Back

Explore every episode of the podcast 1st Talk Compliance

Dive into the complete episode list for 1st Talk Compliance. Each episode is cataloged with detailed descriptions, making it easy to find and explore specific topics. Keep track of all episodes from your favorite podcast and never miss a moment of insightful content.

Rows per page:

1–50 of 273

TitlePub. DateDuration
Medicare Advantage in the Crosshairs: Risk Adjustment, the False Claims Act, and AI16 Jul 202600:34:36
Fraud risks in Medicare Advantage, which now covers more than half of all Medicare beneficiaries, have been flagged as a top priority for government agencies. With that in mind, Rachel Rose, JD, MBA, joins the 1st Talk Compliance podcast to bring her expertise in False Claims Act litigation to the discussion on how best to avoid these risks, or run afoul of the DOJ or CMS. Listen now for firsthand insight into how these cases actually unfold and what providers can do to protect themselves and their practices.
The Importance of the OIG’s Exclusions List16 Jun 202600:19:39
In this episode of 1st Talk Compliance, Kevin Chmura is joined by Mike Herold to discuss the crucially important LEIE. The LEIE, or List of Excluded Individuals or Entities, also known as the OIG Exclusions List, is a fundamental piece of any medical practice’s compliance program. Yet so few people working in the healthcare space, even some compliance specialists, have never even heard of the list, or do not know the details of checking it.
Telehealth Extensions & 2026 Compliance Priorities: A Compliance Cliffs Update04 Feb 202600:19:51

In this episode of 1st Talk Compliance, Kevin Chmura is joined by Robyn Johns, as they discuss recent updates to their November live webinar, Compliance Cliffs: Navigating Telehealth Waivers and Reimbursement Changes.

Learn how the policy landscape has shifted in recent months—especially around telehealth flexibilities, controlled substance prescribing, and the 2026 CMS payment rules.

 


Kevin Chmura

Welcome to 1st Talk Compliance. I’m Kevin Chmura, CEO of Panacea Healthcare Solutions. Today we’re bringing you a timely update on our November live webinar, Compliance Cliffs: Navigating Telehealth Waivers and Reimbursement Changes.

Since that webinar, several policy changes have moved quickly, especially in telehealth flexibilities. Controlled substance prescribing and 2026 CMS payment rules. Before we jump in, just a quick note. 1st Talk Compliance is brought to you by 1st Healthcare Compliance, a part of Panacea Healthcare Solutions. We help healthcare organizations strengthen their compliance programs with practical education tools and compliance management support. So teams can reduce risk, keep pace with regulatory change and operate with confidence.

Now I’m pleased to welcome back Robyn Johns from Med USA.

Robyn, thanks for coming back.


Robyn Johns

Thanks, Kevin. I’m happy to be here.


Kevin Chmura 

Great. So, let’s jump in. So, in November on the webinar, we spent a lot of time on what people were calling the telehealth cliff, which was creating a tremendous amount of uncertainty on whether flexibilities would expire. Can you catch us
up on what the status is now?


Robyn Johns 

Yeah. The major update is that the spending package released on January 20th includes extensions of the telehealth flexibilities all the way through December 31st of 2027.


Kevin Chmura

So that’s a pretty meaningful runway. That’s great, but I guess doesn’t eliminate compliance obligations, but it is reducing near-term uncertainty which give everybody some time to standardize workflows. So, it’s in the news, but maybe you could tell. So, what’s in the spending package at a high level and what should healthcare leaders like us be paying attention to?


Robyn Johns  

Right. So, it was the one from the 20th was a $1.2 trillion spending package released by the House Appropriations Committee and it was just passed yesterday on the 22nd in two separate votes by the full House. So, those bills included the remaining six of the twelve appropriations necessary to avert a government shutdown. So that’s good news for everyone. If we can get them across the finish line, they funded many of the federal government agencies such as HHS, Labor, Defense, HUD, and also Homeland Security. That was a contentious one. That’s why they had to do two separate votes. It funds them through fiscal year 2026, which ends on September 30th of this year.


Kevin Chmura 

So, OK, so we have a funding package with multiple healthcare policy riders. Not, I guess not too surprising in today’s day and age. So, besides the telehealth through 2027, what else is included in there that compliance and operational leaders should know about?


Robyn Johns  

So the writers also include PBM reform and it extends hospital at home actually through 2030, which is another one that hit a lot of facilities hard with the government shutdown. It extends Medicare dependent hospital and low volume hospital programs, which is really beneficial for our rural providers and it delays the Medicaid disproportionate share cut again until fiscal year 2028. Notably, for a lot of people, it does not include an extension of the ACA subsidies, which were such a sticking point in the government shutdown last fall.


Kevin Chmura 

Yeah, that that that last point is operationally really important and coverage instability often turns into eligibility churn and puts real pair mix pressures on the you know same patients, different coverage, right.? And that’s just you know probably increases downstream compliance and documentation stress. Yeah that’s a that’s a tough one. So what’s the timing of congressional action now?


Robyn Johns

So with the House passing all of the bills, they now send the full appropriations package to the Senate. The Senate will take all of that up when they return from recess on Monday the 26th, and will hopefully pass them all ahead of the January 30th deadline. And hopefully without any significant changes which might require them to go back to the house because the house will be on recess next week.


Kevin Chmura 

Wow. So split schedule, it’s why we should keep ourselves in a monitoring posture. I guess we should always be monitoring, but things are moving pretty quickly right now and you sort of get into that world of what is expected is not what’s in effect.

Which is always, always a tough place to operate, but hey, that’s healthcare, isn’t it? So, given the extension to 2027, in your opinion, what should compliance teams be doing now? Like what’s some practical next steps?


Robyn Johns

First, you’ll want to make sure that your internal policies and educational materials reflect what’s currently in effect. No major changes since most of those telehealth things were extended, but it’s always good to double check because lots of things change around the beginning of the year. Also validate your payer specific rules. Medicare policy direction is influential, but commercial payers and state laws differ. So, you got to make sure that you are matching up with those differences. And then third, we should we talk about strengthening your auditing of documentation, the modifiers, your place of service, medical necessity, all of those things that can vary depending on the payer and the specific situation of the patient.


Kevin Chmura 

Yeah, that that payer variation point is where a lot of organizations end up being exposed, I guess, right? Telehealth’s not really governed by one rule. You’ve got federal policy, state overlays, and then you have commercial policy updates really coming at you a number of different ways. So, I guess a good controls to maintain maybe a payer policy matrix and try to align it into your documentation and coding guidance. Probably a solid piece of advice.


Robyn Johns  

Absolutely.


Kevin Chmura  

Yeah. So, let’s move on to probably one of the highest risk areas that we covered in the webinar, and that’s controlled substance prescribing via telehealth. What’s the latest there?


Robyn Johns  

Good news there as well. At the end of the year, DEA and HHS extended the telehealth flexibilities for prescribing controlled substances through this year, December 31st of 2026. There are a few rules that can apply, but because they extended the flexibilities, it’s pretty much status quo until they change it again at the end of the year.


Kevin Chmura  

Cool, so that’s a critical compliance area because of the high risk profile and it that really includes some regulatory scrutiny and enforcement, not really just a reimbursement issue.


Robyn Johns  

Yes, it’s highly watched.


Kevin Chmura  

Yeah. And I guess as well, it should be. So given that, what control should organizations prioritize right now to reduce risk in that area?


Robyn Johns 

Definitely you’ll want to have clear prescribing policies, good documentation standards, and role-based training. Also, usually they want to include identity verification and required checks when they’re applicable, and consistent auditing to ensure that your process is followed, not just written down. This is another area where state regulations can vary, so you would want to make sure that you are compliant in every state where you see patients.


Kevin Chmura  

Yes and you’re the expert, not me. But I guess I’d add if you expand health to if you expand the telehealth quickly, take time now to ensure your governance is mature. And I’m thinking credentialing, supervision, documentation and audit trails always the basics that can help you pulled up under scrutiny.


Robyn Johns  

Definitely. When you expand quickly, sometimes you sacrifice certain things for speed. So, you have a minute now to go back now that you’re sure that those policies aren’t changing anytime soon to just go back and make sure that everything’s in place, all of those areas.


Kevin Chmura 

Yeah, I mean like any business runs better and with certainty, but at healthcare we rarely have that. So, great. So, moving on to the 2026 CMS updates that that we talked about a little bit.

So, there’s been some changes in payment policy that are driving operational changes and it’s where those operational changes come in, where we introduce compliance risks if teams can’t keep pace and often they can’t. So, what are the 2026 physician fee schedule highlights?


Robyn Johns  

Yeah. So, we talked about these back in November and of course they went into place at the beginning of this year. So, a little bit of good news there with the conversion factor. It included the 2.5% increase that had been mandated by Congress. It also included a .75% increase for clinicians in advanced APMs or a
.25% increase for clinicians who participate in MIPS or who are exempt. And then there was also a .49 budget neutrality increase.


Kevin Chmura

So, so the real impact varies by payer mix, site of service and quality of participation. What about RVU related changes?


Robyn Johns  

So that’s kind of the devil in the details there. It also implemented a -2.5% efficiency adjustment on certain non-time based services to the physician work RVU and there is also a + or -50% practice expense RVU adjustment for facility based services. So, it’s -50% if it’s facility based services or a +50% for non-facility based services.


Kevin Chmura  

Wow. So site of service is increasingly strategic and it’s where we see compliance issues often arise, right? You get inconsistent documentation, coding and policy adoptions across different departments and locations. Certainly not easy.


Robyn Johns  

No. Something you definitely need to watch closely because it is different depending on where you are and what services you’re providing.


Kevin Chmura  

Yeah. So, one other hotspot or another hotspot that that we often see is incident to. What’s going on there?


Robyn Johns 

So the physician fee schedule in that they updated the definition of direct supervision for incident to billing to permanently allow supervision through real-time audio video communication except for services that have a 10 or a 90-day global surgery period. So, the supervising physician no longer has to be physically present in the office suite, they just have to be immediately available through real time audio video communication.


Kevin Chmura  

OK, so that’s operationally pretty significant, right? But I guess the compliance take away is relatively simple. If you’re using remote supervision, your incident to workflows must be precise. I guess who supervises, how it’s documented, and where the exceptions apply as precise as you can make all of those, huh?


Robyn Johns  

Yes, absolutely. Because you are relying on remote supervision, you’ll want to make sure that that is documented very effectively.


Kevin Chmura  

Yeah, cool. So, what about the OPPS and ASC final rule highlights for 2026?


Robyn Johns

Yeah. For those that these apply to, there was a 2.6% increase as well in the payment rates. They also expanded hospital price transparency requirements and we’re seeing a lot more attention and probably enforcement in that as well. There was a three-year phase out of the inpatient only list. Site neutral payments were expanded to include Drug Administration Services and the ASC covered procedures list is expanded much in relation to the inpatient only list Phase out.


Kevin Chmura

Yeah, that that that that’s an interesting one. So the phase out of the inpatient only list is a real operational shift and it’s one of those opportunities for providers to move volume to better cost locations, but really your compliance needs to follow those patients, right and where you’re having them. And so, when your volume moves, audits and education have to move with it, which is probably a challenge and what we know and we at our parent company, at Panacea, price transparency just remains a compliance and reputational priority because failures lead to penalties, but bad data also leads to a lot of scrutiny. So, good that there’s some, you know some guidance there, but it’s clear that those are going to be things that really need to be paid attention to from a compliance perspective.


Robyn Johns

Yes, for sure.


Kevin Chmura

So it was hard to watch the news over the last, I don’t know, six to twelve months without talking about the One Big Beautiful Bill Act. So, we’ve been tracking it. I know you’ve been tracking it. So, what’s the timing on practice impacts that you expect?


Robyn Johns

So most of those One Big Beautiful Bill Act Medicaid requirements that are likely to impact practices, they don’t actually begin until January of 2027. So, practices still have some time to continue their assessment and preparation for those. The immigrant eligibility changes do take effect on October 1st of this year, 2026. So that’s a little bit shorter period of time, but you do have a little bit of time to continue to figure out how that may affect your practice if you have a high number of Medicaid patients, and prepare for the ways that you can offset those eligibility changes and payment requirements.


Kevin Chmura

Yeah, that clarity on the effective dates really can help teams allocate resources correctly and that’s often a challenge especially when you’re tracking proposed rules versus final rules and not sure when things will go into effect. So that’s good. So, as you’re looking out on the landscape in 2026, what are some of your top compliance priorities that you’re advising organizations to focus on?


Robyn Johns

Yeah, we’re currently focused on probably five or so top priorities for 2026, not in any specific order, but we are watching data privacy and security. Part of that is because HIPAA updates are underway to both the privacy and security rules, though timelines are unclear. We’re not sure when or i f we’ll see any final rules on those, but we do know that healthcare remains a prime target of cyber-attacks, so we have to constantly be vigilant to that and related to that, but also separately, is AI and other emerging technologies.

AI is changing the landscape for the types of attacks we receive, but also the way we have to respond to them. It also is changing the landscape of healthcare generally, both in the provider office and at the payers and at the government. Those other emerging technologies like digital tools, those can increase the compliance risk in your environment, and we need to remember that both government and commercial payers are using AI to identify outlier claims faster and increase their auditing.

Then we also have the fraud, waste and abuse enforcement. CMS we know has currently been focused a lot on Medicare Advantage, but that scrutiny can shift oversight over to providers as well because that’s where so much of the data that the Medicare Advantage plans use comes from. The OID also continues to focus on telehealth. There are other focuses are drug device and biologics and program integrity areas such as DME, Hospice and Drug Administration. So, want to make sure that you’re watching all of those if you practice there.

Fourth one we have is vendor and third-party oversight. Many of the largest breaches that have we’ve seen have originated with third parties. So, organizations really need to make sure that you have careful oversight and maintain good monitoring on your third-party vendors and others who may have access to your systems and data.

And finally, we know we’re going to continue to see those rapid regulatory updates. Federal and state changes often conflict. We have lots of states that are currently in their legislative period. So that will bring out some changes. And then in addition to that, commercial payers are tightening their policies and auditing in response to the pressures that are being put on that on them, whether from the government or just from a financial perspective.


Kevin Chmura

Yeah, it is something the pace of acceleration of some of the advances in technology and how they how they’re going to impact us. But I guess you know that’s really the reality of 2026 and beyond. You’re going to see an uptick in in in speed to policy changes, faster detection, which will be something and probably more third-party exposure as we rely on more and more vendors and others to help us do what we need to do every day, but I’m sure you know the advice I’ve heard you give many times and we have to agree with it. A strong compliance program has to be built to adapt. That means clear governance, repeatable monitoring and targeted auditing tied to the current risk with an eye on the future and where everything’s going.


Robyn Johns

Yeah, definitely. It’s an exciting time, lots of opportunities for improving our programs and really tightening things up to make sure that we’re protecting ourselves and all the information that we are responsible for.


Kevin Chmura

Yeah, great. So, Robyn, thank you for the update and for helping our listeners translate policy movement into practical compliance actions. To everyone listening, if you want the full context and deeper discussion, you can access the webinar on demand at 1st Healthcare Compliance’s website. It’s called Compliance Cliffs:
Navigating Telehealth Waivers and Reimbursement Changes.

Thank you for listening to 1st Talk Compliance and we’ll see you next time. Thanks, Robyn.


Robyn Johns

Thanks, Kevin.

Update to the HIPAA Privacy Rule to Support Reproductive Healthcare Privacy Compliance14 Jul 202500:33:21

In this episode of 1st Talk Compliance, Kevin Chmura is joined by Rachel Rose, JD, MBA, as they discuss recent changes to the HIPAA Privacy Rule to Support Reproductive Health Care and Privacy in relation to recent court rulings. This rule, which went into effect in April of 2024, still has certain components which practices need to know about and adhere to heading into 2026.

Learn about how these rulings are, and will, impact this important rule, and what HIPAA regulated organizations need to know concerning these updates. In addition, hear about what might be coming in the future of not only reproductive health regulations, but also various other areas of healthcare with regards to privacy.

 

Kevin Chmura

Hello and welcome to today’s episode of First Talk Compliance. I’m your host, Kevin Chmura, CEO of First Healthcare Compliance and Panacea Healthcare Solutions. And I’m excited to bring you an important discussion about a major legal development that impacts all HIPAA regulated entities. By way of background, on June 18th, 2025, the U.S. District Court for the Northern District of Texas issued a nationwide order striking down the HIPAA Privacy Rule Amendments designed to strengthen reproductive health care privacy.

The amendments had been mandatory since December 2024, and this court decision has created a new compliance challenge for covered entities and business associates. To help us understand what happened, why it matters, and what organizations should do now, we’re joined by our expert guest. Rachel V. Rose, J.D. MBA, who’s a leading authority on HIPAA healthcare privacy law.

If you listen to our podcast, you’ve heard Rachel many times. In fact, we’ve discussed this particular topic, or issues around it, pretty recently. So it’s great to have her back. So, Rachel, welcome back. Thank you for coming to share your expertise with us today.

 

Rachel V. Rose

Kevin, it’s always my pleasure and thank you for having me back.

 

Kevin Chmura

Yeah, your content is always heavily consumed because it’s very important. So we thank you for being here. So, maybe probably best way to just start off is if I can ask you to just briefly explain what the U.S. District Court’s order did, why it’s significant and who it applies to?

 

Rachel V. Rose

Absolutely. So on June 18th of this year, the United States District Court for the Northern District of Texas, and specifically the Amarillo Division, in the case caption Carmen Purl et all v. United States Department of Health and Human Services et all. And for those who are interested, that case number is 224-CV-228-Z. And the Z, it correlates to the judge at any time you see initials or an initial after a case number, it’s the judge. And I’ll just simply refer to this case as the Purl case, P-U-R-L. Basically, what the court did was to issue an order vacating the April 16th, 2024 HIPAA Privacy Rule to Support Reproductive Health Care and Privacy.

And for simplicity’s sake, I’ll just call that the HIPAA Reproductive Privacy Rule. And basically what it did was to leave intact the requirements regarding the updates to the notice of privacy practices, which are due in early 2026. And to focus on that, there really hasn’t been any guidance yet from HHS. But every covered entity and business associate and subcontractor need to be aware that the notice of privacy practices updates, which really incorporate the HIPAA provisions along with 42 CFR part two regulations, are still in play, and the part two regulations specifically relate to the substance use disorder regulation.

So that’s something that again, covered entities, business associates and subcontractors should put on their calendar, and look for updates from First Healthcare Compliance, whenever HHS releases some more guidance related to what should be included. As many know who have been in healthcare a long time. Oftentimes HHS and SAMHSA, the Substance Abuse and Mental Health Services Administration, which oversees 42 CFR part two, will issue guidance or form types of agreements or other relevant compliance items. One great example is the Business Associate Agreement.

So that’s the part that should be calendar and people should make sure that they are staying abreast of. Now that brings us to what was vacated. And so basically, procedurally, the court granted the plaintiff’s motion for summary judgment. And for those non-lawyers, summary judgment is available when there is no issue of a material fact.

In essence, it is judgment as a matter of law, and in doing so, denied the defendants, which in this case is the United States Department of Health and Human Services motion, to dismiss for lack of jurisdiction. And the specific section that was vacated pursuant to five U.S.C. Section 7062, except for the modifications that I mentioned to C.F.R. Section 164.520 with the notice of privacy practices are the provisions associated with what were 45 C.F.R. section 1604 520b, 1, 2, F, G, and H. And so for those who were familiar with what was required under those particular items, that had to do with the reporting requirements and the attestation requirements under law, and that’s distinct from the law enforcement exception.

A couple of items that are also notable, Kevin, and other healthcare attorneys in the space have also honed in on this, is that the plaintiff indicated, and the court honed in on this, saying that under the Administrative Procedures Act that the government exceeded its rulemaking authority. However, a lot of lawyers are of the opinion that Congress merely barred rules that supersede state statutes, not those that add reasonable conditions.

And so that’s something that I want to emphasize too, as I normally do in our discussions that state laws cannot be overlooked.

 

Kevin Chmura

So that’s significant given that you and I not that long ago discussed some of the updates to HIPAA 2024 rules. So it’s interesting that we’re talking about it this soon thereafter, kind of thought that we were a little bit settled there. So maybe just do a quick check. Are there any other reproductive rights related lawsuits that are significant that that we should know about and be paying attention to?

 

Rachel V. Rose

I would say the one that is very prominent is the recent Supreme Court opinion in United States versus Skrmetti, the attorney general and reporter for the State of Tennessee. And what’s notable about that case is that it was a 6-3 opinion which upheld Tennessee’s ban on puberty blockers and hormone therapy for transgender teenagers.

Texas also actually had a similar law, and last year, in 2024, the Texas Supreme Court upheld a state law banning doctors from prescribing gender affirming care to transgender minors ,and a state policy expanding the definition of child abuse to include gender affirming care remains blocked following a state court of appeals decision last year. So notably, the court, actually, has agreed to hear a couple of other transgender related cases, including transgender, participation in female sports.

And so this is an area that should be read in conjunction with any HIPAA Privacy, any law enforcement exception, which is found under the HIPAA regulations at 164.51 Q, and just really be conscientious and cautious about what the individual states are requiring, as well as following the United States Supreme Court’s ruling. Because, this particular case, the court held that Tennessee’s law prohibiting certain medical treatments for transgender minors is not subject to heightened scrutiny under the equal protection clause of the 14th Amendment and satisfies rational basis review.

So whenever one looks at civil rights issues under a constitution analysis, we have what’s known as strict scrutiny. We have intermediate scrutiny, and then the lowest level of review is rational basis. Strict scrutiny, we typically see applied to those items that are expressly mentioned in the 1964 Civil Rights Act: race, gender, religion. And for those who read any employment agreement with the nondiscrimination provisions, those same items are included there as well.

Intermediate scrutiny is a level below, and then we have rational basis, which is the lowest level of review. I would also add that in relation to some of the 14th Amendment issues and strict scrutiny, one cannot overlook any executive order that is being issued right now. And as it relates to discrimination and the DEI initiatives, the executive orders that were published in January of 2025 that relate to this expressly upheld the Civil Rights Act of 1964.

So you still cannot run afoul of that.

 

Kevin Chmura

Wow. So just to clarify in question for non-attorney, because that’s amazing. So with respect to Skrmetti, or really any recent Supreme Court cases, well, any of those have or could have an impact on an appeal or the ultimate outcome of the parole case?

 

Rachel V. Rose

I think that’s a great question for three main reasons, Kevin. First and foremost, the Purl case. The judge used, as I mentioned earlier, the Administrative Procedures Act, and that’s very relevant because of the recent Supreme Court Trump versus Casa Inc. And what’s relevant about Casa Inc., even though that’s a completely different area of law, is that the Supreme Court case, Casa, basically held that nationwide injunctions are invalid and they cannot be issued.

They’re only specific to the individual parties to that case, right? That was brought, which typically makes sense whenever I’ve used in injunctive relief at the state court level, it’s to either get a temporary hold, so to speak, or to have conduct stop, but it only pertains to the parties. It doesn’t go beyond that. I can’t say every oil company, right, or every healthcare company is involved in this. And so basically what Casa did, and there’s been a lot of debate over nationwide injunctions by federal courts in their nationwide applicability for a very long time. So this issue really isn’t new. But Casa affirmatively stated that nationwide injunctions can no longer be issued, and they’re only specific to the parties.

What is relevant to the Purl case is that the court also discussed the Administrative Procedures Act and said this does not relate to the Administrative Procedures Act, and I believe it’s footnote ten in the Casa opinion that highlights that. And what’s notable is that even some of the entities who were involved in some of the nationwide injunctions honed in on that fact.

So will we see an appeal by the United States government? According to the HHS website, they’re evaluating their options. That’s the first item. The second item is since nationwide injunctions are now not permissible, how can a single district court’s ruling invalidate a particular regulation and have that apply to the rest of the country?

When, if even non-lawyers know if you’re in a particular jurisdiction? Typically the district court’s opinion is only binding not only on the parties, but it then becomes precedential within that particular district. So every other case that were to follow in the Northern district of Texas, for example, would have to cite the Purl case. Now up on appeal, once an appellate court rules on something, that then applies to every district court, which is under that particular circuit and then if the Supreme Court rules, as we saw in the Dobbs case, right. Which overturned Roe or Loper, which is the case. So the Loper Bright versus Raimondo case, which honed in on the Administrative Procedures Act and overturned the Chevron Doctrine, at least in part, the Supreme Court has the ultimate authority to invalidate a law or regulation as it may be applied across the entire country.

So I do think that we will see potentially the government appeal the district court’s opinion, although there’s a potential policy issue there. And then the other item is we could see other cases arise under this that challenge this district court out of a different circuit or district within the United States.

 

Kevin Chmura

It’s interesting and nationwide bans are a hot topic of late I’m sure in your world especially and so it’s, it is not necessarily always black and white as you point out, which is interesting maybe we can, that’s all super helpful. Perhaps we switch gears just a little bit and think through.

Okay. We know where we are right now. What should we be thinking about doing? So I guess maybe to frame it as a question with this order in place now, what should HIPAA regulated entities, covered entities, business associates alike, but what are they still required to do with respect to reproductive health information as it stands now?

 

Rachel V. Rose

Well, one item that stood out to me about the Purl case was the definition of a child. And I really do think there’s a lot of interplay there with a variety of different state laws, because even if you look at the United States Census Bureau, they do not include unborn individuals in the definition of a child. So a fetus is not included there.

