purposes of the FCRA, conducting background checks in a manner that violates the FCRA credit check requirements itself can be a source of significant liability.
©2012 Cynthia Marcotte Stamer. All rights reserved.
1 Comment |
Affordable Care Act, Claims Administration, Corporate Compliance, Employers, ERISA, Excise Tax, Fiduciary Responsibility, Health Plans, Human Resources, Income Tax, Patient Empowerment, Patient Protection and Affordable Care Act, Payroll Tax, Preemption, Privacy, Reporting & Disclosure, Tax, Wellness | Tagged: compliance, Employee Benefits, Employer, Finance, Health Benefits, Health Care Reform, Health Care Reform. Employer, Health Plans, Management, Plan Sponosr, Risk Managment |
Permalink
Posted by Cynthia Marcotte Stamer
August 6, 2012
August 1 Effective Date Of Obama Administration Addition of Contraception & Other Women’s Health Services To Already Lengthy List of Prevention Services Plans Must Cover
Effective August 1, 2012, federal regulators expanded the list of prevention-related services that the Patient Protection & Affordable Care Act (Affordable Care Act) requires that non-grandfathered group health plans cover in-network at no cost to covered persons to include eight more prevention-related health services for women including coverage for the mandate to cover certain contraceptive services that has engendered much debate and opposition from various religious organizations and others.
Employers and other sponsors and insurers of group health plans should review and update their health plan documents, contracts, communications and administration practices to ensure that their health plans and policies appropriately cover these and other prevention-related services that current federal regulations mandate that group health plans (other than grandfathered plans) must cover to comply with the Affordable Care Act.
Non-Grandfathered Health Plans Must Cover Expansive List of Prevention Services
As part of the sweeping reforms enacted by the Affordable Care Act, Congress has mandated that except for certain plans that qualify as “grandfathered,” group health plans and insurers generally must pay for 100% of the cost to cover hundreds of prevention-related health care services for individuals covered under their health plans without any co-payments or other cost-sharing.identified in the services without cost sharing.
Federal regulations have mandated since 2010 that group health plans and insurers provide in-network coverage in accordance with federal regulations implementing the Affordable Care Act’s prevention-related health services mandates for more than 800 prevention-related services listed in regulations originally published in 2009. See Agencies Release Regulations Implementing Affordable Care Act Preventive Care Mandates. The Affordable Care Act gives federal authorities the power to expand or modify this list. Following publication of the original list, the Obama Administration engaged in lengthy discussion considerations about the scope of contraceptive and other women’s health services that would qualify as prevention related services including lengthy discussions and negotiations about mandates to provide contraceptive services viewed as highly controversial by many religious organizations and several other employers. See Affordable Care Act To Require Health Plans Cover Contraception & Other Women’s Health Procedures.
Obama Administration Adds Contraceptive & Other Women’s Health Services To Required List Effective 8/1/2012
The Obama Administration moved forward on its promise to add contraceptive services and a broad list of other women’s health services to the list of prevention-related health services that employer-sponsored health plans must cover without cost to employees despite objections from religious organizations and others that the contraception mandate violates the Constitution’s freedom of religion protections.
The Obama Administration’s announcement earlier this year that it intended to move forward with plans to mandate that group health plans – including those of certain employers affiliated with religious organizations to cover contraceptive counseling and other services as prevention-related services has prompted outcry and legal challenges from a broad range of religious organizations and others. See e.g., University of Notre Dame v. Sebelius; Hercules Industries, Inc. v. Sebelius. On July 27, 2012, a Colorado District Court granted a temporary injunction barring enforcement of the contraceptive coverage mandate against a small, Catholic family-owned business challenging the mandate as a violation of the Constitutional religious freedoms of its owners. See Hercules Industries, Inc. v. Sebelius.
While these and other litigants continue to challenge the contraceptive mandates, Obama Administration officials continue to voice their commitment to standby and enforce the contraceptive and other prevention-related services mandates as implemented by current regulation. Employer and other health plan sponsors and fiduciaries that do not wish to risk exposure for violating these mandates should review and update their health plan documents, summary plan descriptions and other communications, and administrative and other procedures as necessary to comply with the applicable requirements of the regulations.
For Help or More Information
If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on leading health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and register to receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For important information concerning this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2012 Cynthia Marcotte Stamer. Non-Exclusive License To Republish Granted To Solutions Law Press, Inc. All Other Rights Reserved.
1 Comment |
Affordable Care Act, Claims Administration, Corporate Compliance, Employers, ERISA, Excise Tax, Fiduciary Responsibility, Health Plans, Human Resources, Patient Empowerment, Patient Protection and Affordable Care Act, Preemption, Privacy, Reporting & Disclosure, Tax, Wellness | Tagged: compliance, Employee Benefits, Employer, Finance, Health Care Reform. Employer, Health Plans, Management, Mandated Benefits, Plan Sponosr, preventive care, Risk Managment, Women's Health |
Permalink
Posted by Cynthia Marcotte Stamer
August 1, 2012
August 1 marked the effective date of yet another Affordable Care Act mandate: the controversial contraceptive coverage and other women’s health preventive coverage benefits mandates. Although many mandates have taken effect over the past two years, few employer plans are adequately updated. Here’s some suggestions about what employers and fiduciaries responsible for group health plan sponsorship or administration and their vendors should do now to manage exposures arising from current Affordable Care Act and other federal health plan rules. Following the Supreme Court’s June 28, 2012 National Federation of Independent Business v. Sebelius ruling, most employers and insurers of employment based group health plans now are bracing to cope with radical changes in their health plan related responsibilities scheduled to take effect in 2014.
While anticipating and preparing to cope with these future changes health plan sponsors, fiduciaries, administrators and advisors need to manage the substantial and growing health plan related costs and liabilities that the sponsorship or administration of an employee health plan between now and 2014 is likely to create for their company and its management. Consequently, while planning for 2014, employers sponsoring health plans and their management, insurers, administrators and vendors must act now to update and administer their group health plans timely to comply with the requirements of the Affordable Care Act and other federal rules that have, or in coming months will, take effect pending the law’s full rollout in 2014.
For most health plans, these steps should include the following:
- Know The Cast Of Characters & What Hat(s) (Including You) They Wear & Prudently Select, Contract With & Monitor Them To Manage Risks
Employers and their management rely upon many vendors and advisors and assumptions when making plan design and risk management decisions. Many times, employer and members of their management unknowingly assume significant risk because of misperceptions about these allocations of duties and operational and legal accountability. An correct understanding of these roles and responsibilities is the foundation for knowing where the risks come from, who and to what extent a business or its management can rely upon a vendor or advisor to properly design and administer a health plan or carry out related obligations, what risks cannot be delegated, and how to manage these risks.
Under the Employee Retirement Income Security Act (ERISA), party or parties that exercise discretion or control over health plan administration, funds or certain other matters are generally called “fiduciaries.” Fiduciaries generally are personally liable for prudently and appropriately administering their health plan related responsibilities prudently in accordance with ERISA and other applicable laws and the plan terms. Knowing who is acting as a fiduciary and understanding those duties and liabilities and how to manage these risks significantly affects the exposure that an employer or member of its management risks as a result of an employer’s sponsorship in a group health plan or other employee benefit program. Also, knowing what duties come first and how to prove that the fiduciary did the right thing is critical to managing risks when an individual who has fiduciary responsibilities under ERISA also has other responsibilities in the management of the sponsoring employer, a vendor or elsewhere that carries duties or interests that conflict with his health plan related fiduciary duties.
The plan sponsor or members of its leadership, a service provider or members of their staff generally may be a fiduciary for purposes of ERISA if it either is named as the fiduciary, it functionally exercises the discretion to be considered a fiduciary, or it otherwise has discretionary power over plan administration or other fiduciary matters. Many plan sponsors and their management unwittingly take on liability that they assume rests with an insurer or service provider because the company or members of its management are named as the plan administrator or named fiduciary with regard to duties that the company has hired an insurer or service provider to provide or allowed that service provider to disclaim fiduciary or discretionary status with regard to those responsibilities. Also, by not knowing who the fiduciaries are, plans and their fiduciaries often fail to confirm the eligibility of all parties serving as fiduciaries, to arrange for bonding of service providers or fiduciaries as required to comply with Title I of ERISA. Failing to properly understand when the plan sponsor, member of its management or another party is or could be a fiduciary can create unnecessary and unexpected risks and lead to reliance upon vendors who provide advice but leave the employer holding the bag for resulting liability.
In addition to fiduciary status, employer and other plan sponsors also need to understand the additional responsibilities and exposures that the employer bears as a plan sponsor. Beyond contractual and fiduciary liabilities, federal law increasingly imposes excise tax or other liability for failing to maintain legally compliant plans, file required reports, provide required notifications or fulfill other requirements. The Affordable Care Act, the Internal Revenue Code, the Social Security Act, the Privacy, Security, and Administrative Simplification For instance, the Health Insurance Portability & Accountability Act (HIPAA) and various other federal laws also impose certain health plan related obligations and liabilities on employer or other health plan sponsors and other parties. The Internal Revenue Service interprets Internal Revenue Code § 6039D as obligating employers sponsoring health plans that violate these and certain other federal health plan rules to self-identify, self-report, and self-assess and pay excise and other taxes due under the Internal Revenue Code as a result of this non-compliance. Knowing what everyone’s roles and responsibilities are is a critical first step to properly understanding and managing health plan responsibilities and related risks.
An accurate understanding of the risks and who bears them is critical to understand the risks, opportunities to mitigate risk through effective contracting or other outsourcing, when outsourcing does not effectively transfer risks, where to invest resources for contract, plan or process review and changes or other risk management, and where to expect costs and risks and implement processes and procedures to deal with risks that cannot be outsourced or managed.
- Know What Rules Apply To Your Plan, The Sponsoring Employer, The Plan Its Fiduciaries & Plan Related Vendors & How This Impacts You & Your Group Health Plan
The requirements and rules impacting health plans and their liabilities have undergone continuous changes. Amid these changing requirements, health plans, their sponsors, fiduciaries, insurers, and service providers often may not have kept their knowledge, much less their plan documents, summary plan descriptions and other communications, administrative forms and procedures and other materials and practices up to date. These requirements and their compliance and risk management significance may vary depending upon whether the reviewing or regulated party is the plan, its sponsor, fiduciary, insurer or services in some other rules; how the plans are arranged and documented, the risk and indemnification allocations negotiated among the parties, the risk tolerance of the party, and other factors. Proper understanding of these rules and their implications is critical to understand and manage the applicable risks and exposures.
- Review & Update Health Plan Documents, SPDs & Other Communications, Administrative Forms & Procedures, Contracts & Processes To Meet Requirements & Manage Exposures
Timely updating written plan documents, communications and administration forms, administrative practices, contracts and other health plan related materials processes and procedures has never been more critical.
Federal law generally requires that health plan be established, maintained and administered in accordance with legally complaint, written plan documents and impose a growing list of standards and requirements governing the design and administration of these programs. In addition, ERISA, the Internal Revenue Code, the Social Security Act, federal eligibility and coverage continuation mandates of laws like the Consolidated Omnibus Budget Reconciliation Act (COBRA), the Health Insurance Portability & Accountability Act, the Family & Medical Leave Act, Michelle’s Law and others require that health plan administrators or sponsors communicate plan terms and other relevant information to participants and beneficiaries.
Failing to update documents, communications, administrative forms and processes and other materials and practices can unleash a host of exposures. Among other things, noncompliant plans, communications and practices can trigger unanticipated costs and liabilities by undermining the ability to administer plan terms and conditions. They also may expose the plan, plan fiduciaries and others to lawsuits, administrative enforcement and sanctions and other enforcement liabilities.
Beyond these exposures, employers who sponsor group health plans that violate certain federal group health plan mandates have a duty to self-report certain regulatory plan failures and pay excise taxes where such failures are not corrected in a timely fashion once discovered, or are due to willful neglect. Internal Revenue Code Section 6039D imposes excise taxes for failure to comply with health care continuation (COBRA) , health plan portability (HIPAA), genetic nondiscrimination (GINA), mental health parity (MHPAEA) , minimum hospital stays for newborns and mothers (Newborns’ and Mothers’ Health Protection Act), coverage of dependent students on medically necessary leaves of absence (Michelle’s Law), health savings account (HSA) and Archer medical savings account (Archer MSA) contribution comparability and various other federal requirements incorporated into the Internal Revenue Code. Since 2010, Internal Revenue Service regulations have required employers sponsoring group health plans not complying with mandates covered by Internal Revenue Code Section 6039D to self-report violations and pay related excise taxes. Under these regulations, the sponsoring employer (or in some cases, the insurer, HMO or third-party administrator) must report health plan compliance failures annually on IRS Form 8928 (“Return of Certain Excise Taxes Under Chapter 43 of the Internal Revenue Code”) and self-assess and pay resulting excise taxes. The potential excise tax liability that can result under these provisions can be significant. For example, COBRA, HIPAA, and GINA violations typically carry excise tax liability of $100 per day per individual affected. Compliance with applicable federal group health plan mandates is critical to avoid these excise taxes as well as other federal group health plan liabilities.
For this purpose of deciding what and how much to do, it is critical to keep in mind the devil is in the details. Not only must the documentation meet all technical mandates, the language, its clarity and specificity, and getting the plan document to match the actual processes that will be used to administer the plan and ensuring that the plan documents and processes match the summary plan description, summary of benefits and coverage, administrative forms and documentation and other plan communications and documentation in a legally compliant way significantly impacts the defensibility of the plan terms and the cost that the plan, its sponsor and fiduciaries can expect to incur to defend it.
- Update & Tighten Claims and Appeals Plan & SPD Language, EOBs & Other Notifications, Processes, Contracts & Other Practices For Changing Compliance Requirements & Enhanced Defensibility
Proper health plan claims and appeals plan and summary plan description language, procedures, processing, notification and documentation is critical to maintain defensible claims and appeals decisions required to enforce plan terms and manage claims denial related liabilities and defense costs. Noncompliance with these requirements may prevent health plans from defending their claims or appeals denials, expose the plan administrator and plan fiduciaries involved or responsible for these activities to penalties, prompt unnecessary lawsuits, Labor Department enforcement or both; and drive up plan administration costs.
Unfortunately, most group health plans, their insurers and administrators need to substantially strengthen their plan documentation; handling; timeliness; notifications and other claims denials; and other claims and other appeals processes and documentation to meet existing regulations and otherwise strengthen their defensibility. Among other things, existing court decisions document that many plans existing plan documents, summary plan descriptions and explanations of benefits, claims and appeals investigations and documentation and notifications often need improvement to meet the basic plan document, summary plan description and reasonable claims rules of the plan document, summary plan description, fiduciary responsibility, reasonable claims and appeals procedures of ERISA and its implementing regulations. Court precedent shows that inadequate drafting of these provisions, as well as specific provisions coverage and benefit provisions frequently undermines the defensibility of claims and appeals determinations. In addition to requiring that claims be processed and paid prudently in accordance with the terms of written plan documents, ERISA also requirements that plan fiduciaries decide and administer claims and appeals in accordance with reasonable claims procedures. Although the Labor Department updated its regulations implementing this reasonable claims and appeals procedure requirement more than 10 years ago, the Department of Labor updated its ERISA claims and appeals regulations to include detailed health plan claims and appeals requirements, many group health plans, their administrators and insurers still have not updated their health plans, summary plan descriptions, claims and appeals notification, and claims and appeals procedures to comply with these requirements. The external review and other detailed additional requirements that the Affordable Care Act dictates that group health plans not grandfathered from its provisions and its provisions holding these non-grandfathered plans strictly liable for deficiencies in their claims and appeals procedures makes the need to address inadequacies even more imperative for those non-grandfathered group health plans. Inadequate attention to these concerns can force a plan to pay benefits for claims otherwise not covered as well as other defense costs and penalties.
- Consistency Matters: Build Good Plan Design, Documentation & Processes, Then Follow Them.
Defensible health plan administration starts with the building and adopting strong, legally compliant plan terms and processes that are carefully documented and communicated in a prudent, legally compliant way. The next key is to actually use this investment by conducting plan administration and related operations consistent with the terms and allocated responsibilities to administer the plan in a documented, legally compliant and prudent manner. Good documentation and design on the front end should minimize ambiguities in the meaning of the plan and who is responsible for doing what when. With these tools in place, delays and other hiccups that result from confusion about plan terms, how they apply to a particular circumstance or who is responsible for doing what, when should be minimized and much more easily resolved by timely, appropriate action by the proper responsible party. This facilitation of administration and its consistency can do much to enhance the defensibility of the plan and minimize other plan related risks and costs.
- Ensure Correct Party Carefully Communicates About Coverage and Claims in Compliant, Timely, Prudent, Provable Manner
Having the proper party respond to claims and inquiries in a compliant, timely, prudent manner is another key element to managing health plan risk and promoting enforceability. Ideally, the party appointed to act as the named fiduciary for purposes of carrying out a particular function also should conduct all plan communications regarding that function in terms that makes clear its role and negates responsibility or authority of others. When an employer or other plan sponsor goes to the trouble to appoint a committee, service provider or other party to serve as the named fiduciary then chooses to communicate about the plan anyway, the Supreme Court in FMC v. Halliday made clear it runs the risk that the plan related communications may be considered discretionary fiduciary conduct for which it may be liable as a functional fiduciary. Meanwhile, these communications by non-fiduciaries also may create binding obligations upon the plan and its named fiduciaries to the extent made by a plan sponsor or conducted by a staff member or service provider performing responsibilities delegated by the plan fiduciary. Beyond expanding the scope of potential fiduciaries, communications conducted by nonfiduciaries also tend to create defensibility for many other reasons. For instance, allowing unauthorized parties to perform plan functions may not comport with the plan terms, and are less likely to create and preserve required documentation and follow procedures necessary to promote enforceability. Also, the communications, decisions and other actions by these non-fiduciary actors also are unlikely to qualify for discretionary review by the courts because grants of discretionary authority, if any in the written plan document to qualify the decisions of the named fiduciary for deferential review by courts typically will not extend to actions by these non-fiduciary parties. Furthermore, the likelihood that the communication or other activity conducted will not comply with the fiduciary responsibility or other requirements governing the performance of the plan related functions is significantly increased when a plan sponsor, service provider, member of management, or other party not who has not been appointed or accepted the appointment act as a named fiduciary undertakes to speak or act because that party very likely does not accept or fully appreciate the potential nature of its actions, the fiduciary and other legal rules applicable to the conduct, and the potential implications for the non-fiduciary actor, the plan and its fiduciaries.
- Design and Implement Updated, Properly Secured Payroll, Enrollment, Eligibility and Other Data Collection Features To Meet New Requirements and Prepare For Added Affordable Care Act Data Gathering and Reporting Requirements.
Existing and impending Affordable Care Act mandates require that group health plans, their sponsors collect, maintain and administer is exploding. Existing eligibility mandates, for example, already require that plans have access to a broad range of personal indentifying, personal health and a broad range of other sensitive information about employees and dependents who are or may be eligible for coverage under the plan. While employers and their health plans historically have collected and retained the names, place of residence, family relationships, social security number, and other similar information about employees and their dependents, these data collection, retention and reporting requirements have and will continued to expand dramatically in response to evolving legal requirements. Already, health plans also from time to time need employee earnings, company ownership, employment status, family income, family, medical, military, and school leave information, divorce and child custody, enrollment in Medicare, Medicaid and other coverage and a broad range of other additional information. Under the Affordable Care Act, these data needs will explode to include a whole new range of information about total family income, availability and enrollment in other coverage, cultural and language affiliations, and many other items. Collecting, retaining and deploying this information will be critical to meeting existing and new plan administration and reporting requirements. How this data collection is conducted, shared, safeguarded against misuse or other legally sensitive contact by the employer, service providers, the plan and others will be essential to mitigate exposures to federal employment and other nondiscrimination, HIPAA and other privacy, fiduciary responsibility and other legal risks and obligations. To the extent that payroll providers, third party administrators or other outside service providers will participate in the collection, retention, or use of this data, time also should be set aside both to conduct due diligence about their suitability, as well as to negotiate the necessary contractual arrangements and safeguards to make their involvement appropriate. Finally, given the highly sensitive nature of this data, employers, health plans and others that will collect and use this data will need to implement appropriate safeguards to prevent and monitor for improper use, access or disclosure and to conduct the necessary training to suitably protect this data.
- Monitor, Assess Implications & Provide Relevant Input to Regulators About Emerging Requirements & Interpretive Guidance Implementing 2014 Affordable Care Act & Other Mandates.
While the Supreme Court’s decision upholds the constitutionality of the Affordable Care Act’s individual mandates, many opportunities to impact its mandates remain. Beyond the highly visible, continuing and often heated debates ranging in Congress and the court of public opinion concerning whether Congress should modify or repeal its provisions, a plethora of regulatory interpretations issued or impending release by the implementing agencies, the Internal Revenue Service, Department of Health & Human Services, Department of Labor and state insurance regulators will significantly impact what requirements and costs employers, insurers, individuals and governments will bear when the law takes effect. Businesses sponsoring health plans should carefully scrutinize this regulatory guidance and provide meaningful, timely input to Congress, the regulators or both as appropriate to help influence the direction of regulatory or Congressional actions that would materially impact these burdens.
- Help Employees & Their Families Build Their Health Care Coping Skills With Training & Supportive Tools
Whether or not your company plans to continue to sponsor employee health coverage after 2014, providing training and tools to help employees and their families strengthen their ability to understand and manage their health, health care needs and benefits can pay big dividends. Beyond the financial costs to employees and employers of paying to care for a serious illness or injury, productivity also suffers while employees dealing with their own or a family member’s chronic or serious health care condition. Wellness programs that encourage and support the efforts of employees and their families to stay healthy may be one valuable part of these efforts. Beyond trying to prevent the need to cope with illness behind wellness programs, however, opportunities to realize big financial, productivity and benefit value recognition rewards also exist in the too often overlooked opportunity to provide training, education and tools that employees and their families need to better understand and self-manage care, benefits, finances and life challenges that commonly arise when dealing with their own or a family member’s illness. Providing education, tools and other resources that can help employees access, organize and effectively use health care and benefit information to manage care and the consequences of illness, their benefits and how to use them, to take part more effectively in care and care decisions, to recognize and self-manage financial, lost-time and other challenges associated with the illness not addressable or covered by health benefit programs, and other practical skills can help reduce lost time and other productivity impacts while helping employees and their families get the most out of the health care dollars spent.
- Pack Your Parachute & Locate The Nearest Exit Doors
With the parade of expenses and liabilities associated with health plans, businesses sponsoring health plans and the management, service providers and others involved in their establishment, continuation, maintenance or administration are well advised to pack their survival kit and develop their exit strategies to position to soften the landing in case their health plan experiences a legal or operational disaster.
Employers and other health plan sponsors and fiduciaries typically hire and rely upon a host of vendors and advisors to design and administer their health plans. When selecting and hiring these service providers, health plan sponsors and fiduciaries are well-advised to investigate carefully their credentials as well as require the vendors to provide written commitments to stand behind their advice and services. Too often, while these service providers and advisors encourage plan sponsors and fiduciaries to allow the vendor to lead them or even handle on an ongoing basis plan administration services by touting their services, experience, expert systems and process and commitment to stand behind the customer when making the sale or encouraging reliance upon their advice when tough decisions are made, they rush to stand behind exculpatory and on-sided indemnification provisions in their service contracts to limit or avoid liability, demand indemnification from their customer or both when things go wrong. While ERISA may offer some relief from certain of these exculpatory provisions under some circumstances, plan sponsors and fiduciaries should work to credential service providers and require service providers to commit to being accountable for their services by requiring contracts acknowledge all promised services and standards of quality, require vendors to commit to provide legally compliant and prudently designed and administered services that meet or exceed applicable legal requirements, to provide liability-backed indemnification or other protection for damages and costs resulting from vendor imprudence or malfeasance, to allow for contract termination if the vendor becomes unsuitable for continued use due to changing law or other circumstances and requiring the vendor to return data and other documentation critical to defend past decisions and provide for ongoing administration. Keep documentation about advice, assurances and other relevant evidence received from vendors which could be useful in showing your company’s or plan’s efforts to make prudent efforts to provide for the proper administration of the plan. When concerns arise, use care to investigate and redress concerns in a timely, measured fashion which both shows the prudent response to the concern and reflects sensitivity to the fiduciary and other roles and responsibilities of the employer sponsor and other parties involved.
- Get Moving Now On Your Compliance & Risk Management Issues.
Since many compliance deadlines already have past and the impending deadlines allow plan sponsors and fiduciaries limited time to finish arrangements, businesses, fiduciaries and their service providers need to get moving immediately to update their health plans to meet existing and impending compliance and risk management risks under the Affordable Care Act and other federal laws, decisions and regulations.
- Monitor, Assess Implications & Provide Relevant Input to Regulators About Emerging Requirements & Interpretive Guidance Implementing 2014 Affordable Care Act & Other Mandates.
While the Supreme Court upheld the individual mandate, employer and other health plan sponsors, Congress continues to debate changes to the Affordable Care Act and other federal health plan rules. Meanwhile, significant opportunity still exists to provide input to federal and state regulators on many key aspects of the Affordable Care Act and its relationship to other applicable laws even as court challenges to contraceptive coverage and other specific requirements are emerging. Businesses and other health plan sponsors, plan fiduciaries, insurers and administrators, and other vendors must stay involved and alert. Zealously monitor new developments and share timely input with Congress and regulators about existing and emerging rules that present concerns and other opportunities for improvement even as you position to respond to these rules before they become fully implemented.
For Help or More Information
If you need help reviewing and updating, administering or defending your group health or other employee benefit, human resources, insurance, health care matters or related documents or practices to respond to emerging health plan regulations, monitoring or commenting on these rules, defending your health plan or its administration, or other health or employee benefit, human resources or risk management concerns, please contact the author of this update, Cynthia Marcotte Stamer.
A Fellow in the American College of Employee Benefit Council, immediate past Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and current Co-Chair of its Welfare Benefit Committee, Vice-Chair of the ABA TIPS Employee Benefits Committee, a council member of the ABA Joint Committee on Employee Benefits, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is recognized, internationally, nationally and locally for her more than 24 years of work, advocacy, education and publications on cutting edge health and managed care, employee benefit, human resources and related workforce, insurance and financial services, and health care matters.
A board certified labor and employment attorney widely known for her extensive and creative knowledge and experienced with these and other employment, employee benefit and compensation matters, Ms. Stamer continuously advises and assists employers, employee benefit plans, their sponsoring employers, fiduciaries, insurers, administrators, service providers, insurers and others to monitor and respond to evolving legal and operational requirements and to design, administer, document and defend medical and other welfare benefit, qualified and non-qualified deferred compensation and retirement, severance and other employee benefit, compensation, and human resources, management and other programs and practices tailored to the client’s human resources, employee benefits or other management goals. A primary drafter of the Bolivian Social Security pension privatization law, Ms. Stamer also works extensively with management, service provider and other clients to monitor legislative and regulatory developments and to deal with Congressional and state legislators, regulators, and enforcement officials concerning regulatory, investigatory or enforcement concerns.
Recognized in Who’s Who In American Professionals and both an American Bar Association (ABA) and a State Bar of Texas Fellow, Ms. Stamer serves on the Editorial Advisory Board of Employee Benefits News, the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, and active in a multitude of other employee benefits, human resources and other professional and civic organizations. She also is a widely published author and highly regarded speaker on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, Modern and many other national and local publications. You can learn more about Ms. Stamer and her experience, review some of her other training, speaking, publications and other resources, and registerto receive future updates about developments on these and other concerns from Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
For important information concerning this communication click here. THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2012 Cynthia Marcotte Stamer. Non-Exclusive License To Republish Granted To Solutions Law Press, Inc. All Other Rights Reserved.
Comments Off on 12 Steps Every Employer With A Health Plan Should Do Now To Manage 2012-14 Health Plan Risks & Liabilities |
Affordable Care Act, Claims Administration, Corporate Compliance, Data Security, Employers, ERISA, Excise Tax, Fiduciary Responsibility, Health Plans, Human Resources, Income Tax, Patient Empowerment, Patient Protection and Affordable Care Act, Payroll Tax, Preemption, Privacy, Reporting & Disclosure, Tax, Wellness | Tagged: compliance, Employee Benefits, Employer, Finance, Health Benefits, Health Care Reform, Health Care Reform. Employer, Health Plans, Management, Plan Sponosr, Risk Managment |
Permalink
Posted by Cynthia Marcotte Stamer
November 9, 2011
The kickoff of a new compliance audit pilot program provides another reason for health care providers, health plans, healthcare clearinghouses and their business associates to get serious about compliance with the privacy, security and data breach requirements of the Health Insurance Portability and Accountability Act of 1996 (HIPAA).
OCR Pilot Audit Program Begins
On November 8, 2011, the Office of Civil Rights (OCR) of the Department of Health & Human Services (HHS) announced that it will begin auditing HIPAA compliance this month under a new pilot program.
As amended by the American Recovery and Reinvestment Act of 2009 in Section 13411 of the HITECH Act, requires HHS to provide for periodic audits to make sure covered entities and business associates are complying with the HIPAA Privacy and Security Rules and Breach Notification standards. To carry out this mandate, OCR is piloting a program to perform up to 150 audits of covered entities to assess privacy and security compliance between November 2011 and December 2012.
The commencement of OCR HIPAA compliance audits is yet another sign that covered entities and their business associates should get serious about HIPAA compliance. The audit program serves as a new part of OCR’s health information privacy and security compliance program. While OCR says that it presently views the pilot audits as primarily a compliance improvement tool, this does not mean violators should expect a free walk.
Even before the impending audits, HIPAA Privacy exposures of covered entities for failing to comply with HIPAA already had risen significantly. Earlier this year, OCR imposed a $4.3 Million Civil Money Penalty (CMP) against Cignet Health of Prince George’s County (Cignet) for violating HIPAA. Meanwhile, the Department of Justice has secured several criminal convictions or pleas under HIPAA’s criminal provisions. Under amendments made by the HITECH Act, state attorneys general also now are empowered to bring civil lawsuits against covered entities and business associates that commit HIPAA violations that injure citizens in their state under certain circumstances. Eventually, individuals injured by HIPAA violations also will get the right to share in a portion of certain HIPAA recoveries.
These and other audit and enforcement activities send a strong message that covered entities and their business associates need to get serious about HIPAA compliance. As stated by OCR Director Georgina Verdugo when announcing the Mass General Resolution Agreement, “To avoid enforcement penalties, covered entities must ensure they are always in compliance with the HIPAA Privacy and Security Rules,” Verdugo added, “A robust compliance program includes employee training, vigilant implementation of policies and procedures, regular internal audits, and a prompt action plan to respond to incidents.” Learn more here.
For Help With Monitoring Developments, Compliance, Investigations Or Other Needs
If you need assistance monitoring federal health reform, policy or enforcement developments, or to review or respond to these or other health care or health IT related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, can help.
Vice President of the North Texas Health Care Compliance Professionals Association, a member of the American College of Employee Benefit Counsel, Past Chair of the ABA RPTE Employee Benefits & Other Compensation Arrangements Group, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies. Ms. Stamer also regularly helps clients deal with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. Her insights on the required “culture of compliance” with HIPAA are frequently included in medical privacy related publications of the Atlantic Information Service, Modern Health Care, HealthLeaders and many others. Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, employee benefit and other clients, trade and professional associations and others. You can get more information about her HIPAA and other experience here or may contact her at (469) 767-8872 or via e-mail here.
You can review other selected publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here.
Other Resources
If you found this update of interest, you also may be interested in reviewing some of the other updates and publications authored by Ms. Stamer available including:
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available at www.solutionslawpress.com.
THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2011 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on OCR 1st HIPAA Privacy, Security & Breach Notification Compliance Audits Begin |
Data Security, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, Health Plans, Human Resources, Internal Controls, Internal Investigations, Patient Empowerment, Privacy, Tax | Tagged: Data Breach, Health Care Provider, Health Plans, HHS, HIPAA, OCR, Privacy, Privacy Rules |
Permalink
Posted by Cynthia Marcotte Stamer
May 20, 2011
The National Labor Regulations Board (NLRB)’s announcement of a settlement against a Connecticut nursing home operator this week in conjunction with a series of other enforcement actions highlight the need for businesses to tighten defenses and exercise other caution to minimize their organization’s exposure to potential NLRB charges or investigation. As reflected by many of these enforcement acts, the exposures arise both from active efforts by businesses to suppress union organizing or contracting activities, as well as the failure to identify and manage hidden labor law exposures in the design and administration of more ordinary human resources, compliance, business operations and other policies and practices.
On May 17, 2011, the NLRB announced here that Connecticut nursing home operator Spectrum Healthcare has agreed to settle a NLRB case involving multiple allegations of unlawful suspensions, discharges and unilateral changes in violation of the National Labor Relations Act and other federal labor laws by offering reinstatement and back pay to all discharged and striking workers and signing a new three-year collective bargaining agreement with its employees’ union, New England Health Care Employees Union District 1199, SEIU.
Along with the contract and reinstatement of all employees, the company agreed to pay $545,000 in back pay and pension benefits to employees who were harmed by the unfair labor practices, and to expunge any disciplinary records related to the case. As a result, all NLRB charges against the company have been withdrawn. Spectrum admits to no wrongdoing in the settlement.
The settlement, reached midway through a hearing before an NLRB administrative law judge in Connecticut and approved by the judge yesterday, ends a long-running dispute which grew into a strike by almost 400 employees at four nursing homes in Connecticut operated by Spectrum Healthcare, LLC. Complaints issued by the NLRB Regional Office in Hartford alleged that, beginning in the fall of 2009, several months after the prior collective bargaining agreement expired, Spectrum discharged seven employees and suspended three others to retaliate against their union activities and to discourage other employees from supporting the union. In addition, one employee was discharged and seven others were suspended after the employer unilaterally changed its tardiness discipline policy without first bargaining with the union.
The complaints further alleged that in April 2010, employees at the four nursing homes — in Derby, Ansonia, Winsted, and Hartford — went on strike to protest the unfair labor practices. When the strikers offered unconditionally to return to work in late August, the employer refused to take them back. Under federal labor law, if a strike is called because of an unfair labor practice, employees are entitled to reinstatement after an unconditional offer to return to work.
The reinstated employees are due to return to the facilities this week.
The Spectrum Healthcare settlement is reflective of the growing number of NLRB enforcement orders against employers generally and health care providers specifically under the Obama Administration. The Obama Administration has close ties and has expressed its strong and open support for union and union organizing activities. The adoption of a series of union friendly labor law reforms was one of the key campaign promises of President Obama during his election campaign. While other legislative priorities and the change in the leadership of the House of Representatives appears to have slowed efforts to push through this agenda, it has not slowed the Administration’s efforts to support unions with strong enforcement activities. Empowered by a difficult economic and job situation and an awareness of the Obama Administration’s strong support for union organizing and other activities, unions are stepping up organizing efforts and more aggressively challenging employers actions.
Over the past few months, public awareness of the Obama Administration’s aggressive enforcement agenda on behalf of unions has drawn new attention as a result of the widespread media coverage of NLRB actions challenging Boeings planned relocation of certain manufacturing jobs intervention in a planned relocation of certain manufacturing operations. See, e.g., Acting General Counsel Lafe Solomon releases statement on Boeing complaint; National Labor Relations Board issues complaint against Boeing Company for unlawfully transferring work to a non-union facility. However, the Boeing and Spectrum Healthcare actions represent only the tip of the iceberg of the rising number of NLRB enforcement activities, most of which take place with little media or public attention.
Along side the Spectrum Healthcare and Boeing actions, in recent weeks, the NLRB also has been busy with several other enforcement activities. For instance:
- On May 9 2011, the NLRB issued a complaint against Hispanics United of Buffalo (HUB), a nonprofit that provides social services to low-income clients, that alleges that HUB unlawfully discharged five employees after they took to Facebook to criticize working conditions, including work load and staffing issues. The case involves an employee who, in advance of a meeting with management about working conditions, posted to her Facebook ; and
- On May 17, the NLRB secured a temporary injunction from a U.S. District Court in San Jose California against San Jose area waste hauling company OS Transport LLC, charged with engaging in unfair labor practices including the termination of a lead organizer and another Union supporter, retaliation against Union efforts in the form of unfavorable assignments, threats to Union supporters, and promises of improved treatment of employees who disavow the Union for the alleged purpose of defeating a union. o offer reinstatement to two drivers and restore full assignments to other drivers who had expressed support for a union during an organizing campaign. More Details here.,
In addition, in recent weeks, the NLRB also has:
Amid this difficult enforcement environment, business leaders should exercise special care to prepare to defend their actions against both potential organizing efforts, to understand the types of actions and activities that may help fuel charges, and take steps to manage these and other union organization and other labor risks.
For Help With Labor & Employment, Employee Benefits Or Other Risk Management and Defense
If you need assistance in auditing or assessing, updating or defending your labor and employment, employee benefits, compliance, risk manage or other internal controls practices or actions, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping employers; employee benefit plans and their sponsors, administrators, fiduciaries; employee leasing, recruiting, staffing and other professional employment organizations; and others design, administer and defend innovative workforce, compensation, employee benefit and management policies and practices. Her experience includes extensive work helping employers implement, audit, manage and defend wage and hour and other workforce and internal controls policies, procedures and actions. The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on wage and hour, worker classification and other human resources and workforce, employee benefits, compensation, internal controls and related matters. She also is recognized for her publications, industry leadership, workshops and presentations on these and other human resources concerns and regularly speaks and conducts training on these matters. Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here .
©2011 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Spectrum Healthcare NLRB Charge Settlement Highlights Need To Defend Against Possible Unfair Labor Practices & Other Union Exposures |
105(h), Absenteeism, ADA, Affirmative Action, Affordable Care Act, ARRA, Bankruptcy, Cafeteria Plans, Child Labor, CHIP, Claims Administration, COBRA, COBRA Subsidy, Corporate Compliance, Data Security, Defined Benefit Plans, Defined Contribution Plans, Disability, Disability, Disability Plans, Discrimination, Disease Management, Drug & Alcohol, E-Verify, EEOC, Employee Benefits, Employers, Employment Agreement, Employment Tax, ERISA, Excise Tax, Fair Labor Standards Act, family leave, Fiduciary Responsibility, FMLA, GINA, Government Contractors, H.R. 4872, Health Care Reform, Health Plans, HIPAA, Human Resources, I-9, Immigration, Income Tax, Insurance, Internal Controls, Internal Investigations, Labor Management Relations, Leave, Malpractice, medical leave, Medicare Part D, Mental Health, Mental Health Parity, Military Leave, Non-Compete, Non-Competition Agreement, Nonresident aliens, OFCCP, OSHA, Pandemic, Patient Empowerment, Patient Protection and Affordable Care Act, Payroll Tax, Preemption, Prescription Drugs, Privacy, Professional Liability, Protected Health Information, Public Policy, Refunds, Rehabilitation Act, Reporting & Disclosure, Restructuring, Retaliation, Retirement Plans, Risk Management, Safety, Sexual Harassment, Stimulus Bill, Swine Flu, Tax, Tax Credit, Tax Qualification, Telecommuting, Uncategorized, Unemployment Benefits, Unemployment Insurance, Union, USERRA, VEVRRA, Wage & Hour, Wellness, Wellness Programs, Whistleblower | Tagged: ADAAA, Americans With Disabiltiies Act, Employer, employment discrimination, facebook, HR, Human Resources, NLRA, social medial, unfair labor practices, Union |
Permalink
Posted by Cynthia Marcotte Stamer
May 10, 2011
The National Institute of Standards and Technology (NIST) and the Department of Health and Human Services (HHS), Office for Civil Rights (OCR) are making presentations from the 4th annual conference on “Safeguarding Health Information: Building Assurance through HIPAA Security” co-hosted in Washington, D.C. on May 10 & 11, 2011 available on line for review. The training is part of a series of continuing efforts by the agencies to outreach to various parties on the Privacy and Security Rules of the Health Insurance Portability & Accountability Act of 1996, as amended (HIPAA). Meanwhile, OCR’s Susan McAndrew is scheduled to share insights on OCR’s HIPAA regulatory and enforcement agenda at a teleconference to be hosted by the American Bar Association Joint Committee on Employee Benefits at Noon Central on May 16, 2011.
The Security Rule sets federal standards to protect the confidentiality, integrity and availability of electronic protected health information by requiring HIPAA covered entities and their business associates to implement and maintain administrative, physical and technical safeguards. Presentations cover a variety of current topics including updates on HHS health information privacy and security initiatives, OCR’s enforcement of health information privacy and security activities, integrating security safeguards into health IT and security automation, insider threat trends and safeguards, and more.
The conference is designed to explore the current health information technology security landscape and the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, the agencies share their practical strategies, tips and techniques for implementing the HIPAA Security Rule.
For details about reviewing the May 10-11 presentations, see the 2011 HIPAA Conference website here. For details about the May 16 teleconference, see here.
For Help With Monitoring Developments, Compliance, Investigations Or Other Needs
If you need assistance monitoring federal health reform, policy or enforcement developments, or to review or respond to these or other health care or health IT related risk management, compliance, enforcement or management concerns, the author of this update, attorney Cynthia Marcotte Stamer, can help. Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 23 years experience advising health industry clients about these and other matters. Ms. Stamer has extensive experience advising and assisting health care providers, health plans, their business associates and other health industry clients to establish and administer medical privacy and other compliance and risk management policies, to health care industry investigation, enforcement and other compliance, public policy, regulatory, staffing, and other operations and risk management concerns. She regularly designs and presents HIPAA and other risk management, compliance and other training for health plans, employers, health care providers, professional associations and others.
Ms. Stamer also regularly works with OCR and other agencies, publishes and speaks extensively on medical and other privacy and data security, health and managed care industry regulatory, staffing and human resources, compensation and benefits, technology, public policy, reimbursement and other operations and risk management concerns. Her publications and insights appear in the Health Care Compliance Association, Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Modern Health Care, Managed Healthcare, Health Leaders, and a many other national and local publications. For instance, On May 3, 2011, Ms. Stamer served as the appointed scribe for the ABA Joint Committee on Employee Benefits Agency meeting with OCR and will moderate a teleconference featuring comments by OCR’s Susan McAndrew for the Joint Committee on Employee Benefits scheduled for May 16. Her insights on the required “culture of compliance” with HIPAA also recently were quoted in medical privacy related publications of the Atlantic Information Service. Among others, she has conducted privacy training for the Association of State & Territorial Health Plans (ASTHO), the Los Angeles Health Department, the American Bar Association, the Health Care Compliance Association, a multitude of health industry, health plan, employee benefit and other clients, trade and professional associations and others.
You can get more information about her HIPAA and other experience here.
If you need assistance with these or other compliance concerns, wish to inquire about arranging for compliance audit or training, or need legal representation on other matters please contact Ms. Stamer at (469) 767-8872 or via e-mail here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here. For important information concerning this communication click here.
THE FOLLOWING DISCLAIMER IS INCLUDED TO COMPLY WITH AND IN RESPONSE TO U.S. TREASURY DEPARTMENT CIRCULAR 230 REGULATIONS. ANY STATEMENTS CONTAINED HEREIN ARE NOT INTENDED OR WRITTEN BY THE WRITER TO BE USED, AND NOTHING CONTAINED HEREIN CAN BE USED BY YOU OR ANY OTHER PERSON, FOR THE PURPOSE OF (1) AVOIDING PENALTIES THAT MAY BE IMPOSED UNDER FEDERAL TAX LAW, OR (2) PROMOTING, MARKETING OR RECOMMENDING TO ANOTHER PARTY ANY TAX-RELATED TRANSACTION OR MATTER ADDRESSED HEREIN.
©2011 Cynthia Marcotte Stamer, P.C. Non-exclusive license to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on OCR’s McAndrew Speaks At 5/16 JCEB HIPAA Teleconference; OCR/NIST To Share Other HIPAA Training On Line |
Data Security, GINA, Health Plans, HIPAA, Human Resources, Privacy, Uncategorized, Wellness Programs | Tagged: Health Care, Health Care Provider, Health Plans, HIPAA, OCR, Protected Health Information |
Permalink
Posted by Cynthia Marcotte Stamer
February 23, 2011
A $4.3 million civil monetary penalty (CMP) imposed by the U.S. Department of Health and Human Services’ (HHS) Office for Civil Rights (OCR) against Cignet Health of Prince George’s County, Md., (Cignet) signals the growing need for health plans and their sponsors, health care providers, health care clearinghouses and their business associates covered by the Health Insurance Portability & Accountability Act (HIPAA) Privacy Rule to get serious about HIPAA compliance.
The first CMP ever assessed by OCR under the HIPAA Privacy Rule, the Cignet CMP assessment announced February 22, 2011, the $4.3 million CMP against Cignet announced February 22, 2011 applies the expanded HIPAA violation categories and increased HIPAA civil monetary penalty amounts authorized as part of the expansion of HIPAA obligations and penalties enacted as part of the Health Information Technology for Economic and Clinical Health (HITECH) Act in 2009.
The Cignet penalty announcement is the latest in a series of developments documenting the rising risks that health care providers, health plans, health care clearinghouses and their business associates (“covered entities”) face for violations of HIPAA.
Even before the announcement of the Cignet CMP, the HIPAA Privacy exposures of covered entities for failing to comply with HIPAA already had risen significantly. While OCR had not assessed any civil monetary penalties against any covered entity for violation of HIPAA before Cignet, OCR’s collection of $1 Million from Rite Aid in a 2010 Resolution Agreement, $2.25 million from CVS Pharmacy, Inc. under a 2009 Resolution Agreement and $100,000 from Providence Health & Services under a 2008 Resolution Agreement demonstrated that covered entities could face significant civil liability for willful violations of the Privacy Rules. In addition, the Department of Justice has secured several criminal convictions or pleas under HIPAA’s criminal provisions. OCR data confirms that the covered entities involved in these actions included health care providers, health plans, and others.
Health plans and other covered entities as well as their business associates should tighten privacy policies, breach and other monitoring, training and other practices to mitigate against exposures in light of recently tightened requirements and new enforcement risks. To minimize the potential that the health plan’s sharing of information with the employer will create or spread HIPAA or other privacy risks to the employer or members of its workforce, employers and other plan sponsors and members of their workforce also should take steps to ensure not only that their health plan documents, policies and procedures, as well as those policies and practices applicable to employer, its human resources, and benefits advisors when accessing or handling health plan or other medical information on behalf of the employer, rather than the plan, are appropriately designed and administered.
Read more details and get tips here.
For Help With Investigations, Policy Review & Updates Or Other Needs
If you need assistance in auditing or assessing, updating or defending your HIPAA or other health plan, or other labor and employment, employee benefit, compensation, privacy and data security, or other internal controls and practices, please contact the author of this update, attorney Cynthia Marcotte Stamer here or at (469)767-8872.
Ms. Stamer, a noted Texas-based employee benefits and employment lawyer Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, will discuss HIPAA and other privacy risks and risk management strategies for employers, health and employee benefit plan sponsors and their administrators at the Southwest Benefits Association/IRS Plan Administrator Skills Workshops to be held February 25 in Dallas and March 4 in Houston.
The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, and past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer works, publishes and speaks extensively on HIPAA and other privacy and data security, health plan, health care and other human resources and workforce, employee benefits, compensation, internal controls and related matters.
For more than 23 years, Ms. Stamer has counseled, represented and trained employers and other employee benefit plan sponsors, plan administrators and fiduciaries, insurers and financial services providers, third party administrators, human resources and employee benefit information technology vendors and others privacy and data security, fiduciary responsibility, plan design and administration and other compliance, risk management and operations matters. She also is recognized for her publications, industry leadership, workshops and presentations on privacy and data security and other human resources, employee benefits and health care concerns. Her many highly regarded publications on privacy and data security concerns include “Privacy Invasions of Medical Care-An Emerging Perspective.” ERISA Litigation Manual. BNA, 2003-2009; “Privacy & Securities Standards-A Brief Nutshell.” BNA Tax Management and Compliance Journal. February 4, 2005; “Cybercrime and Identity Theft: Health Information Security beyond HIPAA.” ABA Health eSource. May, 2005 and many others. She also regularly conducts training on HIPAA and other privacy and data security compliance and other risk management matters for a broad range of organizations including the Association of State and Territorial Healthcare Organizations (ASTHO), the Los Angeles County Health Department, a multitude of health plans and their sponsors, health care providers, the American Bar Association, SHRM, the Society for Professional Benefits Administrators and many others.t Her insights on these and other matters appear in the Bureau of National Affairs, Spencer Publications, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, and many other national and local publications. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, data security and privacy, insurance, health care and other key compliance, risk management, internal controls and operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources including:
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information here.
©2011 Cynthia Marcotte Stamer. Non-exclusive right to republish granted to Solutions Law Press. All other rights reserved.
Comments Off on Health Plans & Employers Beware! $4.3 Million Civil Penalty Shows OCR Serious About HIPAA Enforcement |
ARRA, Employee Benefits, Employers, ERISA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Protected Health Information, Stimulus Bill, Tax | Tagged: Employer, Health Plans, HIPAA, OCR, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
November 9, 2010
The U.S. Equal Employment Opportunity Commission (EEOC) today issued final regulations (“Final Regulations”) implementing the employment provisions (Title II) of the Genetic Information Nondiscrimination Act of 2008 (GINA). Employers, employment agencies, labor organizations, joint labor-management committees, and others impacted by GINA should carefully review and update their hiring and background check, sick and family leave, disability accommodation, and other existing policies and practices to comply with the updated guidance provided by the Final Regulations to avoid liability under new GINA’s rules governing genetic information collection, use, protection and disclosure
Effective since November 21, 2009, Title II of GINA prohibits employers of 15 or more employees from discriminating in employment based on genetic information and restricts the acquisition and disclosure of genetic information by covered employers and certain other parties.
Under GINA, employers, employment agencies, labor organizations and joint labor-management committees face significant liability for violating the sweeping nondiscrimination and confidentiality requirements of GINA concerning their use, maintenance and disclosure of genetic information. Under GINA, employees and individuals can sue for damages and other relief like currently available under Title VII of the Civil Rights Act of 1964 and other nondiscrimination laws.
Meanwhile, Title I of GINA prohibits group health plans and health insurers from discriminating in eligibility or premium based on genetic information and requires these plans and insurers to protect the privacy of genetic information (Title I) for plan years beginning after May 20, 2009.
When assessing potential GINA risks and exposures, employers and others covered by its provisions must exercise care not to overlook or underestimate the genetic information collected or possessed by their organizations and the risks attendant to collecting or using this information. Many employers will be surprised by the breadth of the depth of “genetic information.” Because of GINA’s broad definition of “genetic information,” its provisions create potential liability concerns for a surprisingly wide range of employment and health plan practices.
The Final Regulations published today implement the employment discrimination rules of GINA Title II. The EEOC previously published proposed regulations interpreting Title II of GINA in March, 2009. Concurrent with its release of the Final Regulations, the Commission also issued two question-and-answer documents on the final GINA regulations. For links to today’s guidance and more details, see here.
Failing to properly address GINA compliance could expose employers to substantial risk. Violation of the employment provisions of Title II subjects an employer to potentially significant civil judgments like those that generally are available for race, sex, and other federal employment discrimination claims covered by the Civil Rights Act. Accordingly, employers and others who have not already done so should act quickly to review and update their policies and procedures to manage their new compliance and liability exposures under GINA. Employers and others covered by GINA also should assess their leave and other records and practices for data that could be considered genetic information and take appropriate steps to safeguard this information to comply with the confidentiality, nondiscrimination and anti-retaliation rules of GINA, the Americans with Disabilities Act and other applicable laws.
For More Information Or Assistance
If you need assistance evaluating or defending existing or proposed practices under GINA or with other workforce, employee benefit, compensation, internal controls or risk management practices, please contact the author of this update, Board Certified Labor & Employment attorney Cynthia Marcotte Stamer at (469) 767-8872 or via e-mail here.
About Ms. Stamer
Board Certified in Labor and Employment Law by the Texas Board of Legal Specialization, Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Group, a Council Member of the ABA Joint Committee on Employee Benefits, Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, management attorney and consultant Cynthia Marcotte Stamer has more than 23 years experience advising and representing employers, health and other employee benefit plans, their sponsors, fiduciaries and plan administrators, consultants, vendors, outsourcers, insurers, governments and others about employment, employee benefit, compensation, and a wide range of other performance, legal and operational risk management practices and concerns. As a part of this work, Ms. Stamer has worked extensively with client to manage risks and defend practices under GINA, the ADA and a wide range of employment discrimination, privacy and other laws. A prolific author and popular speaker, Ms. Stamer also publishes, conducts client and other training, speaks and consults extensively on GINA and other employment and employee benefit risk management practices and concerns for the ABA, World At Work, SHRM, American Health Lawyers Association, Institute of Internal Auditors, Society for Professional Benefits Administrators, HCCA, Southwest Benefits Association and many other organizations. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To learn more about Ms. Stamer, her experience, involvements, programs and publications, see here or contact Ms. Stamer.
Other Resources & Developments
If you found this information of interest, you also may be interested in reviewing other recent Solutions Law Press updates including:
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here.