Yet, Purl reached the opposite conclusion. Right? And the plaintiffs in the Purl case kind of raised that in the reporting of child abuse obligations. So to answer your question, what remains. First and foremost and for those individuals who are clients of First Healthcare Compliance, I created a revised FAQ regarding the Privacy Rule and basically, in light of the opinion as it stands now, because we have no other cases, we don’t have a Fifth Circuit opinion, we don’t have a United States Supreme Court opinion on the APA being able to be utilized at a district court level to overturn an entire statue and make it invalid.

I would recommend that individuals put a placeholder on what was previously required to be implemented by December of 2024, with the exception of those notice of privacy practices, Kevin, and I would also make sure that people are very aware of the obligations under the law enforcement exception which have been in place for over 20 years. So that’s not new, and in compliance with the law enforcement exception, I specifically would initially go to 164.512 F12. And that relates to a court or court ordered warrant or subpoena or summons issued by a judicial officer, a grand jury subpoena, or an administrative request for which response is required by law, including an administrative subpoena or summons, a civil or an authorized investigative demand or a similar process under law, provided that first the information sought is relevant and material to a legitimate law enforcement inquiry.

The request is specific and limited in scope to the extent reasonably practicable, in light of the purpose for which the information is sought, and de-identified information could not be reasonably used. A couple of examples related to that have actually come out of State Supreme Courts. And one case that is very much an example of not adhering to the law enforcement exception that got a practice in hot water is a civil case, and it’s the Byrne case, B-R-Y-N-E, versus Avery Center for Obstetric and Gynecology.

It’s case number 18 904. It was a Connecticut Supreme Court case and it was decided on November 11th of 2014. And basically, as everyone in healthcare should know, through their training, before you send any HIPAA information out, you should look at that patient or the legal representative’s HIPAA authorization and see if any individual or entity is excluded.

So what happened in the Connecticut case was that a woman learned she was pregnant and expressly stated on her HIPAA authorization that no provider was to release her protected health information to the child’s father with whom she was no longer in a relationship. So the practice gets served with a subpoena from the child’s father, and instead of going to a lawyer, the practice simply released the medical records.

And so the Connecticut Supreme Court said, Hey, from our review of the record in the present case, it appears that the defendant did not even comply with the face of the subpoena, which is required by the custodian of records for the defendant to appear in person before the attorney who was issued the subpoena. Instead, the defendant mailed a copy of the plaintiff’s medical records directly to the court.

And then secondly, although it was a civil case, the costs to the plaintiff in terms of losing trust in the healthcare system and to the practice in the form of a lawsuit is significant. And there is a provision in the law enforcement exception which actually requires a covered entity to contact the patient first. And so not meeting those fundamental requirements of the law enforcement exception is critical and something that’s related to that.

Lastly, Kevin, which dovetails into the compliance, is absolutely making sure that you’re looking at two things: state laws again and then secondly, it has to be, is the demand that has been received compliant with due process. So is it official? Is it a response required by law, things of that nature. And I always advise all clients to absolutely reach out to an attorney when you get any sort of request for HIPAA information that’s not directly from the patient.

 

Kevin Chmura

And Rachel, I take that advice myself from you and reach out to you whenever I have a question. So that’s excellent advice for the listeners. So the Connecticut case is a great example and I guess maybe it leads to a more obvious question or something that’s a little more practical for people. Certainly keeping up on state laws and rulings, that’s important, that requires really the expertise of an attorney.

I wonder if you can give the listeners any advice on any immediate steps they should be taking to adjust their HIPAA policies, procedures and training in light of this decision and the entire environment? I mean, that’s really where they can have the most immediate impact on their organizations. Any advice for folks?

 

Rachel V. Rose

Absolutely. So as I mentioned, I would put an update in red in any policy changes that were put into place as required in December of 2024. So just place hold it and, as I did for your clients in our model policies and procedures, just put that this update, the policies and procedures pursuant to this court ruling, and then note that there could be changes and that appeals and HHS, the landscape need to be stayed abreast of to know how this may shift.

Right? Because it may shift back. We don’t, we don’t know. So that’s the first thing. The second thing, again, is to reiterate the law enforcement exception and as you also know, Kevin, under HIPAA, there is the ability for any provider to potentially report child abuse. Right. Or suspected child abuse or under Tarasoff, which is a California Supreme Court cases, Tarasoff 1 and Tarasov 2, a provider has the option of notifying law enforcement if a person is a risk to themselves or to another person. So appreciating other items which may come into play and then reading what’s known as, Amparo Materia is the Latin, or the in conjunction with the state law for what is a child right under state law and what constitutes child abuse?

What requirements are in place for reporting that? Because what you want to avoid and we’ve seen this already, not only on the reporting of child abuse, but there was that case out of Ohio when a medical professional was naturally suffering a miscarriage and actually miscarried at home because the hospital sent her home. And as a result, there was a criminal investigation into abuse of a corpse.

Now, that was not upheld. The autopsy revealed that the miscarriage was, in fact, natural. It wasn’t induced by any chemical which would have run afoul of that particular state’s law. And as a result, and rightly so, the certain entities are being sued by this individual. So it’s a balance of the potential harm to individuals. And looking at that potential downstream liability as well as child abuse and potential Tarasoff abuse reporting.

 

Kevin Chmura

Yeah. Wow. So great advice as usual. So, Rachel, we up to this point, I wanted to make sure we kept everything grounded in in what’s happening now. Factor in your expert advice, now I’m going to ask you to look into your crystal ball maybe, and get to the place of speculation. So relative to Purl, do you expect HHS to appeal the decision?

And if they do, what would that process look like?

 

Rachel V. Rose

So, the process is something that is set forth in the rules of procedure. And because the northern District of Texas falls under the umbrella of the Fifth Circuit, a notice would be filed in the district court and then the appeal would eventually be filed in the Fifth Circuit Court of Appeals. So, whether or not HHS does that, I from my perspective and from other perspectives that I’ve read, there’s really a tension here on the public policy because it’s reproductive healthcare related.

But the fact that HHS does have some issues to contend with, including the definition of a child, which is I mentioned the U.S. Census Bureau defines differently, is something that we could see, another item that we could see potentially as a case being brought in another district court in another circuit. And so we could see that being an issue or an appeal specific to the APA.

So I think we have a lot of different options that we could see play out. Ultimately, it is at the discretion of the government and then any other cases which may be brought on this topic or the APA topic in general.

 

Kevin Chmura

Yeah, that was well said. So maybe as we move to our closing, what, I’ll ask you a few more sort of simple things for practical advice for our listeners. Do you think there’s any other potential future legal or regulatory changes they should really be watching out for? And maybe, two-part question, How do they stay informed and prepare for any additional changes in the area?

 

Rachel V. Rose

That’s a great question. I think first and foremost, your primary sources are your best sources. So I would always look at state websites, typically their own HHS items. I also would look to trusted partners such as Panacea and First Healthcare Compliance. And for example, AHIMA normally has really good reviews and experts. There are, there’s NAMAS. I mean, there are a lot of really good, reputable third parties that are conscientious about the content that they put out.

So trying to stay abreast of all of the myriad of changes can be daunting. But I will say appreciating where to go in your own state is probably first and foremost what’s important, because as we’ve discussed, some of this is going to come down to the state level as well. And that’s something that is, you know, I tell your clients all of the time and I’m very cautious whenever I get asked questions to say state law may differ or alter the outcome.

So it’s imperative that any covered entity or business associate consult those state laws and the HHS website.

 

Kevin Chmura

That’s great advice and I will add to it for our listeners case follow Rachel as well. She recently authored an article on this exact topic, which was helpful in me preparing for this today. So with that, Rachel, I say thank you very much as always, your expert advice here is invaluable.

This is a shifting topic. So what I would say is for the listeners, pay attention. We’re likely to put out more content on this face. Rachel, I’ll reserve the right to ask you to come back and keep us updated because it feels like there will be more to talk about relative to Purl and other areas. We have a lot happening right now.

So Rachel, thank you very much as always.

 

Rachel V. Rose

You’re very welcome, Kevin. And one thing just to bear in mind is that the reproductive healthcare definition that was initially issued was broadly defined and actually not only considered maternity care and contraception, it also impacted vasectomies, mammograms, sexually transmitted infection screenings and in vitro fertilization, as well as the gender affirming care, which we also discussed.

 

Kevin Chmura

Wow, yeah, so and that’s the complexity of these issues goes often beyond just the headline, which is why your advice is so helpful for everybody. So thank you again.

 

Rachel V. Rose

Thank you, and we’ll look forward to next time, Kevin.

 

Kevin Chmura

Thank you. So to our listeners, we encourage you to review your HIPAA policies, procedures, and training materials in light of these court decisions and stay informed as legal landscape changes. So please pay attention. We’re here for you, at First Healthcare Compliance and Panacea. Rachel is a great resource for you as well. If you’d like to learn more, just visit our website at First Healthcare Compliance, which is 1sthcc.com. Or you can go to Panacea and follow the links for Compliance or reach out to our team at any time with questions. Don’t forget to subscribe to 1st Talk Compliance on your favorite platform and never miss another episode. Thanks for tuning in and we’ll see you next time.

The Role of Compliance Programs in Mitigating False Claims Act Liability11 Jun 202500:36:11

In this episode of 1st Talk Compliance, Kevin Chmura is joined by Rachel Rose, JD, MBA, as they discuss the False Claims Act in detail. The FCA, one of five federal laws built to combat fraud, waste, and abuse, is the government’s primary fraud fighting tool, with the healthcare industry paying the largest contributor in recoveries for over a decade.

Learn not only about how to avoid running afoul of this law, but also some details of cases in which it was violated, and the repercussions those who did so faced. In addition, find out how a proper compliance program can protect your practice in various ways, including staying up to date on cybersecurity training.

Kevin Chmura

Rachel, welcome to the podcast. Thanks for joining us.

 

Rachel V. Rose

Thank you, Kevin, for having me back for another round of a very major healthcare compliance topic.

 

Kevin Chmura

It very much is, yeah. This one generates some revenue for the government. So this is one that I think especially in today’s environment, people should be paying a lot of attention to. So as I said in the intro, we’re here to talk about the False Claims Act. It’s one of the most important fraud, waste and abuse laws that applies to physicians and health care practitioners of all kinds.

The healthcare industry has consistently been one of the, if not the highest contributor to funds received under the False Claims Act. And it’s essential to be familiar with the law and maintain compliance programs to mitigate that risk. Rachel, I know you spend a fair amount of time in your practice in and around the False Claims Act defending and representing customers and providers.

So you’re perfect to cover this topic for us. Wondering, though, if you could give us a brief synopsis of the False Claims Act and why is it unique?

 

Rachel V. Rose

Absolutely. So as you mentioned, my practice focuses a lot on the False Claims Act, and I am fortunate to do a lot of compliance work not only around the False Claims Act, but HHS. OIG has identified five important federal fraud, waste and abuse laws. The False Claims Act, the Anti-Kickback Statute, the Stark Law, the Exclusion Authorities, and the Civil Monetary Penalties.

And Kevin, as you mentioned, the False Claims Act is really the federal government’s primary fraud fighting tool. And in 2024, there were more than $2.9 billion in recoveries and, moreso healthcare represented over two thirds of that amount. That healthcare trend, as you mentioned, being the largest contributor, has gone on for at least the last decade.

And what the False Claims Act does that makes it unique are really, I would say, five main things. But first, the False Claims Act goes back to 1863, and it is also known as the Lincoln Law. Its primary purpose, even back during the Civil War, was to root out fraud that was being perpetrated on the government. So how would that be done?

Congress thought about it and said, well, the government could do it on its own if they caught wind of something, or they could insert a provision which gave an individual known as a relator, also known as a whistleblower, the potential to bring fraud to the government’s attention and receive a portion of the recovery. It’s very important to note that a relator and I represented several relators successfully, sometimes with co-counsel, sometimes with not, so I get to see the False Claims Act from the whistleblower standpoint as well. But this notion of being able to represent a whistleblower is the first distinguishing factor. And that’s because most other civil cases, a person can represent themselves on a pro say basis, meaning they don’t need a lawyer. There was a provision in the False Claims Act which in fact requires an individual to be represented by a lawyer.

So unless the relator is a lawyer, then the individual needs to obtain counsel in order to file a False Claims Act case. That’s the first thing. Secondly, only the government can choose to open a criminal investigation. So even though certain laws like the federal Anti-Kickback Statute can have criminal penalties or civil penalties associated with them, only the federal government, or if a state has a similar type of law, the state can actually move and bring a parallel criminal investigation in potential proceeding.

So that notion that only the government can bring in a criminal case is not unique to the False Claims Act. But what is unique is that a private party can bring a type of case, and that’s how the government learns of something to then potentially open a parallel criminal action. The process for the relator’s counsel is also very different.

Normally, if I want to file a lawsuit in federal district court, I have to make sure that either a federal question is involved under 1331, or I need to meet the amount in controversy and diversity of the party’s requirement under 1332. While first, the False Claims Act is a federal statute, so it falls under 1331. So that’s the same.

What is not the same is that before I even file a case under seal in a United States District Court, I have to provide a disclosure in evidence to the local United States attorney where I’m going to file the case, as well as providing that same information to Main Justice in Washington, D.C.. Another area that is relevant that I just mentioned is the seal.

So that’s the third item. And initially, the statute itself provides for 60 days that the case is filed under seal, meaning no one knows about it but the relator, the lawyers, the judge, and whatever the court staff are, and that’s the way it has to stay. Now, the government may request what are known as deal extensions in this type of case.

And another provision relates to the breaching of the seal. In the 2016 Supreme Court case, Rigsby versus State Farm, is the case that outlined different fact orders, which first stated A. Just because there may be a seal breached doesn’t mean that the case is automatically dismissed. But the court said we get to apply these factors and make that determination.

I will say that even if the court says no, this case doesn’t need to be dismissed and the Government agrees with that, that the government on the back end, when we start to get to the fee issue where the relator can recover, they, the government, has the right to drop the recovery. If there has been a breach of the seal below what the typical statutory threshold is, and I’ll get to that in a moment.

The other distinguishing factor in a False Claims, that case is once I filed the case, it’s really in the government’s hands until they make a decision. And there are three ways a case can go. The government can intervene in the case and intervention can occur at different times. I’ve had cases that have settled under seal and then the intervention decision is made and the seal is lifted by the court, so the government has taken the case through settlement, even though there has not been any action in court, so to speak.

The second way to intervene is that if the defendant won’t settle while the case is under seal, the government can say, Hey, all right, relator, we like the case, we have adequate resources. And I don’t necessarily mean monetary resources. I made the specific notion of adequate human resources, right? Because the government only employs so many people and so many assistant U.S. attorneys to work on these cases. So the Georgia Tech case is an excellent example where the government intervened and they’re the ones who are leading trial.

So in that instance, the relator’s counsel and the relator just sit back, and if the government needs help with something, then they’ll ask. Declining to intervene means that the government is not going to intervene, but they say to myself or other relator’s counsel, if you would like to move forward with the case and prosecuted, you’re able to. And so I’ve had that scenario as well. And then lastly, they can dismiss the case under C two way, and that’s always the government’s discretion.

And the Supreme Court case, the Polansky case is a case from 2023 that actually addressed that very issue. Now, penalties and damages, damages can be trebled under these circumstances. Penalties up until 2016 ranged from $1500 to approximately, not  $1500, $5500 to approximately $11,000 per violation. So that was per healthcare claim. Now the absolute minimum is over $11,500, and the upper end of that penalty range per claim is closer to $25,000.

Oftentimes we don’t see penalties assessed unless a case goes all the way through to verdict in a trial. But it can still be costly for damages being trebled depending on the type of case. The relator’s recovery, if the government intervenes in the case, is between 15 to 25% of the total recovery. If the government declines, then the relator is entitled to 25 to 30% in the event of a successful recovery. And it’s important to note that the False Claims Act is not an intent based statute.

 

Kevin Chmura

So. Well, wow that was great, that’s so, it’s dense, right. And there’s, yeah there’s a lot there, and expensive for those that find themselves on the wrong end of this, and so super important. And you touched on I think a few of them but I wonder if you could zero in a little bit on what healthcare laws are often included in False Claims Act cases.

 

Rachel V. Rose

Several laws that are included, Kevin, include the Stark Law and the Toomey case, which was brought several years ago and to date is still one of the largest False Claims Act cases involving the Stark Law. It went up to the Fourth Circuit and that had to do with, in essence, paying kickbacks to physicians where a Stark exception was not met and they were getting remuneration outside of what met fair market value in order to refer patients for designated health services.

Now, designated health services is a term of art within the Stark Law. We don’t see that term in the Anti-Kickback Statute, which is another term. One main difference, aside from the designated health services being the only areas that apply to Stark Law, is that Stark is a civil statute, and more importantly, it’s a strict liability. So it’s like speeding.

If you go over the speed limit, you can get a ticket the same as the Stark Law. By way of contrast, the Anti-Kickback Statute, which actually predates Stark Law by at least 17 years, is a criminal statute. It applies to every single federal healthcare program, with the exception of the federal employee health benefits program, and it applies to any type of remuneration, whether in cash or in-kind, for referrals to, or utilization of, goods or services related to the provision of health care to a Medicare beneficiary, Medicaid beneficiary, TRICARE or beneficiary, etc..

And there are safe harbors.

 

Kevin Chmura

That’s good stuff. I know from my now a few decades in healthcare and all of the compliance and other training that you are really required to do, I spent a fair amount of time being educated on particularly Anti-Kickback, and I wonder if it would be helpful. Maybe if you could highlight a few recent cases involving AKS violations.

I think it is kind of where the rubber meets the road on these. It can be very, very informative for folks.

 

Rachel V. Rose

Absolutely. And one unique aspect of the False Claims Act that I did not address earlier, because I highlighted more of the procedure associated with the False Claims Act. But one of the more unique or interesting items, especially as it relates to the Anti-Kickback Statute, is the idea that first there’s a different see/enter requirement or knowledge requirement.

So knowledge under the False Claims Act is defined as actual knowledge, deliberate disregard for truth or falsity of the information, or reckless disregard for truth or falsity of the information. Now, the Anti-Kickback Statute is intent based. Remember, the False Claims Act is not. So intent must be proven and it must meet that statute’s definite kind of knowing or willful.

But a nice thing occurred in 2010 for relator’s counsel, and that was that Congress said, if you can substantiate and clear the hurdle of an AKS violation, then the False Claims Act violation really comes along for the ride, which makes sense because it’s a higher level of see/enter. And as I mentioned before, the AKS itself is criminal.

So when we think about the types of cases where we see a lot of AKS violations, one great case is from 2021 is the settlement date on that. And that was United States Ex Rel Goodman versus Areva medical. And that was a case out of the middle District of Tennessee. That case settled for $160 million after the relator’s counsel, it was a decline case and the relator’s counsel move forward, responded to the defendant’s motion to dismiss. The judge denied the motion to dismiss, and the case settled. At issue was a type of kickback, which some people may not be as familiar with, but it has to do with the carte blanche waiver of co-pays and deductibles. And so a co-pay is able to be waived if there’s documentation that an individual had a financial need, but only for that individual.

So you can’t just say, I’m going to waive all co-pays or deductibles without having individual documentation substantiating it. So that case is really telling in terms of that area, and that’s an area too, Kevin, as you can imagine, that a lot of providers could really sidestep and eventually end up in hot water for not appreciating that type of risk.

Another case that involved the Anti-Kickback Statute was actually a case that I had that the government intervened in and settled while it was under seal in May of 2024. So just about a year ago, and that was in the Northern District of Texas, and there the medical device company had physician owners and there is a safe harbor in the Anti-Kickback Statute known as the 4060 Rule, or the small business safe harbor, where if you, an individual physician or a group of physicians, own a certain amount of a company, then the revenues that they generate cannot be a certain amount.

And so, a certain percentage of total revenues. And that’s what happened here. They didn’t meet the framework. And for anyone who looks at compliance of fraud, waste and abuse laws, it’s very important to note that you have to fit within the four corners of the safe harbor in order for it to be applicable.

A couple of other really big cases that have been around lately. One is one of my favorite cases. It’s called the Sayid case, and it went up to the Seventh Circuit. And the Seventh Circuit issued an opinion on May 2nd of 2024. And in this instance, a creative entrepreneur, I will say, started coloring outside the lines. And instead of being satisfied with the existing relationship he had with the Healthcare Consortium of Illinois, which really had a primary purpose of coordinating healthcare for lower income seniors in the state, he created a third entity and entered into a managed services agreement to pay this consortium $5000 a month for allegedly providing management services.

But in practice, what he was doing was accessing the patient data, using that patient data to solicit business, and that in turn was billed to Medicare. And as you hear the term PHI, your HIPAA flare should be going off, too. And that’s exactly what the judges both at the district court level and at the appellate court level said.

And one of the things that caught their attention and this is, this is pretty rich, which is why it always stands out in my mind. But Sayid testified that he had spent over three decades in the healthcare industry and knew that buying protected health information was illegal. And as we know, HIPAA has a criminal provision as well.

And so what the appellate court says was, you know, the district court was right. They did not err in finding that the defendant knowingly and willfully violated both the Anti-Kickback Statute and HIPAA, and also that this type of personal service or management contract did not qualify under that particular safe harbor for the AKS.

And then very recently, Kevin, we have a few cases. One was against Omnicare, CVS, we had Controlled Substances Act violations which were very significant. And then there was a case that was actually filed in 2012 and that was United States and various states Ex Relator Panelo versus Janssen products. And as I mentioned, that case has been ongoing since 2012. The original firm that filed the lawsuit brought in really good trial counsel, who I’ve been fortunate to co-counsel with, and it went to a jury trial.

The jury did not focus on the Anti-Kickback claims, but what they did focus on was the illegal promotion of an HIV drug. And the judge entered a final judgment of $1.6 billion.

 

Kevin Chmura

Wow, that is a very large number. You know, and so, you know, there is the big is why it’s helpful to look at actual cases, right. Where these, like I said before, where’s the rubber meeting the road in terms of actions being brought in settlements being a tell you what, you know, there are bad actors out there and some people that are knowingly skirting.

So it’s, I think when you tell the story about the co-pay waiving it’s really, it really highlights why it’s so important to understand the False Claims Act, particularly in AKS, you know, that you could really just be in a situation where you think you’re doing something kind or nice for an individual or group of individuals and not even realize that you’re in violation of this.

And it just speaks to the criticality of the understanding of what your obligations are. So that was super helpful. I wonder if we could pivot for just a just a few minutes, because you can’t really talk about healthcare today without also covering cybersecurity. There’s been such a huge push to digitizing everything over the last several decades, and we were digitizing things faster than we could keep up with. Those people that wanted to get at those digital records.

And I wonder if you could highlight a few recent cybersecurity case settlements.

 

Rachel V. Rose

Yeah, absolutely. So in terms of False Claims Act cases, I was fortunate, along with my co-counsel, to represent the whistleblower who brought the first case that settled under the DOJ’s Civil Cyber Fraud Initiative, and that announcement was made in March of 2022. At issue, there was a government contract with the State Department and some of our armed services.

And in essence, there was a requirement to safeguard the information. There was an additional requirement to ensure that the HIPAA information was being secured in a way that HIPAA information should be secured. So in that instance, the government intervened and that was the first case. So I’d seen it, cybersecurity violations from the whistleblower side, I have actually conducted HIPAA audits for well over a decade and I’ve also represented people post-breach on the enforcement side, some more recent cybersecurity-related cases are, one of my favorite ones is actually the Jelly Bean case that came out of the middle district of Florida that was not a whistleblower case.

The government brought that on its own. And it’s unfortunate because there was a breach of over 500,000 minors’ information. And what the government said about this company, Jelly Bean, and their owner was, hey, we contracted with you to provide services to keep this information secure. And it was an item that came about because of the breach, but what they found upon doing due diligence was that the common patches that should be done with software weren’t done for over a decade. They were using non-supported software, data was not encrypted, there were password issues, you name it, in this company had it. So they actually brought a False Claim that case because as we learned right out of the gate, the government can bring that too. So that was the Jelly Bean case. We’ve also seen it more recently, again with government contracts, That’s the morse case MORSE, that’s it, one that’s important.

Penn State University settled a case. A colleague of mine brought that case that was brought in the Eastern District of Pennsylvania. And I will say this because in my experience, the whistleblowers in cyber cases are very sophisticated. They’re typically Chief Information Officers or highly educated people who understand what regulations are supposed to be met and what’s not being met.

So I would say that if I am any type of company, whether it’s a business associate or a covered entity, I would ensure that I have my items in a row in terms of HIPAA compliance, because that’s one of the greatest areas of potential risk. And this area of the law is only going to be a focus of the DOJ, per their January of this year statement, that cybersecurity is going to continue to be an area that they focus on.

 

Kevin Chmura

Yeah, totally. And really in healthcare today, you should have an orientation towards data security, cybersecurity training, all safeguards, and many of them are just good business practices to begin with, right? Certain things can be more complicated than others. But the, really to just run a business in healthcare, which we all do, it’s not really that complicated to stay to stay in good stead, but it’s something you were touching on there, and I think it’s maybe a good way to close. And that’s really, you know, how do we mitigate all of these risks really through, I guess, an effective compliance program?

I mean, if you’re up on compliance, if you take it seriously, these things should fall into order. But I wonder if you could give our listeners maybe some advice and guidance in that direction.

 

Rachel V. Rose

Absolutely. So there are five main areas that I would focus on. The first is make sure, to your point, Kevin, that your HIPAA compliance is where it needs to be in terms of the Security Rule, the Privacy Rule, the Breach Notification Rule, as well as information blocking, which was part of the 21st Century Cures Act. And as you and I talked about in another podcast episode, the HIPAA Reproductive Rules.