If you or someone else you know would like to receive future updates and notices about upcoming programs and events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. To unsubscribe, send an e-mail with “Unsubscribe” in the subject here. For important information concerning this communication click here.
©2010 Cynthia Marcotte Stamer PC. Reprint Permission Granted To Solutions Law Press. All other rights reserved.
Comments Off on Update Employment Practices To Manage Genetic Info Discrimination Risks Under New EEOC Final GINA Regulations |
Disability, Discrimination, EEOC, Employee Benefits, Employers, GINA, Human Resources, Privacy, Risk Management, Union | Tagged: ADA, EEOC, Emloyment Discrimination, Employment, GINA, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
July 30, 2010
Learn If Your Plan Will Be Grandfathered Plan & What You Must Do Now To Meet Key 2010/2011 Affordable Care Act & Other Federal Health Plan Compliance Deadlines
A Solutions Law Press Live Internet Broadcast Briefing
August 24, 2010
10:00 A.M.-12:30 P.M. Eastern
11:00 A.M.- 1:30 P.M. Central
9:00 A.M-11:30 A.M. Pacific
Solutions Law Press invites you to catch up on the latest guidance about the new group health plan mandates imposed under the Patient Protection and Affordable Care Act (Affordable Care Act) and other federal health plan regulations by participating in a live “2010 Health Plan Update” internet[*] broadcast briefing on Tuesday, August 24 2010. The briefing will be conducted via live video broadcast from 11:00 A.M.-1:30 P.M. Central Time. Register here for a registration fee of $150.00[†] per participant.
Affordable Care Act Requires Prompt Action By Group Health Plans, Sponsors, Fiduciaries & Administrators
The Affordable Care Act and other impending federal health plan changes will require employment-based group health plans, their employer and other plan sponsors, plan fiduciaries, plan administrators and other service providers and insurers to make quick decisions and to act quickly to meet impending federal compliance deadlines while preserving flexibility. All employer and other group health plan sponsors, fiduciaries, insurers and administrators must act quickly to update their health plan documents, communications, insurance and vendor agreements and other practices to comply with new federal requirements that become effective under the Affordable Care Act on the first day of the plan year beginning after September 22, 2010 and various other changes in federal health plan rules effective or scheduled to take effect during 2010 or 2011 plan years. Many plan sponsors also may need to act quickly to cancel or revise plan design or vendor changes planned or already implemented since March 23, 2010 to position their health plan to qualify for grandfather status. Quick action also may be needed to claim small employer tax credits, retiree medical subsidies or other benefits.
Register Now To Get Key Information In August 24 Internet Briefing
The August 24, 2010 “2010 Health Plan Update” briefing will cover the latest guidance on Affordable Care Act and other federal health plan regulatory changes impacting employment-based group health plans and their sponsors for plan years beginning between September 23, 2010 and September 22, 2011 and other key information to help employers, group health plans, insurers, plan administrators, fiduciaries, broker and others working with these plans to understand and respond to these new requirements including:
- How to qualify your health plan as a grandfathered plan under Affordable Care act
- How to decide if maintaining grandfathered plan status is worthwhile
- Claims & appeals requirements for grandfathered & non-grandfathered plans
- Preventive care coverage mandates & wellness program requirements & rules under Affordable Care Act & other federal regulations
- Updated dependent child eligibility, pre-existing condition & other requirements for grandfathered & non-grandfathered plans
- Special enrollment, preexisting condition & other eligibility mandates for grandfathered & non-grandfathered plans under new Affordable Care Act, new FMLA, COBRA, Michelle’s Law, HIPAA & other federal regulations
- Mental health & substance abuse, provider choice & other benefit mandates under Affordable Care Act, Mental Health Parity & other federal rules
- Update on other recent & pending Affordable Care Act group health plan rule guidance
- Tips to review & update your plans, vendor agreements & processes to meet Affordable Care Act & other federal group health plan dictates
- Expected future Affordable Care Act & other federal rule changes & tips for preparing
- Practical strategies for responding to new requirements & changing rules
- Participant questions
About The Presenter
The program will be conducted by attorney Cynthia Marcotte Stamer. With more than 23 years of experience advising employers, group health plans, plan fiduciaries, plan administrators and vendors, insurers and others about health plan and managed care matters, Ms. Stamer is nationally known for her work, publications and presentations on health plan and other employee benefit, health care and insurance matters.
Current Chair of the American Bar Association (ABA) RPTE Employee Benefit & Other Compensation Committee, a Council Member of the ABA Joint Committee on Employee Benefits and Past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer continuously advises employers, health plans, plan sponsors, fiduciaries, plan administrators, plan vendors, insurers and others about health program related legal, operational, documentation, public policy, enforcement, privacy, technology, litigation and risk management and other concerns. Ms. Stamer also publishes and speaks extensively on these and other health and managed care program concerns and practices. Her insights on these and related topics have appeared in Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, Managed Healthcare, Health Leaders, various ABA publications and a many other national and local publications. To contact Ms. Stamer or for additional information about Ms. Stamer, her experience, involvements, programs or publications, contact Ms. Stamer at (469) 767-8872 or via e-mail here, or see here.
About Solutions Law Press
Solutions Law Press™ provides business risk management, legal compliance, management effectiveness and other resources, training and education on human resources, employee benefits, compensation, data security and privacy, health care, insurance, and other key compliance, risk management, internal controls and other key operational concerns. If you find this of interest, you also be interested reviewing some of our other Solutions Law Press resources available for review here. If you or someone else you know would like to receive future updates and notices about other upcoming Solutions Law Press events, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word ©2010 Solutions Law Press. All rights reserved.
[*] A limited number of participants on a space available basis will have the opportunity to participate in the briefing as a member of the live studio audio audience in Plano, Texas. Interested persons should e-mail support@solutionslawyer.net.
[†] Discounts available for groups registering three or more participants. Sponsorship opportunities also available. For information, E-mail support@solutionslawyer.net.
Comments Off on Register Now For 8/24 2010 Health Plan Update Briefing |
ADA, Affordable Care Act, COBRA, Disease Management, Employee Benefits, Employers, ERISA, Excise Tax, family leave, Fiduciary Responsibility, FMLA, GINA, HIPAA, Human Resources, Insurance, Internal Controls, Leave, medical leave, Mental Health, Patient Protection and Affordable Care Act, Payroll Tax, Privacy, Protected Health Information, Risk Management, Tax, Wellness | Tagged: Affordable Care Act, COBRA, FLSA, GINA, grandfathered plan, Health Plan, HIPAA, Mental Health Parity, Michelle's Law |
Permalink
Posted by Cynthia Marcotte Stamer
May 19, 2010
Cynthia Marcotte Stamer will discuss “Health Care Reform’s Implications for Employers, Health Plans and Employee Benefits Practitioners” at the June 9, 2010 meeting of Houston WEB. The program is scheduled for Wednesday, June 9, 2010 at the DoubleTree Guest Suites, 5353 Westheimer, Houston, Texas from 11:30 a.m. to 1:30 pm.
Narrowly passed by Congress in March after a year of contentious debate, the comprehensive health care reform legislation imposes a complex array of reforms impacting employment based health plans, employers, and the insurers and other vendors and administrators of these programs. Ms. Stamer will explore key elements of these reforms impacting employers and employment based health coverage and their implications for employers, employment based health plans, and employee benefits and other attorneys providing advice about these arrangements.
To register or for more information about this event, see here. If you need assistance reviewing or responding to these or other employee benefit, compensation or labor and employment concerns, contact the author of this update, Cynthia Marcotte Stamer, for assistance at (469) 767-8872 or here.
About Ms. Stamer
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 23 years of work helping businesses manage labor and employment, employee benefits, performance management and discipline, compliance and internal controls, risk management, and public policy matters including significant, cutting edge experience advising employer and other health plan sponsors, fiduciaries, insurers, administrators and others design, administer, and defend defensible, cost-effective health and other employee benefit programs.
As a core focus of her practice, Ms. Stamer works extensively with employer and other health plan sponsors, fiduciaries, administrative and other service providers, insurers, and other clients on health benefit program and product design, documentation, administration, compliance, risk management, and public policy matters. The publisher of Solutions Law Press, Ms. Stamer also publishes, conducts training and speaks extensively on these and related concerns for the ABA, the Bureau of National Affairs and many other organizations. Please join us for what promises to be a most interesting discussion
The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, and the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications, Ms. Stamer also is recognized for her publications, industry leadership, workshops and presentations on these and other health industry and human resources concerns. She regularly speaks and conducts training for the ABA, Institute of Internal Auditors, Society for Professional Benefits Administrators, Southwest Benefits Association and many other organizations. Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Aspen Publishers, Schneider Publications, Spencer Publications, World At Work, SHRM, HCCA, State Bar of Texas, Business Insurance, James Publishing and many others. You can review other highlights of Ms. Stamer’s experience here. Her insights on these and other matters appear in Managed Care Executive, Modern Health Care, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, MDNews, Kentucky Physician, and many other national and local publications.
If you need help with human resources or other management, concerns, wish to ask about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer here or (469)767-8872.
Other Resources
If you found this information of interest, you also may be interested in reviewing other updates and publications by Ms. Stamer including:
- Defined Contribution Plans Investing In Publically Traded Employer Securities Face New Requirements
- CBO Raises Estimated Cost of Health Care Reforms As Employers, Health Plans Brace Costs Of Newly Effective & Impending Mandates
- Join Project COPE: Help Develop Real Tools To Meaningfully Empower Patients & Improve Health Care Access, Affordability & Quality
- Unemployment, COBRA Premium Subsidy Temporarily Extended As Congress Mulls Passing Longer Relief
- Agencies Invite Public To Share Input About Insurer Obligation To Report About Health Premium Use Under Health Care Reform Law
- TSHHRAE Provides Health Industry HR & Other Managers Employment Law Update & Other Timely Management Training At April Barnstorm 2010: Creating Effective Leaders Programs
- New Study Shares Data On Migrant Health Care Challenges Along The Border
- Getting Your Health Care Reform Message Heard By Key Congressional Leaders
- Extension of Unemployment Benefits Signed Into Law & Immediately Effective As Filibuster Ends
- COBRA Premium Subsidy Requirements Expanded & Extended Under Newly Signed Unemployment Extension Legislation
- Employers Concerned About New Union Powers As NLRB Orders Union Elections In 31 California Health Care Facilities To Proceed
- Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates
- Stamer To Present “2010 Health Plan Checkup” At Annual DFW ISCEBS Employee Benefits Fundamentals Workshop
- SouthWest Benefits e-Connections Highlights Stamer Article About Importance For Health Plans, Their Sponsors & Business Associates To Update HIPAA Policies, Practices & Agreements
- Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates
- Employers, Group Health Plans Subject To New CHIP/Medicaid Notice, Coordination of Benefits & Special Enrollment Requirements
- Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes
- St. Louis Employer’s OSHA Violations Trigger Contempt Order and Penalties
- Labor Department Final H-2A Certification Procedures Tighten Requirements For Employment Of Temporary Agricultural Employment Of Workers
- COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations
- Inapplicability of HIPAA Privacy To Disability Insurer Not License To Impose Unreasonable Claims Requirements
- New Mental Health Parity Regulations Require Health Plan Review & Updates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to receive our Solutions Law Press distributions here. For important information about this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.
©2010 Solutions Law Press. All rights reserved.
Comments Off on Stamer Speaks June 9 On “Health Care Reform’s Implications For Employers, Health Plans & Employee Benefits Practitioners” In Houston |
Affordable Care Act, CHIP, COBRA, COBRA Subsidy, Corporate Compliance, Employee Benefits, Employers, Employment Tax, ERISA, Fiduciary Responsibility, FMLA, HIPAA, Human Resources, Insurance, Internal Controls, Medicare Part D, Mental Health, Mental Health Parity, Payroll Tax, Prescription Drugs, Privacy, Protected Health Information, Public Policy, Risk Management, Tax, Uncategorized, Wellness, Wellness Programs | Tagged: Affordable Care Act, Employee Benefits, Employers, ERISA, Fiduciary, Health Care Reform, Health Insurance, Health Plan, Health Plans, Insurer |
Permalink
Posted by Cynthia Marcotte Stamer
May 15, 2010
By Cynthia Marcotte Stamer
New analysis released Tuesday, May 11 by the non-partisan Congressional Budget Office shows H.R. 3590, the Patient Protection and Affordable Care Act, Public Law 111-148 (Health Care Reform Law) passed in March will cost $115 Billion more than originally estimated in the CBO’s March 15, 2010 discretionary spending analysis. News of the cost estimate increase comes as U.S. employer and other health plan sponsors, insurers and others are bracing for the first wave of new federal health plan mandates enacted as part of the Health Care Reform Law to take effect in September and a host of other federal mandates previously enacted that take effect in the 2009 and 2010 plan years.
Projected Cost of Health Care Reform Increased
According to CBO, additional information about the potential effects of the Health Care Reform Law on spending funded through the annual appropriation process (discretionary spending). By their nature all such potential effects on discretionary spending are subject to future appropriation actions, which could result in greater or smaller costs than the sums authorized by the legislation. While still limited in certain respects, the updated CBO analysis provides information on the major components of such costs in three general categories:
- The costs that will be incurred by federal agencies to implement the new policies established by the Health Care Reform Law, such as administrative expenses for the Department of Health and Human Services and the Internal Revenue Service for carrying out key requirements of the legislation.
- Explicit authorizations for future appropriations for a variety of grant and other program spending for which the act identifies the specific funding levels it envisions for one or more years. (Such cases include provisions where a specified funding level is authorized for an initial year along with the authorization of such sums as may be necessary for continued funding in subsequent years.)
- Explicit authorizations for future appropriations for a variety of grant and other program spending for which no specific funding levels are identified in the legislation. That type of provision generally includes legislative language that authorizes the appropriation of “such sums as may be necessary,” often for a particular period of time.
According to the updated analysis, CBO estimates that total authorized costs in the first two categories probably exceed $115 billion over the 2010-2019 period. CBO still does not have an estimate of the potential costs of authorizations in the third category.
CBO previously issued an estimate of the Health Care Reform Law’s direct spending and revenue effects in combination with the Reconciliation Act of 2010 (Public Law 111-152), which amended it. (Direct spending effects are those that do not require subsequent appropriation action.) CBO estimated that those two laws, in combination, would produce a net reduction in federal deficits of $143 billion over the 2010-2019 period as a result of changes in direct spending and revenues.
Impending Federal Health Plan Mandate Changes Bring New Costs, Risks Now
CBO’s adjustment to its cost projections comes as U.S. employers and insurers already are bracing to cope with a host of new federally imposed health plan mandates and accompanying costs that already have or will in the next 12-months impact their existing health benefit programs. Examples of these new mandates include:
- COBRA Stimulus Bill Premium Subsidy and Other Mandates
- New FMLA and USERRA Coverage Continuation Mandates
- Dependent Care Coverage Extension Mandates For Students Requiring Medical Leave Effective
- Genetic and Other Disability Discrimination Mandates under GINA, ADA Amendments Act of 2008, HIPAA Portability and Other Federal Mandates
- Expanded Mental Health Parity Mandates
- HIPAA Data Breach and Other Protected Health Information Privacy and Data Security Mandates
- New IRS Excise Tax Self-Assessment & Reporting Mandates For Plans Violating COBRA, Mental Health Parity and Wide Range of Other Federal Mandates
- Changes To Retiree Medical Subsidy Rules
- Early Retiree Medical Reinsurance Program For Employers Providing Qualifying Retiree Coverage
- New Small Employer Tax Credit Rules
- Mandated extension of dependent coverage to age 26
- Prohibition of Pre-Existing Condition Limits on Dependent Coverage
- New restrictions on annual and lifetime benefit limitations
- Mandate to cover 100% of preventative care
- Prohibition against coverage rescissions
- Primary Care Physician choice mandates
- Restrictions on coverage limitations for emergency and obstetrical care
- Extension of Internal Revenue Code Section 105(h) nondiscrimination mandates to certain insured health plans
- Many others
Employer and other health plan sponsors, their insurers, administrators and others responsible for updating and administering group and other health plans must move immediately to meet these evolving mandates while bracing for anticipated increased costs and other obligations expected to result as the Health Care Reform Law takes effect over the next few years. Employers, administrators and insurers needing additional information about these changes can review the resources and training materials available here and/or contact the author of this update, attorney and consultant Cynthia Marcotte Stamer, for assistance at (469) 767-8872 or here
Responsible & Prompt Action Needed
Employer and other health plan sponsors, administrators, fiduciaries and insurers both should act quickly to update their programs, plan documents, communications and practices to comply with federal mandates that have and are scheduled to take effect and stay involved with regulators and Congress as the regulatory rules and processes to implement the Health Care Reform Law are developing. Ultimately, the cost and other implications of the Health Care Reform Law will depend largely upon how its provisions are construed and implemented by federal and state regulators, along with any subsequent adjustments, if any that Congress may elect to enact. With federal officials hard at work preparing implementing regulations and other guidance and procedures, health industry leaders and other concerned Americans should stay informed and continue to share their input on these critical issues as these decisions are shaped. Join the discussion by participating in the Coalition For Responsible Health Care Policy linked in group and/or its subgroup, Project COPE: Coalition for Patient Empowerment and/or register to receive updates Coalition for Responsible Heath Care Policy by RSS Feed.Coalition for Responsible Health Care PolicyCoalition for Responsible Health Care PolicyCoalition for Responsible Health Care Policy
The author of this update, Cynthia Marcotte Stamer, recently has conducted briefings on the implications of the Affordable Care Act and other regulatory changes impacting health plans and their employer and other sponsors, insurers, administrators and others for the Society of Professional Benefits Administrators, the Dallas Bar Association and others. Several other presentations and update are scheduled in the upcoming months. For information about these programs or to register to receive information about these programs, see here.
About Ms. Stamer
Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, management attorney and consultant Ms. Stamer is nationally and internationally recognized for more than 22 years of work helping businesses manage labor and employment, employee benefits, performance management and discipline, compliance and internal controls, risk management, and public policy matters including significant, cutting edge experience advising employer and other health plan sponsors, fiduciaries, insurers, administrators and others design, administer, and defend defensible, cost-effective health and other employee benefit programs.
The Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Committee, a Council Representative on the ABA Joint Committee on Employee Benefits, Government Affairs Committee Legislative Chair for the Dallas Human Resources Management Association, Vice President of the North Texas Health Care Compliance Professionals Association, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, and the editor and publisher of Solutions Law Press HR & Benefits Update and other Solutions Law Press Publications Ms. Stamer also is recognized for her publications, industry leadership, workshops and presentations on these and other health industry and human resources concerns. She regularly speaks and conducts training for the ABA, American Health Lawyers Association (AHLA), Health Care Compliance Association, Institute of Internal Auditors, Harris County Medical Society, the Medical Group Management Association, Society for Professional Benefits Administrators, Southwest Benefits Association, Harris County Medical Society, Medical Group Management Association, Society of Human Resources Management, and many other organizations. Publishers of her many highly regarded writings on health industry and human resources matters include the Bureau of National Affairs, Aspen Publishers, ABA, AHLA, Aspen Publishers, Schneider Publications, Spencer Publications, World At Work, SHRM, HCCA, State Bar of Texas, Business Insurance, James Publishing and many others. You can review other highlights of Ms. Stamer’s experience here. Her insights on these and other matters appear in Managed Care Executive, Modern Health Care, the Wall Street Journal, the Dallas Business Journal, the Houston Business Journal, MDNews, Kentucky Physician, and many other national and local publications.
If you need help with human resources or other management, concerns, wish to ask about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer here or (469)767-8872.
Other Resources
If you found this information of interest, you also may be interested in reviewing other updates and publications by Ms. Stamer including:
- Join Project COPE: Help Develop Real Tools To Meaningfully Empower Patients & Improve Health Care Access, Affordability & Quality
- Unemployment, COBRA Premium Subsidy Temporarily Extended As Congress Mulls Passing Longer Relief
- Agencies Invite Public To Share Input About Insurer Obligation To Report About Health Premium Use Under Health Care Reform Law
- TSHHRAE Provides Health Industry HR & Other Managers Employment Law Update & Other Timely Management Training At April Barnstorm 2010: Creating Effective Leaders Programs
- New Study Shares Data On Migrant Health Care Challenges Along The Border
- Getting Your Health Care Reform Message Heard By Key Congressional Leaders
- Extension of Unemployment Benefits Signed Into Law & Immediately Effective As Filibuster Ends
- COBRA Premium Subsidy Requirements Expanded & Extended Under Newly Signed Unemployment Extension Legislation
- Employers Concerned About New Union Powers As NLRB Orders Union Elections In 31 California Health Care Facilities To Proceed
- Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates
- Stamer To Present “2010 Health Plan Checkup” At Annual DFW ISCEBS Employee Benefits Fundamentals Workshop
- SouthWest Benefits e-Connections Highlights Stamer Article About Importance For Health Plans, Their Sponsors & Business Associates To Update HIPAA Policies, Practices & Agreements
- Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates
- Employers, Group Health Plans Subject To New CHIP/Medicaid Notice, Coordination of Benefits & Special Enrollment Requirements
- Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes
- St. Louis Employer’s OSHA Violations Trigger Contempt Order and Penalties
- Labor Department Final H-2A Certification Procedures Tighten Requirements For Employment Of Temporary Agricultural Employment Of Workers
- COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations
- Inapplicability of HIPAA Privacy To Disability Insurer Not License To Impose Unreasonable Claims Requirements
- New Mental Health Parity Regulations Require Health Plan Review & Updates
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to receive our Solutions Law Press distributions here. For important information about this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.
©2010 Solutions Law Press. All rights reserved.
Comments Off on CBO Raises Estimated Cost of Health Care Reforms As Employers, Health Plans Brace Costs Of Newly Effective & Impending Mandates |
Affordable Care Act, ARRA, CHIP, COBRA, COBRA Subsidy, Disease Management, Employee Benefits, Employers, Employment Tax, ERISA, Excise Tax, family leave, Fiduciary Responsibility, FMLA, GINA, H.R. 4872, Health Plans, HIPAA, Human Resources, Income Tax, Leave, medical leave, Medicare Part D, Mental Health, Mental Health Parity, Military Leave, Payroll Tax, Prescription Drugs, Privacy, Protected Health Information, Public Policy, Risk Management, Stimulus Bill, Tax, Uncategorized, Wellness | Tagged: Affordable Care Act, dependent coverage, Employer, Health Care Reform, Health Plans, Insurer, Mental Health Parity, preexisting condition |
Permalink
Posted by Cynthia Marcotte Stamer
March 13, 2010
Curran Tomko Tarski LLP Labor & Employment Practice Chair and Solutions Law Press Publisher Cynthia Marcotte Stamer will discuss “TPA & Other Plan Services Agreements- Managing Risks & Improving Effectiveness” At 2010 Great Lakes Benefits Conference to be held at the Wyndham Chicago Hotel on June 16-17, 2010.
Growing regulatory, fiduciary and other compliance risks magnify the importance of the careful negotiation and documentation of third party administration and other plan-related service agreements for plans, plan sponsors, plan fiduciaries and service providers. Careful credentialing, negotiation and documentation of administrative and other services relationships plays an increasingly key role in the ability of plan sponsors, plans, fiduciaries and service providers to allocate and efficiently manage plan operations, meet compliance obligations, and allocate and manage fiduciary and other legal risks.
Ms. Stamer’s workshop will examine key concerns like how administrative services contract terms, plan terms, the parties of actions and other factors help determine which parties are exposed to fiduciary and other liabilities; who is responsible for fiduciary, administrative, reporting and disclosure, bonding, indemnification and other responsibilities; and terms and processes that may help parties manage their relationships and legal risks by exploring some of the common issues and concerns that need to be considered when entering into these contractual arrangements.
Co-hosted by the Internal Revenue Service and ASPPA, this two day Conference features presentations on regulatory, legislative, administrative and actuarial and other employee benefit issues lead by local, regional and national government representatives from the Internal Revenue Service and the Department of Labor and nationally recognized employee benefit leaders from private industry. To register for the Conference or for additional information, see here.
Chair of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice and former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer is nationally recognized for more than 22 years domestic work with employer and other plan sponsors, fiduciaries, administrative and other service providers, insurers, and other clients on employee benefit program and product design, documentation, administration, compliance, risk management, and public policy matters. The publisher of Solutions Law Press, Ms. Stamer also publishes, conducts training and speaks extensively on these and related concerns. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
If you need assistance with vendor or other outsourcing contracts, or other employee benefits, employment, compensation or other management concerns, wish to inquire about compliance, risk management or training, or need legal representation on other matters please contact Cynthia Marcotte Stamer, CTT Labor & Employment Practice Chair at cstamer@cttlegal.com, 214.270.2402; or your other preferred Curran Tomko Tarski LLP attorney.
If you found this information of interest, you also may be interested in reviewing other updates and publications by Ms. Stamer including:
- Extension of Unemployment Benefits Signed Into Law & Immediately Effective As Filibuster Ends
- COBRA Premium Subsidy Requirements Expanded & Extended Under Newly Signed Unemployment Extension Legislation
- Employers Concerned About New Union Powers As NLRB Orders Union Elections In 31 California Health Care Facilities To Proceed
- Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates
- Stamer To Present “2010 Health Plan Checkup” At Annual DFW ISCEBS Employee Benefits Fundamentals Workshop
- SouthWest Benefits e-Connections Highlights Stamer Article About Importance For Health Plans, Their Sponsors & Business Associates To Update HIPAA Policies, Practices & Agreements
- Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates
- Employers, Group Health Plans Subject To New CHIP/Medicaid Notice, Coordination of Benefits & Special Enrollment Requirements
- Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes
- St. Louis Employer’s OSHA Violations Trigger Contempt Order and Penalties
- Labor Department Final H-2A Certification Procedures Tighten Requirements For Employment Of Temporary Agricultural Employment Of Workers
- COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations
- Inapplicability of HIPAA Privacy To Disability Insurer Not License To Impose Unreasonable Claims Requirements
- New Mental Health Parity Regulations Require Health Plan Review & Updates
- Health Plans & Employers Can Expect Pressure To Pay For Childhood Obesity Counseling From New American Academy of Pediatrics Report
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here and learn more about other Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press distributions here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Stamer To Speak About TPA & Other Plan Services Agreement Contracting Strategies For Managing Risks & Improving Effectiveness At 2010 Great Lakes Benefits Conference |
CHIP, COBRA, Corporate Compliance, Defined Benefit Plans, Disability Plans, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, FMLA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Malpractice, Medicare Part D, Mental Health, Mental Health Parity, Preemption, Prescription Drugs, Privacy, Professional Liability, Reporting & Disclosure, Retirement Plans, Risk Management, Tax, Wellness Programs | Tagged: administrative services agreement, bonding, compliance, ERISA, Fiduciary Responsibility, Health Plans, Insurance, Retirement Plans, Risk Management, tpa, trustees |
Permalink
Posted by Cynthia Marcotte Stamer
February 23, 2010
By Cynthia Marcotte Stamer
The Department of Health and Human Services Office of Civil Rights (OCR) has begun disclosing on its website the employer and other health plans, health care providers, health care clearinghouses and their business associates (Covered Entities) that report breaches of unsecured protected health information (UPIC) affecting more than 500 individuals as required by new rules enacted as part of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). This posting of Covered Entities reporting breaches comes just days after these and other Covered Entities became subject on February 17, 2010 to a host of other tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA) also enacted as part of the HITECH Act. As failing to comply with the amended rules effective February 17, 2010 can trigger obligations under the Breach Regulations and other exposures, prompt action to manage risk under both the Breach Regulations and the revised HIPAA rules is critical to minimize Covered Entity and business associate exposures under both these rules. With criminal, administrative and civil prosecutions of such violations increasing and likely to expand, timely action to manage compliance and other risks is warranted. Health plans and their business associates also should prepare for increased awareness and oversight of the adequacy of their medical information safeguards as these disclosures and other enforcement actions heighten interest and awareness of employees and others in these rules.