So that’s one area that’s key. Cybersecurity also dovetails into a case in Stark Law, because of the December 2nd, 2020 Final Rules. Those are the, quote, “New Stark and AKS Final Rules,” but they updated their safe harbors related to what types of cybersecurity services or goods could be provided and what needs to be done.

So you need to have an agreement in place. You need to make sure it’s not based on volume or value, and it needs to be for fair market value. So those are some areas to look at when you’re considering the intersection of cybersecurity as well as fraud, waste and abuse laws. In terms of fraud, waste and abuse, 42 C.F.R. Section 483.85 requires a mandatory compliance program, and this specific provision was highlighted in the November 2023 HHS OIG guidance.

And although guidance is not binding in that sense, it provides a great roadmap. But the laws and the regulations that it references are binding. So it’s a great item to look at right out of the gate. So the seven elements, I call them the dirty seven, that are required for fraud, waste and abuse laws are: written policies and procedures, compliance and leadership, and oversight training, effective lines of communication, with a compliance point person in forcing the standards, having consequences, and incentives.

Those should be documented both in an employee handbook as well as your regular policies and procedures. There should also be a non-retaliation provision for concerns that are brought in good faith. And I added that term good faith because I actually represented a client where they had a rogue former employee file, literally, a false claim with the government agency that they were not compliant.

And so, it came back after I defended them that, yeah, they were compliant with everything that they had, and the individual did not bring that concern either to the company. He didn’t bring it to the company first, but he went externally and just filed it completely invalid and factually false complaint with a government agency. So that’s why if it’s in good faith, then people should listen.

And I, on the flip side of that, a positive situation I had with another client was that they had someone who was in billing bring a coding issue to their attention. And lo and behold, there was a glitch in the EHR system. So it was applying the wrong code. They were able to get the EHR company involved, address that, and then resubmit the claims right away to government and private insurers.

And that isn’t a great example of a good faith concern that was brought. It was investigated, and it really ended up helping the organization. And so that’s the benefit of looking like that instead of just retaliating against someone.

Last two items are a risk assessment. And for audit, that’s a great way to have a third party come in and do an audit assessment and then responded to detected offenses as well. So the last part is just to review your contracts and make sure that if persons are receiving money that there is a contract that is in place and that it’s legal.

 

Kevin Chmura

Wow. So a lot, but a very important topic because you can see it intersects with day to day life in healthcare myriad ways. So that’s great. Maybe a quick summary. I mean, if organizations are proactively investing in a compliance program, living it, taking it seriously, and it’s not just a binder on the shelf, it’s going to mitigate risk through from the False Claims Act, potentially reduce penalties, and avoid legal repercussions that can just, that can linger for quite some time.

So Rachel, this has been great. Appreciate you as always. Your knowledge in this space is unbound and we’re really glad that you choose to share it with us, and I’ll reserve the right to bring you back for future episodes. Maybe catch up on some other things that are happening relative to this very important topic.

So with that, I’ll say thank you, Rachel.

 

Rachel V. Rose

Thank you, Kevin. And thank you, Panacea and First Healthcare Compliance for having me again as a guest.

 

Kevin Chmura

We’ll have you back soon. Thanks.

 

Rachel V. Rose

Thanks.

HIPAA Privacy Rule to Support Reproductive Healthcare Privacy Compliance12 May 202500:20:10



In this episode of 1st Talk Compliance, Kevin Chmura is joined by Rachel Rose, JD, MBA, to discuss the HIPAA Privacy Rule to Support Reproductive Healthcare Privacy, passed in 2024. With the reproductive healthcare landscape being very dynamic, this new rule has already passed one compliance date, with a second important date coming in February 2026.

Tune in to learn about this new rule, and what it means in terms of reproductive health, patient privacy, and the legality between different states. In addition, learn some best practices for implementing the requirements of this rule into your practice.

On June 18, 2025, The U.S. District Court for the Northern District of Texas – Amarillo Division (Carmen Purl, et al v. United States Department of Health and Human Services, et al., Case No. 2:24-cv-228-Z (N.D. Tex.)), issued an order vacating the HIPAA Privacy Rule to Support Reproductive Health Care Privacy, published on April 26, 2024, which amended the HIPAA Privacy Rule (Reproductive Health Rule). The decision left intact amendments to the HIPAA rule regarding certain Notice of Privacy Practice provisions pertaining to substance use disorder regulations, which need to be adhered to by early 2026.

 

Kevin Chmura

Rachel, thank you for joining us. Appreciate you joining us and looking forward to a timely discussion.

 

Rachel V. Rose

Thank you, Kevin, for having me, as well as to Panacea and First Healthcare Compliance, it’s always my pleasure to coordinate and converse with you on our favorite healthcare compliance topics.

 

Kevin Chmura

And it’s always great having you helping us with this and your expertise is invaluable. And you helped us and were the contributor, really writer, of an e-book on this particular subject that will be released very soon. Really this podcast is somewhat of a companion piece to that. And so what we’re talking about today is the HIPAA privacy rule to support reproductive health care privacy, passed in 2024.

Reproductive health is a prominent and evolving topic within the healthcare policy landscape. It really, major changes have come down in recent years, and so there’s just a ton. So we thought it would be great to publish a book to get everybody up to speed and, but moreover, this podcast is an opportunity for people to hear directly from the person who helped us develop that. And that is Rachel. So, Rachel, I wonder, can you just start off by giving us a synopsis of the 2024 Final Rule, maybe some key terms we should be thinking about?

 

Rachel V. Rose

Sure. As you mentioned, Kevin, the reproductive healthcare landscape is very dynamic and the rule itself was issued on April 22nd of 2024 with an effective date of June 25th of 2024. And basically what an effective date does is to start the clock running as to when certain requirements need to be implemented. In this particular rule, which I will refer to as the HIPAA Reproductive Rule, has two prongs of compliance dates. The first already passed and that had to be done by December 23rd, 2024.

And for your clients who were with First Healthcare Compliance or Panacea at the time, they were able to access FAQs. And the first prong of the requirements really addressed every applicable item that I’ll run through, with the exception of the notice of privacy practices. Now, for anyone who’s been in the healthcare sector for a long time, and for anyone who goes to the doctor, a dentist or even a pharmacy to pick something up, we all know we have to sign the HIPAA authorization form, and then covered entities are required to post their notice of privacy practices.

So the updated privacy practices, which need to include some of the reproductive health requirements among other items, does not need to be done until February 16 of 2026. So this is similar to the staggering of the compliance dates which we saw with the Final OmnibusRrule, which was published in the Federal Register, it’s hard to believe, but going on over 12 years ago and that was January 25th of 2013.

Now specifically, the HIPAA reproductive rule really prohibits the disclosure of protected health information related to in these terms I need you to focus on: lawful reproductive health care in certain circumstances. And the reason it’s important is because legal means that whatever service or good is being sought, it has to be legal within the jurisdiction where the individual is receiving that care or that good, so to speak.

And so if we want to take certain types of surgeries or certain types of procedures that in a viable fetus’s life, then you need to be in a jurisdiction or a state where that is permissible. So the terms are the meaning of a person. What is a person? If you read the Final Rule, it means a natural person, meaning a human being that is born alive, a trust or estate, a partnership, corporation, professional association or corporation, or other entity, public or private.

And this definition is common. It was adopted by the U.S. Supreme Court several years ago. So when someone says a person, it can mean either an individual human being or one of the other more business-oriented items. Now, public health is also a term. And for this Final Rule, it’s used in terms of public health surveillance, public health investigation and public health intervention, and this means population level activities to prevent disease in, or promote the health of, populations.

For those who are familiar with HIPAA, there has always been what’s known as the public health exception, and that has limited applicability. But one of the exceptions is to report a positive test for a communicable disease. We saw this during COVID. It is required for sexually transmitted diseases and other kinds of diseases. We’re seeing it now with all of the media attention on measles and those types of conditions.

What’s important to note about public health is that those activities, which include identifying, monitoring, preventing or mitigating ongoing or prospective threats to health or safety, do not include any of the three following purposes, and that’s: to conduct a criminal, civil or administrative investigation into any person for the mere act of seeking, obtaining, providing or facilitating health care. Secondly, to impose criminal, civil or administrative liability on any person for the mere act of seeking, obtaining, providing or facilitating health care. And lastly, to identify any person for the activities that I just described.

And I’m often asked, well, Rachel, what do you mean? If I’m seeking and what do you mean about going to a different jurisdiction? And for those who are familiar with the old school drinking age laws, for example, in Louisiana, the age used to be eighteen.

So if you were eighteen, even though you were a Texas resident and went over the border to drink in Louisiana, it was legal and there was nothing that Texas could do as you were coming across the border. Now, intoxication while driving is a separate animal. But just because a person went over the border to drink in a jurisdiction or a state where it was legal doesn’t mean that Texas had any recourse against that person so long as they were sober coming back over the border. Right.

A similar situation with reproductive health care. And that’s what the focus of this privacy is, if a person goes to a state to seek certain types of care, and the two areas that seem to be at issue particularly are surgical abortions or transgender care, especially as it relates to minors. So the other key term that everyone needs to be familiar with, and that should be in policies and procedures as well as training, is the term reproductive healthcare, and that means healthcare that’s been defined in this particular section, that affects the health of an individual and all matters relating to the reproductive system and to its functions and processes. This definition shall not be construed to set forth the standard of care or regulate what constitutes clinically appropriate reproductive healthcare.

So what HHS, OCR said here is we are not looking to step into the shoes of the physician and determine what is appropriate under certain circumstances. We are not involved in the practice of medicine. We are just giving a roadmap of what is particular. And everything I just read really comports with the July 2022 opinion in Dobbs versus Jackson Women’s Health Organization, which overturned Roe v Wade.

And what’s important about that opinion is actually Justice Kavanaugh’s concurrence. And it’s important because just as I mentioned, going across state lines to receive care or use the purchase and consumption of alcohol situation, by way of analogy. Justice Kavanaugh expressly stated that nothing in this opinion is meant to contradict or inhibit any other part of the Constitution, and interstate commerce is expressly stated in our Constitution.

So really everything is aligned with Dobbs as well as the opinions in the case.

 

Kevin Chmura

Yeah, it’s a great, great rundown. It’s impossible to talk about reproductive health in any context over the last several years in America without intersecting with Dobbs some way or another, right? That’s the seismic shift and I’m glad you touched on that. I think that’s a real critical area. And so, you know, the Final Rule is in concert with, or interacts is I guess a better way of saying it, considers Dobbs in the rule itself in all of the areas of Dobbs, correct?

 

Rachel V. Rose

That’s absolutely correct, Kevin. And it goes back to that legally attainable reproductive health care, right? So if you’re in a jurisdiction where it’s not permissible or it’s not legal, then this rule is not going to help you on that front, right? It’s meant for individuals who are seeking care in a jurisdiction where it’s legal and nothing in this final rule tries to interfere with that.

But it does make clear that just because someone goes across to seek care in another jurisdiction when they come back to their home state, the home state really has no recourse against them.

 

Kevin Chmura

By the way, I’m just old enough to remember my oldest brother driving over the border from New Jersey to New York for the 18-year-old drinking age. I was not so lucky. But, so that’s a great analogy and it’s a great way of looking at it. So are there any other compliance items or dates that are critical that we should be thinking about?

 

Rachel V. Rose

Well, as we mentioned from the outset, individuals and covered entities, etc. should have had the attestations which are now under 45 CFR Section 164.509. This is new as part as of the reproductive HIPAA rules and here regulated entities are required to obtain an attestation when it receives a request for PHI potentially related to reproductive health care. So what they need to do is first, create the attestation. Second, obtain the attestation from the requester that the use or disclosure is not for a prohibited purpose, and a prohibited purpose would be for health oversight activities, law enforcement purposes, and disclosures to coroners and medical examiners.

So from these three bullet points, I would recommend A. Training the people who actually handle the medical records for your organization and making sure that they understand that if one of these requests are made and if you’re working in an OBGYN practice, it’s probably pretty easy, right? To make this a normal part of the processes. For other types of specialties, it might not be as common, but still training needs to occur. There is already a law enforcement exception under HIPAA and that’s found at CFR 164.512. But as we know, even with that law enforcement exception, it safeguards our due process, right? So really, this serves as a further safeguard so that law enforcement is not trying to get around the normal processes such as going to court, getting a warrant, getting a subpoena.

I would recommend having an outside legal counsel review the requests, especially for the first few of them, snd also, if something just doesn’t seem appropriate. So that’s what I would recommend doing. And then we have a little bit of time left until February 16th of 2026, and that’s when covered entities are going to be required to update their notice of privacy practices to reflect changes to both the HIPAA Privacy Rule by including this reproductive component, as well as 42 CFR Part Two, which is more relevant to substance abuse and mental health disorders. And that relates more to SAMHSA, the Substance Abuse and Mental Health Services Administration.

 

Kevin Chmura

That’s great. So throughout there you touched on Ithink a number of best practices necessary, but also best practices. Wonder for the listeners, maybe we wrap with as much advice as you’re willing to give to folks on how best to comply, what they should be thinking about immediately.

 

Rachel V. Rose

Sure. So I think one thing to think about, if you haven’t already implemented what should have been implemented in December of 2024, I would jump on that. Secondly, what is your electronic health record doing? Are you working with your organization’s IT and provider to have a tab in the individual’s medical record, which requires a separate audit log and log in for sensitive information related to reproductive healthcare items?

Psychotherapy note should already be in there if it’s that type of practice or the 42 CFR Part Two, so the substance use disorder item. So that’s one area to focus on there. Another area is the revised notices and there should be a separate provision that documents the Part Two changes. And then lastly, as part of the annual HIPAA risk analysis, I would absolutely recommend having the auditor include these facets of the HIPAA Reproductive Rule into the risk analyses so that you can ensure that it is covered.

 

Kevin Chmura

That’s great and auditors are always looking for one more thing to audit for. So I’m sure that the audit community is happy to hear that. So Rachel, I think this has been great. I, we really appreciate it. This is a timely topic, probably one that’s worth revisiting as we move through February Compliance dates, and then into the future to probably talk about enforcement and other things that are happening all around this, because this is a topic that’s evolving and we’re coming into the middle of.

So I would like to thank you for joining us and providing us so much information. Thank you.

 

Rachel V. Rose

Oh, you’re most welcome, Kevin. And as always, thank you for having me as your guest.

 

Kevin Chmura

And we look forward to bringing you back to continue the discussion on this. Thank you.

 

Rachel V. Rose

Thank you.

 

RE-RELEASE Employee Snooping & Insider Threats18 Mar 202500:29:16

1st Talk Compliance features guest Raymond Ribble, CEO and Founder at SPHER, Inc., on the topic of “Employee Snooping & Insider Threats.” Ray joins our host Catherine Short to discuss snooping and insider threats and why user monitoring and ePHI access strategies are vital to the security of sensitive patient information and data protection. With so much attention and money surrounding cybersecurity in the healthcare industry, malicious employees may decide to purposefully disclose patient information. Since employees and contractors may have knowledge of your network setup, vulnerabilities, and access codes, snooping employees with malicious intent hold the key to exposing your organization to a series of unwanted risks and threats. Listen as we identify signs of unauthorized access, provide guidelines to prevent snooping, and offer procedures to detect insider threats.

Catherine Short:

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

On today’s episode, we are speaking with Raymond Ribble, CEO and founder at SPHER Inc, a market leading compliance analytics cybersecurity solution addressing HIPAA compliance, state privacy laws and ePHI security threats on the topic of “Employee Snooping and Insider Threats.” Snooping and insider threats are exactly why user monitoring and ePHI access strategies are vital to the security of sensitive patient information and data protection. With so much attention and money surrounding cybersecurity in the healthcare industry, malicious employees may decide to purposefully disclose patient information. Since employees and contractors may have knowledge of your network setup vulnerabilities and access codes, snooping employees with malicious intent hold the key to exposing your organization to a series of unwanted risks and threats. Listen, as we identify the signs of employee and contractor unauthorized access, provide guidelines to prevent employee snooping, and offer procedures to detect insider threats.

So thank you, Ray, for joining me on First Talk Compliance. It’s a pleasure to have you on.

Raymond Ribble

Thank you for having me today. It’s great.

 

Catherine Short

Yes, always wonderful to talk to you. So Ray, I have a question for you to start off. I know when people think about threats to their organization, they worry often about external risks such as hackers. Would you say that this is the right focus?

 

Raymond Ribble  2:15

For an organization, it’s not the wrong focus. It’s what we read about in the press the most. We’re online looking at some healthcare rag, what they’re talking about is some type of external threat that impacts the organizations. And I think from a cost perspective, it is the most impactful. Somebody coming in from the outside, a hacker to use the term, can cause hundreds of thousands if not millions of dollars in damage to an organization. Ransomware would be a perfect example of that. You or I don’t want to have to pay some X number of bitcoins in order to get access back to our data knowing that now that they’ve done that, that they’re probably going to come back and do it again. Having said that, I think the equal component of that is what we talked about in terms of snooping and the insider threat, because an individual snooping and then taking that information that they get through snooping and sharing it through social media, or in gossip to somebody on the outside, potentially could have a financial impact to an organization more so today in 2022, than say 20 years ago, or 30 years ago. So are hackers real? Yes, they are. Is the hacker the thing that you should stay awake at night worrying about? Not as much as you think. 26% of the breach events that are captured by most organizations that are responding to our surveys out there, IBM Parliament being the best, indicate that snooping and insider threats are much more detrimental to the business than the hackers on the outside. I think they’re more prevalent. I think that 67%, if I remember the number correctly, is what we have in terms of the percentage of healthcare breach types come from inside the organization, not outside. I think we tend to focus on what that cost is to the organization if we get caught, when we get caught and so therefore, hackers are more prominent because we use that word as a catch all for everything from phishing, to ransomware to XYZ. Does that make sense?

 

Catherine Short

It does. So all the time in the news and media and everything we hear about ransomware, ransomware there’s a cyber attack. So if you were talking about ransomware and cyber attacks, versus insider snooping, which is one of the topics here and employees snooping, what would you say then? Could you expand on that just a little bit more?

 

Raymond Ribble

I’m more worried about the insider threat personally, I think that there are things that we can do from a technology perspective to significantly limit our exposure to ransomware type events. So if we can educate our end users to not click on anything that comes up on their screen, to not look at third party applications or ads, and click on them to go see if that shirt from China is really interesting, and I really can get something for $25 that I’d have to pay $200 for, is worth it. Because when I click on that, what I’m actually doing is opening up a hole into my data system. So if we can educate people not to do those types of actions, through technology and encryption and such, then we can reduce the exposure to a ransomware event through that.

On the other hand, if I have people in my office, who are snooping or worse, in a malicious sense, stealing the credentials, and giving those credentials to somebody else in order to create havoc, that cost is exponential to our organization. That goes back to a major breach, it goes back to being measured in hundreds of thousands, if not millions of dollars. The impact to your organization from a cybersecurity insurance perspective, is significant. The reason we have that feeling, Catherine is because what articles we typically see out there in the press, whether it’s online or in print are stories about ransomware, a hospital being shut down, not being able to access their files. It’s rare that we see a story about a snooping incident, such as say, the Justice Mueller in Chicago, where it makes it to the point of news that’s worthy of being talked about. So it’s kind of a hidden crime in an organization that a lot of people think well is really causing the damage?

 

Catherine Short

So right. Can you give me some examples of what you’re talking about? When you mentioned insider threats or employee snooping?

 

Raymond Ribble

Yeah, the worst one that we’ve had with our organization where we work with a client, was an incident where they were brand new to our technology, we implemented the system for them. And maybe a little bit of background. It is a rural hospital. You and I both know that we love to talk about others. I mean, TV is loaded with shows about other people’s lives and reality TV, but what’s more reality than snooping that what’s happening in my community, viz a viz their healthcare and what they’re coming in, what type of ailments they have. This organization went live with SPHER and in the first month of using the system, they had 1800 snooping alerts. 1800.

 

Catherine Short   7:50

Wow, that was from one organization

 

Raymond Ribble

That was for one place, it was the hospital and when we sat down with that team, and investigated the 1800s, they were all legitimate. There was no false positives, everything was legitimate. They were they had a very, very bad problem in this hospital.

 

Catherine Short

That was in a month?

 

Raymond Ribble

That was in one month.

 

Catherine Short

Oh, my gosh, there must be a lot of gossiping going on there.

 

Raymond Ribble  8:22

Yeah. I’m not gonna say where it was, other than it was a rural hospital. It would be bad. But let’s just say yeah, there was a lot of gossiping in an area that’s famous for gossip like that. Everybody listening can say, now that’s my area. But now though, this is one that we probably would all agree upon. We sat down with them and this is where once they understood this was real, then they said, Okay, how are we going to solve this problem? And it really came down to the CIO. In this case, the CISO, saying, Okay, we’re clearly not educating our users on security and we don’t have a culture of compliance in this organization. So she decided to make it very public what they had found, to share some of the analytics without calling anybody out since it was everybody and saying, Okay, this is going to change immediately. We’ve implemented the system to monitor so I’m looking at you, just know that from today. Within two months, the snooping dropped from 1800 to five, five incidents, and those five incidents she told us, could all be explained. So you know, in essence, she said, Yeah, they did look, but here’s the reason they looked and she could accept that so basically, zero. Once people knew that somebody was looking at them looking at other people’s data, they stopped. Maybe they found a new way to do it, but they weren’t using the EHR system or the EMR system as their main source of Office gossip. How’s that?

 

Catherine Short

Wow. So when you have an incident where someone is looking at someone’s medical records, say like an ex spouse or the ex spouses new wife or something like that, what do you do?

 

Raymond Ribble

So we have to be very careful. I think I mentioned this to many people. At SPHER, we’re not the HIPAA police. My tool that I make available to my clients, the SPHER dashboard and the alerts that you get, that’s where you start. We do the hard job of identifying areas that might be worthy of an investigation, you’re then looking at that data and determine is this meaningful information that SPHER is giving me and should I take action on it? Yes, or no. If it’s a normal action, you tell the system it’s normal and you won’t see that again. That becomes part of that person’s profile. However, in many instances, when people do identify and do the investigation, they’ve called us to say, hey, look, I just saw something here, I did an investigation, can you look at it with me, we have their permission to do so. And then we’re just looking with them to make sure that they’re interpreting the data correctly. Final decision is theirs, not ours. And as I say, whenever I speak, this is where they want to reach out to an organization like yours, Catherine, and have a conversation with somebody who’s like a HIPAA consultant, or like Rachel Rose, somebody who is a HIPAA law attorney, and have a discussion about how should I handle this going forward? We’ve had incidents where physicians have gone into the system and taken data that was so random that it showed up in the alert, and they were giving that data it turns out, to somebody else that used it, as part of your example, in a divorce proceeding for custody of the children. And the only way that that data could have been gotten on the wife in this instance, was through the medical record, because it was very private. How did he get it? Of course, somebody else took it out of the system, gave it to him, and he used it in a court of law. That was a no, no, and they should have thought about that before they did it but they did it anyways and so they got busted for that. I mean, think about the ramifications of a doctor in that in court.

So we do see real instances of people at very high levels going in and snooping or maliciously exfiltrating data for the purposes of something that might be legal in nature or monetary in nature. And we see that more often than you’d like to believe.

 

Catherine Short 

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Raymond Ribble, CEO and Founder at SPHER, Inc., on the topic of “Employee Snooping & Insider Threats.” Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.

I have a question then. How do you recommend to administrators and managers for balancing and creating a culture of compliance and then balancing this with the feeling for employees? When a new system is implemented, that they might feel like they’re being micromanaged.

 

Raymond Ribble

They’re very concerned, the administrators and the senior managers CISOs that we work with, they’re really concerned about that question that you’re asking. I want to do this but I don’t want to send a negative message to my employees. I don’t want to tell them I don’t trust them. I don’t want them to think that. Oh, you know, we’re watching everything they did – we are. How do I do this proactively? And so we’ve had some really creative organizations that have shared with us what they did do. That’s how I’ll answer your question, by sharing with you what I heard people do that I thought was very innovative

So they have a regular lunch, or they have a regular session that’s scheduled every month or every couple of months in the organization. They take some of the analytics that they’ve learned from SPHER and integrate that into the learning process. They talk about, hey, we’ve noticed over the last couple of years in the United States, that the threat vector in terms of breaches through phishing, and hackers and even insider threats, is increasing and as an organization, we want to do what we can to protect ourselves, protect our patients. So it’s a bit of a manipulation of the words, but they come up with a very creative way of saying, We’re doing this to protect the people who come in here in order to get healthy and you know, this is a team effort. It’s not a me looking at you effort. It’s us looking at what’s happening effort in order to make sure that we’re protecting our patients from any external threat. The byproduct is the internal threat gets addressed as well.

 

So they take it from a negative message to a positive message and they use different vehicles like team training, or the company lunch or some type of a newsletter that they have in the organization to start making that a regular part of the presentation, and maybe introducing incidents that happened in the past and the corrective action that the organization took. It sends a secondary message of, hey, I am looking and we are aware of these things, and if that happens to you, you might be the person or at least the incident’s going to be highlighted in the next newsletter or the next company meeting. So let’s watch our P’s and Q’s let’s be better at how we access data and what we share.

 

Catherine Short   15:44

I think that’s very helpful for everyone.

 

Raymond Ribble

You know, we always talk about penalties, we never talk about rewards. So if employees were to come to us with ideas on how we could improve our security posture, maybe there should be reward for them doing that versus penalties for somebody who does something wrong.