Covered Entity Breach Notification Requirements
OCR posted the initial list of Covered Entities disclosing these breaches on its website for the first time yesterday (February 22, 2010) to comply with breach notification requirements imposed by Section 164.408 of the interim “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here.
The Breach Regulation requires Covered Entities subject to the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals, OCR and certain other parties following a “breach” of “unsecured” protected health information occurring on or after September 23, 2009. The Breach Regulation implements new breach notification requirements added to HIPAA by Section 13402(e)(3) of the Health Information Technology for Economic and Clinical Health Act (HITECH Act). It and the posting of Covered Entities reporting breaches of protected health information are part of the ongoing implementation and enforcement of new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under provisions of the HITECH Act and expanded remedies for violations signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).
You can review the list of Covered Entities that have reported breaches on the OCR website here. Learn more about the Breach Regulation requirements here.
Broader & Stricter Medical Privacy Mandates Effective 2/17/210
Just last Wednesday (February 17, 2010) Covered Entities and their business associates also became subject to tighter federal requirements for the use, access, protection and disclosure of protected health information under amendments to HIPAA’s Privacy & Security Standards enacted by the HITECH Act. The changes that became effective on February 17, 2010 generally require that Covered Entities and their business associates make specific changes to update their written policies, operational procedures, privacy notices, business associate agreements, training, and other management procedures in several respects. For more details, see here.
While the HITECH Act gave Covered Entities and business associates a year to complete the necessary arrangements to comply with these HITECH Act changes, many Covered Entities and business associates have remain unnecessarily exposed under these new requirements by not completing or otherwise failing to adequately implement the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, Covered Entities and their business associates should act quickly to review and update their policies, procedures, training, business associate and other services agreements, and other practices and procedures, as well as to implement the training, oversight, and other management necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.
Exposures Significant & Growing
Covered Entities and business associates failing to devote adequate attention and resources to managing HIPAA compliance and associated risks risk increasing peril. Aside from the potential implications that disclosures of violations may have on patients and others impacting their business, the legal risks of noncompliance for Covered Entities, business associates and others mishandling protected health information are real and growing.
Timely action to comply with the amended HIPAA requirements and Breach Regulations is important both to preserve critical trust in the business, to avoid triggering breach notifications that can undermine this trust and fuel legal complaints, and to avoid exposure to an expanding range of sanctions that can result when a violation occurs.
Amendments made under the HITECH Act have expanded the size and availability of remedies that can be imposed for HIPAA violations as well as the parties empowered to pursue these remedies. Wrongful use, access or disclosure of protected health information in violation of HIPAA subjects participating health plans, health care providers, health care clearinghouses, their business associates and other workforce members and others to civil penalties, criminal prosecution and, since February 17, 2009, civil lawsuits brought by state attorneys general on behalf of citizens of their states whose HIPAA rights were violated. Since September 23, 2009, health plans and other HIPAA Covered Entities as well as their business associates also became obligated to provide breach notification under new mandates imposed by the HITECH Act. Coupled with increased enforcement emphasis by regulators, these expansions to HIPAA’s remedy provisions increase the risk that Covered Entities or business associates violating HIPAA face investigation and sanction. Furthermore, the wrongful use, access or disclosure of protected health information or other confidential information also increasingly is the basis of civil or criminal actions brought under a variety of other federal and state laws.
Expanded HIPAA & Other Federal Prosecutions & Remedies
The expanded requirements imposed under the Breach Regulation and the other HITECH Act changes that took effect on February 17, 2010 follow the implementation changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, when President Obama signed the HITECH Act into law. The HITECH Act amendments to HIPAA’s remedies significantly increase the risk that health plans and other Covered Entities and their business associates will face civil lawsuits, civil or criminal penalties or other consequences for violating HIPAA. Noncompliance with these and other HIPAA requirements subjects Covered Entities and business associates to civil penalties, criminal prosecution, civil damage awards under lawsuits brought by state attorneys general, and other legal remedies. In addition, timely update written policies, procedures, business associate agreements, training and documentation is imperative in order for Covered Entities and their business associates to fulfill their breach notification obligations under new rules enacted as part of the HITECH Act.
HITECH Amendments Expand Liability Exposures
The expanded risks stem in part from the HITECH Act’s amendments to HIPAA’s remedy provisions. Among other things, the HITECH Act amended HIPAA to:
- Allow a State Attorney General to sue health plans or other Covered Entities, business associates or both that harm state citizens by committing HIPAA violations after February 16, 2009;
- Expand the mandate by OCR to investigate violations and audit compliance with HIPAA;
- Require Office of Civil Rights to impose civil sanctions against Covered Entities and business associates involved in violations of HIPAA in accordance with tightened standards added to HIPAA by the HITECH Act;
- Revise the criminal sanctions that the Department of Justice can seek against Covered Entities, their business associates and others for violations of HIPAA; and
- Amend HIPAA to make clear that HIPAA’s criminal sanctions also can imposed on business associates, workforce members and other persons that improperly use, access and disclose protected health information in violation of HIPAA.
State Attorney General Lawsuit Exposures
Covered Entities and their business associates now also need to be concerned about the potential that a state Attorney General may bring civil suit to remedy damages caused to state citizens by a breach of HIPAA.
The HITECH Act empowers a state attorney general to sue Covered Entities or business associates engaging in HIPAA violations that harms citizens of the state for statutory damages equal to the sum of the number of violations multiplied by 100 up to a maximum of $25,000 per calendar year plus attorneys fees and costs
A HIPAA civil lawsuit filed on January 13, 2010 demonstrates the willingness of at least some states to exercise the new authority created by the HITECH Act on February 17, 2009 to sue Covered Entities and business associates that violate HIPAA for civil damages.
On January 13, 2010 Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. (Health Net) for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers endangered by the security breach. The suit also names UnitedHealth Group Inc. and Oxford Health Plans LLC, who have acquired Health Net. The first attorney general enforcement action brought based on amendments made to HIPAA under the HITECH Act, Connecticut charges that Health Net violated HIPAA by failing to safeguard protected medical records and financial information on almost a half million Health Net enrollees in Connecticut then allowing this information to remain exposed for at least six months before notifying authorities and consumers.
Stepped Up Federal Enforcement
Even before the HITECH Act amendments, however, OCR and Department of Justice already were stepping up HIPAA investigation and enforcement. The Department of Justice has obtained a variety of criminal convictions against violators of HIPAA. See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health Information. Meanwhile, OCR also is emphasizing HIPAA enforcement. In February, 2009, for instance, OCR announced that CVS Pharmacies, Inc. would pay $2.25 million to resolve HIPAA charges. This announcement followed OCR’s announcement in July, 2008 that Providence Health Care would pay $100,000 to resolve HIPAA violation charges. OCR also has taken HIPAA enforcement actions against a broad range of other Covered Entities to redress HIPAA violations or other compliance concerns. To review examples of these other actions, see here. While not resulting in the significant payments involved in CVS or Providence, all Covered Entities involved in these and other enforcement actions or investigations have incurred significant legal and other defense costs, loss of community trust, or both.
In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can give rise to liability for health plans and other Covered Entities, business associates, employees and other members of their workforce and others improperly using, accessing or disclosing protected health information. Federal and state prosecutions may and increasingly do criminally prosecute individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws . See e.g., Cybercrime & Identity Theft: Health Information Security Beyond HIPAA; NY AG Cuomo Announcement of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A Year. Additionally, State courts also increasingly are permitting individuals harmed by HIPAA violations to use HIPAA as the foundation of state law duties used to maintain state negligence, invasion of privacy, retaliation or other claims for damages. Read more here.
State Civil Lawsuits
Along side these governmental actions, state courts also increasingly are willing to allow individual plaintiffs to rely on violations of HIPAA as the basis for bringing state privacy, retaliation or other actions. While prior to the recent HITECH Act amendments, federal courts had ruled that private plaintiffs could not sue under HIPAA for damages they incurred from a Covered Entity’s violation of HIPAA, state courts have allowed private plaintiffs to use the obligations imposed by HIPAA as the basis of a Covered Entity’s duty for purposes of certain state law lawsuits. In Sorensen v. Barbuto, 143 P.3d 295 (Utah Ct. App. 2006), for example, a Utah appeals court ruled a private plaintiff could use HIPAA standards to establish that a physician owed a duty of confidentiality to his patients for purposes of maintaining a state law damages claim. Similarly, the Court in Acosta v. Byrum, 638 S.E. 2d 246 (N.C. Ct. App. 2006) ruled that a plaintiff could use HIPAA to establish the “standard of care” in a negligence lawsuit.
Meanwhile, disgruntled employees or other business partners also increasingly raise alleged HIPAA misconduct as a basis of their legal complaints. For instance, private plaintiffs employed by Covered Entities also are increasingly pointing to HIPAA as the basis for their retaliation or wrongful discharge claims. See, e.g., Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim. Coupled with the HITECH Act changes, these and other enforcement actions signal growing potential hazards for Covered Entities and their business associates that fail to properly manage their HIPAA compliance obligations and risks.
Given these and other developments, Covered Entities and their business associates generally should resist the temptation to underestimate their potential HIPAA exposure for a variety of reasons. In fact, a number of factors demonstrate that the risks are significant and growing for Covered Entities, business associates and others that breach HIPAA’s mandates or otherwise inappropriately access protected health information.
Covered Entities & Business Associates Urged To Act Promptly To Manage Expanded HIPAA Risks & Obligations
As a consequence of these collective HITECH Act changes and growing HIPAA-related and other exposures, Covered Entities, their business associates and business associates generally will find it necessary or advisable among other things to:
- Conduct well-documented due diligence within the scope of attorney-client privilege on their own practices and procedures;
- Review the adequacy of the practices, policies and procedures of the Covered Entities, business associates, and others that may come into contact with protected health information;;
- Renegotiate their service provider agreements to detail the specific compliance obligations of each party relating to for auditing compliance, investigating potential breaches; providing required breach notifications; specify leadership and required cooperation in the event of a breach, charge, or other concern; indemnification and other liability allocations; and other related matters;
- Update policies, privacy and other notices, practices, procedures, training and other practices as needed to promote compliance and defensibility;
- Conduct well-documented training as necessary to ensure that business associates and other members of the Covered Entity’s workforce understand and are prepared to comply with the expanded requirements of HIPAA, can detect potential breaches or other compliance concerns, and understand and are prepared to follow appropriate procedures for reported suspected violations; and
- Pursue appropriate liability and other protection as appropriate to improve their ability to demonstrate both their commitment to compliance and their realistic efforts to ensure that these commitments are both appropriately documented on paper and operationalized in performance.
As part of these compliance and risk management efforts, most Covered Entities and their business associates will find it advisable to devote significant attention to the business associate relationship and its associated business associate agreements. Proper management of the expanded compliance obligations and liability exposures created by the HITECH Act generally will necessitate that Covered Entities and their business associates focus significant attention on the reworking of their operating and contractual relationships including the definition of detailed procedures for monitoring, reporting, investigating, and resolving potential breaches or other compliance concerns.
Even before the impending HIPAA changes scheduled to take effect on February 17, 2010, a strong need for more detailed contracting and planning of these relationships already existed. Since the enactment of HIPAA, the practice of many Covered Entities and their business associates of appending generic “business associate” representations onto existing services contracts without specific tailoring and planning has created undesirable ambiguities in these agreements. Further updating and tailoring of these and other provisions of services agreements has become even more important over the past year in light of the new breach notification mandates that took effect under the HITECH Act in September, 2009, changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, and the impending extension by the HITECH Act to business associates of direct liability for compliance with HIPAA scheduled to occur on February 17, 2010.
These and other stepped up oversight and enforcement activities make it critical that all Covered Entities and their business associates update their policies and practices, conduct training, tighten their compliance and data breach monitoring processes, strengthen their internal controls and documentation, and take other steps to prepare to defend their actions under the newly strengthened Privacy Rules. Covered Entities and their business associates more than ever must ensure their ability to demonstrate to federal regulators the effectiveness of their HIPAA compliance efforts by both adopting the written policies and procedures required by HIPAA and continuously monitoring and administering these safeguards. Covered Entities should consider reviewing the adequacy of their current HIPAA Privacy and Security compliance practices taking into consideration the Corrective Action Plan, published OCR noncompliance and enforcement statistics, their own and reports of other security and privacy breaches and near misses, and other developments to determine if additional steps are necessary or advisable.
For Assistance With Compliance Or Other Concerns
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting the author of this article, Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer at (214) 270-2402 or via e-mail here.
Ms. Stamer is nationally known for her work, training and presentations, and publications on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts.
Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 22 years experience advising clients about health and other privacy and security matters. A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters. Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications. For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.
Other Recent Developments
If you found this information of interest, you also may be interested in information about upcoming programs to be presented by Ms. Stamer, acquiring a copy of a recording or materials from previous programs she has presented, or arranging training for your organization. For more information about these opportunities, contact Ms. Stamer directly.
If you found this information of interest, you also may be interested in reviewing some of the following recent Updates available online by clicking on the article title:
Curran Tomko Tarski LLP Can Help
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.
A widely published author and speaker on HIPAA and other employee benefit and human resources related matters, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates that may be of interest include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Privacy Rule Changes & Posting of Breach Notices On OCR Website Signal New Enforcement Risks For Health Plans, Their Sponsors & Business Associates |
Corporate Compliance, Data Security, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Privacy, Risk Management, Wellness Programs | Tagged: Corporate Compliance, Employee Benefits, Employer, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Medical Coverage, Privacy, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
February 17, 2010
Today (February 17, 2010), employer and other health plans and health insurers (“covered entities”) and service providers performing functions on behalf of these entities (“business associates”) must begin complying with tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). Coming as U.S. employers continue to struggle to provide health benefits in the face of skyrocketing health benefit costs, these and other new federal regulations impacting employment-based health plans and their sponsoring businesses, fiduciaries and administrators are forcing U.S. business leaders to make appropriate health plan cost and compliance management a key management priority.
2/17/10 & Other HIPAA Privacy Rule Changes Require Prompt Attention
The HIPAA Privacy Rule changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects.
While the HITECH Act gave covered entities and business associates a year to complete the necessary arrangements to comply with these impending HITECH Act changes, many health plans and business associates have not completed the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, covered entities and their business associates should act quickly both to update their services agreements, plans and policies, practices, and procedures, and to implement the training, oversight, and other management procedures necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.
The risks of noncompliance for health plans, business associates and others mishandling protected health information are real and growing. Wrongful use, access or disclosure of protected health information in violation of HIPAA subjects participating health plans, health care providers, health care clearinghouses, their business associates and other workforce members and others to civil penalties, criminal prosecution and, since February 17, 2009, civil lawsuits brought by state attorneys general on behalf of citizens of their states whose HIPAA rights were violated. Since September 23, 2009, health plans and other HIPAA covered entities as well as their business associates also became obligated to provide breach notification under new mandates imposed by the HITECH Act.
In addition to these HIPAA-specific exposures, wrongful use, access or disclosure of medical information also can give rise to liability for health plans and other covered entities, business associates, employees and other members of their workforce and others improperly using, accessing or disclosing protected health information. Federal and state prosecutions may and increasingly do criminally prosecute individuals for improperly accessing or using medical or other personal information under a variety of other federal or state laws . See e.g., Cybercrime & Identity Theft:Health Information Security Beyond HIPAA; NY AG Cuomo Annoucment of 1st Settlement For Violation of NY Security Breach Notification Law; Woman Who Revealed AIDs Info Gets A Year. Additionally, State courts also increasingly are permitting individuals harmed by HIPAA violations to use HIPAA as the foundation of state law duties used to maintain state negligence, invasion of privacy, retaliation or other claims for damages. Read more here.
To manage these and other HIPAA-related risks, sponsoring employers, fiduciaries, administrators, insurers and their vendors should begin with carefully and timely reviewing and updating existing plan documents, vendor agreements, privacy notices and other communications and associated practices and policies. The focus of these efforts definitely should seek both to adopt the specific technical changes necessary to make the health plans and their contracts technically comply on paper with these and other HIPAA mandates, and to tailor these documents, communications and practices promote operational compliance and minimize exposure to associated risks. In relation to these efforts, sponsoring employers, insurers, fiduciaries and administrators also should ensure that required certifications from employers and other plan sponsors, representations from business associates, training and other compliance conditions are properly in place. In this respect, employers sponsoring health plans should not overlook the potential need to adopt appropriate policies and implement needed training and safeguards to enable the health plan and the employer demonstrate, if necessary that HIPAA’s requirements for sharing protected health information with members of the employer’s workforce for plan administration, underwriting or certain other purposes have been satisfied.
Other Health Plan Updates Also Required
The HIPAA Privacy Rule changes effective today are only part of the ever-growing list of federal mandates that group health plan sponsors, fiduciaries, insurers, administrators and service providers need to be concerned about. In addition to the new HIPAA Privacy Rule requirements taking effect today, health plans, their sponsors, administrators, fiduciaries, insurers, business associates and other service providers face a host of other new federal health plan and privacy mandates that have taken effect over the past year, and will become subject to additional mandates in upcoming months. Consequently, while focusing on HIPAA compliance, health plans, their employer or other sponsors, insurers, fiduciaries, administrators and service providers also should not overlook the need to review and update their health plans in response to a host of other changes in federal health plan mandates.
In addition to otherwise applicable civil damage awards and civil penalty exposures that can result from violations of these requirements, new Internal Revenue Service regulations that took effect January 1, 2010 also require that employers, health plans or others self-report violations of certain of these requirements and self assess and pay resulting excise taxes arising under the Internal Revenue Code. See, e.g., COBRA, HIPAA, GINA, Mental Health Parity or Other Group Health Plan Rule Violations Trigger New Excise Tax Self-Assessment & Reporting Obligations.
The highly volatile health plan regulatory environment makes it likely that many health plans are not appropriately updated to comply with these and other federal requirements. In recent months, health plans, their employer or other sponsors, administrators and others also have become obligated to comply with a host of other expanded federal health plan rules and requirements. See e.g., New Mental Health Parity Regulations Require Health Plan Review & Updates; New Labor Department Rule Allows Employers 7 Days To Deliver Employee Contributions To Employee Benefit Plans; Newly Extended COBRA Subsidy Rules Require Employers, Administrators Send Required Notices & Update Health Plan Documents & Procedures Quickly; Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23.
These and other developments make it imperative that health plans, their employer or other sponsors, administrators, insurers, fiduciaries and service providers get serious about complying with these and other federal health plan mandates and managing health plan related liabilities and costs. Sponsors, insurers, fiduciaries and administrators should ensure that health plan documents, insurance and other vendor contracts, policies, procedures and communications are timely updated to comply with these and other emerging mandates. When implementing these updates, parties concerned about costs or liabilities also should exercise care to ensure that plan documents, communications, contracts, administrative forms and procedures are optimally designed and drafted not only to be technically compliant, but also to support the enforceability of plan design and cost expectations, minimize administrative and other avoidable costs, and minimize liability exposures. In furtherance of these efforts, employer and other plan sponsors also should consider tightening their practices and requirements for credentialing, selection, oversight and contracting with administrators and vendors, and take other prudent steps to manage health plan related risks.
Curran Tomko Tarski LLP Can Help
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.
A widely published author and speaker on HIPAA and other employee benefit and human resources related matters, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates that may be of interest include:
For important information concerning this communication click here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Health Plan Liability Heats Up As Plans & Businesses Face New Obligations, Costs & Exposures under New HIPAA Privacy Rules Effective 2/17 & Other Expanding Federal Health Plan Mandates |
COBRA, Corporate Compliance, Data Security, ERISA, Fiduciary Responsibility, FMLA, GINA, Health Care Reform, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Prescription Drugs, Privacy, Wellness Programs | Tagged: Corporate Compliance, Employer, Health Plans, HIPAA, internal control, Mental Heatlh Parity, Privacy, Privacy Standards, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
February 15, 2010
Connecticut AG Lawsuit Highlights Expanding Civil Damage Exposure Risks Of Noncompliance
By Cynthia Marcotte Stamer
By Wednesday, February 17, 2010, employer and other health plans and health insurers (“covered entities”) and service providers performing functions on behalf of these entities (“business associates”) must begin complying with tighter federal requirements for the use, access, protection and disclosure of protected health information under Privacy & Security Standards of the Health Insurance Portability & Accountability Act (HIPAA), as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH Act). The changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects.
While the HITECH Act gave covered entities and business associates a year to complete the necessary arrangements to comply with these impending HITECH Act changes, many health plans and business associates have not completed the necessary arrangements despite expanding liability exposures that can result from noncompliance. To mitigate these exposures, covered entities and their business associates should act quickly both to update their services agreements, plans and policies, practices, and procedures, and to implement the training, oversight, and other management procedures necessary to comply with the HITECH Act changes and to mitigate other HIPAA risks.
2/17/10 Deadline To Comply With HITECH Act HIPAA Amendments
On February 17, 2010, health plans and other covered entities and their business associates will become subject to the latest to take effect in a series of amendments to the HIPAA enacted under the HITEC Act. The new rules are part of a broader series of changes to HIPAA made by the HITECH Act that collectively both significantly expand the obligations of covered entities and their business associates to regarding the use, protection and disclosure of protected health information and the liability exposures that can result when covered entities or business associates violate these requirements.
The changes scheduled to take effect February 17, 2010 are likely to require that health plans and their business associates update their written policies, operational procedures, privacy notices and business associate agreements in several respects. For instance, effective February 17, 2010, the HITECH Act generally requires that covered entities and their business associates revise their written privacy policies, privacy notices and operating procedures:
- To meet expanded requirements to honor individual’s requests for special restrictions on uses and disclosures of protected health information to health plans for payment purposes
- To restrict protected health information disclosures to the minimum necessary required to accomplish otherwise allowable purpose;
- To comply with new rules that require that the covered entity and its business associates treat any use, access or disclosure of any protected health information made for purposes of making communications about products or services as made for marketing, rather than operational, purposes which are prohibited by HIPAA except where HIPAA’s requirements are met;
- To comply with new restrictions on certain fundraising communications made for operational purposes including expanded obligations to allow recipients to opt out of further fundraising communications;
- To prohibit covered entities or business associates from selling protected health information without meeting the amended requirements of HIPAA that a valid HIPAA authorization from the subject of the information and specific reassurances from the purchaser concerning its subsequent use of the protected health information except as otherwise permitted by HIPAA;
- To take into account these tightened restrictions on the use, access or disclosure of protected health information for purposes of complying with new HITECH Act breach notification requirements that took effect in September, 2009, which apply when a covered entity or its business associate knows or should know a breach of “unsecured protected health information” has occurred and for purposes of making the necessary changes in written policies and business associate agreements, training and operational procedures necessary to comply with these rules;
- To directly require business associates comply with HIPAA’s requirements in the same manner as other covered entities and make it necessary or advisable that that service provider agreements between health plans and business associates be updated to reflect these and other changes to HIPAA; and
- To implement the necessary written policy changes, notification updates, business associate agreement amendments, training, management oversight and other procedural changes necessary to demonstrate fulfillment with these requirements.
Noncompliance with these and other HIPAA requirements subjects covered entities and business associates to civil penalties, criminal prosecution, civil damage awards under lawsuits brought by state attorneys general, and other legal remedies. In addition, timely update written policies, procedures, business associate agreements, training and documentation is imperative in order for covered entities and their business associates to fulfill their breach notification obligations under new rules enacted as part of the HITECH Act.
Under the HITECH Act, health plans and other covered entities and their business associates have been obligated since September 23, 2009 to notify individuals who are the subject of protected health information, the Department of Health & Human Services and in some cases the media if and when a breach of “unsecured protected health information occurs. Failing to timely update written policies, procedures and training increases the likelihood that health plans, other covered entities or business associates will be obligated to provide breach notifications under these new rules, in addition to their otherwise applicable exposures under HIPAA.
HIPAA Enforcement & Liability Exposures Real and Rising
Health plans and other covered entities, their business associates and others involved in health plan design and operations generally should resist the temptation to underestimate their potential HIPAA exposure based on the limited enforcement of HIPAA by the Office of Civil Rights between 2003 and 2009 for a variety of reasons.
First, the changes taking effect on February 17, 2010 follow the implementation changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, when President Obama signed the HITECH Act into law and the new breach notification requirements added by the HITECH Act that took effect on September 23, 2009. The HITECH Act amendments to HIPAA’s remedies significantly increase the risk that health plans and other covered entities and their business associates will face civil lawsuits, civil or criminal penalties or other consequences for violating HIPAA.
The expanded risks stem in part from the HITECH Act’s amendments to HIPAA’s remedy provisions. Among other things, the HITECH Act amended HIPAA to:
- Allow a State Attorney General to sue health plans or other covered entities, business associates or both that harm state citizens by committing HIPAA violations after February 16, 2009;
- Expand the mandate by the Office of Civil Rights to investigate violations and audit compliance with HIPAA;
- Require Office of Civil Rights to impose civil sanctions against health plans and other covered entities and their business associates involved in violations of HIPAA in accordance with tightened standards added to HIPAA by the HITECH Act;
- Revise the criminal sanctions that the Department of Justice can seek against health plans and other covered entities, their business associates and others for violations of HIPAA;
- Amend HIPAA to make clear that HIPAA’s criminal sanctions also can imposed on business associates, workforce members and other persons that improperly use, access and disclose protected health information in violation of HIPAA.
A HIPAA civil lawsuit filed on January 13, 2010 demonstrates the willingness of at least some states to exercise the new authority created by the HITECH Act on February 17, 2009 to sue covered entities and business associates that violate HIPAA for civil damages.