 

Catherine Short

Right, everyone likes to be rewarded. No one likes to feel like they’re a bad dog, you know, with a smack with a newspaper or worse, obviously

 

Raymond Ribble

I think it gets viewed by the team, the employees in a much more positive light, if this is something we’re doing together. Hey, and if you have an idea on how we can improve it, I’d love to hear it. We sat down with the doctors and I’m thinking about who we work with a lot of clinics that are somewhere in the range of say 100 to maybe 1000 employees. So they’re always looking for creative ways to incentivize everybody doing better, it’s performance based. So security becomes a performance metrics as well and providing better security and doing a better job of creating that culture should be something that can be rewarded within the organization.

 

Catherine Short

True. I have a question again about audit. So what’s the probability that someone would get audited? What are your thoughts on that?

 

Raymond Ribble

Yeah, broad question. I’m going to attack it based on just what I’ve seen. I live in California, Catherine. So last year, I think was last year, I lose track now, we passed the California Consumer Privacy Act. My understanding is within the next two years, if not all, almost all of the 50 states and territories will have some type of Consumer Privacy Act in place. In many instances, like in California, some of that law supersedes HIPAA, in terms of reporting, in terms of having to grant access to patient data to the consumer, to the patient, and that could result in punitive actions and or investigation. So when we think about audit, you and I, we probably focus more on OCR related,  health and human services related activities. I think what’s happened is the landscape has changed. It’s gone from a Federal HHS issue, to include state level, privacy and security laws that now in many instances, again, can supersede what we have in terms of accountability, record keeping, documenting, and being able to prove that somebody did or didn’t do something within an organization. I think the probability of an audit today is much higher than the probability of an audit, say, two years ago or five years ago. It’s not a real number for you. That’s what people are faced with today. So I can’t give you a specific number. I don’t know one. But I know that that threat vector for us as organizations is increasing, not decreasing, because now we have federal and state that impact us. Does that make sense to you in the way that I’m stating that?

 

Catherine Short   18:45

Absolutely, actually, yes. And I’m glad you mentioned California, because California I know, I always think of being kind of like Europe with the GDPR and having more stringent laws, than federal

 

Raymond Ribble

A lot of other states flew into Sacramento and sat down with the state of California to see how they put that consumer privacy act together and in many instances, the other states, it’s a derivative of the California Privacy Act.

 

Catherine Short

Right. I have another question concerning security. What are your thoughts on the security of automatic logins on the computer like if it asks you if you want to save the password, and then you can just log in automatically next time? And then following up on that isn’t a problem when it asks you show your password? I always feel like I’m suspicious that someone out there might be capturing my screen. I might be extra paranoid, but at that, I think maybe not. I don’t think so. I feel like somebody’s watching

 

Raymond Ribble

Good question. I hate passwords. I bet you hate passwords too passwords. I’m a big advocate for at some point, I think we are going to move away from them, I think we’re going to move more towards biometrics, which I think is a better way to secure the data anyways, then whether it’s a fingerprint or a voiceprint, or an eyeball, whatever the case may be, I think they’re coming up with some really innovative solutions that we can incorporate. And I think we’re gonna see the MacBooks in the  Microsoft workstations out there start to incorporate that technology in the years to come. That will allow us to move away from passwords. So your question is about having those passwords saved? Because I know that in a Microsoft and in an Apple world, you find online they will say, Oh, do you want to save this password? and it gives you the username and the password and boom, it’s sitting there. So if somebody were to break into your PC, they can go find that file, it’ll tell them every application that you have access to and what the login and password is. So is that dangerous? Yes, it is.

 

I guess if you’re really smart, you know what you’re using? Don’t do it. Your question, you kind of answered your question in the way that you asked it, don’t do it. Is it a risk? Yes, it’s a risk. I would start by saying, make sure your PC is encrypted, make sure you actually have a sophisticated login process to get into your PC itself. Because there’s only a few barriers of deterrent between your PC and all that data that we’re talking about. So please make sure you have a real stringent password in place that you can remember, that’s not written down, by the way that one doesn’t get saved into that file, and you’re gonna have to remember that, right? otherwise, you’d have to do a jailbreak to get into your own machine. So you know, you’ve probably had those instances, and they’re like, well,  you don’t know the password and we’ve got to break into it, kind of a thing. So that’s a real problem.

 

The first part of my answer is, yeah, I think that is a risk. I know I have some there, I tried to think about which ones I want to have saved on there versus the ones that do. So I don’t want my bank information on there. I don’t want access to any sensitive materials on there. I don’t even want my Amazon account on there because God forbid somebody gets on Amazon and my cards already loaded into Amazon and they go on a shopping spree right? It might seem innocuous, but it actually can be very damaging to you. If you if you can avoid doing it, please do. And your applications on whether you’re using Chrome or whatever says, hey, do you want to store it? And you’re like, sure why not? That way, one more, I don’t have to remember. The problem is, the bad guys know how to find that file probably faster than you and I could.

 

Catherine Short

Right. That’s why I’m asking

 

Raymond Ribble

But the reality is, no, you don’t want to use it. If you can avoid using it, you want to create sophisticated passwords, which I think is the solution to that. Your username is usually your email, I mean, it’s almost 90% of the bar. And then sophisticated passwords, I always use the example and is just an example. I like the Boston Red Sox count that out in terms of the number of characters, anything longer than 12 characters, is really sufficient at defeating the algorithms that the hackers or a malicious insider might use in order to run against your machine to break the password code and get in. Most of the algorithms that they use are looking for an eight character based password. Once you move from eight to nine, nine to ten, ten to twelve, twelve to whatever, the time it takes for it to break into your machine grows exponentially. We’ll come back to why it’s taking too long, I don’t want to get into it. Now if they’re really hell bent on breaking into your PC or into your server, they’re going to do it because they’re happy to sit there hours, days, weeks to break into your PC will, you’re dead in the water. But most incidents are not that way. Another thing I might throw in here, just as a side note, Catherine, don’t use your PC at Starbucks or the local coffee shop because there are too many unscrupulous people out there using very simple $20 devices that can hack into your machine while you’re logged in. So, you know, if you’re on your phone, be careful what you’re looking at. Don’t do that kind of work, and don’t access those applications when you’re out in public. Keep that to your house and again, make sure you encrypt your PC and to the extent that you can avoid putting those passwords on your PC. There’s a long answer to an easy question, but sorry.

 

Catherine Short

Okay, very sound advice. I very much appreciate that. Well, I think that we are just about out of time here. Have you thought of any words of advice that you wanted to leave with our listeners?

 

Raymond Ribble

No, I don’t think so. I think what I try to do in my presentations, Catherine is the salient points that I’m trying to get across. I think for me, it’s upgrading your systems and making sure that the patches are properly up to date. It’s talking to your teams about security, I think it’s that simple. If they know that you’re thinking about it, they’ll think about it. If you don’t talk about it, they’re not going to be worried about it, talk about security, start talking about what can we do to improve security and work with my IT team to make sure that we have systems in place that allows us to regularly and properly monitor what’s happening within our system, not about trusting or not trusting your employees, we don’t know who’s surrounding them, we don’t know what’s happened in their life in terms of some life changing incident, that may move them from being the regular employee to be willing to do something that we might judge as malicious. And it could be again, for that personal gain but more importantly, it could be a reason for financial gain. If somebody is in a situation where they need to get money really fast, and the wrong person approaches them and tells them that, hey, some of those medical records would be worth thousands of dollars to me, you go from a very good employee to a very bad employee and sadly, it happens a lot. I’ve sat down with the FBI, I’ve sat down with OCR investigators, and they’ve heard enough stories about those types of situations, to know that it’s very real, that it’s that one incident that’s kind of broke the camel’s back and allowed or encouraged somebody to go do something that for many, many years they’ve never done before. So yeah, we trust our employees. I think we all do I do, I trust all the employees in my office, but having some type of regular and appropriate system that’s documented, that I can demonstrate to an outside party, defense lawyer during an audit or during a deposition that, hey, we do these things to protect our office and therefore, it’s not about not trusting my employees, it’s just making sure that we’ve done everything to protect our patients, I tend to look at it that way, Catherine

 

We had an organization who, using our technology, identified a user who had been with them for 17 years, who is going in and modifying records after the fact during lunch. Now, they were new to SPHER so they caught this with SPHERE. They radically looked at it, they started going back in the records, and they found that she’d been doing it for 10 years. Why? for financial gain. She was taking a little bit off the top and when we sat down with the doctor as part of the investigation, they indicated that Oh, wow, every year, we always seem to be coming up short in different areas and we thought it was really bad. We even changed our organization that did our collections for us a couple of times thinking that they were the ones doing it wrong. We never once considered there might have been somebody internally that was doing this.

 

Catherine Short

Oh, wow! that’s actually very sad. You never know.

 

Raymond Ribble

You never you never know. I don’t think you should feel bad about monitoring your end users. We’re just protecting our business from some event that could be catastrophic in terms of everybody losing their jobs because of a breach. With SPHER, we look at 100% of all the activity of all the users every day because you couldn’t possibly do that. Our users can read easily, and intuitively say oh, yeah, that’s a problem. I can see why SPHER flag that and let me investigate that. Bam. Make sense?

 

Catherine Short  28:22

Yes. Okay. Well, I think we’re about ready to wrap up our presentation then. So I wanted to thank you again, so much for sharing your time with us and your expertise. So thank you for being with us today.

 

Raymond Ribble

Thank you for having me today. It’s always a pleasure and good luck to everybody out there.

 

Catherine Short 

And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

RE-RELEASE Mastering Defensible Pricing in the Era of Price Transparency19 Feb 202500:15:55

In this episode of 1st Talk Compliance, we dive into an increasingly crucial topic in healthcare: price transparency and its ever-growing impact on the industry. Kevin Chmura, CEO at Panacea Healthcare Solutions, joins us to share expert insights on strategic pricing and compliance, emphasizing the transformative benefits for healthcare providers. Learn how to proactively engage with CMS regulations and set your organization apart as an ethical leader in the realm of price transparency.

RE-RELEASE The Sky’s the Limit: How Price Transparency Can Empower Healthcare Providers18 Feb 202500:27:19

Grace Walsh speaks with Kevin Chmura, CEO at Panacea Healthcare Solutions, to explore an extremely timely topic: price transparency and its far-reaching impact on how healthcare providers interact with consumers, with each other, and with the market at large. Tune in as Kevin shares some important insights about how price transparency has opened the door to a whole new world of data analysis and strategic business strategies for healthcare providers, and covers what we might expect to see for the future of price transparency. We’ll also include some key resources for listeners hoping to boost their knowledge of CMS price transparency regulations and learn how they can leverage price transparency data to empower their own strategic initiatives.

New HCPCS Code Requirements for Supplies: Managing Your CDM to Avoid Claim Denials03 Feb 202500:16:04

In this episode of 1st Talk Compliance, Kevin Chmura and BreAnn Meadows discuss the challenges healthcare providers face due to payers increasingly denying claims for supplies that are missing HCPCS codes. The issue stems from recent payer policy changes, with supplies that were previously chargeable now being rejected if they lack a corresponding HCPCS code. The conversation tackles the complexities providers face in managing their chargemaster (CDM), maintaining accurate HCPCS coding, and addressing claim denials, which can result in lost revenue.

Tune in to equip yourself with actionable strategies to avoid claim denials, as Bre underscores the importance of adopting a strategic, focused approach to managing your CDM, adapting to evolving payer practices, and staying proactive in compliance efforts.

The Two-Midnight Rule: Navigating the Complexities and Achieving Compliance08 Jan 202500:18:42

The Centers for Medicare and Medicaid Services (CMS) recently released additional guidance on the Two-Midnight rule that carries important implications for hospitals seeking to apply the rule correctly and consistently. In this episode of 1st Talk Compliance, host Kevin Chmura is joined by Stacy Pereira, Executive Director of Coding and Clinical Services in Panacea’s KA Consulting Division, to continue the discussion surrounding the Two-Midnight rule and the challenges it poses.

If you enjoyed Panacea’s recent webinar on the topic, or you’re simply looking for more information on how the rule might impact you, tune in for a deep dive into the potential challenges involved for hospitals seeking to apply the rule correctly, possible financial impacts of the rule’s enforcement, and pitfalls of over- or underusing observation status.

In case you missed our webinar on the Two-Midnight rule, you can watch it on-demand here.

Delivering Innovative Solutions: A Conversation with Panacea’s Newest Division President14 Oct 202400:24:07

In a landmark episode of 1st Talk Compliance, Kevin Chmura, CEO of Panacea Healthcare Solutions and host of the show, is joined by George Kelley, president of Panacea’s KA Consulting Services division.

For over 40 years, KA Consulting Services has delivered unmatched revenue cycle solutions, helping hospitals and health systems nationwide enhance reimbursement, improve compliance, and streamline Medicaid eligibility. Known for its eligibility services, clinical coding and auditing services, and revenue integrity solutions, KA Consulting has earned a reputation for providing solutions that go the extra mile to obtain appropriate reimbursement and to improve compliance. We are thrilled to welcome them as a division of Panacea Healthcare Solutions, further enhancing our commitment to delivering industry-leading healthcare financial, revenue integrity, and clinical solutions nationwide.

Tune in to get the inside scoop on this latest development as Kevin and George delve into KA’s background and our shared history and discuss how our newly combined expertise complements each other’s teams.

The Role of Compliance Programs in Mitigating False Claims Act Liability26 Jul 202401:01:48

The False Claims Act—alongside the Anti-Kickback Statute and Stark Law—represents one of the five core fraud, waste, and abuse laws identified by the HHS Office of the Inspector General. Out of the billions of dollars reclaimed through False Claims Act recoveries in 2023, the majority was attributed to the healthcare industry. This concerning trend highlights the importance of maintaining robust compliance programs and prioritizing education surrounding these regulations.

In this episode of 1st Talk Compliance, Rachel Rose, JD, MBA discusses recent key developments in the False Claims Act landscape and shares tips on how healthcare providers can enhance their compliance strategies and mitigate regulatory risks. Tune in to gain a comprehensive understanding of the False Claims Act and its role in the healthcare sector, hear updates on several recent significant fraud, waste, and abuse cases, and receive actionable insights into bolstering your organization’s compliance initiatives.

Part 2: The Sky’s The Limit – How Price Transparency Can Empower Healthcare Providers13 Jun 202400:56:39

Previously on First Talk Compliance, we spoke with Kevin Chmura, CEO of Panacea Healthcare Solutions, about how the advent of price transparency has caused the business of healthcare to evolve and opened up fresh possibilities for healthcare providers to gain a competitive advantage.

In this episode, we continue that conversation by inviting on two additional experts from Panacea—Govind Goyal, President of Financial Services, and Henry Gutierrez, Senior Vice President, Financial Consulting Services—to dive deeper into the recent changes to price transparency requirements and expand upon the many ways healthcare providers can adapt to succeed in this new consumer-driven arena. From navigating compliance regulations to leveraging data for a competitive advantage, tune into Part 2 of “The Sky’s the Limit – How Price Transparency Can Empower Healthcare Providers” to gain insight into the evolving landscape of price transparency and what lies ahead.

Navigating Private Equity in Healthcare02 May 202400:28:02

Private equity has become increasingly entrenched in the healthcare sector, offering various financing options for providers to consider. However, like all types of financing, private equity introduces its own unique set of benefits and drawbacks and carries important legal implications. It’s essential to understand all the factors at play in order to maximize financial impact and preserve operational efficiencies while avoiding sacrificing compliance and quality of care.

Tune in to hear Grace Walsh in conversation with Rachel Rose, JD, MBA, to explore this timely topic. In addition to providing a detailed overview of private equity in healthcare and its various pros and cons, Rachel shares valuable updates on enforcement actions by the U.S. Department of Justice and Congressional inquiries.

The Sky’s the Limit: How Price Transparency Can Empower Healthcare Providers26 Mar 202400:27:19

Grace Walsh speaks with Kevin Chmura, CEO at Panacea Healthcare Solutions, to explore an extremely timely topic: price transparency and its far-reaching impact on how healthcare providers interact with consumers, with each other, and with the market at large. Tune in as Kevin shares some important insights about how price transparency has opened the door to a whole new world of data analysis and strategic business strategies for healthcare providers, and covers what we might expect to see for the future of price transparency. We’ll also include some key resources for listeners hoping to boost their knowledge of CMS price transparency regulations and learn how they can leverage price transparency data to empower their own strategic initiatives.

The Importance of Defensible Pricing20 Feb 202400:15:55

Grace Walsh is joined by Govi Goyal, President of Panacea’s Financial Services Division, and Brian Prokop, Senior Vice President of Financial Consulting Services at Panacea, to discuss the importance of undertaking a strategic pricing initiative for your organization. In our current healthcare climate, it’s more crucial than ever to maintain defensible and rational healthcare pricing while remaining competitive and optimizing net revenue. As Govi and Brian can tell you, it’s a tricky balance to strike. Tune in as they share their tried-and-true approaches to developing defensible pricing strategies and learn how these measures can position hospitals for success in the era of price transparency.

2024 E/M Updates: What You Need to Know (Extended)31 Jan 202400:15:55

Grace Walsh is joined by Becky Jacobsen, Vice President of CDM, Coding & Audit Services at Panacea Healthcare Solutions, to explore the key updates to evaluation and management (E/M) guidelines for 2024. On the surface, this year’s changes may appear fairly straightforward, but dig a little deeper and you’ll find that the updates have important implications for correct coding procedures. From payers, providers, and coders to those who work in auditing or IT template development, it is essential to keep up a comprehensive grasp on E/M coding guidelines. Tune in as Becky breaks down a few of the most significant guideline updates, clarifies some common areas of confusion, and shares her insider tips as an expert in the field of coding compliance auditing and education.

2024 E/M Updates: What You Need to Know22 Jan 202400:15:55

Grace Walsh is joined by Becky Jacobsen, Vice President of CDM, Coding & Audit Services at Panacea Healthcare Solutions, to explore the key updates to evaluation and management (E/M) guidelines for 2024. On the surface, this year’s changes may appear fairly straightforward, but dig a little deeper and you’ll find that the updates have important implications for correct coding procedures. From payers, providers, and coders to those who work in auditing or IT template development, it is essential to keep up a comprehensive grasp on E/M coding guidelines. Tune in as Becky breaks down a few of the most significant guideline updates, clarifies some common areas of confusion, and shares her insider tips as an expert in the field of coding compliance auditing and education.

Mastering Defensible Pricing in the Era of Price Transparency08 Nov 202300:15:55

In this episode of 1st Talk Compliance, we dive into an increasingly crucial topic in healthcare: price transparency and its ever-growing impact on the industry. Kevin Chmura, CEO at Panacea Healthcare Solutions, joins us to share expert insights on strategic pricing and compliance, emphasizing the transformative benefits for healthcare providers. Learn how to proactively engage with CMS regulations and set your organization apart as an ethical leader in the realm of price transparency.

The Increasing Role of the FTC in the Poaching of PHI – A Discussion of Better Help, GoodRx & Flo: Audio Version of the Webinar08 Jun 202300:53:30

Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX will be presenting this informative webinar. Cybersecurity risk management and the potential for enforcement actions is not diminishing. An area of increasing interest by the Federal Trade Commission, the United States Department of Justice, and Congress is third parties taking sensitive data (especially by social media and search engine giants), including protected health information, without obtaining affirmative patient/consumer consent and benefiting financially. The U. S. Department of Health and Human Services, the agency tasked with enforcing HIPAA, also plays a critical role. The purpose of this presentation is to address different federal government initiatives, recent enforcement actions and incidents, and risk mitigation.

This webinar will cover the following objectives:

1. Learn about the differences between various laws and the implications for liability in relation to not obtaining the appropriate patient/consumer consent before using sensitive information for sales and marketing purposes.
2. Appreciate the various initiatives, incidents, and enforcement actions taken by private entities in disclosing potential breaches, as well as different federal government enforcement action.
3. Glean risk management tools to incorporate into compliance programs.

Evolution of Price Transparency and How to Stay Ahead of CMS Requirements07 Jun 202300:28:05

1st Talk Compliance features guest Govi Goyal, President, Financial Services, at Panacea Healthcare Solutions, on the topic of Evolution of Price Transparency and How to Stay Ahead of CMS Requirements. Govi joins our host Catherine Short to discuss how the new CMS Price Transparency Rule and No Surprises Act are closely related. By providing Good Faith Estimates for healthcare services, hospitals can comply with both regulations. This helps patients understand their expected costs upfront and avoid surprise medical bills. Panacea’s CMS Price Transparency and Hospital Zero-Base Pricing software solutions can assist hospitals in providing accurate Good Faith Estimates to their patients and stay compliant with the latest regulations.

 

 

 

 

 

Healthcare Assets – How to Preserve and Protect30 May 202300:27:56

1st Talk Compliance features attorneys Sean McKenna, Lauren Nelson, and Vincent Aiello of Spencer Fane LLP, on the topic of Healthcare Assets: How to Preserve and Protect. Sean, Lauren, and Vince join our host Catherine Short to discuss the interplay between enforcement and liability proceedings with asset protection, explore how government and private litigation matters can impact healthcare companies, clinicians, and executives, and provide tips and preventative strategies to preserve income and assets prior to such action to ensure business continuity and succession planning.

 

 

A Harassment-Free Workplace vs the Right to Engage in Concerted Activity08 May 202300:29:05

1st Talk Compliance features guest Lauren Moak Russell, Counsel at Young Conaway Stargatt & Taylor, LLP in Wilmington, Delaware, on the topic of “A Harassment-Free Workplace vs the Right to Engage in Concerted Activity.” Lauren joins our host Catherine Short to discuss how the National Labor Relations Board under the Biden Administration has expressed a renewed interest in expanding its influence into non-unionized work forces. This includes reviewing and–in the right circumstances challenging–employers’ use of workplace civility, confidentiality, and anti-harassment policies. Listen as we discuss what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.

Catherine Short:  0:01

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

On today’s episode, we are speaking with Lauren Moak Russell, Counsel at Young Conaway Stargatt & Taylor, LLP in Wilmington, Delaware, on the topic of a harassment free workplace versus the right to engage in concerted activity. The National Labor Relations Board under the Biden administration has expressed a renewed interest in expanding its influence into non-unionized workforces. This includes reviewing and in the right circumstances, challenging employers use of workplace civility, confidentiality, and anti-harassment policies. Listen as we discuss what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.

 

Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals, and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Sharon Miller, administrator at Gulf Coast Dermatopathology Laboratory. Sharon says “patient care is paramount and by creating a culture of caring, compassion and respect, we have succeeded in all we do. We try to promote a family atmosphere which in turn translates to ultimate patient care”. Congratulations, Sharon. Our team is honored to have the privilege of working with you.

 

Well, thank you so much, Lauren, for being on First Talk Compliance. Thank you for being here.

 

Lauren Russell  2:16

My pleasure. Thank you for having me.

 

Catherine Short  2:18

Today, we’re talking about workplace civility, and also about the National Labor Relations Board. Can you get us started in talking about how things have changed as opposed to the previous administration?

 

Lauren Russell  2:34

Absolutely. So I think that the first thing that listeners really need to understand is that the National Labor Relations Board is not just for unionized workforces, that it has a role in regulating nonunion workforces, particularly where employer policies impact what we call section seven rights, and that’s really employee’s rights to talk about the terms and conditions of their employment.  This is an area where we see a lot of ebb and flow between Republican and Democratic administrations at the federal level. I know it’s not a popular thing to talk politics these days, it’s oftentimes very inflammatory, but the reality is that the board changes its conduct very significantly between administrations. And so we had under the Trump administration, a board that really saw its role as very limited in terms of just regulating the relationship between organized labor, which is what we call a unionized workforce and management. To a Biden administration and a board that really sees its role as very expansive and is very focused on ensuring that even in a non-organized workforce, so a non-unionized workforce, that employers are conducting themselves in a way that does not adversely impact employees, what we call Protected Concerted Activity. So their ability to talk about the terms and conditions of employment. This includes a lot of things that make employers uncomfortable, including wages, compensation, comparing how much I make to how much you make, masking, vaccination requirements, anything that keeps a manager up at night, is something that almost certainly touches on Protected Concerted Activity and that can be protected by the National Labor Relations Board.

 

Catherine Short  4:33

So, employees have the right then to discuss their pay with each other. Is that correct?

 

Lauren Russell  4:41

Yes, it is. This is something that makes employers really uncomfortable. I understand. I come from a family where we don’t talk about money because I think a lot of us do, right? It’s very crass.

 

Catherine Short  4:59

Yeah. I never asked my parents or if I did, I was shut down right away. You know, like what you don’t talk about, you don’t ask people how much they make, what’s wrong with you?

 

Lauren Russell  5:09

Even at 40, I don’t know how much my parents made at any point in their lives. So no, it’s not just about being a child. It doesn’t change. That was very much the way of things. In my parent’s generation, it was simply something that wasn’t done, and certainly my grandparents never, never, never, never, in a million years, never. But wages are really the heart of the terms and conditions of employment, that is the most essential thing. So, the National Labor Relations Board for a very long time predating my practice, starting back in 2009, well before that, the National Labor Relations Board has said policies that prohibit employees from discussing and comparing wages are a violation of the National Labor Relations Act. It does not matter if you have a unionized or a non-unionized workforce, you still may not have policies like this. It’s hard, it does create resentment and frustration and questions and gossip among employees. We have to look at it from the flip side, from the public policy perspective. On that side, employees can’t know if they’re being treated unfairly unless they’re able to talk about wages. That’s really the impetus for these policies and I think that it’s helpful, it keeps employers from getting really angry when we look at it from the public policy perspective. Then you can say, well, it makes my life more difficult. I guess I can understand that women or minorities or individuals with disabilities, they couldn’t discover that they were being treated differently if they were never, ever under any circumstance allowed to talk about their wages with other employees. That’s the way we figure this stuff out.