The HITECH Act empowers a state attorney general to sue covered entities or business associates engaging in HIPAA violations that harms citizens of the state for statutory damages equal to the sum of the number of violations multiplied by 100 up to a maximum of $25,000 per calendar year plus attorneys fees and costs
On January 13, 2010 Connecticut Attorney General Richard Blumenthal sued Health Net of Connecticut, Inc. (Health Net) for failing to secure private patient medical records and financial information involving 446,000 Connecticut enrollees and promptly notify consumers endangered by the security breach. The suit also names UnitedHealth Group Inc. and Oxford Health Plans LLC, who have acquired Health Net. The first attorney general enforcement action brought based on amendments made to HIPAA under the HITECH Act, Connecticut charges that Health Net violated HIPAA by failing to safeguard protected medical records and financial information on almost a half million Health Net enrollees in Connecticut then allowing this information to remain exposed for at least six months before notifying authorities and consumers.
Even before the HITECH Act amendments, however, the Office of Civil Rights and Department of Justice already were stepping up HIPAA investigation and enforcement. The Department of Justice has obtained a variety of criminal convictions against violators of HIPAA. See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health Information. Meanwhile, the Office of Civil Rights in February, 2009 announced that CVS Pharmacies, Inc. would pay $2.25 million to resolve HIPAA charges. This announcement followed the Office of Civil Rights announcement in July, 2008 that Providence Health Care would pay $100,000 to resolve HIPAA violation charges. While not resulting in the significant payments involved in CVS or Providence, the Office of Civil Rights also taken HIPAA enforcement actions against a broad range of other covered entities to redress HIPAA violations or other compliance concerns. To review examples of these other actions, see here.
Along side these governmental actions, state courts also increasingly are willing to allow individual plaintiffs to rely on violations of HIPAA as the basis for bringing state privacy, retaliation or other actions. While prior to the recent HITECH Act amendments, federal courts had ruled that private plaintiffs could not sue under HIPAA for damages they incurred from a covered entity’s violation of HIPAA, state courts have allowed private plaintiff’s to use the obligations imposed by HIPAA as the basis of a covered entity’s duty for purposes of certain state law lawsuits. In Sorensen v. Barbuto, 143 P.3d 295 (Utah Ct. App. 2006), for example, a Utah appeals court ruled a private plaintiff could use HIPAA standards to establish that a physician owed a duty of confidentiality to his patients for purposes of maintaining a state law damages claim. Similarly, the Court in Acosta v. Byrum, 638 S.E. 2d 246 (N.C. Ct. App. 2006) ruled that a plaintiff could use HIPAA to establish the “standard of care” in a negligence lawsuit. Meanwhile, private plaintiffs employed by covered entities also are increasingly pointing to HIPAA as the basis for their retaliation claims. See, e.g., Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim. Coupled with the HITECH Act changes, these and other enforcement actions signal growing potential hazards for covered entities and their business associates that fail to properly manage their HIPAA compliance obligations and risks.
Health Plans & Business Associates Should Take Timely Action To Comply & Manage Risks
As a consequence of these collective HITECH Act changes and growing HIPAA-related exposures, both health plans and business associates generally will find it necessary or advisable among other things to:
- Conduct well-documented due diligence on each other’s practices and procedures to improve their ability to demonstrate both their commitment to compliance and their realistic efforts to ensure that these commitments are operationalized in performance;
- Renegotiate their service provider agreements to detail the specific compliance obligations of each party relating to for auditing compliance, investigating potential breaches; providing required breach notifications; specify leadership and required cooperation in the event of a breach, charge, or other concern; indemnification and other liability allocations; and other related matters; and
- Pursue appropriate liability and other protection as appropriate.
As part of these compliance and risk management efforts, most covered entities and their business associates will find it advisable to devote significant attention to the business associate relationship and its associated business associate agreements.
Proper management of the expanded compliance obligations and liability exposures created by the HITECH Act generally will necessitate that health plans and other covered entities and their business associates focus significant attention on the reworking of their operating and contractual relationships.
Even before the impending HIPAA changes scheduled to take effect on February 17, 2010, a strong need for more detailed contracting and planning of these relationships already existed. Since the enactment of HIPAA, the practice of many covered entities and their business associates of appending generic “business associate” representations onto existing services contracts without specific tailoring and planning has created undesirable ambiguities in these agreements.
Further updating and tailoring of these and other provisions of services agreements has become even more important over the past year in light of the new breach notification mandates that took effect under the HITECH Act in September, 2009, changes to HIPAA’s civil and criminal sanctions that took effect on February 17, 2009, and the impending extension by the HITECH Act to business associates of direct liability for compliance with HIPAA scheduled to occur on February 17, 2010.
Given these changes and the associated obligations and risks, both health plans and other covered entities and their business associates generally should act quickly to manage their own compliance and to minimize exposures that may result from the other’s compliance deficiencies. As part of these efforts, both covered entities and their business associates generally should review and tighten business associate and other service agreement provisions to provide for more specific and comprehensive HIPAA-related contractual assurances, as well as improved cooperation, coordination, management and oversight.
Curran Tomko Tarski LLP Can Help
If your organization need advice or assistance in reviewing, updating, administering or defending its HIPAA or other privacy policies, practices, business associate or other agreements, notices or other related activities, consider contacting Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer.
A widely published author and speaker on HIPAA and other related matter, Ms. Stamer has extensive experience advising health plans, their employer and other sponsors, health insurers, TPAs and other business associates and others about HIPAA and other health plan and privacy matters. Currently serving as both Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Group and as an ABA Joint Committee on Employee Benefits Council representative and Former Chair of the ABA Health Law Section Managed Care & Insurance Interest Group, Ms. Stamer has more than 23 years experience assisting employers, insurers, plan administrators and fiduciaries and others to design, implement, draft and administer health and other employee benefit plans and to defend audits, litigation or other disputes by private parties, the IRS, Department of Labor, Office of Civil Rights, Medicare, state insurance regulators and other federal and state regulators. As part of this work, she regularly assists clients to review and update policies, practices, contracts, notices and procedures to comply with HIPAA and other requirements. A nationally recognized author and lecturer, Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates that may be of interest include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2010 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Health Plans & Business Associates Face 2/17 Deadline To Update Policies, Contracts & Procedures For HIPAA Privacy Rule Changes |
ARRA, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Internal Investigations, Privacy, Protected Health Information, Risk Management, Stimulus Bill | Tagged: Breach Notice, Corporate Compliance, Data Breach, Employee Benefits, Employers, ERISA, GINA, Health Insurance, Health Plans, HIPAA, Human Resources, Insurance, Insurer, Internal Controls, Internal Investigations, Managed Care, Medical Coverage, PHI, Privacy, Privacy Rule, Risk Management, Security Rule |
Permalink
Posted by Cynthia Marcotte Stamer
December 28, 2009
Accountants and their clients face increasing regulatory and business pressures to protect the sensitive business and personal information collected and maintained in the course of their operation to minimize their exposure to personal identity theft and other cybercrime scams by employees, business partners and others. Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer will speak about “Privacy & Information Security: Managing Your Accounting Practice’s Liabilities & Counseling Your Clients” to members of the Dallas CPA Society on January 12, 2010 beginning at 2:00 p.m.
Part of the Dallas CPA Society Member Appreciation CPE Series Meeting, Ms. Stamer’s presentation will be part of four hours of free CPE training to be provided at a program open to members only at the Hilton Lincoln Centre Hotel located at 5410 LBJ Freeway, Dallas TX 75240 from 1 p.m. to 4:50 p.m. Central Time. (Parking at the facility costs $5.00). To register or for additional information, see here.
If you need help responding to these developments or other legislative, regulatory or enforcement concerns, Curran Tomko Tarski LLP can help. Curran Tomko and Tarski LLP and its attorneys have significant experience assisting businesses and business leaders to manage and defend privacy, data security, tax employee benefit, employment, health care, environmental, safety, securities and other compliance and risk management concerns.
Curran Tomko Tarksi LLP Partner Cynthia Marcotte Stamer has more than 22 years experience helping businesses to use the law, process and technology to manage people and processes, and to manage technology, privacy and data security, employment and other legal and operational risks affecting their businesses. Author of “Privacy & Securities Standards-A Brief Nutshell,” “Privacy Invasions of Medical Care-An Emerging Perspective,” and “E-Health Business and Transactional Law Other Liability-Tort and Regulatory;” published by The Bureau of National Affairs, Inc., and many other publications, Ms. Stamer has extensive experience advising a accounting firms, law firms, banks and financial services organizations, insurers, consultants, health plans, health care providers and others about HIPAA, FACTA, and other privacy, trade secret and other information security and data breach risk management and compliance concerns. Ms Stamer also speaks, publishes and provides public policy input extensively on data security, technology and other internal controls and risk management matters. Chair of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, and Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice, Ms. Stamer also is Board Certified in Labor & Employment law. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
If you need assistance with these or other compliance concerns, wish to inquire about federal or state regulatory compliance audits, risk management or training, assistance investigating or responding to a known or suspected compliance or risk management concern, or need legal representation on other matters please contact the author of this update, Cynthia Marcotte Stamer, CTT Labor & Employment Practice Chair at cstamer@cttlegal.com, 214.270.2402; or your other preferred Curran Tomko Tarski LLP attorney.
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here /the Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press HR & Benefits Update distributions here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Stamer Speaks To CPAs About “Privacy & Information Security: Managing Your Accounting Practice’s Liabilities & Counseling Your Clients” January 12, 2010 |
Corporate Compliance, Data Security, EEOC, Employee Benefits, Employers, ERISA, Fiduciary Responsibility, GINA, Health Plans, Human Resources, Internal Controls, Malpractice, Privacy, Professional Liability, Protected Health Information, Risk Management | Tagged: Acountant's Liability, Corporate Compliance, CPA, CPE, Employee Benefits, Employer, GINA, Health Insurance, Health Plans, Human Resources, Internal Controls, Medical Coverage, Privacy, Risk Management, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
December 25, 2009
Health plans and their business associates should review and update their practices and policies concerning the use access and disclosure of protected health information in response to changing requirements and expanding enforcement exposures under the Health Insurance Portability & Accountability Act of 1996 (HIPAA) Privacy and Security Rules.
A series of Office of Civil Rights (OCR) enforcement action against health plans highlights the need for group health plans and insurers to exercise care to comply with HIPAA’s Privacy & Security Rules. For example, OCR recently required a HMO to take a series of corrective actions based on findings from its investigation of a complaint that the HMO impermissibly disclosed a member’s protected health information by sending her entire medical record to a disability insurance company without her authorization. Based on its investigation, OCR found the HMO violated HIPAA by relying on a form to make the disclosure that failed to meet the Privacy Rule requirements to qualify as a valid authorization under the Privacy Rule. Based on these findings, OCR required the HMO among other things:
- To create a new HIPAA-compliant authorization form that specifies what records and/or portions of the files will be disclosed, that the respective authorization will be kept in the patient’s record, together with the disclosed information and otherwise to meet the content requirements of the Privacy Rule for an authorization; and
- To implement a new policy that directs staff to obtain patient signatures on these forms before responding to any disclosure requests, even if patients bring in their own “authorization” form.
Another action resulted after a national health maintenance organization sent explanation of benefits (EOB) by mail to a complainant’s unauthorized family member. OCR’s investigation determined that a flaw in the health plan’s computer system put the protected health information of approximately 2,000 families at risk of disclosure in violation of the Privacy Rule. To resolve this case, OCR required among other things that the insurer to correct the flaw in its computer system, review all transactions for a six month period and correct all corrupted patient information.
In yet another case, OCR found an employee of a major health insurer impermissibly disclosed the PHI of one of its members without following the insurer’s authorization and verification procedures. Among other corrective actions to resolve the specific issues in the case, OCR required the health insurer to train its staff on the applicable policies and procedures, to take action to mitigate the harm to the individual and to counsel and give a written warning to an employee who made the disclosure.
While OCR declined to impose any civil penalties in any of these three instances, violations of the Privacy Rules have resulted in both criminal prosecutions by the Department of Justice and the payment of large civil settlements to OCR. See, e.g., 2 New HIPAA Criminal Actions Highlight Risks From Wrongful Use/Access of Health Information HIPAA Risks Soar As CVS Agrees to Pay $2.25 Million To Resolve HIPAA Charges & Stimulus Bill Amends HIPAA. Furthermore, recent amendments to the Privacy Rules increase the likelihood that health plans and other covered entities violating the Privacy Rules will incur civil penalties. The American Recovery and Reinvestment Act of 2009 (ARRA) amended the Privacy Rules effective October, 2009 to increase the civil penalties for Privacy Rule violations and to include new breach notification requirements for covered entities. Additional ARRA amendments to HIPAA scheduled to take effect February 17, 2010 will further tighten the conditions under which covered entities may use, access or disclose PHI under the Privacy Rules, will expand the circumstances under which health plans and other covered entities will be required to account for dealings with PHI under HIPAA, and will extend the duty to comply with and liability for violations of the Privacy Rules to business associates. In the meanwhile, employees increasingly are alleging Privacy Rule violations as part of their whistleblower or other wrongful discharge claims. See, e.g. Retaliation For Filing HIPAA Complaint Recognized As Basis For State Retaliatory Discharge Claim.
In light of these changing rules and expanding liabilities, health plans and their business associates need to review and update their Privacy and Security practices, business associate agreements and privacy notices for compliance in light of the expanding enforcement activities of OCR and these evolving Privacy and Security Rules. These and other developments make it imperative that health plans and other covered entities and their business associates immediately review and update their HIPAA and other data security and privacy practices to guard against growing liability exposures under HIPAA and other federal and state laws.
If your organization needs assistance reviewing, updating, administering or defending privacy and data security practices under HIPAA, state data breach or other laws, Curran Tomko Tarski LLP can help. The author of this update, Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer has extensive experience advising and assisting health plans, health insurers, and other covered entities and business associates to review, update, document, enforce and defend their HIPAA and other privacy and data security policies and practices. The author of numerous publications on HIPAA and other privacy and data security rules, she also speaks and conducts training extensively on these concerns.
Ms. Stamer is experienced with assisting employers, insurers, administrators, and others to design and administer group health plans cost-effectively in accordance with HIPAA and other applicable federal regulations as well as well as advising and defending employers, health plans, insurers and others against privacy, tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the OCR, DOJ,IRS, Department of Labor and other federal and state regulators.. Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group, a representative to the ABA Joint Committee on Employee Benefits Council, past Chair of the ABA Health Law Section Managed Care & Insurance Interest Group and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, employee benefit and other personnel and staffing matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Some other recent updates that may be of interested include the following, which you can access by clicking on the article title:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Rising Enforcement and Changing Rules Require Prompt Review & Update of Health Plan Privacy & Data Security Policies & Procedures |
Corporate Compliance, Data Security, Employee Benefits, Employers, ERISA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Privacy, Protected Health Information, Risk Management | Tagged: ARRA, Health Plans, HIPAA, OCR, PHI, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
November 30, 2009
As the 2009 Holiday Season moves into full swing, your company may want to take some common sense precautions to minimize the risk of waking up with a post-Holiday Season business liability hangover. The music, food, game playing, toasting with alcohol and other aspects of the celebratory atmosphere at holiday parties and in the workplace during the Holiday Season heighten the risk that certain employees or other business associates will engage in, or be subject to, risky or other inappropriate behavior that can create liability exposures or other business concerns for your business.
Discrimination & Sexual Harassment
Whether company-sponsored or not, holiday parties and other celebrations where employees celebrate with other employees or clients tend to fuel bad behavior by inviting fraternization, lowering inhibitions and obscuring the line between appropriate and inappropriate social and business behavior.
The relaxation of the environment heightens the risk that certain employees or clients will make unwelcome sexual advances, make sexually suggestive or other inappropriate statements, or engage in other actions that expose the business to sexual harassment or other employment discrimination liability. To minimize these exposures, businesses should take steps to communicate and reinforce company policies and expectations about sexual harassment, discrimination, fraternization and other conduct viewed as inappropriate by the company. The company should caution employees that the company continues to expect employees and business partners to adhere to company rules against sexual harassment and other inappropriate discrimination at company sponsored and other gatherings involving other employees or business associates. To enhance the effectiveness of these reminders, a company should consider providing specific guidance about specific holiday-associated activities that create heightened risks. For instance, a business that anticipates its employees will participate in white elephant or other gift exchanges involving other employees or business associates may wish to specifically include a reminder to exercise care to avoid selecting a gift that may be sexually suggestive or otherwise offensive. Businesses also may want to remind employees that the company does not expect or require that employees submit to unwelcome sexual or other inappropriate harassment when participating in parties or other social engagements with customers or other business partners.
Businesses also should use care to manage other discrimination exposures in the planning of holiday festivities, gift exchanges, and other activities. Exercise care to ensure that business connected holiday parties, communications, gifts and other December festivities reflect appropriate sensitivity to religious diversity. Businesses also should be vigilant in watching for signs of inappropriate patterns of discrimination in the selection of employees invited to participate in company-connected social events as well as off-duty holiday gatherings sponsored by managers and supervisors.
Alcohol Consumption
The prevalence of alcohol consumption during the Holiday Season also can create a range of business concerns. Most businesses recognize that accidents caused by alcohol intoxication at work or work-related functions create substantial liability exposures both to workers and any third parties injured by a drunken employee. Businesses also may face “dram shop” claims from family members or other guests attending company sponsored functions injured or injure others after being allowed to over-imbibe. To minimize these risks at company-sponsored events, many companies elect not to serve or limit the alcohol served to guests at company sponsored events. To support the effectiveness of these efforts, many businesses also choose to prohibit or restrict the consumption of guest provided alcohol at company events.
Businesses concerned with these liability exposures should take steps to manage the potential risks that commonly arise when employees or clients consume alcohol at company sponsored events or while attending other business associated festivities. Businesses that elect to serve alcohol at company functions or anticipate that employees will attend other business functions where alcohol will be served need to consider the potential liability risks that may result if the alcohol impaired judgment of an employee or other guest causes him to injure himself or someone else. Any company that expects that an employee might consume alcohol at a company sponsored or other business associated event should communicate clearly its expectation that employees not over-imbibe and abstain from driving under the influence. Many businesses also find it beneficial to redistribute information about employee assistance programs (EAPs) along with this information. You can find other tips for planning workplace parties to minimize alcohol related risks on the U.S. Department of Labor’s website here.
When addressing business related alcohol consumption, many businesses will want to consider not only alcohol consumption at business related events as well as potential costs that may arise from off-duty excess alcohol consumption. Whether resulting from on or off duty consumption, businesses are likely to incur significant health and disability related benefit costs if an employee is injured in an alcohol-related accident. Furthermore, even when no injury results, productivity losses attributable to excess alcohol consumption, whether on or off duty, can prove expensive to business. Accordingly, virtually all businesses can benefit from encouraging employees to be responsible when consuming alcohol in both business and non-business functions.
Businesses also may want to review their existing health and other benefit programs, liability insurance coverage and employment policies to determine to ensure that they adequately protect and promote the company’s risk management objectives. Many health and disability plans incorporate special provisions affecting injuries arising from inappropriate alcohol use as well as mental health and alcohol and drug treatment programs. Similarly, many businesses increasingly qualify for special discounts on automobile and general liability policies based upon representations that the business has in effect certain alcohol and drug use policies. Businesses can experience unfortunate surprises if they don’t anticipate the implications of these provisions on their health benefit programs or liability insurance coverage. Reviewing these policies now to become familiar with any of these requirements and conditions also can be invaluable in helping a business to respond effectively if an employee or guest is injured in an alcohol-related accident during the Holiday Season.
Concerned employers may want to listen in on the “Plan Safe Office Parties this Holiday Season” seminar that the National Safety Council plans to host on December 9, 2009 from 10:30 a.m. -11:30 a.m. Central Time. For more information or to register call (800) 621-7619 or see here.
Gift Giving & Gratuities
The exchange of gifts during the Holiday Season also can raise various concerns. As a starting point, businesses generally need to confirm that any applicable tax implications arising from the giving or receiving of gifts are appropriately characterized and reported in accordance with applicable tax and other laws. Government contractors, health industry organizations, government officials and other entities also frequently may be required to comply with specific statutory, regulatory, contractual or ethical requirements affecting the giving or receiving of gifts or other preferences. In addition to these externally imposed legal mandates, many businesses also voluntarily have established conflict of interest, gift giving or other policies to minimize the risk that employee loyalty or judgment will be comprised by gifts offered or received from business partners or other outsiders. Businesses concerned about these and other issues may want to review the adequacy of current business policies affecting gifting and adopt and communicate any necessary refinements to these policies. To promote compliance, businesses also should consider communicating reminders about these policies to employees and business associates during the Holiday Season. Even a simple e-mail reminder to employees that the company expects them to be familiar with and comply with these policies can help promote compliance and provide helpful evidence in the event that an employee engages in an unauthorized violation of these rules.
Performance, Attendance & Time Off
Businesses also commonly face a range of attendance and productivity concerns during December. The winter cold and flu season and other post-celebration illnesses, vacations, and winter weather inevitably combine to fuel a rise in absenteeism in December. Managing staffing needs around the legitimate requests for excused time off by employees presents real challenges for many businesses. Further complications can arise when dealing with employees suspected of mischaracterizing the reason for their absence or otherwise gaming the company’s time off policies. Meanwhile, performance and productivity concerns also become more prevalent as workers allow holiday shopping, personal holiday preparations, and other personal distractions to distract their performance. Businesses concerned with these challenges ideally will have in place well-designed policies concerning attendance, time off and productivity that comply with the Fair Labor Standards Act and other laws. Businesses should exercise care when addressing productivity and attendance concerns to investigate and document adequately their investigation before imposing discipline. Businesses also should ensure that their policies are appropriately and even-handedly administered. They also should exercise care to follow company policies, to maintain time records for non-exempt workers, to avoid inappropriately docking exempt worker pay, and to provide all required notifications and other legally mandated rights to employees taking medical, military or other legally protected leaves. In the event it becomes necessary to terminate an employee during December, careful documentation can help the business to defend this decision. Furthermore, businesses should be careful to ensure that all required COBRA notifications, certificates of creditable coverage, pension and profit-sharing notice and distribution forms, and other required employment and employee benefit processes are timely fulfilled.
Timely Investigation & Notification
Businesses faced with allegations of discrimination, sexual harassment or other misconduct also should act promptly to investigate any concerns and if necessary, take appropriate corrective action. Delay in investigation or redress of discrimination or other improprieties can increase the liability exposure of a business presented with a valid complaint and complicate the ability to defend charges that may arise against the business. Additionally, delay also increases the likelihood that a complaining party will seek the assistance of governmental officials, plaintiff’s lawyers or others outside the corporation in the redress of his concern.
If a report of an accident, act of discrimination or sexual harassment or other liability related event arises, remember to consider as part of your response whether you need to report the event to any insurers or agencies. Injuries occurring at company related functions often qualify as occupational injuries subject to worker’s compensation and occupational safety laws. Likewise, automobile, employment practices liability, and general liability policies often require covered parties to notify the carrier promptly upon receipt of notice of an event or claim that may give rise to coverage, even though the carrier at that time may not be obligated to tender a defense or coverage at that time.
If your organization needs assistance with assessing, managing or defending these or other labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer or another Curran Tomko Tarski LLP attorney of your choice. Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, risk management and internal controls matters. Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. She has counseled and represented employers on these and other workforce matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates you may have missed include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Preventive HR Strategies to Minimize Post Holiday Celebration Legal Hangovers |
Absenteeism, Disease Management, EEOC, Employers, Human Resources, Internal Controls, Internal Investigations, Leave, OSHA, Privacy, Risk Management, Safety, Sexual Harassment, Wage & Hour, Wellness | Tagged: COBRA, Corporate Compliance, Employee Benefits, Employment, Health Plans, Human Resources, Internal Controls, Internal Investigations, Labor, Minimum Wage, Occupational Injury, Privacy, Risk Management, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
November 30, 2009
As the Centers for Disease Control (CDC) continues cautioning Americans to expect a resurgence of the H1N1 virus, employers should continue to take prudent steps to defend their organization and their workers against a widespread H1N1 outbreak and the attendant lost time, health and disability costs, OSHA and other liability exposures and other personal and financial consequences likely to result from an outbreak.
Employers wishing to deter the spread of the disease in their workplace should educate workers about these recommendations and consider taking steps to encourage workers to comply with these recommendations. When planning or taking steps to protect their workplaces from the H1N1 virus pandemic or other outbreaks of communicable diseases, however, employers must use care to avoid violating the Americans With Disabilities Act or other employment laws.
Preventing, Recognizing & Mitigating Risks of H1N1
Although the number of reported cases of H1N1 virus cases has declined in many states in recent weeks, CDC officials are warning American’s that the crisis is not over yet. CDC officials last week warned Americans to expect H1N1 infection to rise as the holiday approaches and the winter progresses. With flu activity already higher than what is seen during the peak of many regular flu seasons and the H1NA virus accounting for almost all of the flu viruses identified so for this season, Accordingly, the CDC continues to encourage Americans to be alert for symptoms of H1N1 or other flu and to take other precautions including to get vaccinated.
Employers should continue to encourage workers and their families to take precautions to avoid catching the virus, to be on the watch for H1N1 virus or other flu infection and to respond appropriately if they, members of their families or others in the workplace exhibit these symptoms. To help promote health habits within their workforce, many businesses may want to download and circulate to employees and families the free resources published by the CDC here. Businesses and other concerned parties also can track governmental reports about the swine flu and other pandemic concerns at here.
For those not already suffering from the virus and particularly for those at higher risk, the CDC continues to recommend vaccination. People recommended by the CDC to receive the vaccine as soon possible include: health care workers; pregnant women; people ages 25 through 64 with chronic medical conditions, such as asthma, heart disease, or diabetes; anyone from 6 months through 24 years of age; and people living with or caring for infants under 6 months old. As the vaccine becomes available, many employers are encouraging workers and their families to get vaccinated by offering vaccination clinics at or near their worksites, arranging for health plan coverage for vaccinations with reduced or no co-payments or deductibles, and/or sharing information about government sponsored or other vaccination clinics.
While the CDC says getting employees and their families to get a flu shot remains the best defense against a flu outbreak, it also says getting employees and family members to consistently practice good health habits like covering a cough and washing hands also is another important key to prevent the spread of germs and prevent the spread of respiratory illnesses like the flu. Employers should encourage employees and their families to take the following steps:
- Avoid close contact with people who are sick. When you are sick, keep your distance from others to protect them from getting sick too;
- Stay home when you are sick to help prevent others from catching your illness;
- Cover your mouth and nose;
- Cover your mouth and nose with a tissue when coughing or sneezing. It may prevent those around you from getting sick;
- Clean your hands to protect yourself from germs;
- Avoid touching your eyes, nose or mouth;
- Germs are often spread when a person touches something that is contaminated with germs and then touches his or her eyes, nose, or mouth; and
- Practice other good health habits. Get plenty of sleep, be physically active, manage your stress, drink plenty of fluids, and eat nutritious food.