 

The Obama administration was very focused on the expansion of the role of the National Labor Relations Board, the Trump administration, I had a much more conservative view of the role of the federal government, and really pared back the enforcement activities that the board was engaged in. Now that we are back under a Democratic administration, that role is expanding, again. I happen to be somebody who thinks that predictability is a very important thing for business. So, whether you are going to have an expansive view or a retracted view of the board’s role, and there are grounds to argue for both, it’s not that one side is patently wrong and the other is patently right. It’s really a matter of philosophy, on whatever the case may be, it is good for businesses to know what the expectations of them are. The National Labor Relations Board swings much more broadly than any other federal enforcement agency. That’s a tough thing for employers to cope with so this is really a problem for both sides of the aisle. I don’t think that anybody is conducting themselves, necessarily in the way that provides the most predictability for business. The best we can do here on the outside is to make sure that employers are educated and know that these risks are out there. I’m certainly talking about it a lot more because I am seeing and I was in practice, under the Obama administration, the Trump administration, and now under the Biden administration, I have never seen as much effort to enforce against the private sector, as I am seeing now. So, Biden has held true to his promise to be the most labor friendly president that many of us will see in our lifetimes. So, even though the Obama administration expressed an interest in pursuing these matters, we’re seeing the enforcement drive from the Biden administration that perhaps was not quite so present before.

 

Catherine Short  9:19

Okay, so it sounds like there’s a lot of reason to be concerned. And I know this from talking to a lot of our administrators, like hospital administrators, practice administrators, all kinds of CEOs and CFOs, etc., that they have a lot on their plates right now and so much to be concerned about. It feels probably for some, that this is just another thing that they need to be worried about, right? If you could give one piece of advice to businesses and if they can only do one thing, what should it be?

 

Lauren Russell  9:52

I would take a really careful look at handbooks. That is an area that almost every business I represent neglects because, it’s there and this other thing is an emergency and  I’ve got to put out that fire. And to your point, everybody has a tremendous amount of work on their plates right now. This is the most difficult environment to operate and that I’ve ever seen. It is truly amazing that people are able to get up and soldier on every morning. That’s from the management side and from the labor side, everybody’s got a lot on their plate. If we could move the handbook to the top of your non-emergency stack, that’s what I would do. Handbooks should really get a thorough going over every couple of years anyway. If you haven’t taken a careful look at your handbook in the last two years, to update it and make sure that it’s compliant with your current labor and employment laws, that’s a great thing to do. And take a look at those things: workplace civility, social media, and make sure that you’re really focused on illegal behavior and not just that employee shouldn’t say things that make us unhappy. Any policy that’s designed to keep employees from saying embarrassing things in public is going to likely be a problem. We should really be focused on: do not engage in illegal behavior, if you are on Facebook with a picture of you and your favorite marijuana paraphernalia that’s something we can prohibit. We can prohibit harassment and discrimination and defamation. Defamation is illegal behavior. That is it’s a tort, it is unlawful. You can prohibit defamatory conduct. But when we’re talking about general civility and being nice and be courteous, that’s a tough thing to enforce.

 

Catherine Short  11:44

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Lauren Russell, Council at Young Conaway Stargatt & Taylor, LLP, on the topic of a harassment free workplace versus the right to engage in concerted activity.

Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.

 

Okay, could you talk to us about the National Labor Relations Board or the NLRB’s current enforcement policies?

 

Lauren Russell  12:35

Yeah, I mean, as I said a few minutes ago, there’s really been a focus on expanding their role in the private sector non-unionized workforce. When we’re looking at that, the driving force behind this is the current general counsel for the board, Jennifer Abruzzo. She is a brilliant woman. There has been a sense at times that she may be a little bit more aggressive than even sometimes the unions are comfortable with. But she is the driving force behind these priorities, and they include a couple of things.

She certainly is very focused on lowering barriers to unionization in the workforce. And so she’s looking to bring back certain on administrative policies from the Obama era that either got stalled out or were challenged in court, including lowering thresholds to union organizing, and in a non-unionized workforce. And then also making it harder to oust a union, once it’s in. She is looking to reverse past decisions by the National Labor Relations Board under the Trump administration. It’s helpful to understand a little something about the composition of the board. The board consists of five individuals, five members who are appointed. Under a Democratic administration, it’s usually three Democrats, two Republicans, under a Republican administration, it’s usually three Republicans and two Democrats, and then the general counsel is a presidential appointee. So, she was appointed by Biden, after he terminated her predecessor, who was a Trump appointee who refused to step down. So, there’s a bit of a kerfuffle there. The board changes its orientation very promptly upon a change in administration. You usually have to wait for some for one of the members to come to the end of their tenure, but then you have a very rapid switch, and so the board can completely flip from a Democratic and Republican administration. With that in mind, with that background, she’s looking to reverse precedent on a couple of things including when an employee is engaged in Protected Concerted Activity. She wants to reverse some case law that held that an employee is not engaged in protected activity when other employees don’t join in complaint or offended by the complaint. This is really designed to protect individuals who are expressing unpopular opinions. She wants to reverse past case law that gave employers discretion, she wants to limit employers’ ability to impose confidentiality in the course of internal investigations and in settlement agreement and challenge that, because it impacts an employee’s freedom to speak about the terms and conditions of employment.

 

Then she really wants to focus on limiting what an employer can do in a handbook. So, limiting a handbook policies that in any way, on their face, would make a cautious employee less likely to engage in their section seven rights. By that I mean to talk to other coworkers about terms and conditions of employment. When we’re looking at those kinds of policies, we’re looking at confidentiality, non-disparagement, social media, media communications, civility, and respectful workplace policies, offensive language prohibitions, and no cameras at work rules. All of those things, when they are applied in just the right way can make a cautious employee and that’s the standard she wants. Not an average employee. Usually in the law, we look at a reasonable person, right? That is an imaginary reasonable person is who we look at when we decide what the legal standard is. She says, no, I don’t want you to think about a reasonable person. I want you to think about a cautious employee. That is our standard. If they feel like an employer policy, inhibits their ability to speak freely to coworkers about terms and conditions of employment her position is that handbook policy gotta go

 

Catherine Short  17:20

Can you expand a little bit more on what her definition of what a cautious employee might be?

 

Lauren Russell  17:25

Well, it’s certainly not a defined concept. But I’ll tell you a cautious employee is one that complains to the board.

 

Catherine Short  17:31

In my mind, a cautious employee would be somebody who’s super careful, but who would not complain, who would be really careful about what they say. Cautious to me is caution.

 

Lauren Russell  17:42

Keep in mind that the National Labor Relations Board, like every other federal agency has very limited resources. So as a general rule, they do not have a practice of auditing, non-unionized workplaces. The board would not knock on the door at First Healthcare Compliance and say “we’d like to see your employee handbook, please show it to us”. Similarly, they would not do that at my firm. So what has to happen is an employee has to go to the board and say, I think this, this handbook is discouraging. It’s somebody who’s not necessarily complaining internally and that is very frustrating to employers as well. How was I supposed to know you felt discouraged? I didn’t intend to discourage you. You never told me you felt discouraged. Instead, you went off and filed a charge. That’s the cautious employee.

 

Catherine Short  18:38

Okay. All right. Interesting. Okay, let’s talk about social media for a second. Can you explain a little bit about what is expected concerning social media at this time?

 

Lauren Russell  18:52

Social media is my nightmare.

 

Catherine Short  18:56

And for a lot of employers. You have some employees who don’t engage in social media whatsoever, and then some employees who are extremely engaged. So what’s the role right now?

 

Lauren Russell  19:07

Yeah. Certainly, you can expect employees to be lawful online. That is a perfectly reasonable expectation to say. Believe it or not, I’ve got clients who have to have a policy that says, Please do not post photos of unlawful activity. You should not have open containers of alcohol in a vehicle. You should not post photos of your marijuana paraphernalia. You should not post racist diatribes on Facebook. Depending on your workforce that may or may not be something you need to say. All of that behavior is something that you can expressly prohibit. What you can’t prohibit and what a lot of social media policy say is that you may not post anything online that criticizes the company or its customers client, patients etc. Now, in the healthcare context, we have some additional overlays. Most employees have HIPAA obligations, and you can absolutely say you may not post anything online that violates your duty of confidentiality under HIPAA. You cannot say Mrs. Smith was in today and she was a raging you-know-what, and I hate her and I hope she never comes back to this practice.

 

Catherine Short  20:26

I know perhaps some people like to go on diatribes on social media, personally, as themselves not as representative of their company and say, all kinds of things.

 

Lauren Russell  20:38

When we’re talking about where the board wants to flex its authority, it comes in two places. One is the policy itself. If you have no social media policy, then then there’s nothing for them to look at. The other is, when we apply the policy, are we adversely impacting Protected Concerted Activity. Going on Facebook and saying every member of the Green Party is an unmitigated idiot is not protected concerted activity, it’s not about the workplace, it’s about the world out there. So you can absolutely and if a patient or a coworker comes in and says, your receptionist on Facebook called me an idiot, and I don’t want to deal with them anymore, if you don’t fire them, I’m going to leave the practice. That’s okay. You can fire the employee, because their social media conduct has adversely impacted the business and they have tied themselves to the business in some way. Very frequently this happens because somebody tagged themselves to your company’s Facebook page, or they have a picture of themselves wearing a First Healthcare Compliance T shirt, and so they associate themselves online, and then somebody figures it out. They say,  so and so was saying offensive things on the internet, I see they’re wearing their shirt, I went to your website and see that they work for you and I think you should know about that.  I have had those cases and that person’s gone. They were the ones who tied themselves to your company on the internet and that’s their fault.

 

When we’re talking about actual concerted activity or the impact on the workplace, and this does happen, somebody posts on the internet, for example, something inflammatory about undocumented immigrants that borders on racist right on or says every member of the Republican Party is a racist, you can’t be Republican and not be racist, and you have a Republican employee who says, this is outrageous. This person is calling me racist on the internet, I’m deeply offended, I don’t feel comfortable working with them anymore. Again, that behavior is not protected, concerted activity. They’re talking about Republicans out in the world, they’re not saying the Republicans I work with are racists, they’re saying all of them in their totality. That is again, behavior that creates a hostile environment, it makes people deeply uncomfortable, and you can discipline that behavior, or you can terminate the employee. In the same way if somebody was posting racist or sexist messages, so instead of calling somebody else racist, I am posting deeply inappropriate things on the internet, jokes and memes about women should be barefoot and, in the kitchen, right? Because a female coworker comes in and says, I am deeply offended. I am a working woman and a mother, and this person thinks my only worth is to be at home. Like that’s, that’s offensive to me. Okay, we can discipline that behavior.

Where the board gets interested, is when an employee goes on social media and criticizes the employer. If I go in on social media and say, my manager at XYZ company is racist, he will not denounce police violence in the country. Or he is paying female employees less well than male employees. That is Protected Concerted Activity. I have gone into a public environment and on behalf of myself and other workers have criticized management and said, this is an illegal environment, or there were unlawful behaviors happening here. I don’t know a single manager that I’ve ever met, who wouldn’t be deeply offended and upset that somebody took that to Facebook instead of talking to them first. And so the gut reaction is always fire them, discipline them. They took internal business to Facebook, they never talked to me. I had no chance to deal with this and now they’re defaming us on social media that’s Protected Concerted Activity and that is a real risk to the business if you discipline.

 

Catherine Short  24:47

So I have a question about employee expectations and labor rights perhaps do they extend to part time contract employees and also interns?

 

Lauren Russell  24:57

They apply to part time employees. Yes. Contractors? No. When you have independent contractors who are regularly working on your site like temporary staffers, the answer is often Yes because there’s a joint employment relationship. Interns, it depends. But generally if they’re paid interns like a summer intern, yes, they’re going to be covered. If it’s a volunteer, like at a hospital, you often have individuals who come in to read to sick children, or they will sit with the elderly patients. Those are not employees of any stripe, they’re volunteers. And even if it’s sort of a summer internship candy striper situation, it’s really more on the nature of volunteerism, and not within the scope of the board’s authority.

 

Catherine Short  25:47

Okay, well, I think we’re just about out of time. Did you have any other words of advice or things that you wanted to discuss that we didn’t talk about? Perhaps,

 

Lauren Russell  25:59

No solid guidance, but I will tell you anecdotally that I have watched businesses unionized, and I have watched them vote out unions. The key distinction is a level of basic respect between management and labor. You know, there’s a lot of research out there on healthy marriages. The marriages that succeed are ones where there’s mutual respect between spouses. If there’s a lack of respect, if spouses roll their eyes at each other, that’s a sure sign that one day they’re going to be divorced. That same guidance applies to labor management relations. You don’t have to agree on everything, and they oftentimes don’t. But when you can have dignity and respectful communications, that is a workforce where you are much less likely to see unionizing efforts generally, and specifically where you’re going to see even in non-unionized workforces, where you’re going to see charges brought before the board. When employees feel respected, and like their partners, you are always going to be in better stead. It’s a hard thing to do, but cultivating respect, making sure that even your low-level employees feel like they are a critical part of your success, and that they help you to have a voice in how decisions are made. It’s hard to do, but that makes a huge difference. Okay,

 

Catherine Short  27:33

Well, I want to just thank you so much. Lauren, did you have any other words of advice that you wanted to leave us with today?

 

Lauren Russell  27:39

Tolerance, kindness. I will tell you that you run into union problems when both sides of the equation management and employees are not able to take a deep breath and say, hey, I really need you to hear me but I could have said that nicer. I keep seeing these news headlines about how mean people are right now, that people are just hit their limits and they are mean. I hear that anecdotally from clients too. I think we’ve got to take a deep breath and be a little less mean. When there was a sense of respect and dignity between labor and management you really avoid the vast majority of these issues. So kindness.

 

Catherine Short  28:22

Great. That’s always wonderful advice. I wanted to thank you so much for being here today.

 

Lauren Russell  28:27

Very happy to be here. Thank you for the opportunity.

 

Catherine Short  28:31

And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

False Claims Act “Hot Areas” – What You Need to Know: Audio Version of the Webinar18 Apr 202301:05:08

Expert presenter, Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX guides us through current trends and tips.
With its roots stemming back to 1863, the False Claims Act continues to be the U.S. Department of Justice’s primary enforcement tool for returning money to the Federal Treasury. It is also considered one of five fundamental fraud, waste, and abuse laws, which potentially impact a provider every time a claim is submitted to Medicare, Medicaid, and other government programs because of the attestation language. The purpose of this webinar is to provide a synopsis of the False Claims Act and the current landscape in relation to coverage determinations and the federal Anti-Kickback Statute.

This webinar will cover the following objectives:

  1. Learn about current case law and some of the diverging opinions in different federal courts.
  2. Appreciate the hot areas of potential liability.
  3. Understand how a legitimate and robust compliance program comes into play with the recent changes to the DOJ’s cooperation credit and compensation reforms from both the criminal and civil divisions.
A Practical Approach to The Safe Harbor Law10 Apr 202300:28:22

1st Talk Compliance features guest Raymond Ribble, CEO and Founder at SPHER, Inc., on the topic of A Practical Approach to The Safe Harbor Law. Ray joins our host Catherine Short to discuss how HIPAA data breach penalties typically get measured in millions of dollars, even following an organization implementing NIST cybersecurity framework measures. However, with the new HIPAA Safe Harbor Law, signed in January 2021, HHS and OCR may consider some penalty mitigation. It is important to understand that the Safe Harbor Law, while offering substantial protection, does not provide a true safe harbor and only offers some protection. This episode will examine what the established security practices for healthcare are, and how to pivot your organization’s security profile to mitigate breach penalties if an event occurs.

Catherine Short 0:01

Welcome, and let’s, 1st Talk Compliance. I’m Catherine Short, Marketing Manager for First Healthcare Compliance, a division of Panacea Healthcare Solutions. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes, and be sure to follow us on social media and subscribe to our YouTube channel.

On today’s episode, we are speaking with Raymond Ribble, CEO and Founder at SPHER Inc, on the topic of A Practical Approach to The Safe Harbor Law. HIPAA data breach penalties typically get measured in millions of dollars even following an organization implementing NIST cybersecurity framework measures. However, with the new HIPAA Safe Harbor Law signed in January 2021, HHS and OCR may consider some penalty mitigation, it is important to understand that the Safe Harbor Law while offering substantial protection does not provide a true Safe Harbor and only offers some protection. This episode will examine what the established security practices for healthcare are, and how to pivot your organization’s security profile to mitigate breach penalties if an event occurs.

 

Catherine Short 1:39

So Ray, thank you so much for joining me on 1st Talk Compliance. It’s a pleasure to have you on.

 

Raymond Ribble 1:42

Thank you for having me, I appreciate it.

 

Catherine Short 1:43

Again, I’m so happy you’re here today. Today we’re discussing about the Safe Harbor Law and we’re going to be talking about a practical approach. For people who are new to this, can you give us a good background or a brief description about what we are going to be discussing as far as some compliance background? Or how we got here as far as I know that HIPAA has a Safe Harbor Law? And I know that that affects how people need to protect their health data and their data in general. Can you give us a little bit of background of what we should be protecting and what we should be careful of and what we should be discussing?

 

Raymond Ribble 2:27

Sure. For our listeners, I’ll try to give you the cliff note version of what it is. What I wanted to do for everybody who’s listening today is just give you a brief introduction to what is the Safe Harbor Law. I don’t want you to become experts on the Safe Harbor Law, I don’t want you to be able to click off the five things that it does. That’s not the background. It’s just that some well thought politicians in both the Senate and the House got together and said, Hey, look, we’ve provided all this money to help these medical institutions move from paper to digital. In doing so, we’ve exposed them to a brand new set of risks in terms of data breaches that can occur that didn’t exist before. And now we’re asking them to spend more money to implement policies and procedures and potentially technology solutions in order to protect that digital data. So that’s the first part of it. And they said look, for the organizations that embrace these ideas that go the extra mile that implement these policies and procedures, that are not experts on the Privacy Rule in the Security Rule and HIPAA, but they do understand that protecting patient data is a new requirement that they have to adhere to, and they want to do their best. They don’t want to do the best. They want to do their best to protect that data. They wanted to incentivize those organizations for implementing cybersecurity best practices.

And in doing so, they put out what was called the House Resolution 78 98, which became the Safe Harbor Law. It was signed into law on January 5, 2021, by the President, and basically, that became public law 116-321, which is affectionately called the Safe Harbor Law. There are Safe Harbor Laws in other industries. This particular Safe Harbor Law is specific to the healthcare industry. So that’s why it’s important to you and I and to our listeners today.

 

This Safe Harbor Law again, 116-321 is the high-tech Safe Harbor Law if you want to think of it that way. And what it says is that if you implement policies and procedures, technologies, training, documentation around protecting your patients PHI (Protected Health Information), and you still experience a breach, that when the investigation from the OCR auditors occurs, and it will occur, that you will not be penalized as heavily as an organization who did nothing. That you should be incentivized ie through that lack of penalties and monetary penalties, you should be incentivized to do that, so that there is a risk-reward type scenario that’s set up in this. If you’re going to spend the money to protect that data, and then ultimately, it really happens and you have a breach, you should be getting a pat on the back and a reward for having spent that money and the time and the investment and the education with your staff to do the best that you can do. Nobody can fully prevent a breach, but you went the extra mile, and they wanted those organizations to be rewarded.

The word they use, is it mitigates the probability of a major penalty, but in my opinion, really what they’re saying is attaboy, it’s not going to cost you 8.1 3 million and might cost you 50,000. You had a breach, that’s a bad thing. There’s some risk slapping that has to take place, but you’re not going to pay millions of dollars, because you paid up front, you made the investment to do the best that you could do, those cybersecurity best practices that I spoke about, you implemented parts of NIST, you went out and purchase some third party products, you educated your staff, you documented all of that, you did your security risk assessment every year, you did what was reasonable and appropriate for an organization of your size, and you still had a breach. Should you be blamed for that? The bad guys can basically spend 365 days a year trying to break into your system. You’re not going to spend 365 days trying to prevent them from breaking into your system. So there’s got to be some risk reward there. That’s where the Safe Harbor Law is coming from.

 

Catherine Short 7:17

That was a really great explanation. Thank you so much. That actually was a very practical approach. Concerning standards of security. What should we be using as a guide? For example, does HHS  provide a guidebook?

 

Raymond Ribble 7:32

I think a great starting point is NIST. For those of you who don’t know what NIST is or what it stands for, so National Institute of Science and Technology. Basically what they do is they provide a security framework for many industries, not just the healthcare industry. What I’ve recommended to organizations is if you take a look at NIST in the five key areas that they identify, and then you put that together with the recommendations coming from the 405(d) taskforce, then I think that that is a blueprint that you can start going down towards protecting your organization without making mistakes or spending money where you don’t need to spend money.

 

Catherine Short 8:16

What is NIST cybersecurity framework?

 

Raymond Ribble 7:20

The NIST cybersecurity framework comes from the National Institute of Standards and Technology. It was developed many years ago, as a guideline to help organizations to understand what they need to do in order to identify, protect, detect, respond, and recover important data. So outside of healthcare, it might be PII, in healthcare world what we call PHI (Protected Health Information).

It’s a set of guidelines that we can look at and apply to our organization. Some of them are procedural. Some of them are technical in terms of third party products, or downloadable products from manufacturers that cost us nothing, that we can put in place that allows us to see who’s looking at our data, when are they looking at the data? Is that appropriate for them to look at the data? If it’s not appropriate, and we’ve determined that it’s a problem, then how do we recover that and how do we respond to that? So NIST security framework would be complimentary to us following the HIPAA rules, whether it’s the Security Rule, the Privacy Rule, the Breach Notification Rule. By following NIST and the NIST cybersecurity framework. This is very much in line with what we’re doing for our HIPAA compliance

 

Catherine Short 9:53

If a facility can afford to do this does that in itself, grant them the protection and penalty mitigation that you’ve talked about previously?

 

Raymond Ribble 10:04

I like that question. Let me do my best to answer it. Let’s just take make the assumption that we don’t have a lot of money and historically, my organization has never spent a lot of money on technology to protect patient data. Let’s just that’s our example for this question. But I took the time to look at this NIST cybersecurity framework and I can see what the five key areas are. They’re making some recommendations, I went over to 405(d) task group, and I saw what they had and I said, Okay, I’m going to pick two or three things from each of those five things. I’ll repeat them just for the sake of the audience: identity, protect, detect, respond, and recover. And I’m going to apply a few of these rules to each of these that I think best aligns with the type of organization we have, whether we’re a pediatrics, an oncology, dermatology, plastic surgery, whatever type of practice we are, we all fall under that HIPAA umbrella. And what I’m trying to do is apply certain rules or guidelines that NIST provides in order to protect the data. Even if none of the things that I do involve me purchasing a third party product to do it. If I can accurately, regularly and appropriately document that I’m doing that, then the answer to your question is yes, that would allow us to mitigate, in the event of a breach mitigate the

exposure to penalties that might come from an OCR investigation.

 

Catherine Short 11:40

If you had to name perhaps three security practices, what do you see as being the most important first to use today?

 

Raymond Ribble 11:50

Three that I think would be the most important, I think protecting your email is extremely important. It is probably the one thing that everybody listening today uses and probably uses almost from the minute they get up until just before they go to bed. They’re accessing email, they’re looking at messages, they’re opening emails from third party, some of them are unknown third parties. So having email protection on your devices, especially devices that handle PHI, to me, is extremely important.

Two, access management. Knowing who’s coming into my system, and who is accessing the PHI and are they accessing that information for the purpose of providing care to our patients, would be equally important to me.

The last thing, if I look at this, I would say is going to be having good cybersecurity policies. So that’s more of not a technical thing. So email, access management, and cybersecurity policies. Educating my staff on what to do, and what to look for, if they see something that seems suspicious, just teaching them not to click on it, not to open it, to ask questions first, can save us millions of dollars. So if I broke down those 10 to three that I feel are important, and a different person might give you three different answers. Those would be the three I would pick off the top of my head.

 

Catherine Short  13:22

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Raymond Ribble, CEO and Founder at SPHER Inc, on the topic of  A Practical Approach to The Safe Harbor Law. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.

 

Catherine Short  13:57

If we’re discussing phishing emails, does it help if we monitor them, if we implement encrypted email?

 

Raymond Ribble 14:04

If we’re trying to prevent phishing emails from getting into our system, we would typically install something like Malwarebytes or Bitdefender, or Sophos, or many of these third-party products. Some of them are even sold with your laptop and your PCs, your Mac books when you buy them. You want to make sure that you activate those licenses and that you use them and they help to prevent certain types of phishing emails to come in.

Having said that, your question was also with regard to just email encryption as well. Email encryption is very different from phishing emails. Email encryption is encrypting, so it’s codifying the email that you’re using to do business and ensuring that if some third-party intercepts that email which is not phishing, that they cannot encode that and look at it unencoded, and see what was in there. Two different things completely. Just to be clear, I hope I’m answering this question correctly.

So I do recommend that you don’t use products like Gmail, or AOL, or any at home third party email system to be sending information to your patients. I think something that was discussed before is, you should be using the portal that’s provided to you by your EHR company, in the best of my knowledge 90% more provide those types of portals that you can use that as a way of communicating and that data is encrypted. So that email is encrypted, they’re providing that encryption for you as a byproduct of using their solution. So that solves a lot of problems for you.

 

If you have your own email server, that you communicate with your patients with for whatever reason, then you should be installing some type of third-party email encryption on that system. The responsibility under the law is you must encrypt that email going out. There is not the equivalent of the patients sending you email and having ePHI in that email, that is not a violation because HIPAA doesn’t apply to them the way it applies to you. So let me pause there and make sure. Am I answering the question correctly?

 

Catherine Short 16:32

Yes, sure.