Employers also should encourage workers and their families to be alert to possible signs of H1N1 or other flu symptoms and to respond appropriately to possible infection. According to the CDC, all types of flu including H1NA typically include many common symptoms, including:
- Fever
- Coughing and/or sore throat
- Runny or stuffy nose
- Headaches and/or body aches
- Chills
- Fatigue
Patients suffering from H1N1 flu usually report these same symptoms, but the symptoms often are more severe. In addition to the above symptoms, a number of H1N1 flu cases reported vomiting and diarrhea.
CDC recommends individuals diagnosed with H1N1 flu should:
- Stay home and avoid contact with others for at least 24 hours after a fever (100°F or 37.8°C) is gone without the use of fever reducing medicine except to get medical care or for other things that must be done that no one else can do;
- Avoid close contact with others, especially those who might easily get the flu, such as people age 65 years and older, people of any age with chronic medical conditions (such as asthma, diabetes, or heart disease), pregnant women, young children, and infants;
- Clean hands with soap and water or an alcohol-based hand rub often, especially after using tissues or coughing/sneezing into your hands;
- Cover coughs and sneezes;
- Wear a facemask when sharing common spaces with other household members to help prevent spreading the virus to others. This is especially important if other household members are at high risk for complications from influenza;
- Drink clear fluids such as water, broth, sports drinks, or electrolyte beverages made for infants to prevent becoming dehydrated;
- Get plenty of rest;
- Follow doctor’s orders; and
- Watch for signs for a need for immediate medical attention. Suffers should get medical attention right away if the sufferer has difficulty breathing or chest pain, purple or blue discoloration of the lips, is vomiting and unable to keep liquids down, or shows signs of dehydration, such as feeling dizzy when standing or being unable to urinate.
In seeking to contain the spread of the virus within their workplace, employers also should be sensitive to workplace policies or practices that may pressure employees with a contagious disease to report to work despite an illness and consider whether the employer should adjust these policies temporarily or permanently in light of the ongoing pandemic. For instance, financial pressures and the design and enforcement of policies regarding working from home and/or qualifying for paid or unpaid time off significantly impact the decisions employees make about whether to come to work when first experiencing symptoms of illness. Employers of workers who travel extensively – may wish to delay or restrict travel for some period.
Employers Must Employment Discrimination & Other Legal Compliance Risks
Many employers may want to evaluate and appropriately revise existing policies with an eye to better defending their workforce against a major outbreak. Whether or not the disease afflicts any of its workers, businesses can anticipate the swine flu outbreak will impact their operations – either as a result of occurrences affecting their own or other businesses or from workflow disruptions resulting from safeguards that the business or other businesses implement to minimize swine flu risks for its workforce or its customers. Many businesses also will want to prepare backup staffing and production strategies to prepare for disruptions likely to result if a significant outbreak occurs.
Employers planning for or dealing with an H1N1 or other epidemic in their workplace should exercise care to avoid violating the nondiscrimination and medical records confidentiality provisions of the Americans with Disabilities Act (ADA) and/or the Genetic Information Nondiscrimination Act (GINA), the Family & Medical Leave Act of 1990 (FMLA), the Fair Labor Standards Act (FLSA) and applicable state wage and hour laws, and other employment and privacy laws.
Improperly designed or administered medical inquiries, testing, vaccination mandates and other policies or practices intended to prevent the spread of disease may expose an employer to disability discrimination liability under the ADA or GINA. For instance, the ADA generally prohibits an employer from making disability-related inquiries and requiring medical examinations of employees, except under limited circumstances permitted by the ADA. Likewise, improperly designed or communicated employer inquiries into family medical status which could be construed as inquiring about family medical history also may raise exposures under genetic information nondiscrimination and privacy mandates of GINA that took effect November 21, 2009.
During employment, the ADA prohibits employee disability-related inquiries or medical examinations unless they are job-related and consistent with business necessity. Generally, a disability-related inquiry or medical examination of an employee is job-related and consistent with business necessity when an employer has a reasonable belief, based on objective evidence, that:
- An employee’s ability to perform essential job functions will be impaired by a medical condition; or
- An employee will pose a direct threat due to a medical condition.
This reasonable belief “must be based on objective evidence obtained, or reasonably available to the employer, prior to making a disability-related inquiry or requiring a medical examination.”
Additionally, the ADA prohibits employers from making disability-related inquiries and conducting medical examinations of applicants before a conditional offer of employment is made. It permits employers to make disability-related inquiries and conduct medical examinations if all entering employees in the same job category are subject to the same inquiries and examinations. All information about applicants or employees obtained through disability-related inquiries or medical examinations must be kept confidential. Information regarding the medical condition or history of an employee must be collected and maintained on separate forms and in separate medical files and be treated as a confidential medical record. The EEOC Pandemic Preparedness In The Workplace and The Americans With Disabilities Act Guidance makes clear that employer inquiries and other H1N GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” is likely to present a liability trap door for many unsuspecting employers H1N1 and other epidemic planning and response activities should be carefully crafted to avoid violating these proscriptions.
GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” also could present a liability trap door for some employers designing pandemic or other workplace wellness, disease management or other programs. GINA defines “genetic information” broadly as including not only information about genetic tests about an individual or his family member as well as information about the “manifestation of a disease or disorder in family members of such individual, GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology. For more information about the new GINA genetic information employment discrimination rules, see here.
As part of their pandemic planning, employers also generally should review their existing wage and hour and leave of absence practices. Employers should ensure that their existing or planned practices for providing paid or unpaid leave are designed to comply with the FLSA and other wage and hour and federal and state leave of absence laws. Employers also should review and update family and medical leave act and other sick leave policies, group health plan medical coverage continuation rules and notices and other associated policies and plans for compliance with existing regulatory requirements, which have been subject to a range of statutory and regulatory amendments in recent years. If considering allowing or requiring employees to work from home, employers also need to implement appropriate safeguards to monitor and manage employee performance, to protect the employer’s ability to comply with applicable wage and hour, worker’s compensation, OSHA and other safety, privacy and other legal and operational requirements.
Businesses, health care providers, schools, government agencies and others concerned about preparing to cope with pandemic or other infectious disease challenges also may want to review the publication “Planning for the Pandemic” authored by Curran Tomko Tarski LLP partner Cynthia Marcotte Stamer available at here. FLU.gov is a one-stop resource with the latest updates on the H1N1 flu. An additional resource is CDC INFO, 1-800-CDC-INFO (1-800-232-4636), which offers services in English and Spanish, 24 hours a day, 7 days a week. Schools, health care organizations, restaurants and other businesses whose operations involve significant interaction with the public also may need to take special precautions. These and other businesses may want to consult the special resources posted here.
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending these or other labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer. Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, health and other employee benefit and other personnel and staffing matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here. Examples of other recent updates you may have missed include:
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Employer H1N1 Virus Risk Management Requires Employer Care To Manage Virus Risks Without Violating Employment Discrimination or Other Laws |
ADA, COBRA, Disease Management, EEOC, Employee Benefits, Employers, family leave, FMLA, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Leave, medical leave, OSHA, Pandemic, Privacy, Protected Health Information, Risk Management, Safety, Swine Flu, Wage & Hour, Wellness | Tagged: ADA, COBRA, Corporate Compliance, Disability Discrimination, Disease Management, Employee Benefits, Employers, Employment, Health Insurance, Health Plans, Human Resources, Internal Controls, Labor, Medical Coverage, Minimum Wage, Pandemic, Privacy, Risk Management, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
November 24, 2009
Updated Employment Poster, Policies & Procedures Required Immediately
Employers, unions, employment agencies, employment training agencies and their agents face significant new employment discrimination liability risks if they violate new genetic information-based employment non-discrimination or fail to comply with genetic information confidentiality requirements that took effect under Title II of the Genetic Information Nondiscrimination Act (GINA) on Saturday, November 21, 2009. Employers need immediately to update their employment posters, carefully audit their existing records and practices to identify existing information and practices that may create special risks under GINA and take appropriate action to comply with the GINA rules. Employers needing an updated poster can find a copy on the Equal Employment Opportunity Commission website here.
Under the newly effective employment provisions of Title II of GINA, Federal law now prohibits employers of 15 or more employees and certain other entities from using individuals’ “genetic information” when making hiring, firing, job placement, or promotion decisions, requires “genetic information” be kept separately and confidential, and prohibits retaliation.
When assessing their risk under GINA, employers should be careful not to overlook or underestimate the genetic information collected or possessed by their organizations and the risks attendant to this information. Many employers will be surprised by the breadth of the depth of “genetic information.” GINA defines “genetic information” broadly as including not only information about genetic tests about an individual or his family member as well as information about the “manifestation of a disease or disorder in family members of such individual. GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology. Pending issuance of regulatory guidance, GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” is likely to present a liability trap door for many unsuspecting employers.
Failing to properly address GINA compliance could expose employers to substantial risk. Violation of the employment provisions of Title II subjects an employer to potentially significant civil judgments like those that generally are available for race, sex, and other federal employment discrimination claims covered by the Civil Rights Act. Accordingly, employers and others who have not already done so should act quickly to review and update their policies and procedures to manage their new compliance and liability exposures under GINA Title II.
While the agency responsible for construing and enforcing Title II of GINA, the Equal Employment Opportunity Commission (EEOC), to date has published only limited guidance about it, the absence of this final guidance should not be read by employers as a sign their compliance may be delayed. While not yet issued in final form, proposed regulations interpreting Title II of GINA accessible here published by the EEOC in March, 2009 and a subsequently released factsheet accessible here published by the EEOC in May, 2009 titled “Background Information for EEOC Notice of Proposed Rulemaking On Title II of the Genetic Information Nondiscrimination Act of 2008” provide insights about how the EEOC may be expected to view its provisions. While many employers have delayed taking action to update their policies and procedures in hopes that final guidance would be forthcoming before Title II took effect, time has now run out. Accordingly, employers who have not already done so should act quickly to implement all necessary changes to position themselves to defend against a potential claim that their organization may have violated GINA Title II.
Employment-Related Genetic Information Nondiscrimination Rules In Focus
Applicable to employers, unions, employment agencies, employment training agencies and their agencies based on genetic information by employers, Title II imposes sweeping prohibitions against employment discrimination based on genetic information. Title II generally has three components:
Employment Discrimination Prohibited. Section 202 of GINA makes it illegal for an employer:
- To fail or refuse to hire, or to discharge, any employee, or otherwise to discriminate against any employee with respect to the compensation, terms, conditions, or privileges of employment of the employee, because of genetic information with respect to the employee;
- To limit, segregate, or classify the employees of the employer in any way that would deprive or tend to deprive any employee of employment opportunities or otherwise adversely affect the status of the employee as an employee, because of genetic information with respect to the employee; or
- To request, require, or purchase genetic information with respect to an employee or a family member of the employee except as specifically permitted by GINA and otherwise applicable law.
GINA §§ 203 and 204 extend similar prohibitions to employment agencies, labor unions and training programs.
Confidentiality Mandates. Under GINA § 206, an employer, employment agency, labor organization, or joint labor-management committee that possesses genetic information about an employee or member must protect the confidentiality of that information. Under its provisions, employers and other covered entities must:
- Treat the genetic information as a confidential medical record of the employee or member and maintain it on separate forms and in separate medical files in the same manner as required for other medical records required to be maintained as confidential by Americans With Disabilities Act § 102(d)(3)(B); and
- Only disclose it in the narrow circumstances specifically allowed by GINA.
Anti-Retaliation. GINA also prohibits retaliation or other discrimination against any individual because such individual has opposed any act or practice prohibited by GINA, for making a charge, testifying or assisting or participating in any manner in an investigation, proceeding, or hearing under GINA.
GINA’s Additional Group Health Plan Nondiscrimination & Privacy Rules Also Require Attention
In addition to taking appropriate steps to comply with the employment rules of Title II of GINA, employers and their group health plan fiduciaries and service providers also should ensure that the group health plan has been appropriately updated to comply with the group health plan nondiscrimination and privacy mandates of Title I of GINA.
Effective for all group health plan years beginning on or after May 21, 2009, GINA’s new restrictions on the collection and use of genetic information by group health plans added under Title I of GINA are accomplished through the expansion of a series of already existing group health plan nondiscrimination and privacy rules. GINA’s group health plan provisions amend and expand the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), Title VII of the Civil Rights Act, the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act to implement sweeping new federal restrictions on the collection, use, and disclosure of information that falls within its broad definition of “genetic information” by group health plans. For individual health insurers, GINA’s restrictions take effect May 22, 2009. The broad definition of the term “genetic information” in GINA will require group health plan sponsors and insurers to carefully review and update their group health plan documents, communications, policies and practices to comply with forthcoming implementing regulations to avoid liability under new GINA’s rules governing genetic information collection, use, protection and disclosure in a series of areas.
In this respect, wellness and disease management programs are likely to require special scrutiny and attention. GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” raises potential challenges for a broad range of group health plan health assessment and other wellness and disease management programs which provide financial incentives or condition eligibility on the provision of family health histories or other information that could be construed as genetic information. The implications of these GINA prohibitions are further complicated by recent changes in the disability nondiscrimination rules and guidance under the Americans With Disabilities Act.
Title I of GINA generally prohibits group health plans from collecting genetic information for underwriting or eligibility purposes. It also expands already existing federal rules prohibiting group health plans from discriminating among individuals for purposes of determining eligibility or setting premiums based on health status previously enacted as part of HIPAA. These existing rules already prohibit group health plans and health insurance issuers from discriminating based on health related factors including genetic information for purposes of determining eligibility or premiums. GINA expands these existing nondiscrimination requirements to further regulate group health plan’s use and collection of genetic information. Under GINA’s nondiscrimination rules, group health plans and health insurers may not:
- Request, require or purchase genetic information for underwriting purposes or in advance of an individual’s enrollment;
- Adjust premiums or contribution amounts of the group based on genetic information;
- Request or require an individual or family member to undergo a genetic test except in limited situations specifically allowed by GINA;
- Impose a preexisting condition exclusion based solely on genetic information, in the absence of a diagnosis of a condition;
- Discriminate against individuals in eligibility and continued eligibility for benefits based on genetic information; or
- Discriminate against individuals in premium or contribution rates under the plan or coverage based on genetic information, although such a plan or issuer may adjust premium rates for an employer based on the manifestation of a disease or disorder of an individual enrolled in the plan.
GINA also prohibits insurers providing individual health insurance from establishing rules for eligibility, adjusting premiums or contribution amounts for an individual, imposing preexisting condition exclusions based on, requesting or requiring individuals or family members to undergo genetic testing.
Of particular concern to many plan sponsors and fiduciaries are the potential implications of these new rules on existing wellness and disease management features group health plans. Of particular concern is how regulators will treat the collection of family medical history and certain other information as part of health risk assessments used in connection with these programs. Although official guidance is still pending, many are concerned that regulators will construe certain commonly used practices of requiring covered persons to provide family medical histories or other genetic information through health risk assessments (HRAs) to qualify for certain financial incentives as a prohibited underwriting practice under GINA. Even where health risk assessments are not used, however, most group health plan sponsors should anticipate that GINA will require specific amendments to their plan documents, communications and processes.
Taking timely action to comply with these nondiscrimination and collection prohibitions is important. Under amendments to ERISA made by GINA, group health plan noncompliance can create significant liability for both the plan and its sponsor. Participants or beneficiaries will be able to sue noncompliant group health plans for damages and equitable relief. If the participant or beneficiary can show an alleged violation would result in irreparable harm to the individual’s health, the participant or beneficiary may not have to exhaust certain otherwise applicable Department of Labor administrative remedies before bringing suit. In addition to these private remedies, GINA also authorizes the imposition of penalties against employers and other sponsors of group health plans that violate applicable requirements of GINA of up to $500,000. The minimum penalties generally are set at the greater of $100 per day or a minimum penalty amount ranging from $2,500 for de minimus violations corrected before the health plan received notice of noncompliance to $15,000 in cases in which the violations are more than de minimus. GINA also includes language allowing the Secretary of Labor to reduce otherwise applicable penalties for violations that could not have been identified through the exercise of due diligence or when the plan corrects the violation quickly.
GINA Amendments To Health Plan Privacy Rules Under HIPAA
In addition to its nondiscrimination rules, GINA also amends HIPAA to make clear that “genetic information” as defined by HIPAA is protected health information protected by HIPAA’s Privacy & Security Standards of HIPAA. This means that it will require that all genetic information be treated as protected health information subject to the Privacy and Security Standards applicable to group health plans covered by HIPAA. Although the statutory provisions that accomplish these changes are deceptively simple, compliance with these requirements likely will require group health plans and their business associates to amend existing privacy policies, notices and practices to appropriately restrict disclosures for underwriting, operations and certain other uses to withstand scrutiny under the GINA privacy rule amendments.
When contemplating these changes, many plan sponsors and administrators also will want to consider and begin preparing to comply with other refinements to their existing privacy and security practices required in response to HIPAA privacy and security rule amendments enacted as part of the HITECH Act provisions of the Health Information Technology for Economic and Clinical Health Act (“HITECH Act”) provisions of the American Recovery and Reinvestment Act of 2009 (ARRA). As GINA specifies that violations of its privacy rule restrictions trigger the same sanctions as other privacy rule violations, group health plans and their business associates also should give due consideration to these penalty exposures. The HITECH Act amended and increased civil penalties for HIPAA privacy violations in many circumstances effective February 17, 2009.
GINA’s fractured assignment of responsibility and authority to develop, implement and enforce regulatory guidance of its genetic information rules can create confusion for parties involved in compliance efforts. Because the group health plan requirements of Title I of GINA are refinements to the group health plan privacy and nondiscrimination rules previously enacted as part of HIPAA, GINA specifically assigned authority to construe and enforce its group health plan requirements to the agencies responsible for the interpretation and enforcement of those original rules: (1) the Department of Labor Employee Benefit Security Administration (EBSA); (2) the Internal Revenue Services (IRS), and (3) the Department of Health & Human Services.
These three agencies in early October published the interim final regulations construing the group health plan manatees of Title II of GINA, which are available for review here. Group health plans, their employer and other sponsors, fiduciaries and service providers should act quickly to review and update their group health plan documents, procedures and other materials to comply with these new mandates.
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending these or other labor and employment, compensation or benefit practices, please contact the author of this article, Curran Tomko Tarski LLP Labor & Employment Practice Group Chair Cynthia Marcotte Stamer. Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization and Chair of the American Bar Association RPTE Employee Benefits & Other Compensation Group and a nationally recognized author and speaker, Ms. Stamer is experienced with assisting employers and others about compliance with federal and state equal employment opportunity, compensation, health and other employee benefit, workplace safety, and other labor and employment laws, as well as advising and defending employers and others against tax, employment discrimination and other labor and employment, and other related audits, investigations and litigation, charges, audits, claims and investigations by the IRS, Department of Labor and other federal and state regulators. Ms. Stamer has advised and represented employers on these and other labor and employment, compensation, health and other employee benefit and other personnel and staffing matters for more than 22 years. Ms. Stamer also speaks and writes extensively on these and other related matters. For additional information about Ms. Stamer and her experience or to access other publications by Ms. Stamer see here or contact Ms. Stamer directly. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi LLP team, see here.
Other Information & Resources
We hope that this information is useful to you. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information here or registering to participate in the distribution of our Solutions Law Press HR & Benefits Update distributions here.
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on New GINA Genetic Information Based Employment Discrimination & Confidentiality Mandates Take Effect |
ADA, Corporate Compliance, EEOC, Employee Benefits, Employers, ERISA, GINA, Health Plans, HIPAA, Human Resources, Immigration, Privacy | Tagged: ADA, Disease Management, EEOC, Employee Benefits, Employer, Employers, Employment, Employment Agreements, Genetic Inforamtion, GINA, Health Insurance, Human Resources, Insurance, Insurer, Risk Management, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
September 2, 2009
September 10, 2009 – Noon to 1:30 P.M. Central Time Participate In Person or Via Remote!
Health care providers, health plans, health clearinghouses and their business associates (Covered Entities) must comply with the new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) by September 23, 2009.
Catch up on what the Breach Rule means for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Thursday, September 10, 2009 from Noon to 1:30 P.M. Central Time for a registration fee of $45.00. Registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201. For information about registering for this program or other questions here,
The Breach Rule requires Covered Entities to notify affected individuals following a “breach” of “unsecured” protected health information. Just published August 24th, the Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA). The briefing will cover:
- Who must comply, health plans, employers, others?
- What your organization must do
- How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
- What is considered a breach of unsecured protected health information
- What steps must a covered entity take if a breach of unsecured protected information happens
- What liabilities do covered entities face for non-compliance
- What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
- How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
- Other recent developments
- Practical tips for assessing, planning, moving to and defending compliance
- Participant questions
- More
About The Presenter
The program will be presented by Curran Tomko and Tarski LLP Health Care & Employee Benefits Practice Leader and Partner Cynthia Marcotte Stamer. Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts. Chair of the ABA RPTE Employee Benefits & Other Compensation Committee, a ABA Joint Committee on Employee Benefits Council Representative, Vice President of the North Texas Health Care Compliance Professionals Association, Past Chair of the ABA Health Law Section Managed Care & Insurance Section and the former Board Compliance Chair of the National Kidney Foundation of North Texas, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters. A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters. Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications. For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.
We hope that this information is useful to you. If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.
Other Helpful Resources & Other Information
If you find this of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.net.
©2009 Solutions Law Press. All rights reserved.
Comments Off on Register Now For HITECH Act Health Data Security & Breach Update: Learn What You Must Do This Month To Comply With New Health Data Breach Regulations |
Corporate Compliance, Data Security, Disease Management, Employers, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Privacy, Protected Health Information | Tagged: Corporate Compliance, Employee Benefits, Employer, Employers, Employment, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, Human Resources, Insurance, Insurer, Internal Controls, Managed Care, Medical Coverage, Privacy |
Permalink
Posted by Cynthia Marcotte Stamer
August 24, 2009
Employer and other health plans, health care providers, health clearinghouses and their business associates must start complying with new federal data breach notification rules on September 23, 2009.
The new “Breach Notification For Unsecured Protected Health Information” regulation (Breach Regulation) published here in today’s Federal Register requires health plans, health care providers, health care clearinghouses and their business associates (Covered Entities) covered under the personal health information privacy and security rules of the Health Insurance Portability & Accountability Act (HIPAA) to notify affected individuals following a “breach” of “unsecured” protected health information.The Breach Regulation is part of a series of guidance that HHS is issuing to implement new and stricter personal health information privacy and data security requirements for Covered Entities added to HIPAA under the Health Information Technology for Economic and Clinical Health (HITECH) Act signed into law on February 17, 2009 as part of American Recovery and Reinvestment Act of 2009 (ARRA).
You are invited to catch up on what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9 2009 from Noon to 1:30 P.M. Central Time.
HITECH Act Data Breach and Unsecured PHI Rules
Published in the August 24, 2009 Federal Register, the new Breach Regulation implements the HITECH Act requirement that Covered Entities and their business associates notify affected individuals, the Secretary of HHS, and in some cases, the media, when a breach of “unsecured protected health information” happens and the form, manner, and timing of that notification. Covered Entities must begin complying with the new Breach Regulation on September 23, 2009.
Part of a series of new HHS rules implementing recent changes to HIPAA enacted under the HITECH Act to strengthen existing federally mandates requiring Covered Entities to safeguard protected health information, the Breach Regulation will obligate Covered Entities and business associates to provide certain notifications following a breach of “protected health information” that not secured at the time of the breach through the use of a technology or methodology meeting minimum standards issued by HHS pursuant to other provisions of the HITECH Act.
Under the HITECH Act, the breach notification obligations contained in the Breach Notification only apply to a breach of “unsecured protected health information.” The Breach Regulation exempts breaches of protected health information that qualify as “secured” under separately issued HHS and Federal Trade Commission (FTC) standards for encryption and destruction of protected health information from its breach notification requirements.
For purposes of the HITECH Act, electronic protected health information is considered “unsecured” unless the Covered Entity has satisfied certain minimum standards for the protection of that data established pursuant to the HITECH Act. Earlier this year, HHS and the FTC issued interim rules defining the minimum encryption and destruction technologies and methodologies that Covered Entities must use to render protected health information unusable, unreadable, or indecipherable to unauthorized individuals for purposes of determining when protected health information is “unsecured” for purposes of the HITECH Act. Concurrent with its publication of the Breach Regulation, HHS also released guidance updating and clarifying this previously issued guidance.
Read the Breach Regulation here . To review the HITECH Act Breach Notification Guidance and Request for Information, see here .
Register For September 9, 2009 “HITECH Act Health Data Security & Breach Update”
Interested persons are invited to register here now to learn what these new rules mean for your organization and how it must respond by participating in the “HITECH Act Health Data Security & Breach Update” on Wednesday, September 9, 2009 from Noon to 1:30 P.M. Central Time. For a registration fee of $45.00, registrants will have the option to participate via teleconference or in person at the offices of Curran Tomko Tarski LLP, 2001 Bryan Street, Suite 2050, Dallas Texas 75201. For questions or other information about this program, e-mail here.
Conducted by Curran Tomko and Tarski LLP Partner Cynthia Marcotte Stamer, the briefing will cover:
- Who must comply
- What your organization must do
- How to qualify protected health information as exempt from the breach regulations as “secure” protected health information
- What is considered a breach of unsecured protected health information
- What steps must a covered entity take if a breach of unsecured protected information happens
- What liabilities do covered entities face for non-compliance
- What new contractual requirements, policies and procedures Covered Entities and Business Associates will need
- How the Breach Regulation, the Privacy Regulation, impending FTC red flag rules and state data breach and privacy rules interrelate
- Other recent developments
- Practical tips for assessing, planning, moving to and defending compliance
- Participant questions
- More
About The Presenter
The program will be presented by Curran Tomko Tarski LLP Partner Cynthia Marcotte Stamer. Ms. Stamer is nationally known for her work, publications and presentations on privacy and security of health and other sensitive information in health and managed care, employment, employee benefits, financial services, education and other contexts.
Past Chair of the ABA Health Law Section Managed Care & Insurance Section and currently the Chair of the American Bar Association (ABA) RPTE Employee Benefits & Other Compensation Section and a Council Representative of the ABA Joint Committee On Employee Benefits, Ms. Stamer has more than 20 years experience advising clients about health and other privacy and security matters. A popular lecturer and widely published author on privacy and data security and other related health care and health plan matters, Ms. Stamer is the Editor in Chief of the forthcoming 2010 edition of the Information Security Guide to be published by the American Bar Association Information Security Committee in 2010, as well as the author of “Protecting & Using Patient Data In Disease Management: Opportunities, Liabilities And Prescriptions,” “Privacy Invasions of Medical Care-An Emerging Perspective,” “Cybercrime and Identity Theft: Health Information Security Beyond HIPAA,” and a host of other highly regarded publications. She has continuously advises employers, health care providers, health insurers and administrators, health plan sponsors, employee benefit plan fiduciaries, schools, financial services providers, governments and others about privacy and data security, health care, insurance, human resources, technology, and other legal and operational concerns. Ms. Stamer also publishes and speaks extensively on health and managed care industry privacy, data security and other technology, regulatory and operational risk management matters. Her insights on health care, health insurance, human resources and related matters appear in the Atlantic Information Service, Bureau of National Affairs, World At Work, The Wall Street Journal, Business Insurance, the Dallas Morning News, Managed Healthcare, Health Leaders, and a many other national and local publications. For additional information about Ms. Stamer, her experience, involvements, programs or publications, see here.
We hope that this information is useful to you. If you need assistance monitoring, evaluating or responding to these or other compliance, risk management, transaction or operation concerns, please contact the author of this update, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or another Curran Tomko Tarski LLP Partner of your choice.
Other Helpful Resources & Other Information
If you found these updates of interest, you also be interested in one or more of the following other recent articles published on our electronic Curran Tomko Tarski LLP publications available for review here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. You can access other recent updates and other informative publications and resources provided by Curran Tomko Tarski LLP attorneys and get information about its attorneys’ experience, briefings, speeches and other credentials here.
For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@cttlegal.com.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Employer & Other Health Plans & Other HIPAA-Covered Entities & Their Business Associates Must Comply With New HHS Health Information Data Breach Rules By September 23 |
ARRA, Corporate Compliance, Data Security, Employee Benefits, Employers, ERISA, GINA, Health Plans, HIPAA, Human Resources, Insurance, Internal Controls, Preemption, Privacy, Protected Health Information, Risk Management, Stimulus Bill, Tax | Tagged: Corporate Compliance, Data Security, Employee Benefits, Employer, Employers, Employment, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, HealthP Plans, Human Resources, Insurance, Insurer, Internal Controls, Internal Investigations, Labor, Managed Care, Medical Coverage, Privacy, Risk Management, Subsidy Bill, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
August 4, 2009
Democratic Leaders in the House of Representatives plan to hammer out differences three versions of the America’s Affordable Health Choices Act (H.R. 3200) as separately passed by three key House Committees in July before House members return from their August recess in hopes of bringing the agreed to version of H.R. 3200 to the full house in September. Each version of H.R. 3200 would impose significant new obligations, regulations and costs on employers, health insurers and health plans, and employees.
After negotiating a last minute pre-August recess deal with certain Blue Dog Democrat Committee members, the House Energy and Commerce Committee on July 31, 2009 passed its version of H.R. 3200, the America’s Affordable Health Choices Act (H.R. 3200). The version of H.R. 3200 passed by the House Energy and Commerce Committee incorporates a series of amendments to the language of H.R. 3200 as originally introduced. For instance, this version of H.R. 3200 provides incentives for states to adopt certain tort reforms, provides for a public plan option that would reimburse physicians based on negotiated rates rather Medicare rates, and would allow states to offer both state-based heath insurance exchanges and health insurance co-ops. To review H.R. 3200 as amended by the House Energy and Commerce Committee, see here.
The approval by the Energy and Commerce Committee of its version of H.R. 3200 follows the July 17, 2009 approval by the House Ways and Means Committee and Education and Labor Committee of their own versions of H.R. 3200. For details on the version of H.R. 3200 approved by the House Ways and Means Committee, see here. For details on the version of H.R. 3200 approved by the House Education and Labor Committee, see here.
Leading House Democrats have announced their intention to work to resolve differences between these three versions of H.R. 3200 as passed by these Committees during August recess in hopes of bringing the agreed to version of H.R. 3200 to a vote of the full House of Representatives in September.
Meanwhile, House members from both parties also generally are using the August recess as an opportunity to reconnect with local constituents on health care reform and other core issues.
For More Information
The author of this article, Curran Tomko and Tarski LLP Partner Cynthia Marcotte Stamer has extensive experience advising and assisting employers and other health plan sponsors, insurers and others about health benefit and other benefits, human resources and health care matters. The current Chair of the American Bar Association Real Propoerty, Probate & Trust Section Employee Benefit Plans and Other Compensation Committee and former Chair of the ABA Health Law Section Managed Care & Insurance Group, she regularly advises these and other clients about the design, administration, defense and regulation of health benefit, wellness and disease management, managed care, onsight wellness, and other benefit and insurance regulations, legislative and regulatory reforms impacting these and other arrangements, and related matters.
We hope that this information is useful to you. If you need assistance monitoring, evaluating or responding to these or other proposed health care or other regulatory reforms or with other health care compliance, risk management, transaction or operation concerns, please contact the author of this update, Curran Tomko Tarski LLP Health Practice Group Chair, Cynthia Marcotte Stamer, at (214) 270-2402, cstamer@cttlegal.com or your other favorite Curran Tomko Tarski LLP Partner.
We also encourage you and others to join the discussion about these and other health care reform proposals and concerns by joining the Coalition for Responsible Health Care Reform Group on Linkedin, registering to receive these updates here.
If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile at here or e-mailing this information to cstamer@cttlegal.com. If you prefer not to receive these updates via e-mail in the future, e-mail your request with “remove” in the subject to support@solutionslawyer.net.
Comments Off on House Democratic Majority Hopes To Iron Out Differences In Key Health Care Reform Legislation During August Recess |
Disease Management, Employee Benefits, Employers, ERISA, Health Care Reform, Health Plans, Insurance, Malpractice, Preemption, Privacy, Public Policy, Tax, Wellness | Tagged: Employee Benefits, Employer, Employers, Employment, ERISA, Health Care Reform, Health Insurance, Health Plans, Human Resources, Insurance, Insurer, Managed Care, Medical Coverage, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
August 3, 2009
The Department of Health & Human Services (HHS) today (August 3, 2009) transferred authority for the administration and enforcement of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Security Rule to the Office for Civil Rights (OCR). Prior to this announcement, responsibility for interpretation and enforcement of the Security Rule rested with the Centers for Medicare & Medicaid Services (CMS). The change reflects the growing seriousness of HHS and others about enforcing federal privacy and data security mandates for health information. HHS anticipates the transfer of authority will eliminate duplication and increase efficiencies in how the department ensures that Americans’ health information privacy is protected.
HHS has the authority for administration and enforcement of the federal standards for health information privacy called for in HIPAA. The Privacy Rule provides federal protections for personal health information held by covered entities and gives patients an array of rights with respect to that information. OCR has been responsible for enforcement of the Privacy Rule since 2003. The Security Rule specifies a series of administrative, technical, and physical security procedures for covered entities to use to assure the confidentiality of electronic protected health information. The Health Information Technology for Economic and Clinical Health (HITECH) Act, part of the American Recovery and Reinvestment Act of 2009 (ARRA), mandated improved enforcement of the Privacy Rule and the Security Rule.
Through a separate delegation, CMS continues to have authority for administration and enforcement of the HIPAA Administrative Simplification regulations, other than privacy and security of health information.
The transfer of Security Rule enforcement authority comes as guidance about new data breach rules for electronic protected health information is impending. This impending guidance relates to the implementation of new breach notification rules for covered entities and their business associates concerning their obligation to use of technologies and methodologies that render protected health information unusable, unreadable, or indecipherable to unauthorized individuals, as required by amendments to HIPAA enacted under the Health Information Technology for Economic and Clinical Health (HITECH) Act passed as part of the American Recovery and Reinvestment Act of 2009 (ARRA) last February. OCR officials have stated that they are working to publish the next set of regulations regarding these new breach notifications before the end of August, 2009.
In addition to adding the breach notification requirements, the HITECH Act also tightened the HIPAA mandates in several other respects. Among other things, it amended HIPAA to:
- Broaden the applicability of the HIPAA’s Privacy Rules and penalties to include business associates;
- Clarify that HIPAA’s criminal sanctions apply to employees or other individuals that wrongfully use or access PHI held by a covered entity;
- Increase criminal and civil penalties for HIPAA Privacy Rules violators;
- Allow State Attorneys General to bring civil damages actions on behalf of certain state citizens who are victims of HIPAA Privacy and Security Rule violations;
- Modify certain HIPAA use and disclosure and accounting requirements and risks;
- Prohibits sales of PHI without prior consent;
- Tighten certain other HIPAA restrictions on uses or disclosures;
- Tighten certain HIPAA accounting for disclosure requirements;
- Clarify the definition of health care operations to excludes certain promotional communications; and
- Expand the Business Associates Agreement Requirements.
These and other developments make it imperative HIPAA covered entities and their business associates take prompt action to immediately review and update their data security and privacy practices to guard against growing liability exposures under HIPAA and other federal and state laws. Covered entities must update policies and practices to avoid these growing liabilities. Business associates that have not already done so also must appoint privacy officers and adopt and implement privacy and data security policies and procedures fully compliant with HIPAA and other applicable federal and state rules, including amendments enacted as part of the American Recovery and Reinvestment Act of 2009 signed into law on February 17, 2009.
For more information about today’s announcement, see here. See here for the initial guidance and request for comments issued by HHS regarding these new security standards.
Chair Elect of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, and Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice, Cynthia Marcotte Stamer is nationally and internationally recognized for her work assisting businesses, employee benefit plan fiduciaries and vendors, governments, and other entities to develop administer and defend cost-effective employee benefit other human resources programs, policies and procedures to meet their budgetary, risk management and compliance and other objectives. Board certified in Labor & Employment law, Ms. Stamer applies her extensive experience regarding employment, employee benefit, tax, privacy and data security and other related laws to assists clients in a wide range of business and litigation contexts. The co-founder of the Solutions Law Consortium, Ms. Stamer also makes extensive use of cloud computing and other technology in her own practice and provides input to human resources and other clients others about the use of these and other technology tools to manage employee benefit, human resources, internal controls and other operations. In connection with this work, Ms. Stamer has works, writes and consults extensively with a diverse range of clients about the development, use technology and other processes to streamline health and other benefit, payroll and other human resources, employee benefits, tax, compliance and other business processes and the management and protection of sensitive personal and other information and data.
If your organization or employee benefit plan needs assistance managing or evaluating options or responsibilities associated with the use of technology and data in connection with its health care, employee benefits, tax or other operation or other human resources, employee benefits or and compliance concerns, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see here.
More Information & Resources
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here /the Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press HR & Benefits Update distributions here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on HHS Reassignment Of HIPAA Enforcement Duties Signals Rising Seriousness of Enforcement Commitment |
Employee Benefits, HIPAA, Human Resources, Insurance, Internal Controls, Privacy | Tagged: Employee Benefits, Employer, Employers, ERISA, GINA, Health Care Reform, Health Insurance, Health Plans, HIPAA, Human Resources, Insurance, Insurer, Internal Controls, Managed Care, Medical Coverage, Privacy, Risk Management |
Permalink
Posted by Cynthia Marcotte Stamer
July 29, 2009
Cynthia Marcotte Stamer will speak about “Technology Issues for Tax Attorneys and their Clients” on September 26, 2009 at the American Bar Association 2009 Fall Joint Tax Meeting in Chicago.
The September 26 program will feature a panel discussion of:
- Research tools, anti-virus, encryption and other technology practice aids, tools and tricks tax practitioners;
- IRS, DOL and other rules impacting opportunities for employers and employee benefit plan administrators to use electronic communications to reduce employment and employee benefit plan communication expenses;
- Electronic communications with government agencies and the need to be prepared to provide electronic records for tax audits;
- Expanding personal information privacy and data security considerations; and
- More.
Moderated by Frank Palmieri of Palmieri & Eisenberg, Alexandria, VA, the confirmed panelists include:
- Catherine Sanders Reach of the American Bar Association, Chicago, IL;
- Cynthia Marcotte Stamer of Curran Tomko Tarksi LLP, Dallas, TX;
- Joy M. Mercer of Joy M. Mercer, PC, Florham Park, NJ; and
- Danny A. Martin, Jr. of Shell Oil Company, Houston, TX.
The session is scheduled to take place from 2:30 p.m. – 4:00 p.m. on Saturday, September 26, 2009. To register for the meeting or other details, see here.
Chair Elect of the American Bar Association RPTE Employee Benefits & Compensation Committee, an ABA Joint Committee on Employee Benefits Council member, and Chair of the Curran Tomko Tarski Labor, Employment & Employee Benefits Practice, Cynthia Marcotte Stamer is nationally and internationally recognized for her work assisting businesses, employee benefit plan fiduciaries and vendors, governments, and other entities to develop administer and defend cost-effective employee benefit other human resources programs, policies and procedures to meet their budgetary, risk management and compliance and other objectives. Board certified in Labor & Employment law, Ms. Stamer applies her extensive experience regarding employment, employee benefit, tax, privacy and data security and other related laws to assists clients in a wide range of business and litigation contexts. The co-founder of the Solutions Law Consortium, Ms. Stamer also makes extensive use of cloud computing and other technology in her own practice and provides input to human resources and other clients others about the use of these and other technology tools to manage employee benefit, human resources, internal controls and other operations. In connection with this work, Ms. Stamer has works, writes and consults extensively with a diverse range of clients about the development, use technology and other processes to streamline health and other benefit, payroll and other human resources, employee benefits, tax, compliance and other business processes and the management and protection of sensitive personal and other information and data.
If your organization or employee benefit plan needs assistance managing or evaluating options or responsibilities associated with the use of technology and data in connection with its health care, employee benefits, tax or other operation or other human resources, employee benefits or and compliance concerns, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see here.
More Information & Resources
You can review other recent human resources, employee benefits and internal controls publications and resources and additional information about the employment, employee benefits and other experience of Ms. Stamer here /the Curran Tomko Tarski LLP attorneys here. If you or someone else you know would like to receive future updates about developments on these and other concerns, please be sure that we have your current contact information – including your preferred e-mail – by creating or updating your profile here or e-mailing this information to Cstamer@CTTLegal.com or registering to participate in the distribution of these and other updates on our Solutions Law Press HR & Benefits Update distributions here. For important information concerning this communication click here. If you do not wish to receive these updates in the future, send an e-mail with the word “Remove” in the Subject to support@SolutionsLawyer.net.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Stamer, Others To Discuss Technology Use/Risks in Employee Benefits, Tax & HR Consulting & Administration |
Employee Benefits, Employers, Employment Tax, ERISA, Health Plans, Income Tax, Internal Controls, Privacy, Professional Liability, Risk Management, Tax, Wage & Hour | Tagged: Data Security, Employee Benefit Communications, Employee Benefits, Health Care, Health Plans, Privacy, Retirement Plans, Tax, Technology |
Permalink
Posted by Cynthia Marcotte Stamer
June 9, 2009
Amid soaring health care costs and tightening corporate budgets, employers and other group health plan sponsors, fiduciaries and administrations now also must update their group health plan eligibility and enrollment practices to comply with the American Recovery and Reinvestment Act of 2009 (the “Stimulus Bill”), COBRA subsidy mandates, HIPAA special enrollment rule amendments and a host of other changes to federal eligibility mandates that already have or will take effect this year. Meanwhile, employers must keep a careful watch on Congress as it considers enacting sweeping health care reforms that are likely to place more obligations on employers.
Health plan eligibility design and administration plays a critical role in controlling health benefit costs and is a leading and growing source of health plan legal risk for employers, fiduciaries and administrators. Understanding and properly managing these concerns is imperative for employers and others sponsoring or administering these programs.
Stamer Discusses Health Plan Eligibility Rules June 23
Cynthia Marcotte Stamer will explain newly effective COBRA Subsidy Rules, genetic information nondiscrimination rules and other recent and impending changes to federal health plan eligibility mandates will be explained on June 23, 2009 during a 2009 Health Plan Eligibility Update briefing hosted by the Dallas Human Resources Management Association including:
Cynthia Stamer will explain to attendees what they need to know and do about:
- New Stimulus Bill COBRA Subsidy Rules and other special COBRA rules that took effect on February 17
- New GINA group health plan information scheduled to take place in 2009
- Changes to HIPAA special enrollment and nondiscrimination rules
- Implications for group health plans based on recent changes to FMLA and USERRA regulations
- Medicare, Medicaid and CHIP nondiscrimination rules
- Impending college student continuation mandates
- And more….
Get details or register on line here or by telephoning Dallas Human Resources Management Association at 214-631-8775.
Stamer’s Health Plan Experience Extensive
The immediate past Chair of the American Bar Association’s Managed Care & Insurance Section, Cynthia Marcotte Stamer is a highly regarded legal advisor, author and speaker recognized both nationally and internationally for her expertise in the areas of health benefits and other human resource compliance matters. Board Certified in Labor and Employment Law by the Texas Board of Legal Specialization, “Cindy” recently joined Curran Tomko Tarski, LLP as the Chair of its Labor & Employment and Health Care Practices April 1, 2009.
The Managing Editor of Solutions Law Press and an Editorial Advisory Board Member and author for Employee Benefit News and other publications, Ms. Stamer is a widely published author and popular speaker. In addition to hundreds of publications on health plan and other human resources, employee benefit and internal controls issues, Ms. Stamer is the author of the “Health Plan Eligibility Toolkit.” Her work has been featured and published by the American Bar Association, BNA, SHRM, World At Work, Employee Benefit News and the American Health Lawyers Association. Her insights on human resources risk management matters have been quoted in The Wall Street Journal, the Dallas Business Journal, Managed Care Executive, HealthLeaders, Business Insurance, Employee Benefit News and the Dallas Morning News.
Ms. Stamer also serves in a number of professional leadership roles including the leadership council of the ABA Joint Committee on Employee Benefits, Vice Chair of the ABA Real Property, Probate & Trust Section and Employee Benefits & Compensation Group.
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other health plan and other employee benefit, labor and employment, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer via e-mail here, or by calling (214) 270-2402. For additional information about the experience, services, publications and involvements of Ms. Stamer specifically or to access some of her many publications, see here, For more information and other members of the Curran Tomko Tarksi, LLP team, see the Curran Tomko Tarski Website.
We hope that this information is useful to you. For additional information about the experience, services, publications and involvements of Ms. Stamer specifically or to access some of her many publications, see here, For more information and other members of the Curran Tomko Tarksi, LLP team, see the Curran Tomko Tarski Website.
You can register to receive future updates and information about upcoming programs, access other publications by Ms. Stamer and access other helpful resources here. If you or someone else you know would like to receive updates about developments on these and other human resources and employee benefits concerns, please be sure that we have your current contact information – including your preferred e-mail- by creating or updating your profile at here. If you would prefer not to receive these updates, please send a reply e-mail with “Remove” in the subject line to support@SolutionsLawyer.net. You also can register to participate in the distribution of these updates by registering to participate in the Solutions Law Press HR & Benefits Update Blog here.
©2009 Cynthia Marcotte Stamer. All rights reserved.
Comments Off on Registration Open For June 23 Dallas HR 2009 Health Plan Eligibility Update Program |
Absenteeism, ADA, COBRA, Disease Management, Employee Benefits, Employers, Employment Tax, ERISA, family leave, GINA, Health Care Reform, Health Plans, Human Resources, Income Tax, Insurance, Internal Controls, medical leave, Military Leave, Privacy, Risk Management, Stimulus Bill, Tax | Tagged: ADA, COBRA, Corporate Compliance, Disability Discrimination, Employee Benefits, Employer, Employers, Employment, Employment Agreements, ERISA, Health Insurance, HealthP Plans, Human Resources, Insurance, Insurer, Internal Controls, Labor, Managed Care, Medical Coverage, Military Leave, Occupational Injury, Premium Subsidy, Risk Management, Stimulus Bill, Subsidy Bill, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
May 21, 2009
New restrictions on the collection, use and disclosure of genetic information applicable to employer and union-sponsored group health plans enacted under Title I of the Genetic Information Nondiscrimination Act of 2008, Public Law No. 110-233 (GINA) for group health plan years that begin on or after today (May 21, 2009). For non-calendar year plans with plan years beginning between June 1 and December 1, the effective date occurs on first day of their 2009 plan year. For example, the effective date will be June 1, 2009 for a plan with a 2009 plan year that begins June 1. For calendar year plans, the compliance deadline is January 1, 2010. All employer-sponsored group health plans are required to comply with GINA. There are no small group exceptions.
GINA In A Nutshell
GINA amended federal law to include specific prohibitions against certain discrimination based on genetic information by group health plans and health insurers (Title I) and to prohibit discrimination based on genetic information by employers of 15 or more employees (Title II).
Effective for all group health plan years beginning on or after May 21, 2009, GINA’s new restrictions on the collection and use of genetic information by group health plans added under Title I of GINA are accomplished through the expansion of a series of already existing group health plan nondiscrimination and privacy rules. GINA’s group health plan provisions amend and expand the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), Title VII of the Civil Rights Act, the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act to implement sweeping new federal restrictions on the collection, use, and disclosure of information that falls within its broad definition of “genetic information” by group health plans. For individual health insurers, GINA’s restrictions take effect May 22, 2009. The broad definition of the term “genetic information” in GINA will require group health plan sponsors and insurers to carefully review and update their group health plan documents, communications, policies and practices to comply with forthcoming implementing regulations to avoid liability under new GINA’s rules governing genetic information collection, use, protection and disclosure in a series of areas.
Meanwhile, employers, unions and others face their own new prohibitions against genetic information based employment discrimination added by Title II of GINA, which take effect November 21, 2009. The Equal Employment Opportunity Commission (EEOC) published proposed regulations interpreting Title II of GINA in March, 2009.
Broad Definition of “Genetic Information”
The broad range of information included within GINA’s broad definition of “genetic information” means its new restrictions have a sweeping reach when applied to most group health plans. GINA defines “genetic information to include with respect to any individual, information about:
- Such individual’s genetic tests;
- The genetic tests of family members of such individual; and
- The manifestation of a disease or disorder in family members of such individual.
GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology.
Pending issuance of regulatory guidance, GINA’s inclusion of information about the “manifestation of a disease or disorder in family members” raises potential challenges for a broad range of group health plan health assessment and other wellness and disease management programs which provide financial incentives or condition eligibility on the provision of family health histories or other information that could be construed as genetic information.
Group Health Plan Genetic Testing Collection and Nondiscrimination Rules
Under GINA’s nondiscrimination rules, group health plans and health insurers may not:
- Request, require or purchase genetic information for underwriting purposes or in advance of an individual’s enrollment;
- Adjust premiums or contribution amounts of the group based on genetic information;
- Request or require an individual or family member to undergo a genetic test except in limited situations specifically allowed by GINA;
- Impose a preexisting condition exclusion based solely on genetic information, in the absence of a diagnosis of a condition;
- Discriminate against individuals in eligibility and continued eligibility for benefits based on genetic information; or
- Discriminate against individuals in premium or contribution rates under the plan or coverage based on genetic information, although such a plan or issuer may adjust premium rates for an employer based on the manifestation of a disease or disorder of an individual enrolled in the plan.
GINA also prohibits insurers providing individual health insurance from establishing rules for eligibility, adjusting premiums or contribution amounts for an individual, imposing preexisting condition exclusions based on, requesting or requiring individuals or family members to undergo genetic testing.
Of particular concern to many plan sponsors and fiduciaries are the potential implications of these new rules on existing wellness and disease management features group health plans. Of particular concern is how regulators will treat the collection of family medical history and certain other information as part of health risk assessments used in connection with these programs. Although official guidance is still pending, many are concerned that regulators will construe certain commonly used practices of requiring covered persons to provide family medical histories or other genetic information through health risk assessments (HRAs) to qualify for certain financial incentives as a prohibited underwriting practice under GINA. Even where health risk assessments are not used, however, most group health plan sponsors should anticipate that GINA will require specific amendments to their plan documents, communications and processes.
Taking timely action to comply with these nondiscrimination and collection prohibitions is important. Under amendments to ERISA made by GINA, group health plan noncompliance can create significant liability for both the plan and its sponsor. Participants or beneficiaries will be able to sue noncompliant group health plans for damages and equitable relief. If the participant or beneficiary can show an alleged violation would result in irreparable harm to the individual’s health, the participant or beneficiary may not have to exhaust certain otherwise applicable Department of Labor administrative remedies before bringing suit. In addition to these private remedies, GINA also authorizes the imposition of penalties against employers and other sponsors of group health plans that violate applicable requirements of GINA of up to $500,000. The minimum penalties generally are set at the greater of $100 per day or a minimum penalty amount ranging from $2,500 for de minimus violations corrected before the health plan received notice of noncompliance to $15,000 in cases in which the violations are more than de minimus. GINA also includes language allowing the Secretary of Labor to reduce otherwise applicable penalties for violations that could not have been identified through the exercise of due diligence or when the plan corrects the violation quickly.
GINA Amendments To Health Plan Privacy Rules Under HIPAA
In addition to its nondiscrimination rules, GINA also amends HIPAA to make clear that “genetic information” as defined by HIPAA is protected health information protected by HIPAA’s Privacy & Security Standards of HIPAA. This means that it will require that all genetic information be treated as protected health information subject to the Privacy and Security Standards applicable to group health plans covered by HIPAA. Although the statutory provisions that accomplish these changes are deceptively simple, compliance with these requirements likely will require group health plans and their business associates to amend existing privacy policies, notices and practices to appropriately restrict disclosures for underwriting, operations and certain other uses to withstand scrutiny under the GINA privacy rule amendments.
The HITECH Act amended and increased civil penalties for HIPAA privacy violations in many circumstances effective February 17, 2009.
Regulatory Guidance Status
As the the deadline for compliance for post May 20, 2009 plan years is rapidly approaching, however, many group health plans and their sponsors will need forward with their compliance arrangements in the absence of regulatory guidance interpreting these requirements.
GINA’s fractured assignment of responsibility and authority to develop, implement and enforce regulatory guidance of its genetic information rules can create confusion for parties involved in compliance efforts. Because the group health plan requirements of Title I of GINA are refinements to the group health plan privacy and nondiscrimination rules previously enacted as part of HIPAA, GINA specifically assigned authority to construe and enforce its group health plan requirements to the agencies responsible for the interpretation and enforcement of those original rules:
- The Department of Labor Employee Benefit Security Administration (EBSA);
- The Internal Revenue Services (IRS), and
- The Department of Health & Human Services.
While these three agencies previously published a request for public comments about issues under Title I’s provisions, see http://edocket.access.gpo.gov/2008/pdf/E8-24194.pdf, none of these three agencies as of May 20, 2009 has published interim or other regulations interpreting the GINA provisions within their scope of responsibility since the formal comments period ended December 9, 2009. Although the EBSA Spring 2009 regulatory agenda reflected it intended to publish interim regulations by today and agency officials continue to indicate they intend to publish guidance “soon,” no guidance had been published as of May 20, 2009.