 

Raymond Ribble 16:34

Okay. Because there are two different things there that you asked me actually.

 

Catherine Short 16:38

So yeah, that was great.

 

Raymond Ribble 16:42

Okay, good. So again, phishing, I want to use third party products, to catch the majority of the phishing emails. And then let me add to that, Catherine, is, let’s be careful. If we see something we recognize, just because we recognize it, please don’t click, look first, put that cursor over wherever it says click here. Look down in the lower left hand corner and see where it’s actually going. Ask yourself, was I expecting this email? Is this email something that I normally get from this organization? And if those answers are no, hey, just leave it alone. Go to your interface that you might interact with that company, whether it’s your bank, or your cable company, or you’re a third party hosting site, and call them and say, Hey, by the way, I got an email from you guys, it says, and I guarantee you 99% of the time, they will say to you, we would never send you an email for something like that, right? You hear it all the time. They don’t send those things because they know that’s what the bad guys are doing. So they don’t send them. So when in doubt, don’t click in check first. That’s I want to add that as a caveat to the answer for phishing. Okay,

 

Catherine Short  17:57

Perfect.  When you’re talking about phishing emails, you probably look at this a lot more as far as where they’re coming from. With phishing emails, do you think that they coming more from organizations, either organizations as far as foreign entities or from criminal organizations and working as employers, there’s a head person, and then they have people working for them? And then they’re sending out tons? Or are there lots of individual people, 15-year-olds out there who are trying to make some dough? What does the stats say about what they think people are doing?

 

Raymond Ribble 18:34

Clearly, you understand the issue, because your examples are really good examples. So, I can share with you a couple of my own personal observations. I think I told you before Catherine, I lived in China for two and a half years and while I was there, and this was in the midst of the explosion of the internet, between 2005 and 2010 I had an opportunity to visit a couple of sites, where there were 1000s of employees who were working in these warehouses and what they were doing was hacking. They were paid to sit down and to hack into various systems using bots, using phishing mechanisms, using third party software, in order to break into the systems. Why I was allowed to go there and why I was there would be a different story, but I saw that, and then it was explained to me that these types of sites exist not only in China, but in a number of other countries, including Africa, Europe, and even unfortunately, here in the United States or in South America. So it’s not one nation, nation state sponsored attempt, but it could be a private industry, it could be for somebody, it’s a business. That’s what scary.

 

How do they target you? They can get third party data. You know, I always tell people, if you’re on Facebook or some social media, don’t answer your friends quizzes about who is your favorite teacher in fifth grade or what was the name of the street you lived on when you were growing up, because unfortunately, nine times out of 10, those are hints to the types of security passwords that you use. These companies are the ones sponsoring those social media trivia contests. They gather that data, they now have your email, they have some answers from you, they know that your proclivity is to answer those questions. And they start to put a behavioral reveal map together. Then what they do is they target you with an Amazon or Barnes and Noble, or they know somehow they figured out you’re an Anthem customer, or you’re using Signa, or whatever the case may be. Verizon, T Mobile AT&T. The probability that you’re using one of those three mobile companies is pretty high. I keep getting this one on my phone for a PayPal, I don’t use PayPal. But I’m getting emails and text messages saying that my PayPal account has been compromised, please login to correct right away. Well, it’s pretty obvious, somebody’s got bad information. But they got my phone number. That’s pretty easy for them to get my phone number. But they keep sending me these messages. And I just laugh at it. And I delete it. And I’ve tried to teach myself to be very diligent to anything that I’m not expecting. And I have a pretty good idea of what I have set up in terms of my automatic payments. I don’t trust anybody. I’m terrible. But what I’m doing is I’m looking at all of this data, and I’m just naturally suspicious. Sounds terrible to be that way.

To answer your question, I think it’s more external than it is internal. I think it is organized by a very large group. If it wasn’t working, if they weren’t able to get what they were looking for, they wouldn’t be doing it. So the bad news is that it’s an effective way for them to reach out to people and to steal data, and sometimes money.

 

Catherine Short  21:54

Great. Well, right. I had a question about employee snooping. I know, there’s probably a number of people who work on their own. And I know that you’ve said that there’s a lot of people who of course, are very curious so that’s always an issue. When we have an issue with employee snooping, is it usually just individuals working or do we sometimes find there are people working in concert with others, and it is sometimes some kind of a criminal type of element?

 

Raymond Ribble  22:30

It could be more of the former and very, very less of the latter. I’ll expand on that answer. What we find at SPHER, because one of the things that SPHER does is it actually monitors for snooping. So I can give you some firsthand examples here. We’re looking at employees that might be looking at their own files, might be looking at files that belong to their neighbors, or to their co workers, or to some VIP. We’re able to determine with our technology, whether or not that glance, or that long look at the record is consistent with their profile and the way that they use the system. Now that’s our perspective. That’s what SPHER is looking for. It’s one of the things we do. Your question isn’t how to SPHER do, your question is how does snooping occur? Who does it and the damage that occurs? So I do believe that snooping is somewhat nefarious for almost all instances.

 

A lot of people snoop just for the sake of gossip, unfortunately. I will tell you for example, that our highest rate of snooping is with our rural customers moreso than our big city customers, if that makes any sense whatsoever. We find that during the pandemic, snooping spiked quite a bit. People working from home, they were finding themselves not as busy or having as many tasks as they might have had in the office, or they weren’t in an environment where people could see over their shoulders to see what they were looking at, so they thought, hey, it’s okay to take a peek, right? All of that fit into that model where they went and took a look at something and forgot that there was some system that was in place that was looking at what they were doing and all of a sudden, they had a knock on their door or phone call from their manager saying, Hey, can you explain to me why you were in so and so’s file because that has nothing to do with anything that you had assigned to you or within your workflow.

 

And so people love what we do in that stage because that’s something they can lock down on. I’ll give you one example if you don’t mind me doing that.

 

Catherine Short  24:47

I would love it.

 

Raymond Ribble  24:48

We had a large organization in the south. I’m going to be very vague here.

Very large organization. When they went live with our technology. In the first month of use, they had 1800 snooping incidents in one month. Yes, it’s pretty bad. Now, the CIO called us and said, you know, I hate you guys, for two reasons. One is, now that I know that, I have to go fix it, and you’ve made my life a living hell, because clearly I don’t have a problem. I have systemic, across the organization problem. Everybody’s looking at everybody’s data. It has nothing to do with their day jobs. Right? So she put together a strategy, she went to market, nobody got fired because she figured it was the entire company doing it.

A side note, the two people who were assigned to review the data coming from SPHER were two of her biggest transgressors. So the guys who are responsible for watching were the ones watching the wrong stuff. Within two months, she was down to eight instances of snooping. Once a new culture was established, once the employees knew they were being watched, that somebody was looking at what they were doing, and what they were looking at, it changed the culture, it changed the habit that fast. Which I think is a testament to okay, we had a bad problem, we got forward, we taught everybody what we’re gonna do. We explained to them what we implemented, and we did it, and they changed. That’s great. That’s a great story. So that was us working together where a client and a really good outcome that happened from that but snooping is really a big issue. And I think a lot of it is gossip.

So I hope that helps to provide some insight.

 

Catherine Short  26:47

Yeah. The eight people who didn’t get the memo?

 

Raymond Ribble  26:52

Well, there’s always the ones who think, hey, I can beat the system. Right? Maybe. Right.

 

Catherine Short  26:58

So I wanted to thank you so much for being on 1st Talk Compliance today. Right? I appreciate it so much. Your explanations were excellent and concise,  and very practical. So thank you so much.

 

Raymond Ribble  27:12

Well, as always, thank you for having me, Catherine. Thank you to everybody at First Healthcare Compliance. And to everybody listening today, I appreciate your time and your efforts as well.

 

Catherine Short  27:21

Thank you. I can’t wait to talk to you again. So appreciate it. Did you have any actual final thoughts before we totally wrap up?

 

Raymond Ribble  27:28

Please don’t be afraid of the answers that I just gave Catherine or the information that I presented. It’s not hard. Take it one step at a time. You’ve probably done better than you think you’ve done. But sitting down and just having a conversation with somebody within your organization and reaffirming that you have done the right things and that you have a plan that you’re working towards is the first step towards protecting your data. And I just recommend everybody do that.

 

Catherine Short  27:48

Great advice. So Ray, I wanted to thank you again so much for being here.

And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

 

 

The Safe Harbor Law: A Practical Approach – Audio Version of the Webinar14 Mar 202301:01:47

Raymond Ribble is the CEO and Founder at SPHER, Inc. a market-leading compliance analytics, cyber-security solution addressing: HIPAA compliance, State Privacy Laws, and ePHI security threats and our expert presenter for this webinar. HIPAA data breach penalties typically get measured in millions of dollars even following an organization implementing NIST cybersecurity framework measures. With the new HIPAA Safe Harbor Law, signed last January of 2021, HHS and OCR may consider increased penalty mitigation when an organization can demonstrate it has been following established good security practices for a period greater than 12 months.

It is important to understand that the Safe Harbor Law, while offering substantial protection, does not provide a true safe harbor. Safe harbor laws normally shield an entity from liability when the criteria are met, however the new HIPAA Safe Harbor Law only offers some protection. The Office for Civil Rights (OCR) may consider whether a covered entity had implemented certain technical safeguards for 12 months. where appropriate, it allows OCR leniency in assessing the breach.
Our presentation will examine what are the established security practices for healthcare, and how to pivot your organization’s security profile in order to mitigate breach penalties in the event of an event.

This webinar will cover the following objectives:

1. What is the HIPAA Safe Harbor Law (Previously HR-7898)
2. Where can I find support
3. Demonstrating Compliance

The Risk of Data Sharing13 Mar 202300:23:44

1st Talk Compliance features guest Iliana L. Peters, Shareholder at Polsinelli PC, on the topic of The Risk of Data Sharing. Iliana joins our host Catherine Short to discuss how these days, health data is an incredibly valuable commodity. Companies of all types should consider the legal risk with data valuation, data ownership, and data sharing agreements. In this episode, we will be discussing the scope and breadth of data sharing projects in development in the health care sector, examine contractual, state, federal, and international legal obligations for data privacy and security for such projects, and discuss issues related to data ownership that may also be part of such projects.

Catherine Short  0:03  

Welcome, and let’s, 1st Talk Compliance. I’m Catherine Short, Marketing Manager for First Healthcare Compliance, a division of Panacea Healthcare Solutions. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes, and be sure to follow us on social media and subscribe to our YouTube channel.

On today’s episode, we are speaking with Iliana L. Peters, Shareholder at Polsinelli PC on the topic of The Risk of Data Sharing. These days health data is an incredibly valuable commodity. Companies of all types should consider the legal risk with data valuation, data ownership, and data sharing agreements. In this episode, we’ll be discussing the scope and breadth of data sharing projects in development in the healthcare sector, examine contractual, state, federal, international legal obligations for data privacy and security for such projects, and discuss issues related to data ownership that may also be part of such projects.

Before we begin, I would like to mention at First Healthcare Compliance we strive to serve as a trusted to resource for compliance professionals and we celebrate their hard work and dedication with our Compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Mika Lantz, Front Office Manager at Mountain Ridge Pediatrics. Mika says what she enjoys most about working at with Mountain Ridge Pediatrics is “interacting and forming relationships with our patients and their families.” Congratulations Mika!  Our team is honored to have the privilege of working with you.

So thank you, Iliana, for joining me on 1st Talk Compliance. It’s such a pleasure to have you on!

Iliana Peters  2:24

Thanks for having me.

Catherine Short  2:26

Why don’t we start with an overview of health data value proposition, and what some of the legal risks are with data sharing projects?

Iliana Peters  2:37

Absolutely. This is a new and evolving area of practice, particularly because we have many different entities that are very interested in engaging in innovative data sharing projects that result from the need to do research of all different types. That is research with a small r in terms of research and developments within entities, development of new products and services and research with a big R, that is human subjects research as defined under the law that may be used to determine new therapies, new drugs, new devices for patients as well. So there are all kinds of research projects going on, related to the use of data, and for many different and important reasons. As a result, we’re seeing a lot of questions about the legal requirements and risks associated with those types of projects, and particularly the agreements that are necessary and that are put in place between business partners related to those projects.

Catherine Short  3:48

Can you give us an example of what some of these new and innovative projects or research?

Iliana Peters  3:55

Sure. For example, we have many different entities that are interested in developing new software applications that may help with treatment or billing or, services in the healthcare sector to some extent, and they need data to really do evaluation and development of those prototypes and tools. We know that there are a lot of entities that are working on developing new drugs or new treatments just based on data that is what kinds of treatments are they seeing working for certain populations of patients over time? And can we implement that same kind of treatment in a larger population? There are entities that are looking at all different types of health disparities issues. So how do we get better treatment to better locations or better population? What does that look like? And how can we help develop tools and technologies to help with those issues? There’s a variety of different projects in this space that have a lot of really important and practical implications for how we provide care in the healthcare sector.

Catherine Short  5:18

That’s really interesting. Some of the ones I would have thought of, and then some of the ones that you mentioned, I never would have thought of such as billing, and a few other things. How about a quick summary of the legal issues involved in these projects? I’m sure it’s Myriad. But if you could tell us some of the legal issues and do you think that there’s serious legal risks associated with some of these issues and projects? What are your thoughts on all of that?

Iliana Peters  5:47

The short answer is, yes, there is serious legal risks. There are requirements at the state, federal and international level in the law itself, related to how we can use and disclose data. And that includes a general prohibition on the sale of data. So many of these innovative projects include some kind of benefit to the entity originating the data, because they are contributing data to an important project that’s going to arguably result in a new service or a new application or some kind of new invention, for lack of a better term. I don’t mean that in the legal sense, I just mean that in a general sense. As a result, these agreements contemplate what we call direct or indirect remuneration, that is some kind of benefit to the entity that’s originating the data. That’s considered a sale of data. And so that would necessitate consent from the individuals whose data we’re using for these projects. It’s really important, I think, that entities understand what this looks like from a legal perspective, because of those risks. As a result, a lot of entities are anonymizing data so that we can use data for projects involving remuneration, without implications for patient privacy, because the patients are arguably not identifiable or we don’t know who those patients are, who those consumers are as part of those projects, because we’ve anonymized the data. But obviously, if we’re going to do that, we have to make sure that we do that properly and in a way that in fact, doesn’t allow for those individuals to be identified, doesn’t allow business partners or downstream users of that data, to re identify or recombine data with other data sets to figure out who those people are, that are the subjects of the data. That’s not easy. It’s a hard issue.

Additionally, we have contractual requirements with our own clients and business partners that may significantly restrict how we can use data, how we can put data together and datasets and how we can anonymize the data. For example, Centers for Medicare and Medicaid Services have significant prohibitions in agreements related to Medicare and Medicaid beneficiary data that we have to be aware of when we’re aggregating data or de-identifying it because we generally can’t use CMS data in that way. That’s just one example from a contractual perspective. And then, of course, we have data breach issues. Anytime we’re putting together lots of data into a big data set, that becomes a target for a criminal, a cyber criminal or threat actor and we have to be very cognizant of the risks there, particularly if we’re providing that data outside our entity, to another business partner, who’s then going to have our data and be subject to those risks.

Finally, there’s always a reputational issue here. Even if we do everything in a legal way, even if we protect the data from a data security perspective, individuals could still find out about how we’re using their data because maybe it’s not identifiable, maybe it’s anonymized data, but it still came from them originally. And they could feel very strongly about how we’re proposing to use data for a particular project. Maybe they don’t agree with that particular project for whatever reason, and that could also create reputational risks for us. So this is all they’re all risks that we have to consider from an underlying legal perspective, a contractual perspective, data ownership, data licensure, all of those important controls that we put in place for data security purposes. Then just considering what the consumer would feel about any particular data project to make sure that we consider their viewpoint on these projects as well.

Catherine Short  10:01

That’s an interesting point, though. But let’s see if data points came from, for example, a patient. I know that occasionally I’ve been in situations where prior to speaking with a doctor,  perhaps a resident has come in and said, Do you mind signing this? We’re doing some research, if you’re okay with this, and I read the paper, etc. and,  I’ve asked some questions, and I assume that I’m not the only one who’s done this. I ask, and I say what is this for? Is this anonymous, etc. and it seems like other people would have done the same thing and if they sign that, it seems like they are being informed,  they gave informed consent about whatever information that they gave about themselves that it would go into this study. I guess that leads a little bit into this next question that I had, how should we consider addressing these issues and risks? I guess maybe one of them would be making human subjects or otherwise people aware of issues and risks.

Iliana Peters  11:06

Absolutely. At the end of the day, we could always get informed consent from the patient for any project that we want to move forward with. And that is the gold standard. So it’s a great point that you made that if what we really want to do is have a well informed consumer or research subject patient, whoever that person is, it’s always good to have a conversation with that patient, and get them to provide an informed consent or a HIPAA authorization for any particular project, because exactly as we say, then it’s clear that we had that conversation with the consumer, and that they’ve made the affirmative decision to share their data for whatever project that we’re contemplating. That said, there are a lot of these projects that we can’t maybe we have the data, and it’s very old, and we can’t go back to the person and get their consent to use it for some of these projects, in those circumstances, or in other circumstances where arguably, we don’t legally need informed consent, because again, it’s anonymized data or de identified data. That’s where those risks that we’ve been talking about come up and that is where we need to make sure that we have very robust contractual protections in place that allow for these projects to proceed in a way that will protect the privacy of those consumers and the ownership of the data for the originating entity. At the end of the day, if we can’t get informed consent, or HIPAA authorization for these projects from the individual, then we need to proceed in a way that is legal, that ensures that we’re not selling this data either directly or indirectly and that provides for good contractual protections for the data, such that we don’t have these really important issues associated with patient privacy, with consumer privacy and what data security

Catherine Short  13:12

Should entities go it alone, do you think or get help on these types of data sharing projects?

Iliana Peters  13:19

It’s a great question. In my experience, it is always good to have outside counsel to consult on these. That doesn’t mean your outside counsel has to look at every single agreement. They certainly can and it helps, but having a specialist in this area is often really helpful to understand the nuances because these are quite complicated issues and very rarely do entities have folks internally that have seen all of these issues, dealt with all of these issues in a way that allows for a really efficient and productive review, revision, negotiation of these types of agreements with business partners.

Catherine Short  14:04

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Iliana L. Peters, Shareholder at Polsinelli PC on the topic of The Risk of Data Sharing. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.

Catherine Short  14:43

What are the most important risks to consider in innovative data sharing projects?

Iliana Peters  14:48

Great question. As we’ve been discussing, I think the most important risks are the risks associated with how the business partners that you’re working with are going to use your data. At the end of the day, making sure that we understand the data ownership and licensure issues, particularly with regard to the type of data that we’re using for any particular project, so that we can ensure the right controls for that data. Again, we want to make sure that we appropriately take care of that data. But that’s really less of a risk in this context because arguably, we can control how we use our own data.

It’s really about when we share that data with business partners, how we do our best to make clear to those business partners how we expect them to use and share our data and how we expect them to protect it. It’s about making sure they understand our ownership of the data, what the license to the data looks like, for purposes of a particular project, and how they’re going to protect the data as they hold it.  I would say that’s the largest risk. It’s really when we share that data outside of our own institutions.

Catherine Short   16:13

Can you explain what some of those risks are? What are some of those various risks once they might start to go outside of your own entity?

Iliana Peters  16:22

I think one of the biggest data breach, obviously, if we don’t have a good data partner, that is as invested in protecting that data as we are and doesn’t have robust security controls for that data, we could very easily have a data breach, because it’s likely that they are a target for threat actors, because they probably do have a lot of data for a lot of different entities.

The other issue is they could also sell our data and we could ultimately be liable for that, because we handed over our data to an entity that then sold it without consent of the individual

We could also have an issue with re identification. So they could, if it’s anonymized data, they could sell it to an entity, which would arguably be permitted because it’s anonymized. And then that entity could re identify it, because we can’t control how they do that. So these are all serious risks associated with working with these business partners. If we don’t have good controls built into our contracts that says specifically, you know, how they can use the data, how they can disclose the data, and the data security controls that we expect them to put in place in their institution to protect the data.

Catherine Short  17:41

What do you mean when you’re saying that they re-identify it? What are they doing?

Iliana Peters  17:45

We could remove all of those 18 identifiers from the data or we could create, for example, what’s called synthetic data, that is data that is similar to an original data set, but not the original data set, or we could remove certain identifiers and not others in a way that we believe based on an expert opinion does not allow for an individual to be identified. We could give it to a vendor and the vendor could negotiate for example, with a very large internet based data company or an Internet service provider, or some someone who has very large amounts of data and based on the remaining items in that data set, whatever that is, that could be, let’s say a type of prescription drugs that someone is taking certain provider certain type of service that they’re getting for purposes of treatment, a certain state that they’re located in, in combination, it’s possible that someone else could have a dataset that includes enough identifiers that overlap with our de identified data, such that they can re identify it. That is, they can identify the individuals to whom it belong.

When we disclose it, it may not be clear that it’s early on as data. But when it goes to another entity, they may know enough about Iliana to re identify it and make it make it clear to them that that’s actually Iliana.

A good example of this was when HHS was working on The Genetic Information Non Discrimination Act. There was discussion about the identifiability of genetic data, and whether or not it could be de identified. The National Institutes for Health (NIH) had genetic databases on its website, and it was not a HIPAA covered entity to be clear, but they provided these genetic databases for purposes of research for different entities that were doing genetic research, and they believe the information that they had online was not identifiable because they had all identifiers for any particular individuals removed from it. That was very purely genetic information. Unfortunately, it was discovered that our researcher cross referenced at least one of these databases. This was obviously some time ago, cross referenced one of these NIH databases with a publicly available criminal database, and was able to identify convicted felon as a result of the data provided between the two databases. That is the kind of re identification problem that we would really want to avoid.

Catherine Short  20:38

Okay, I understand exactly. One other question. Should entities train their staff on these risks and issues?

Iliana Peters  20:49

I think the short answer is yes, but I don’t think this is the kind of training that everyone needs to this level. I think there are certain folks in every institution, legal and compliance that need this level of training. Otherwise, we need our business folks, our marketing folks, really anyone who has contact with business partners and vendors, who may propose these types of projects, to understand what these projects look like, and where the risks are, from a general sense. So they can appropriately identify this type of project and bring it to the folks that really need to take a closer look at it. We wouldn’t expect someone who is out in the community, working with business partners,  to really know the nuances here, but we would want them to be the kind of employee that says “oh, you know what? I think this is one of those complicated data sharing projects, I probably need to work with legal or compliance on this one” so that they’re escalated appropriately. Not so that everybody has to keep this information handy, but so that they have enough knowledge and understanding of how risky this is for organizations, such that they can say, “oh yeah, this is one of those data sharing projects. I need to be sure to escalate this as soon as possible, so that we can have legal and compliance look at this so we can take advantage of this fantastic opportunity in the right way”.

Catherine Short  22:26

All right. I want to thank you so much, Iliana. Did you have any other words of advice or things that you thought of during the presentation that you didn’t bring up at the time?

Iliana Peters  22:36

I don’t think so. I just wanted to say thank you for having me, and that I absolutely understand this is a really complicated area of current legal issues and so I hope that individuals will take a little bit of time to walk this through with their teams, but of course, are free to get in touch if they have any additional questions.

Catherine Short  22:59

Okay, well, thank you so much. Iliana. I really loved having you today on 1st Talk Compliance. Can’t wait to have you back!

Iliana Peters  23:05

Thanks for having me!

Catherine Short  23:17

And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com  I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

DMEPOS – In Compliance with CMS22 Feb 202300:27:03

1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., on the topic of DMEPOS – In Compliance with CMS. Rachel joins our host Catherine Short to discuss special payment rules associated with durable medical equipment, prosthetics, orthotics and supplies. DMEPOS products must meet quality standards, suppliers need to be accepted by Medicare to participate, similar to providers, and are subject to fraud, waste, and abuse laws. This episode will provide an overview of participation and quality requirements, relay the latest compliance and requirements updates, and discuss the consequences of non-compliance, as well as submitting false and fraudulent claims. 

Catherine Short:

Welcome, and let’s, 1st Talk Compliance. I’m Catherine Short, Marketing Manager for First Healthcare Compliance, a division of Panacea Healthcare Solutions. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes, and be sure to follow us on social media and subscribe to our YouTube channel.

On today’s episode, we are speaking with Rachel V Rose, JD, MBA, principal with Rachel V. Rose Attorney at Law P.L.L.C., Houston, Texas on the topic of DMEPOS – In Compliance with CMS. There are special payment rules associated with durable medical equipment, prosthetics, orthotics, and supplies. DMEPOS products must meet quality standards suppliers need to be accepted by Medicare to participate similar to providers and are subject to fraud, waste, and abuse laws. This episode will provide an overview of participation and quality requirements, relay the latest compliance and requirements updates and discuss the consequences of non compliance as well as submitting false and fraudulent claims.

Before we begin, I would like to mention at First Healthcare Compliance we strive to serve as a trusted resource for compliance professionals and we celebrate their dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja, April Collins, Compliance Officer for Anesthesiology and Pain Management Consultants. April says “What I enjoy the most about working at Anesthesiology and Pain Management are definitely the patients. I very much enjoy helping people and find it very rewarding.” Congratulations, April, our team is honored to have the privilege of working with you.

So thank you, Rachel, for joining me on 1st Talk Compliance. It’s such a pleasure to have you on!

Rachel V Rose

Catherine thank you. It’s always my pleasure to be here with you and to engage in a meaningful and interesting dialogue on a variety of different topics.

Catherine Short

Well, thank you. Okay, so as we get started, can you first for our listeners here on 1st Talk Compliance, give us a definition of DMEPOS? what that is exactly?

Rachel V Rose

Sure. I think fundamentally, it is a type of equipment that is utilized by a person and the setting can vary. Typically when you think of Medicare Part B that would be utilized by a Medicare beneficiary in their home and Medicare Part A would be when a Medicare beneficiary utilizes a piece of DME and again, DME can range from anything from a wheelchair to a hospital bed, to a knee brace after a total knee replacement, or an ACL reconstruction, to more disposable items that a person who was diabetic or hypoglycemic or is on a certain medication might use that are disposable. And if we think about the diabetic testing strips, the glucometer, the lancets that are used to pick prick a person’s finger. Obviously, the glucometer is something that should last for at least three years unless it’s defective for some reason. So that’s not something that’s going to be replaced regularly. However, the lancets and the testing strips are single use. That’s something that is disposable and can be discarded. Those are the range and types of items that would be considered a durable medical equipment and the types of settings in which they could be utilized whether it is a skilled nursing facility, or an acute care hospital, which would be billed in a different manner than if someone is, as an example diabetic and utilizing the glucometer, lancets, and testing strips on a regular basis. It’s important that a person appreciate the difference between a long-term care facility which in fact could be a person’s home and Medicare Part B would apply or a skilled nursing facility and while a person is in a sniff, as they’re called, for that 100 day period or shorter depending on what they happen to be there for. It could in fact be a Medicare Part A submission instead.

Catherine Short

Could it include oxygen tanks, or medical foods or nutrition or things like that? Or in this case, are we only talking about just equipment type of things? I didn’t know if you would be able to clarify that, or is there some kind of difference?

Rachel V Rose

Sure. So going back to just DMEPOS that actually stands for Medicare, durable medical equipment, prosthetics, orthotics, and supplies, and you really brought up different rungs of items, if you’re looking at certain prescribed nutrition items that actually might fall under a pharmaceutical which is separate from DMEPOS. And it is separate for a lot of different reasons. One would have to make sure as to what category a particular item fell into, whether it falls under pharmaceutical drugs type item, or if it falls under a DMEPOS. Specific to oxygen and oxygen equipment. there’s actually a fee schedule related with that, and the Consolidated Appropriations Act of 2021, which is found at Public Law 116 -260 and was signed into law on December 27, of 2020 and effective April 1, of 2021, actually eliminated the budget neutrality requirements set forth in a provision of the Social Security Act for separate classes and national limited monthly payment rates established for any item of oxygen and oxygen equipment. Now, no doubt the pandemic had an impact on that because as anyone is mostly aware, a lot of the issues associated with COVID were respiratory in nature.

Catherine Short

Right! Actually, can we discuss that? How is COVID-19 impacting the supply or procurement of DMEPOS?

Rachel V Rose

In terms of the claim submission process, a standard written order from the provider is still required, and I’m using the outpatient setting and not in-patient. With a standard written order, you have to establish medical necessity. If a person has COVID, and they have the residual tests that substantiate the respiratory issues associated with it, meeting medical necessity should not be an issue. Making sure that the requirements for the claims on both the provider side and the supplier side are being met, those really have maintained consistency throughout the pandemic, so to speak. When you start talking about the supply chain side of the equation, as we saw from the outset, even with things such as gloves, and masks and gowns, there has been an impact on the supply chain side across and it just depends on where a person is and what the issues are at any given time. The last part of that which is important, and which may be again, given consideration in light of the requirements of a particular code, or what’s usual and I mentioned the lancets for diabetics, testing strips, different people with diabetes may be required or have a need to test themselves more than before each meal. The reason could be if they’re engaging in an athletic type of activity, or they feel a little wonky because they could have come down with a certain medical condition or a virus or something like that. You could see an increase in their use of lancets and testing strips. It doesn’t mean they’re acting outside of an abnormal use for their particular individual situation, but it is imperative that a medical provider document that and then that is translated to the supplier.

With oxygen and oxygen equipment, as you can imagine, there are CPAP machines or BiPAP machines in addition to, I believe what you articulated earlier with the rolly oxygen tank, right? Where a person has a tube that typically goes into their nose, right and has two nostril plugs. There might be a reason that Medicare typically approves, and I don’t know the number, so I’m just giving a number five of those tubes a month, I don’t know. Because of COVID and other factors that an individual may have to deal with, the provider will say, well, I want this changed more often because bacteria could right form in there and I don’t want that to be reinfecting the patient. He or she may request 10, 20, 30 and as long as that meets medical necessity, and then it’s brought to the attention of the MAC so a potential waiver could be gotten and approved, then there should not be an issue. It’s when it’s just a carte blanche, I’m just going to ship items without either an SWO (standard written order) or other requirements in documentation in place.

Catherine Short 

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V Rose, JD, MBA, principal with Rachel V. Rose Attorney at Law P.L.L.C. on the topic of DMEPOS – In Compliance with CMS. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.

I want to just shift ideas for a second. Anytime there’s stuff that can be bought or sold, there’s an opportunity for fraud. Could you speak to how DMEPOS, what the effects are of fraud or where and how fraud has occurred? And then since fraud is, I’m sure occurring in some places, what are the hottest areas in the US for DME fraud?

Rachel V Rose

So, I’ll take that in bite size type of process here. First, I’m going to go with the inverse and answer your last question first. What areas are hot for DME fraud? Well, if you look at the Z pick zones and the heat zones that HHS has identified, historically, that has included Texas and Florida, for whatever reason, and so a lot of DME fraud, which really isn’t surprising in Florida because it is a hotspot for retirees and therefore, a lot of Medicare beneficiaries live there. Those are two hotspots.

Other items. If you look at some recent actions that the Center for Program Integrity and the Center for Medicare services have taken in conjunction with the FBI and HHS OIG, which were prosecuted by the US Department of Justice that included 17 federal districts, the execution of over 80 search warrants, which resulted in 24 defendants being charged. These included CEOs, COOs, others associated with five telemedicine companies and owners of dozens of DME companies, as well as three licensed medical professionals who participated in a healthcare fraud scheme, involving more than 1.2 billion in losses overall, in relation to $1.7 billion in claims that were submitted. There were 130 DME companies that were investigated. This was a very significant reach.

But if you think about the historical areas where a lot of fraud has been perpetrated in relation to DME, and other types of health care fraud, Florida’s in specific and specifically the Southern District of Florida, as well as Texas, and if you look in particular at the Northern District of Texas and the Southern District of Texas, there is a lot of healthcare fraud. That’s a criminal side and that’s the reach.

If you look at the civil side, that is something that DOJ civil Law Enforcement Division has made a priority because oftentimes illegal inducements which take the form of free items and the routine waiver of co pays, which can result in over utilization and waste for taxpayer funds. Those can be brought in any jurisdiction in the country. A very significant case just came out of the Middle District of Tennessee. Now the Middle District of Tennessee is very interesting because it includes Nashville. And for those of you who know my bio, I am a Vanderbilt grad, so Nashville is near and dear to me. But also, one of the reasons I attended Vanderbilt is that Nashville is known as the Silicon Valley of healthcare. And so it’s not surprising that not only do we have some of the largest health systems located in Nashville, we also have a lot of ancillary businesses, including DMEs, which are located there as well. At one point, Arriva Medical Center was the nation’s largest Medicare mail order diabetic testing supplier, and its parent Alere ended up over shipping and providing free and no cost glucometers and routinely waiving or not collecting copayments for meters and the diabetic testing supplies which include those lancets and the testing strips that I mentioned. Basically, that type of fraud and submission occurred from April 2010 until the end of 2016. It cost that company over $160 million to resolve those allegations. For those who are interested in the citation, this case was brought under the False Claims Act, and it is captioned at United States ex rel Goodman versus Arriva Medical LLC et al., Case number 3:13-cv- 00760 and it is out of the Middle District of Tennessee.

Catherine Short

Are there a certain percentage of people who are accidentally caught up in fraud, doing something incorrectly? And just over and over doing something incorrectly? I mean, how often does that happen?

Rachel V Rose

So I think you raise an excellent point because as the sister webinar to this illustrated, it’s imperative in terms of compliance that you really train your staff, you make sure that they’re up to date on the correct codes, and you have an outside third party auditor come in at least once a year to make sure that a statistical sampling is done to ensure that the claims that are being submitted are being coded correctly, and that they’re meeting the regulatory requirements as well as the national coverage determination and local coverage determinations which are set forth by the max to ensure that people aren’t doing it to your point on a regular basis. And that’s really part of adopting a valid compliance program and cultivating a culture of compliance. There is a thin line at a certain point between what constitutes negligence and what constitutes reckless disregard for truth or falsity of the information and that’s where having the ongoing training and everything else can be absolutely critical to the success and viability of an organization avoiding and mitigating the risk of an enforcement action, whether it is through an administrative agency such as HHS and OIG, or through a whistleblower case under the False Claims Act.

Catherine Short

Can DMEPOS suppliers be excluded from Medicare? Is that a possibility?

Rachel V Rose

Absolutely. And because they are a participating provider, they are just as susceptible as any other individual or entity from being excluded by Medicare or alternatively having to enter into a Corporate Integrity Agreement.

Catherine Short

Okay, and what type of items should auditors consider?

Rachel V Rose

A type of item that an auditor should consider, one item is making sure that that SWO (standard written order) is in place.

Secondly, making sure that it’s updated annually.

Third, making sure that the medical record documents the medical necessity from the provider side, and then from the supplier side, making sure that that SWO is on file, that they have all of the appropriate signatures, that they’re not stamped, and that they’re meeting both the national coverage determinations and local coverage determinations, in addition to the regulatory and Medicare manual requirements.

Finally, on the DME side, the number of items and the waiver of co pays should also be looked into.

Catherine Short

Okay, I think I just had one last question. If you could just expand on how a either hospital administrative team or even a practice administrator in an office could cultivate a culture of compliance.

Rachel V Rose

Okay, so cultivating a culture of compliance is a phrase that is set forth by the government. Cultivating a culture of compliance is really realistic, and just like HIPAA, and the Final Omnibus Rule which is at 78 Federal Register 5566, and it was published on January 25, of 2013 states, you can’t get a certificate right for being HIPAA compliant. The government says they don’t accept that. You can get training certificates, you can indicate that you strive to cultivate a culture of compliance, but the minute someone posts something or sends a bill out to the wrong person, you’re no longer compliant with HIPAA.

Cultivating a culture of compliance means having the requisite items that are required to meet compliance measures to ensure that you’re acting in accordance with the relevant laws and regulations. A key component to doing that, whether it’s HIPAA, or you’re looking at claim submissions, is to make sure that a) you have adequate policies and procedures, b) to make sure that your staff and providers are trained on what is accurate and truthful and what needs to be substantiated in the medical record and also what needs to be sent to the supplier. And then on the supplier side, what they need to keep and what they need to provide in the event of an audit by either a recovery audit contractors Z pick contractor or a MAC contractor with the government. All of that is absolutely critical to document.

And then ensuring that you have the third party person come in and articulate to people where mistakes have been made, if there’s a requirement to pay the government for back overpayments that you weren’t aware of, and the risk that comes along with that.

Cultivating a culture of compliance again, it needs to be done in substance over the form and I always like to use the Tommy Boy movie example, I can crap in a box and stamp it guaranteed, then I’d have a guaranteed piece of crap. You don’t want the guaranteed piece of crap, you want something that guarantees a product or in this case, a compliance program that is absolutely substantive and in good faith when the government comes in or a lawsuit, God forbid, ensues, that you as an organization, or a hospital executive team or an individual providers team or a DME company can say, you know what, we didn’t just give this lip service, this is what we do in order to make sure that we’re adhering to all the regulations. And even if some items got through, it can be a very significant mitigating factor in terms of the amount of the penalty or the Corporate Integrity Agreement being assessed or not being assessed. It is a very dynamic area and a very dynamic time and I think the more proactive organizations could be as we’re transitioning out of COVID and getting out of this treading water period to really moving forward, personally and professionally, I think that’s going to become more and more of a focus for the government.

Catherine Short

Okay, thank you, Rachel, for this comprehensive presentation. And we haven’t had a presentation like this from this perspective. I very much appreciate you sharing your expert advice with us. Thank you for being on. Do you have any other words of advice that you’d like to leave with us concerning our presentation today about durable medical equipment?

Rachel V Rose

The only items that I would reemphasize are, when an entity implements a compliance program and tries to cultivate a culture of compliance, make sure that it is robust, that it’s reviewed at least annually, and that training is included with that. Because when the government comes in, and if you’re on the receiving end as a defendant in a False Claims Act case or a love letter from HHS OIG, you can potentially have a mitigating factor by having valid and robust compliance program. But again, it has to be genuine and they do look at the substance over the form of those types of programs.

Catherine Short

Okay, well, thank you so much for being on 1st Talk Compliance today.

Rachel V Rose

And thank you, Catherine.

Catherine Short 

And thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and lend your voice to the conversation on Twitter @1sthcc or #1stTalkCompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

Evaluation and Management Updates 2023, Training, Q and A- Audio Version of the Training21 Feb 202301:41:42

An audio version from the live event:

It’s important to understand how the application of the 2023 E&M codes impacts reimbursement. Inaccurate coding and inefficient documentation practices can result in a decline in revenue and increase the likelihood of downstream inaccuracies of patient data.

Join Panacea Healthcare Solutions’ Director of Coding & Documentation Services, Becky Jacobsen, CCS-P, CPC, CPEDC, CBCS, MBS, CEMC, BSN, and Executive Vice President of Coding & Documentation, Kathy Pride, RHIT, CPC, CCS-P, for a complimentary 90-minute training where they will review the 2023 E&M documentation guidelines and requirements and provide examples on how to improve your internal documentation processes to ensure appropriate reimbursement and avoid compliance issues.

A live Q&A at the end of the training will provide the opportunity to ask questions. Those who register will receive the recording along with a post-training FAQ sheet to reference as you put these new guidelines into practice.

The learning objectives for this training include:

– Explain the revised 2023 E&M guidelines for selecting the correct level of service
– Cover prolonged service codes, and updates to critical care and split/shared visits.
– Demonstrate efficiencies for documenting E&M levels of service based on the revised guidelines.

The Criminal Side of Cybersecurity and HIPAA – Audio Version of the Webinar16 Feb 202301:15:20

Expert presenter, Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX guides us during this important and informative webinar. Breaches and the lack of the requisite technical, administrative, and physical safeguards can have criminal consequences. While most people are familiar with civil cases, there is the potential for HIPAA violations and ransomware attacks to be prosecuted criminally. The purpose of this webinar is to highlight potential areas of criminal liability, give specific examples, and address mitigation techniques – both before and after a government discovery request or grand jury subpoena emerges.

This webinar will cover the following objectives:

1. Scenarios where criminal liability may arise under HIPAA and related laws.

2. The importance of understanding HIPAA’s law enforcement and whistleblower exception.

3. Mitigation considerations in terms of compliance, risk management, and government factors.

Health Data, A Value Proposition: Legal Risks with Innovative Data Sharing Projects – Audio Version of the Webinar15 Dec 202201:06:32

Iliana L. Peters, Shareholder at Polsinelli PC will be leading this engaging webinar. These days, data is more valuable than oil. And health data is the most valuable of all data! Companies of all types should consider the legal risk with data valuation, data ownership, and data sharing agreements. Data sharing projects take many forms and address many important issues, including improvements in patient safety, fraud and abuse, population health, research, and costs to the health care system. That said, the contractual, state, federal, and international regulatory requirements applicable to such data sharing projects are significant. As such, health care entities may be particularly vulnerable to legal risk related to data sharing projects involving health data. Specifically, health care entities should consider contractual obligation, HIPAA, state privacy laws, and other requirements, as well as discuss risk assessment, data sharing agreements, key provisions, and business associate relationships. The presentation offers best practices for these important issues and projects.

This webinar will cover the following objectives:

1. Understand the scope and breadth of data sharing projects in development in the health care sector
2. Understand contractual, state, federal, and international legal obligations for data privacy and security for such projects
3. Discuss issues related to data ownership that may also be part of such projects

A Business Associate Agreement? Tell Me More!14 Nov 202200:27:57

1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “A Business Associate Agreement? Tell Me More!” Rachel joins our host Catherine Short to discuss how Business Associate Agreements (BAA) are not new; however, some individuals are new to healthcare and others never understood what a BAA is exactly. A BAA is a contract that fundamentally gives assurances that the parties are complying with the Security Rule and Privacy Rule, setting parameters in the event of a reportable security incident or a breach, and states how the sensitive data will be returned and destroyed at the end of the relationship. Some of the items in a BAA are required, while others are optional but common. This presentation not only seeks to dispel myths about why certain language is prevalent in nearly all BAAs, but also provides insight into other provisions, and items for consideration, in light of the 21st Century Cures Act.

Catherine Short:  0:01

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

On today’s episode, we are speaking with Rachel V Rose, JD MBA principal with Rachel V. Rose Attorney at Law PLLC Houston, Texas on the topic of appreciating the content of a business associate agreement. Business Associate Agreements a BAA is a contract that fundamentally gives assurances that the parties are complying with the Security Rule and Privacy Rule, setting parameters in the event of a reportable security incident or a breach and states held the sensitive data will be returned and destroyed at the end of the relationship. Some of the items in the BAA are required, while others are optional, but common. This presentation not only seeks to dispel myths about why certain language is prevalent in nearly all BAAs, but also provides insight into other provisions and items for consideration in light of the 21st Century Cures Act.

Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Wendy Mulkey, Business Development Marketing at Emerald Coast Neurology. Wendy says “I am a lifelong learner. Working at Emerald Coast Neurology has allowed me to continue to grow and learn. I feel my contributions are making a positive impact for the staff and patients. At the end of the day, I just want to make a difference. I feel like I’m accomplishing that at Emerald Coast.” Congratulations, Wendy, our team is honored to have the privilege of working with you.

Catherine Short

So hello, Rachel, thank you so much for joining me today on First Talk Compliance to speak about BAAs.

 

Rachel V Rose

Thank you Catherine. It’s always my pleasure to collaborate with you and First Healthcare Compliance in order to hopefully provide meaningful content to the listeners.

 

Catherine Short

Thank you. So how about some background? First, can you give us an overview of exactly what a BAA or Business Associate Agreement is and who it involves?

 

Rachel V Rose

Absolutely. Not surprisingly, that is a very detailed question. As your introduction mentioned, a business associate agreement, which is referred to in 45 CFR 160.504(e) as a business associate contract is just that. It’s an agreement between two parties to do three primary things. First, ensure that both parties are utilizing the appropriate technical, administrative and physical safeguards in order to ensure that the confidentiality, integrity and availability of the protected health information remains intact. Additionally, it relates to the Privacy Rule, the entire security role and the breach notification rules being adhered to. The second element that always jumps out at me is the notification to the other party and then potentially, to HHS, patients and the media in breaches of 500 or more individuals, and making sure that the parties designate the timeline that party A, the typically the party the breach occurred on, tells party B about this and then what transpires after that. The last main requirement or part of a business associate agreement is what to do when the relationship between the parties terminates. Now that might seem simple. Oh, I just need to either return and or destroy the data in a manner that complies with the HIPAA Security Rule and preferably with NIST. That’s part of it. But as we all know, there are situations where we can’t just return or destroy information. Some of those may be obligations of a legal hold or a government investigation or a lawsuit that might be in place. Under federal HIPAA, it applies to covered entities, which are healthcare providers, healthcare claims clearing houses and insurance companies and their business associates, and then a subcontractor of that business associate.

 

Catherine Short

Okay. What is a primary purpose or purposes of a BAA?

 

Rachel V Rose

So as I mentioned, there are typically three main areas. First, you need to define who the parties are at the very top, and which one assumes what role whether it’s a covered entity and business associate or business associate and subcontractor. All of that is exceptionally important. So just something to be conscientious about there. Then you delve into the three overarching areas or purposes behind the Business Associate Agreement. A) To ascertain that both parties each had been given reasonable assurances that the technical, administrative and Physical Safeguards as well as the privacy rule, security rule and Breach Notification Rule compliance and requirements are being met. Another item that relates to that now is the 21st Century Cures Act and the ability to give patients their medical records in formats such as smartphone apps that weren’t necessarily available before. Along with that related to information blocking are situations where a provider or a business associate may say, the general rule is that we have to provide this but this is not an app that is secure, or that we’re familiar with, and for the safety of the entire IT infrastructure, we’re not going to provide that. So it’s important now to reference state laws and other relevant laws such as a 21st Century Cures Act. The next main area, it has to do with notification to the other party of a reportable cybersecurity incident, typically known as a breach in accordance with the Breach Notification Rule. There are really two steps to that. First, you want to have a timeframe set out between the parties as to when party A if they’re the breaching party has to notify party B that there has been a breach. That’s important because their IT department needs to take appropriate steps in order to safeguard certain things or go to plan B or to go to backups. So it’s really mutual in nature along those lines. The second part of a reportable breach would then be under the Breach Notification Rule, to report to HHS, to report to the patients, and to report to the media if the breach itself affects 500 individuals or more.

 

Catherine Short

Okay, great. Is there any party or person or entity that a facility works with that it’s perhaps safe not to have a BAA with?

 

Rachel V Rose

So that’s a great question, Catherine. First, I will go to what’s known as the conduit exception. That’s something that was highlighted in the Final Omnibus Rule, which is published at 78 Federal Register 5566 on January 25, of 2013. The conduit exception expressly states that there are certain entities and they are very limited, but they are for example, your internet provider would be one, your UPS carrier, whether it’s the United States Postal Service, DHL, UPS, FedEx any one of those types of carriers, so long as none of their entities did anything other than deliver the package, right? They are just transporting data from point A to point B, and that’s it.

 

So having said that, and by way of contrast, I think it’s important to note that data centers are considered Business Associates and do not fall within that exception. Another entity that is considered a Business Associate is a cloud computing provider. So whether you utilize AWS or Microsoft Azure, for example, those are still business associates, and that’s why when you go onto their website, you will see their Business Associate Agreements, as well as some commentary on HIPAA and other data privacy laws. Another one that is often a question, so to speak, is is a lawyer a business associate? The answer there is it depends. Even in my own practice, there are times when I contract with a covered entity. If I’m just reviewing physician contracts, I’m not delving into protected health information, I’m not looking at financials, I’m not looking at anything that would tie any individual back to the past, present or future diagnosis, treatment or financial information associated with any of those items. However, the minute they asked me to look at something that contains PHI, that is absolutely a covered entity, business associate situation, which would require a Business Associate Agreement.

 

Catherine Short

Okay, so example, the custodial company perhaps would not need a business associate, but medical waste hauling would.

 

Rachel V Rose

The cleaning entities are very interesting, because if you think about it, they have access to everything, and typically when no one’s there to supervise them. So hopefully, the organization has all safeguards in place that when everyone goes home, there is no information that’s left on a computer or computers still not on they don’t have their past codes in their top drawer on a sticky note, right? And they have those bins that are locked, so that the information goes to Iron Mountain or another vendor to be shredded, and people can’t access that. I think there’s a distinction too between whether, for example, in a hospital, if the Environmental Services team is hired by the hospital as individual employees, then they are part of the workforce and they should undergo HIPAA training as part of the workforce, but they’re not an independent contractor. Does that make sense?

 

Catherine Short

Right. Yes, I was speaking of perhaps like an outside contract cleaning company or environmental company as opposed to employees of the hospital

 

Rachel V Rose

No, I think Catherine on that one there’s just so much potential liability there, they could let someone in the back door, right, because they have access and that’s something that I do advise people, maybe even to have a modified agreement, if not with all the bells and whistles, but just to ensure that they understand that if they steal something or if there’s an issue, they need to know what to do and what their potential liability is.

 

Catherine Short: 

So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “A Business Associate Agreement? Tell Me More!” Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.

Okay, can you explain reasonable assurances in relation to business associate agreements and maybe tell us a little bit more what reasonable assurances are?

 

Rachel V Rose

Sure, absolutely. Basically, it comes up in a lot of different areas of law. Reasonable assurances in HIPAA would be the following because the first part of the Business Associate Agreement should have both parties, giving assurances that they meet the technical, administrative and physical safeguards in order to ensure the confidentiality, integrity and availability of the data. What would give someone peace of mind is the way I like to think of it and also give them something legally, that they could say, you know what, we know that we do not have a right to go in and inspect everything. So what I do is I have my clients get a signature on an ad test station. The purpose behind it, it’s very short, it’s about half a page in length and all it says is that these reasonable assurances are being provided in order to give peace of mind that the party is adhering to the requirements of HIPAA in the High Tech Act. If people can answer these five questions in earnest, you should walk away with a good feeling that they’re doing everything that needs to be done. The first question is, does the party undergo an annual risk analysis that is comprehensive? Second, do they train their workforce annually? Third is PHI insensitive PII encrypted both at rest and in transit? Fourth, are Business Associate Agreements in place, and are they recorded? And lastly, are policies and procedures at least reviewed annually, and are they comprehensive? So with that, that is A) how I define and think of a reasonable assurance? And secondly, how I advise my clients to protect themselves and then lastly, the types of reasonable assurances are those five that I hone in on.

 

Catherine Short

Okay, great. What are indemnification provisions and what language should be used in indemnification provisions?