Even if the agencies issue guidance by the end of May plan sponsors and administrators of group health plans with new plan years beginning in the next 60 to 90 days are expressing concern that they will have inadequate time to complete compliance arrangements. As a result, in addition to guidance about GINA’s requirements generally, some are hopeful that the guidance with include transition rules or other relief to allow more time to comply with the regulations when finally issued. Regulators as of May 20, 2009 had not given any indication that they plan or perceive that they are authorized to provide such relief.
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the http://www.cttlegal.com.
Other Information & Resources
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at e-mail, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the Curran Tomko Tarski Website or Cynthia Marcotte Stamer, P.C. Website.
We hope that this information is useful to you. You can register to receive future updates and information about upcoming programs, access other publications by Ms. Stamer and access other helpful resources at CynthiaStamer.com For additional information about Ms. Stamer and her experience, see here or contact Ms. Stamer directly. If you or someone else you know would like to receive updates about developments on these and other human resources and employee benefits concerns, please be sure that we have your Currant contact information – including your preferred e-mail- by creating or updating your profile at CynthiaStamer.com. If you would prefer not to receive these updates, please send a reply e-mail with “Remove” in the subject line to support@SolutionsLawyer.net. You also can register to participate in the distribution of these updates by registering to participate in the Solutions Law Press HR & Benefits Update Blog here.
©Cynthia Marcotte Stamer. All rights reserved.
Comments Off on New GINA Health Plan Nondiscrimination Rules Effective For Plan Years Beginning On or After Today |
Corporate Compliance, EEOC, Employee Benefits, Employers, GINA, Health Plans, Privacy, Risk Management, Wellness | Tagged: Corporate Compliance, Disability Discrimination, Disease Management, Employee Benefits, Employer, Employers, Employment, ERISA, GINA, Health Insurance, Health Plans, Human Resources, Insurance, Insurer, Managed Care, Medical Coverage, Risk Management, Tax |
Permalink
Posted by Cynthia Marcotte Stamer
May 13, 2009
Recent concerns over the H1N1 Swine Flu (swine flu) pandemic and warnings of a possible resurgence of the swine flu pandemic or some other pandemic in the future is forcing many employers to question when concerns that an employee suffers from a contagious disease can justify the employer making inquires about the health of an employee or the exclusion of the employee from the workplace. New guidance set forth in the “U.S. Equal Employment Opportunity Commission ADA-Compliant Employer Preparedness For the H1N1 Flu Virus” (Guidance) published by the U.S. Department of Labor Equal Employment Opportunity Commission (EEOC) on May 4, 2009 provides some insights for employers about the EEOC’s perspective on these questions.
The Guidance details the EEOC’s answers to certain basic questions about when the EEOC views certain workplace preparation strategies for responding to the 2009 flu virus as compliant with the Americans with Disabilities Act (ADA). Employers considering updates to their current pandemic and infectious disease response plans are cautioned that in addition to potential ADA exposures, practices for periods after November 21, 2009 also generally must be tailored to comply with new restrictions on employer’s collection of and discrimination based on genetic information based on the Genetic Information Nondiscrimination Act of 2008 (GINA). Proposed regulations interpreting the employment provisions of GINA published by the EEOC in March 2009 do not specifically address the implications of GINA on employer planning or response to pandemic concerns.
ADA Concerns Apply To Employers Planning For & Applying Swine Flu Response
Title I of the Americans with Disabilities Act (ADA) protects applicants and employees from disability discrimination. Among other things, the ADA regulates when and how employers may require a medical examination or request disability-related information from applicants and employees, regardless of whether the individual has a disability. The Guidance confirms that the EEOC views this requirement as affecting when and how employers may request health information from applicants and employees regarding H1N1 flu virus.
Effective January 1, 2009, Congress amended the Americans with Disabilities Act pursuant to the Americans with Disabilities Act Amendments Act of 2008 (ADAAA) to change the way that the ADA’s statutory definition of the term “disability” historically has been interpreted by certain courts. The ADAAA amendments generally are intended and expected to make it easier for certain individuals to qualify as disabled under the ADA. While the Guidance announces that the EEOC intends to revise its ADA regulations to reflect the broader group of persons protected as disabled under the ADAAA amendments, it also indicates that the EEOC does not perceive that the ADAAA changes the actions prohibited by the ADA as they relate to common pandemic planning and response activities. Consequently, the Guidance states that the EEOC views the guidance in “Disability-Related Inquiries & Medical Examinations of Employees Under the ADA” published by the EEOC in 2000 and its “Enforcement Guidance: Preemployment Disability-Related Questions & Medical Examinations” published in 1995 as setting forth the governing rules for medical testing, inquires and other pandemic response planning under the ADA.
Under the ADA, an employer’s ability to make disability-related inquiries or require medical examinations is analyzed in three stages: pre-offer, post-offer, and employment.
- At the first stage (prior to an offer of employment), the ADA prohibits all disability-related inquiries and medical examinations, even if they are related to the job.
- At the second stage (after an applicant is given a conditional job offer, but before s/he starts work), an employer may make disability-related inquiries and conduct medical examinations, regardless of whether they are related to the job, as long as it does so for all entering employees in the same job category.
- At the third stage (after employment begins), an employer may make disability-related inquiries and require medical examinations only if they are job-related and consistent with business necessity.
- The ADA requires employers to treat any medical information obtained from a disability-related inquiry or medical examination (including medical information from voluntary health or wellness programs), as well as any medical information voluntarily disclosed by an employee, as a confidential medical record. Employers may share such information only in limited circumstances with supervisors, managers, first aid and safety personnel, and government officials investigating compliance with the ADA.
Employers deviating from these requirements when administering their pandemic planning or response risk disability discrimination liability under the ADA unless they otherwise can defend their action under one of the exceptions to the ADA’s disability discrimination prohibitions. When making post-offer inquiries or requiring post offer examinations or imposing other conditions for safety reasons, the Guidance and EEOC in unofficial discussions have emphasized the importance of the employer’s ability to demonstrate the job or safety relevance of the medical inquiry or examination based on credible scientific evidence such as the latest scientific evidence available from the World Health Organization (WHO) and the Centers for Disease Control and Prevention (CDC).
Other than emphasizing the importance of acting appropriately in response to credible scientific evidence and pointing to preexisting guidance, the Guidance does not extensively address with specificity the circumstances under which the EEOC will view any particular action taken by an employer as defensible under the safety or other exceptions of the ADA. Likewise, the Guidance does not discuss in any details the conditions, if any, under which the EEOC would view suffering, a history of suffering or association with or exposure to swine flu as qualifying an individual as disabled or perceived to be disabled for purposes of the ADA. Consequently, employer must rely on other less specifically tailored guidance for purposes of assessing the defensibility of a proposed action on these grounds.
Planning for Absenteeism Under ADA
When planning for a possible pandemic, employers must be careful about when and how they ask employees about factors, including chronic medical conditions that may cause them to miss work in the event of a pandemic. According to the Guidance, an employer may survey its workforce to gather personal information needed for pandemic preparation if the employer asks broad questions that are not limited to disability-related inquiries. An inquiry would not be disability-related if it identified non-medical reasons for absence during a pandemic (e.g., mandatory school closures or curtailed public transportation) on an equal footing with medical reasons (e.g., chronic illnesses that weaken immunity). The Guidance includes a sample of what the EEOC views as ADA-compliant survey that could be given to all employees before a pandemic.
The Guidance also indicates that where appropriate safeguards are applied to comply with the ADA, it also may be appropriate for an employer under certain limited circumstances, to require entering employees to have a medical test post-offer to determine their exposure to the influenza virus. According to the EEOC, the ADA permits an employer to require entering employees to undergo a job relevant medical examination after making a conditional offer of employment but before the individual starts work, if all entering employees in the same job category must undergo such an examination. Thus, the Guidance reflects that the requirement by an employer as part of its pandemic influenza preparedness plan that all entering employees in the same job categories undergo the same post offer medical testing for the virus in accordance with recommendations by the WHO and the CDC in response to a new influenza virus may be ADA-compliant.
Infection Control in the Workplace Under the ADA
The Guidance also discusses the EEOC’s perceptions about the ADA implications of employer use of certain infection control practices in the workplace during a pandemic provided that the requirements are applied in a nondiscriminatory fashion consistent with the ADA. For instance, the Guidance states that employers generally may apply with following infection control practices without implicating the ADA:
- Require all employees to comply with certain infection control practices, such as regular hand washing, coughing and sneezing etiquette, and tissue usage and disposal without implicating the ADA;
- May require employees to wear personal protective equipment provided that where an employee with a disability needs a related reasonable accommodation under the ADA (e.g., non-latex gloves, or gowns designed for individuals who use wheelchairs), employer provides these accommodations absent undue hardship;
- Encourage or require employees to telework as an infection-control strategy, based on timely information from public health authorities about pandemic conditions or offer telework as a possible reasonable accommodation.
In all cases, of course, the Guidance cautions that employers must not single out employees either to telework or to continue reporting to the workplace on a basis prohibited by the ADA or any of the other federal Equal Employment Opportunity laws.
Impending GINA Rules
As signed into law, GINA amends Title VII of the Civil Rights Act, the Health Insurance Portability and Accountability Act of 1996 (HIPAA), the Employee Retirement Income Security Act of 1974 (ERISA), the Public Health Service Act, the Internal Revenue Code of 1986, and Title XVIII (Medicare) of the Social Security Act to implement sweeping new federal restrictions on the collection, use, and disclosure of “genetic information” by employers, employment agencies, labor organizations, joint labor-management committees, group health plans and insurers and their agents. GINA’s group health plan restrictions are scheduled to take effect May 21, 2009. The employment related genetic testing rules of GINA take affect November 21, 2009. Employers and other covered entities will need to carefully review and timely update their pandemic and other infectious disease response practices as well as their group health plan, family leave, disability accommodation, and other existing policies in light of these new federal rules.
Although EEOC has not finalized its implementing regulations for GINA yet, employers should anticipate that GINA will impact their pandemic and other related practices. The implications of GINA for employers and other entities covered by its provisions because of its broad definition of genetic information.
Under GINA, “genetic information” is defined to mean with respect to any individual, information about:
- Such individual’s genetic tests;
- The genetic tests of family members of such individual; and
- The manifestation of a disease or disorder in family members of such individual.
GINA also specifies that any reference to genetic information concerning an individual or family member includes genetic information of a fetus carried by a pregnant woman and an embryo legally held by an individual or family member utilizing an assisted reproductive technology.
Pending issuance of final regulatory guidance, Gina’s inclusion of information about the “manifestation of a disease or disorder in family members” raises potential challenges for a broad range of wellness and safety, leave, and other employment and benefit practices, particularly as apparently will reach a broader range of conditions than those currently protected under the disability discrimination prohibitions of the Americans With Disabilities Act (“ADA”).
Depending on the contemplated inquiry or practice, certain inquiries or actions intended for use as part of an employer’s pandemic preparedness or response activities could fall within the scope of GINA’s protections. For this reason, employers also should consider the potential treatment of a proposed pandemic preparation or response activity intended to be applied after GINA takes effect in light of GINA. Additionally, employers also should consider the risk that information collected under existing or previously applied pandemic or other infectious disease prevention and response activities might qualify for additional protection when GINA takes effect in November, 2009.
Other Resources
Businesses, health care providers, schools, government agencies and others concerned about preparing to cope with pandemic or other infectious disease challenges also may want to review the following resources authored by Curran Tomko Tarski LLP partner Cynthia Marcotte Stamer:
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402; or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the www.cttlegal.com.
Comments Off on EEOC GIVES EMPLOYERS LIMITED EMPLOYER GUIDANCE ABOUT ADA ISSUES IN SWINE FLU RESPONSE |
Absenteeism, ADA, Disease Management, EEOC, Employee Benefits, GINA, Health Plans, Human Resources, Internal Controls, Pandemic, Privacy, Risk Management, Swine Flu, Telecommuting | Tagged: ADA, Corporate Compliance, Disability Discrimination, Disease Management, Employee Benefits, Employers, Employment, ERISA, genetic testing, GINA, Health Insurance, Health Plans, Human Resources, Internal Controls, Labor, Light Duty, Medical Coverage, Pandemic, Risk Management, Swine Flu, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
May 12, 2009
The recent sentencing of a West Texas man on a child pornography conviction serves as an important reminder to employers of the need to consider the potential criminal exposures and responsibilities of their organization and its management under the Federal Sentencing Guidelines when an investigation of sexual harassment policy violations uncovers evidence that an employee may have engaged in the transmission or receipt of pornography on company computers or systems.
On May 8, 2009, U.S. District Judge Sam R. Cummings sentenced Rory Dale Worthan, of Big Spring, Texas, to 78 months in prison followed by a 30-year term of supervised release illegal possession of child pornography. Worthan pled guilty in January to one count of possession of child pornography. He admitted that on February 8, 2007, he had an image of child pornography on his computer’s hard drive that he had downloaded from the Internet. His conviction was part of a series of convictions resulting from a West Texas child pornography sting operation.
Although Worthan’s conviction related to his use of his personal computer system, statistics show that workplace access of child and other pornography during company hours is common. In fact, some studies report that 70 percent of all Web traffic to Internet pornography sites occurs between the traditional work hours of 9 a.m. and 5 p.m. See “Workplace Web Use: Give ‘em an inch …,” Douglas Schweitzer, SearchSecurity.com (Sept. 27, 2004).
While most employers already are aware of the substantial employment discrimination and sexual harassment liability exposures that employee access, possession and transmission of pornography and other sexually explicit or suggestive content can create under Title VII and other federal and state employment discrimination laws, many are unaware that the use by employees of their computers to access, store, transmit or engage in other activities involving child pornography or other sexually explicit materials also may have criminal implications for their organization under certain circumstances.
As part of broader prohibitions against activities involving the sexual exploitation of minors, for instance under the U.S. Criminal Code, Title XVIII makes the creation, receipt, transmission possession, retention, transmission and certain other activities involving child pornography or certain other visual depictions involving the use or depiction of a minor engaging in sexually explicit conduct under certain circumstances a felony under federal law.
Under the organizational provisions of the Federal Sentencing Guidelines, a business that employs an employee or agent who engages in these activities during working hours or using company systems or equipment may face vicarious liability for the wrongful criminal actions by its employee in violation of these or other federal laws where the criminal action engaged in by the employee is a Felony or Class A misdemeanor. Under such circumstances, the liability exposure of the employer generally depends upon its ability to demonstrate that it had suitable policies and procedures in place to prohibit and prevent the activity, whether it timely investigated and took appropriate measures to report the violation to federal law enforcement officials and cooperate with them in their investigation and prosecution of the offending employee and other factors.
In addition to these criminal liability risks, employers also may face exposure to civil judgments in lawsuits brought by families of children victimized by employees using employer computers or operating systems. In Doe v. XYC Corp., 887 A.2d 1156 (N.J. Super. Ct. App. Div. 2005), for example, a New Jersey appellate court ruled that an employer could be held liable in a negligence action to a victim of child pornography based on the actions of one of its employees. In Doe, the wife of an employee who used his workstation computer at work to view and circulate nude photographs of his 10-year old stepdaughter sued the employer for negligence claim. The mother claimed the employer acted negligently by failing to detect and stop her husband from using his work computer to interact with child pornography Web sites, thereby allowing him to “continue clandestinely photographing and molesting” his 10-year-old stepdaughter.
For this reason, employers who uncover evidence that an employee or agent during working hours or using company equipment or systems may have created, received, transmitted, or stored child pornography or other sexually explicit materials must take prompt action to mitigate both their civil and criminal liability exposure. In addition to taking prompt action to prevent, investigate and discipline employees and agents that violate employer policies against using or possessing sexually inappropriate materials, businesses also should promptly seek the assistance of competent legal counsel to evaluate whether the prohibited conduct violated federal child pornography or other criminal laws. Where an investigation uncovers evidence of a potential violation of such laws, employers should seek assistance of counsel experienced with both employment and white collar criminal laws about the advisability of notifying federal law enforcement officials about that evidence and the best procedures to use to make those disclosures. In addition, employers should implement reasonable procedures to prevent and minor activities that may suggest employees or others granted access to company systems may be engaging in prohibited actions and take well documented action to investigate and redress this suspected misconduct.
As the monitoring and investigation of these concerns typically will require that an employer search or monitor employee e-mail or other files, employers also should ensure that they have in place appropriate privacy disclaimer, system use and background check and investigations that empower the employer to minimize potential exposures to privacy or other employment claims by employees or others whose e-mail or other files or activities are scrutinized in connection with these activities.
Chair of the Curran Tomko LLP Labor and Employment Practice and Board Certified in Labor & Employment Law by the Texas Board of Legal Specialization, Cynthia Marcotte Stamer regularly assists U.S. businesses to investigate and redress sexual harassment and other employment and internal controls matters. If your organization needs assistance with investigating or responding to a suspected sex discrimination or sexual harassment matter involving pornography or other suspected employee misconduct under company policies or applicable federal or state law, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402 or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarski, LLP team, see the www.cttlegal.com.
Comments Off on Some Sexual Harassment Policy Violations Carry Criminal Risks For Employers |
Corporate Compliance, EEOC, Employers, Internal Controls, Internal Investigations, Privacy | Tagged: Computer Use, Corporate Compliance, Corporate Ethics, Federal Sentencing Guidelines, Internal Investigations, Pornography, Risk Management, Sex Discrimination, Sex Disriminaioin, Sexual Harassment |
Permalink
Posted by Cynthia Marcotte Stamer
May 5, 2009
As the U.S. rushes to try to contain the spread of the swine influenza A (H1N1) virus infection (swine flu), businesses increasingly are facing employee leave requests and other employment and operational disruptions plans caused by school, day care or other closures and other business disruptions resulting from efforts to contain the disease while also working to take appropriate steps to prevent the spread of the disease within their own organizations.
Regardless of how deadly it ultimately proves to be, the pandemic proportion of the swine flu outbreak now ensures that most U.S. businesses will experience some disruption in operations as a result of the epidemic and efforts to contain it.
According to officials from the Centers for Disease Control and Prevention (CDC), as of 11:00 a.m. Eastern Time, 36 states had reported a total of 236 confirmed cases of swine flu and more cases are expected. That number includes the first U.S. swine flu fatality: a 22-month-old child from Mexico who died of the illness at a Houston, Texas hospital while visiting the United States last week. States currently hardest hit include New York (73 cases), Texas (41 cases), California (30 cases), Delaware (20 cases) and Arizona (17 cases). In the near future, however, CDC officials anticipate confirmed cases in all 50 states.
CDC officials and other experts continue to emphasize that the success of efforts to prevent the unnecessary spread of the disease depends largely on good health habits, limiting exposure to the virus and prompt diagnosis and treatment of afflicted persons. Employers can help reduce the risk that members of their workforce and their families will catch the virus by promoting good health habits and encouraging workers and their families to stay home and seek prompt treatment in the event of an illness. Simultaneously planning for and dealing with absences and other staffing challenges result from school, day care and other closings prevents a greater challenge for many employers, however.
Easy Preventive Safeguards
While the CDC says getting employees and their families to get a flu shot remains the best defense against a flu outbreak, it also says getting employees and family members to consistently practice good health habits like covering a cough and washing hands also is another important key to prevent the spread of germs and prevent the spread of respiratory illnesses like the flu. To help promote health habits within their workforce, many businesses may want to download and circulate to employees and families the free resources published by the CDC at http://www.cdc.gov/flu/protect/habits.htm. These and other resources make clear that Employers should encourage employees and their families to practice good health habits by telling employees and their families to take the following steps:
- Avoid close contact with people who are sick. When you are sick, keep your distance from others to protect them from getting sick too.
- Stay home when you are sick to help prevent others from catching your illness. Cover your mouth and nose.
- Cover your mouth and nose with a tissue when coughing or sneezing. It may prevent those around you from getting sick.
- Clean your hands to protect yourself from germs.
- Avoid touching your eyes, nose or mouth.
- Germs are often spread when a person touches something that is contaminated with germs and then touches his or her eyes, nose, or mouth.
- Practice other good health habits. Get plenty of sleep, be physically active, manage your stress, drink plenty of fluids, and eat nutritious food.
Many businesses are promoting these and other conducts that help prevent the spread of disease by sharing educational materials such as the growing range of free materials provided by the CDC and others available at the government sponsored website, http://www.pandemicflu.gov. For instance, business can access and download free copies of the following publications at http://www.cdc.gov/flu/protect/habits.htm:
- Cover Your Cough
- Be a Germ Stopper: Healthy Habits Keep You Well
- Flu Prevention Toolkit: Real People. Real Solutions
- Stopping the Spread of Germs at Home, Work & School
Dealing With Lost Time & Productivity Challenges
Businesses also should begin preparing backup staffing and production strategies to prepare for disruptions likely to result if a significant outbreak occurs. Whether or not the disease afflicts any of its workers, businesses can anticipate the swine flu outbreak will impact their operations -either as a result of occurrences affecting their own or other businesses or from workflow disruptions resulting from safeguards that the business or other businesses implement to minimize swine flu risks for its workforce or its customers.
For many employers, however, planning for and dealing with requests for time off or other workplace disruptions resulting from pandemic containment efforts presents special challenges. While most employers have well established policies and procedures for providing medical leave to employees during periods of their own or a family member’s illness under the Family & Medical Leave Act (FMLA) or otherwise, many employers are experiencing difficulty in responding to leave requests of healthy employees necessitated by school or day care closings, suspected exposures, or other pandemic response disruptions.
Certainly, whether or not legally mandated, the CDC and other official advisories make clear that sick employees should not be in the workplace. Employers of course must provide medical leave as required by the FMLA or other similar state laws as well as any contractually agreed to leave. To better insulate their workforce against potential exposure to the virus, however, many employers also may wish consider temporarily modifying existing leave or other work policies with an eye to better defending their workforce against a major outbreak. In this respect, employers need to consider both how to respond to the present wave of the virus and to plan for the possible need to respond to another potentially stronger outbreak of the swine flu virus that the CDC and other experts caution likely may arise in the Fall or Winter.
As part of their efforts to insulate their workplaces against exposure to the virus, employers generally should discourage workers from coming to work if they or a family member are experiencing symptoms or have been exposed to the virus. For this reason, businesses generally evaluate workplace policies or practices that may pressure or encourage employees with swine flu or any other contagious disease to report to work. Employers should consider whether the potential risks make advisable adjustments to their current attendance, telecommuting, leave and paid time off and other policies.
In light of the current situation, many businesses may want to consider temporarily adjust their leave, telecommuting and other policies in light of the impending health risk. For instance, recognizing that the decision to close a school or child care facility in response to a known or suspected infection seeks to minimize the spread of the disease through exposure to other then undiagnosed cases, businesses generally should think twice about allowing employees to bring these potentially exposed children into the workplace. Instead, employers may wish to consider being more flexible in allowing employees to work from home or take leave to care for children whose schools or child care facilities are closed due to concerns about possible exposure to reduce the risk of creating unnecessary exposure in their workplace.
To help minimize financial pressures on workers to report to work when they may be ill or exposed to the virus, many employers also may want to consider providing or offering short-term disability insurance, expanding the availability of paid or unpaid leave or both.
Regardless of the specific choices a particular business makes, businesses need to take appropriate steps to document, implement, and communicate their decisions. If considering allowing or requiring employees to work from home, employers need to implement appropriate safeguards to monitor and manage employee performance, and to protect the employer’s ability to comply with applicable wage and hour, worker’s compensation, safety, privacy and other legal and operational requirements. They also should review and update family and medical leave act and other sick leave policies, group health plan medical coverage continuation rules and notices and other associated policies and plans for compliance with existing regulatory requirements, which have been subject to a range of statutory and regulatory amendments in recent years.
If considering allowing or requiring employees to work from home, for instance, employers need to implement appropriate safeguards to monitor and manage employee performance, and to protect the employer’s ability to comply with applicable wage and hour, worker’s compensation, safety, privacy and other legal and operational requirements. They also should review and update family and medical leave act and other sick leave policies, group health plan medical coverage continuation rules and notices and other associated policies and plans for compliance with existing regulatory requirements, which have been subject to a range of statutory and regulatory amendments in recent years.
In light of the growing responsibilities and exposures of business to medical privacy and disability liabilities associated with knowledge, collection, protection and use of information about the health and medical conditions of workers and their families, businesses also should review and update their procedures regarding the use, collection, disclosure, and protection of this and other sensitive information. Businesses, health care providers, schools, government agencies and others concerned about preparing to cope with pandemic or other infectious disease challenges also may want to review the publication “Planning for the Pandemic” authored by Curran Tomko Tarski LLP partner Cynthia Marcotte Stamer available at http://www.cynthiastamer.com/documents/speeches/20070530%20Pan%20Flu%20Workplace%20Privacy%20Issues%20Final%20Merged.pdf. Schools, health care organizations, restaurants and other businesses whose operations involve significant interaction with the public also may need to take special precautions. These and other businesses may want to consult the special resources posted at http://www.pandemicflu.gov/health/index.html.
Cynthia Marcotte Stamer and other members of Curran Tomko and Tarski LLP are experienced with advising and assisting employers with these and other labor and employment, employee benefit, compensation, and internal controls matters. Ms. Stamer in particular has worked extensively with health care providers, government officials, and businesses to plan for and deal with pandemic and other absence, disease management and disaster preparedness concerns. If your organization needs assistance with assessing, managing or defending its wage and hour or other labor and employment, compensation or benefit practices, please contact Ms. Stamer at cstamer@cttlegal.com, (214) 270-2402, or your favorite Curran Tomko Tarski, LLP attorney. For additional information about the experience and services of Ms. Stamer and other members of the Curran Tomko Tarksi, LLP team, see the http://www.cttlegal.com.
Comments Off on Mitigating Workplace Fallout of Pandemic Response |
Absenteeism, COBRA, Disease Management, EEOC, Employee Benefits, Employers, Employment Agreement, ERISA, Health Plans, Human Resources, Insurance, Internal Controls, Pandemic, Privacy, Swine Flu, Telecommuting, Wellness | Tagged: Absenteeism, ADA, COBRA, Disability, Disability Discrimination, Disease Management, Employee Benefits, Employer, Employment, Employment Agreements, Family Leave, Health, Health Plans, Human Resources, Labor, Leave, Medical Coverage, Minimum Wage, Overtime, Paid Time Off, Pandemic, Privacy, PTO, Risk Management, Swine Flu, Wellness |
Permalink
Posted by Cynthia Marcotte Stamer
You must be logged in to post a comment.