 

Rachel V Rose   17:30

That’s a loaded question. I’m going to point kind of in jest, but kind of not in jest, and suggest that people listen to our webinar on indemnification. But in all seriousness, it’s typically thought of as a contractual obligation of one party to compensate the loss incurred to the other party, due to certain acts of the indemnitor or any other party. The duty to indemnify is usually but not always, coexisting with the contractual duty to hold harmless or safe, harmless. So let’s step back for a moment. First, before you draft an indemnification provision, you want to make sure that you have an appreciation of a variety of different state laws, whether it is derived from common law, or whether it is like California set forth in a statute. Typically, the way a lot of indemnification provisions are written are to indemnify defend and hold harmless. If you don’t have that exact language, depending on the jurisdiction that you’re in, you may or may not have to defend someone and pay for those costs. It’s so specific to the facts and circumstances in general that I’m trepidatious just to throw out any language surrounding that, but I will say that it’s important to appreciate the significance of an indemnification provision. Some indemnification provisions I read and I’m like, Oh, my gosh, I would not advise anyone to sign that it’s because it’s so one sided, that only one party is held harmless. And in the event of a breach, regardless of whether or not for example, a Business Associate cause the breach some of these indemnification provisions, read that the Business Associate is responsible for all of the costs. So that should be one of the provisions that any person reads very, very carefully because it could A) contradict with your other contracts that you have in place, B) you can be shouldering all of the liability, even if you’re not responsible for the breach or the bad act. So when I write them, I typically make them mutual that if one’s being indemnified, the other one’s going to indemnify if they’re at fault. So it’s mutual defend is the key term that I discuss with the party. And typically, the party will go back to the other entity if they are in a negotiation. and oftentimes, they’ll say, we’ll just agree to be responsible for our own attorney’s fees on this. So that’s what will happen there. And then the last part of that, that something I’ve been doing for a few years now is to really carve out and there there are two schools of thought. When I carve out specific indemnification provisions related to a breach, it’s the breaching party that has the obligation to pay for the notification to government entities, to the media and to the individual patients. But that’s where the liability end so there’s no payment of attorneys fees, there’s no payment of ransomware. There’s no paying for a deductible on an insurance policy, or anything like that. What my clients and actually when I’ve been on the phone with opposing parties as well, what they’ve said is that we like this, because we know upfront what we’re responsible for, and it’s limited to this, and it’s balanced for both of us. So there’s no cookie cutter way to draft an indemnification provision, you just have to literally take it word by word with the parties that you’re dealing with.

 

 

Catherine Short

Okay, I’ve got another question that has some defining in it, and then some explanation. What is a material breach, for those that don’t know? And can you tell us what MSA stands for? And then how can a material breach of the MSA affect the MSA or other contracts?

 

Rachel V Rose

MSA is typically your Master Service Agreement. That’s typically what I have seen, but obviously, it’s your main contract. If you are contracting with an IT provider, typically your MSA is your main contract. If you think about how a breach is defined in HIPAA section 164.402. Basically, it’s “the acquisition, access use or disclosure of protected health information in a manner that is not permitted, which compromises the security or privacy of the protected health information.” So basically, when you think of what a material breach is, one can really think of that, as was the incident one that triggered the following A) requires us to do a root cause analysis to determine whether or not it’s a reportable breach.  And then if it is a reportable breach, then how does that impact the underlying contracts? So it’s a little misleading Catherine and this is a great question for this reason. If we’re thinking about ransomware, or what we think about in cybersecurity, a breach means that definition that I just read in 164.402, but that has to do with a breach of the information. What flows from that breach of the information can be a material breach of either the Business Associate Agreement and or the Master Service Agreement, depending on how things are worded.

 

Catherine Short

Okay, so what if an entity doesn’t fit into one of the HIPAA buckets of covered entities, business associates and or subcontractors. Do they still have potential liability?

 

Rachel V Rose

There is potential liability. The three ways that potential liability may arise are A) under state law. For example, I mentioned Texas that has the definition of a covered entity, which is any person who creates, receives, maintains, or transmits PHI. So while that does include the three federal HIPAA buckets, it actually goes beyond that. That’s one way. Another way is through the Federal Trade Commission. I know in the Related webinar, I delved into that in some detail but basically, the Federal Trade Commission has its own Breach Notification Rule that says if you’re not obligated under HIPAA, you may still have an obligation to report a breach of PHI to consumers from their pursuant to the Federal Trade Commission Act Title Five, courts have held that the Federal Trade Commission does in fact have enforcement authority in that situation. So that’s where you could get another government enforcement action.

The last way would be through either a class action lawsuit or a common law negligence lawsuit for a HIPAA breach. So those are really the three ways that someone can be held liable.

 

Catherine Short

Okay. Is a BAA a binding contract?

 

Rachel V Rose

It is a binding contract and it is binding for a multitude of reasons, but it is per the regulations considered a contract and if you are creating, receiving, maintaining or transmitting protected health information between the covered entity, business associate and sub-contractor, you do have an obligation to enter into a contract.

 

Catherine Short

Okay. Well, thank you so much, Rachel. I think we’re just about out of time. Did you have any other any other thoughts that you wanted to share with us?

 

Rachel V Rose

Just be aware that BAAs are not cookie cutter. However, there are certain terms and certain provisions, which you’ll see over and over again and that’s because they’re required by the statute and then recommended by HHS on their website.

 

Catherine Short

I really wanted to thank you, Rachel, for coming on to 1st Talk Compliance on our show today and discussing this important subject. So, thank you so much.

 

Rachel V Rose

You’re welcome, Catherine, and as always, thank you for having me.

 

Catherine Short 26:21

Me too.  Thank you so much and thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

Have a Breach? Reporting Requirements with the OCR17 Oct 202200:27:07

1st Talk Compliance features guest Trey Scott, Coordinating Attorney at Kennedy, Attorneys & Counselors at Law, on the topic of “Have a Breach? Reporting Requirements with the OCR.”Trey joins our host, Catherine Short to discuss the reporting requirements for a data breach of a healthcare provider, the definition of a breach, different timelines for reporting breaches, as well as how to complete a breach reporting form from the Office of Civil Rights.

 

 

Catherine Short:  0:01

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

On today’s episode, we are speaking with Trey Scott, Coordinating Attorney at Kennedy Attorneys and Counselors at Law on the topic of “Have a breach? Reporting requirements with the OCR.” We will discuss the reporting requirements for a data breach of a health care provider, learn about the definition of a breach, understand the different timelines for reporting breaches, as well as how to complete a breach reporting form from the Office of Civil Rights.

Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition.For this episode, we’re spotlighting Super Ninja, Gail Little-Osberg, Practice Manager at Attachment and Trauma Center of Nebraska. Gail says what she enjoys most about working there is the variety of taking care of a practice, working with a great team of therapists and of course, staying up to date on HIPAA and compliance. Congratulations Gail, our team is honored to have the privilege of working with you.

So, thank you, Trey, for joining me on 1st Talk Compliance. It’s a pleasure to have you on.

 

Trey Scott  2:10

Yes, thank you glad to be here. Glad to talk compliance to your listeners.

 

Catherine Short  2:16

Great. Do you think you could give us a little bit of an overview of what we’re going to be talking about and discussing on today’s program.

 

Trey Scott  2:28

So what we’re talking about here is we’re talking about reporting to the OCR (Office of Civil Rights) whenever there is a breach. Whenever you have a breach, regulations require you to do certain things. If a breach involves more than 500 individuals, you need to report that to the Office of Civil Rights, within 60 days of date of discovery of the breach. You also have certain things you need to do as far as notification of individuals, notification to the media but that’s that’s not really what I want to talk about here. If you have a breach that is less than 500 individuals or less, it ends up being 60 days from the beginning of the new year. If you have a breach that occurs in September, you have until 60 days from the beginning of the new year to report to the secretary now you’re probably wondering, well, this notification, I need to notify the secretary. How do I go about doing that? Well, the Secretary has made it really easy to report. What you do is you go to the HHS Office of Civil Rights. And they have a really, really nice web portal that allows you to report a breach. It asks you a bunch of questions that you answer as you go through. A lot of them are you a covered entity reporting a breach on behalf of yourself? Are you a business associate that has experienced a breach and you are reporting on behalf of a covered entity? Or are you a covered entity reporting on behalf of a business associate who has had a breach? You select those and you go through, you enter contact information for whatever the three options you selected. Then it will start asking you about the breach. It’ll ask you what safeguards you had in place, what information was breached, when the breach occurred, what the discovery date was.

 

The discovery date is when you found out about the breach because there are instances where a breach might occur due to a hack early in the year, and you just don’t discover it for whatever reason until the middle of the year. Well, the date you discovered the breach, that’s the discovery date and it’s when you knew or should have known about the breach. Then the portal questions will ask about the details of the breach, what happened, whether it was an inappropriate disposal of medical records, for example, whether it was the loss of a laptop, whether it was hacked, and then it will ask more details about it and you’ll be able to provide that underneath. Then it will ask what you’ve done following the breach. Have you notified the individuals? Did you have to notify the media? What other additional training have you done? Things of that nature. It’ll go through, and it will ask all of those questions. Finally, the breach portal will ask for an attestation to essentially say that everything you’ve reported here is accurate to the best of your knowledge, you’re not lying about anything, you’re not lying about the breach date, you’re not lying about notifying individuals, you’re not lying about when the discovery date occurred to give yourself more time.

 

Based on information provided, if it’s larger than 500 individuals, then the Secretary will take that information and post it to their website with the list of offenders who have had large breaches, if you go there, you’ll see breaches in the million, because for example, a Florida Health Plan got hacked and I think you will see there 3.5 million or 35 million individuals were affected. So if it’s over 500, you end up on that list, unfortunately. That’s really the process of reporting to the secretary in a nutshell.

 

Catherine Short  7:39

Okay, so we had talked about Civil Monetary Penalties existing. What about criminal penalties? I know you had talked about willful neglect, or you mentioned it, so I assumed that would go under criminal penalties. Could you explain that maybe a little bit more?

 

Trey Scott  7:56

Yes, I can. So whenever the Office of Civil Rights receive all of these breach notifications, if they rise to a level, then the Office of Civil Rights will actually conduct their own investigation. And through the process of their own investigation, if they do, in fact determine willful neglect or neglect that have not been corrected, there is the possibility that they can refer these breaches to the Department of Justice, and they can in fact, pursue criminal actions against the healthcare provider. So yes, it is very possible that a breach could result in criminal penalties if the investigation by OCR shows that.

 

Catherine Short  8:55

Okay, all right. How about an addendum? How long do you have to file an addendum if that’s what you choose?

 

Trey Scott  9:04

I don’t believe there is actually a deadline for when an addendum runs out. What you really need to do is ultimately determine if it’s still part of the same breach that you have already reported, or if it is, in fact, a new breach. So that’s really the key with an addendum. Most of the time, an addendum is used for things like including additional training that your team may have undergone, adding more patients to the total number, if it gets it from the below 500 to over 500 mark. That would be what an addendum is used for. If it was a hacked initially, and you reported that, but you also end up discovering that somehow your email was also hacked as part of that. That’s really what an addendum is for. There really isn’t a timeframe for how long you have to add to an addendum, but you just need to make sure it is still part of the same initial breach and isn’t a new breach.

 

Catherine Short  10:29

Could you expand on that a little bit? At what point would you consider it a new breach and not an addendum? Where’s that line?

 

Trey Scott  10:38

The line to me is, if it involves the same incident, if it is a situation where, for example, going back to the email and the hack, if your team can determine that that was all part of one incident, then you can add it to an addendum. But if you have a situation where, for example, a hack occurred on March 3, and you didn’t discover it until April 3, but then during your investigation, related to the March 3 hack, you find out there was another hack in between, that would be a separate incident. That wouldn’t be part of the same breach even though you may have discovered it around about the same time as the first breach. That would be completely separate and you would need to do a new breach notification and not just an addendum.

 

Catherine Short: 11:41

So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Trey Scott, Coordinating Attorney at Kennedy Attorneys and Counselors at Law on the topic of “Have a breach? Reporting requirements with the OCR.” Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.

How about recommendations to avoiding a breach? What do you recommend?

 

Trey Scott  12:30

Most breaches occur due to poorly trained employees and employee carelessness. So my recommendation to avoid a breach is to make sure that your employees are trained on record security, are trained on not clicking email links that you’ve received, are trained on making sure to not save passwords and EHRs, not save passwords for laptops, make sure you have procedures in place to routinely change access codes for EMRs and building codes. Doing that and making sure it limits the risk of the employee inadvertently disclosing or inadvertently allowing unauthorized access. That’s my main recommendation. Make sure your employees are as trained as possible, because I know hacks, sounds scary and everything and they’re the ones that get the news, whether it’s for example, hacking, a large health plan or whether it’s hacking, even target has been hacked in the past. Those end up getting news because of how many people are affected but the reality is, hacking is more rare whenever it comes to the breaches, than you would necessarily think. A lot of the breaches that we have dealt with involve carelessness, inadvertent disclosures by employees. So make sure your employees are trained, make sure you have a good compliance program in place and that should limit a lot of the risk.

 

Catherine Short  14:45

Right? And even with training, you have to have it as second nature. You get these phishing, either phone calls or emails sometimes, first thing in the morning.

 

Trey Scott  14:57

Right. Example, we had is a client received a document from an email address that they thought was a patient of theirs. If you looked at the actual email address, it was nowhere near anything close to what the patient’s email address was but if you looked at the email display name, it was the patient’s name. The provider clicked on the document and by doing that, they allowed a virus and to get into their system. That ended up being a breach that was completely avoidable by just taking a few seconds to realize, to check the actual email address against what they have on file. It does take a additional step, but making sure your staff is trained to do things like that, or making sure yourself, you’re trained to take those additional steps can prevent a can prevent a breach.

 

Catherine Short  16:11

Right? It’s funny the other day, I had a phone call, and I often screen my calls, you get so many commercial calls, etc. But it said the name of a famous bank calling me and even though I didn’t have a credit card with them, I thought hmm, I wonder why they’re calling me. I answered the phone and what was funny was, so this was the first odd thing. They said, we’re calling from your cell phone company from the fraud department, and I thought, well, that’s odd. I wonder why it says the name of this famous bank on the name coming in from the call. They said, well, we’re calling from such and such phone from your phone company, we’re going to have to shut your phone down, etc. because there’s been some kind of breach or whatever. I was thinking, well, that’s weird. I go into my account fairly often and I can see what’s going on. In fact, I can go into my account right now and look. I said, Well, why does it say bank of such and such on the phone call? And they said, Well, we’re calling from the fraud department. And I said, Well, really? I said, Why doesn’t it say such and such phone company? And I kept asking them that and then they hung up the phone. So obviously,  this was some kind of fraud kind of phishing type of thing. I’m sure they wanted me to give them account information, all this kind of stuff.

 

Trey Scott  17:35

Right!

 

Catherine Short  17:36

It was really bewildering, because when the phone call came in, it looked like some kind of legitimate type of call. Only two things that were really odd were, number one, I don’t have an account or a credit card at this bank, and why would this bank be associated with this phone company? Those two things were just really odd, but they’re very widely used.

 

Trey Scott  18:01

Right. That’s why it’s important to make sure you’re checking things like that. Essentially, your first line of defense against breaches are your employees. You need to make sure they are aware of these attempts, like you just described and make sure they’re extra diligent.

 

Catherine Short  18:27

Yeah. And that their ears are perked, that they they’re trained and ready for these kinds of phishing type of things. I have a question here. Now people being who they are and trying to avoid things, but do we really need to report all breaches, even if it’s only one patient?

 

Trey Scott  18:45

Our recommendation is yes. And the reason why is because the regulations require that anytime there is a breach you obviously need to notify the patient that there was in fact, a breach. So because you’re going through the process of notifying the patient that their information was breached, even if it’s one patient, you need to go ahead and take the next step of notifying the secretary as well, because the worst thing that could happen is that the patient find out that their information was breached, and then the patient reports that their information has been breached, and they want to do something about it to the Office of Civil Rights, and you haven’t reported. That could lead to an investigation by OCR and once they start digging around, they may find more things and it can potentially end up a situation where they ultimately determine what you did was willful neglect, and you can end up with a large penalty. You don’t want to end up doing that. My recommendation is to report everything. I think that is what the rule of notification to the Secretary is saying, because it’s saying, you shall report to the Secretary and isn’t saying that you could, it isn’t saying that if you want to, and isn’t saying that it’s if it’s less than 10 patients, you don’t have to, it’s saying that if a breach occurs, you shall, which means must. I would recommend to all your listeners, if they don’t have one, obviously, make sure you have a compliance program in place because a good compliance program has prevented a lot of our clients from facing those penalties by the Office of Civil Rights. If you have a great program in place that you’re actually using, because it’s almost worse to have a compliance program in place and not use it, than it is to just not even have one. Make sure you have a good compliance program in place and make sure you’re actually following it and using it. If you do have a breach, that will really limit potential penalties that you’re going to be facing,

 

Catherine Short  21:21

If we report a breach are there any financial penalties we might face?

 

Trey Scott  21:26

Yes, yeah, thank you. There are tiers. Tier one, that’s where it was a lack of knowledge, it was not really anything that was too egregious of a breach, you could face a fine of $100 to $50,000 per incident. If you had reasonable cause to know that the breach was possible to occur, then you can face a fine of $1,000 to $50,000 per event. Then there is willful neglect. That’s tier three, that is when you just straight up don’t have any procedures in place, you have no compliance program, you have nothing in place, then that can be a fine of $10,000 to $50,000 per event. The last category is neglect. This is not having a compliance program in place and then you end up having a breach and you still don’t have a compliance program in place after the breach, then that is just straight up neglect, that is not corrected. That’s category four, and that is $50,000 per violation. These numbers are actually adjusted for inflation. I don’t know what the current totals are, but they are adjusted for inflation.

 

Catherine Short  23:01

Okay, how about this? In your opinion, what is the main cause of a data breach? Is it hackers, ransomware or something else? What’s your opinion on that?

 

Trey Scott  23:12

Employees are the main cause of data breaches, whether it’s loss of laptops, whether it’s of theft of laptops, leaving it in a car while you go eat at a restaurant, and someone breaks in and steals it, cell phones, use of email to send medical records that aren’t encrypted, not changing access codes, having an easy password, clicking on links in email that they shouldn’t, which allows a hacker to get into your system. All of that it’s the main cause of breaches our employees. For example, going back to the improper disposal, the reason that breach occurred was because an employee, the office manager, in charge of paying for the storage facility, forgot to pay for the storage facility for several months, and they ended up throwing away all the records. The number one cause of avoidable HIPAA breaches are employees and and why training is so important and why you need a compliance program in place in your organization.

 

Catherine Short  24:31

Trey, I wanted to thank you again so much for being here today. So thank you.

 

Trey Scott  24:36

Yes, thank you. Thank you to all the attendees out there. I definitely appreciate getting to speak with you about OCR reporting. Hopefully this was beneficial. I know there were some areas we didn’t necessarily cover like notification to individuals and notifications to media, and just some other nuances about doing a risk assessment, things of that nature, but hopefully if you do have a breach this will allow you to report to OCR and if you want to get an attorney involved to help you report to OCR, feel free to give us a call.

 

Catherine Short  25:12

Very good. Thank you so much for being on our show today Trey and for helping out our listeners.

 

Trey Scott  25:19

Yes, thank you for having me. It’s always a pleasure. I’m glad I was able to talk about this and hopefully, it’s helpful to the listeners out there. And obviously, if you have any more questions that think up after listening to this, then I’m sure you can reach out to First Healthcare Compliance and they can get in touch with me or if you want to reach me directly, you can email me at trey@markkennedylaw.com. My direct line is 214-998-3825. So if you want to chat over the phone, because you have a really lengthy question, feel free to give me a call.

 

Catherine Short  26:15

Yeah, so thank you so much for being here. It was a true pleasure.

 

Trey Scott  26:18

Definitely can say the same!

 

Catherine Short 26:21

Me too.  Thank you so much and thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

Preserving and Protecting Assets In Healthcare: Audio Version of the Webinar14 Oct 202201:23:32

Expert attorneys Sean McKenna, Lauren Nelson, and Vincent Aiello of Spencer Fane LLP will present this dynamic webinar. They will discuss the interplay between enforcement and liability proceedings with asset protection, explore how government and private litigation matters can impact healthcare companies, clinicians, and executives, and provide tips and preventative strategies to preserve income and assets prior to such action to ensure business continuity and succession planning.

This webinar will cover the following objectives:

1. Discuss the interplay between enforcement and liability proceedings with asset protection
2. Learn how Government and private litigation matters can impact healthcare companies, clinicians, and executives
3. Hear about preventative strategies to preserve income and assets prior to such action to ensure business continuity and succession planning

Automatic Dispensing Cabinets, Patient Care, and Nurse RaDonda Vaught: Audio Version of the Webinar13 Sep 202201:05:02

Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely and fascinating subject for us. A former nurse was charged, criminally prosecuted, and in March 2022, convicted of gross neglect of an impaired adult and negligent homicide for a 2017 fatal drug error. This webinar approaches the facts and circumstances, which led to the fatal error, the role that Automatic Dispensing Cabinets (ADCs) played in the process in order to prevent similar situations. The purpose is to inform participants of a myriad of items so that facilities can evaluate and implement appropriate safeguards, train nurses and other staff, and take corrective actions before an adverse patient outcome occurs. What happened here is preventable and nurses should not flee the profession, especially because of the compassion shown by the judge.

This webinar will cover the following objectives:

1. Appreciate the timeline of events and the role that varies parties allegedly played, including Automatic
Dispensing Cabinets.
2. Understand the process and the interplay of different proceedings.
3. Learn compliance tips to prevent a similar outcome.

How New Legislation Impacts Privacy12 Sep 202200:30:14

1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “How New Legislation Impacts Privacy.” The Dobbs Opinion repealed fifty years of precedent under Roe. The implications of the Opinion extend beyond women’s reproductive rights and impact the privacy rights of all Americans. The purpose of this episode is to explain the key aspects of the Dobbs Opinion related to privacy from both the Majority and the Dissent’s perspective, address the current legislative initiatives, HHS Guidance, and Executive Orders, as well as appreciate the role HIPAA plays in navigating Dobbs.

Catherine Short:  0:01

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

On today’s episode, we are speaking with Rachel V. Rose, JD, MBA Principal with Rachel V. Rose Attorney at Law PLLC Houston, Texas on the topic of how new legislation impacts privacy. The Dobbs opinion repealed 50 years of precedent under Roe. The implications of the opinion extend beyond women’s reproductive rights and impact the privacy rights of all Americans. The purpose of this episode is to explain the key aspects of the Dobbs opinion related to privacy from both the majority and the dissents perspective, address the current legislative initiatives, HHS guidance and executive orders as well as appreciate the role HIPAA plays in navigating Dobbs.

 

Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition.For this episode, we’re spotlighting Super Ninja, Robert Connelly, CEO at Pinnacle. Robert says what he enjoys most about working at Pinnacle is the ability to assist patients in obtaining outstanding Ear, Nose and Throat care by our providers. Congratulations, Robert, our team is honored to have the privilege of working with you.

So thank you, Rachel, so much for being here today on First Talk Compliance. It’s always an extreme pleasure, and this is such an important topic.

Rachel V. Rose  2:08

Thank you, Catherine, for having me here today.

 

Catherine Short  2:11

Okay, so let’s go ahead and get into it. Because this has been a highly charged subject, I know so much information and misinformation has been flying around. If you could help clarify things, and if you could give a high level and brief background to the recent Dobbs opinion and the overturning of Roe and even remind our listeners who the players are here who are Dobbs and Roe, what happened, how did we get here?

 

Rachel V. Rose  2:39

Absolutely, Catherine. I’m going to start with Roe v. Wade, which was the seminal 1973 case, which provided a constitutional right to an abortion and relied upon the right of privacy. In terms of the follow up case to that, it’s called Planned Parenthood versus Casey and Casey was the governor for the state of Pennsylvania, and the United States Supreme Court opined on Casey in 1992 and rendered that opinion. The slight difference there was related to requiring that a woman be informed of the availability of information relating to having an abortion not having an abortion. From my perspective, as someone who’s taught bioethics for nine years, basically, in that situation, all the physician or the clinic was doing was providing enough information of the pros and cons and the options in order for the potential patient to give informed consent. Now, informed consent is premised on one, the individual having decision making capacity, and two the informed consent. There are typically four prongs to informed consent. One is that the patient understands, two is that the patient can reason, three is that there’s assurances and assimilation that occurs, and lastly, it’s a provision of consent. Having that informed consent is key.

The court held that the informed consent provision, which was set forth in Pennsylvania law was not an undue burden on a woman’s constitutional right as to whether or not to terminate a pregnancy. We fast forward to Dobbs and it’s Dobbs vs. Jackson Women’s Health Organization, and specifically, it was decided on June 24 of 2022. The court held that the Constitution does not confer a right to an abortion that Roe and Casey are overruled, and that the authority to regulate abortion is returned to the people and their elected representatives. Well, let’s be clear on elected representatives, because as we know, we elect individuals to the Federal Government and we elect individuals to the State Government here. Basically, it reverted the ability to regulate abortions back to the States, at least in part. Now, the players here in the Dobbs case were the Jackson Women’s Health Organization, which was an abortion clinic and then the petitioner was Jackson, at issue was the Mississippi law called the Gestational Age Act, which actually provided that except in a medical emergency, or in the case of severe fetal abnormality, a person shall not intentionally or knowingly perform or induce an abortion of unborn human being if the probable gestational age of the unborn human being has been determined to be greater than 15 weeks. So basically, the US Supreme Court affirmed what the Fifth Circuit decided.

 

Catherine Short  6:37

Just as a quick reminder, because we have listeners of all ages, and different educational background and everything. So if you could remind us who was Roe again,

 

Rachel V. Rose  6:49

Sure. Roe was an individual and that wasn’t a real name. Sometimes with a certain type of case filing, an individual can use a John Smith or Jane Doe or Roe, whatever it may be. The case actually originated out of Texas and went up all the way to the Supreme Court.

 

Catherine Short  7:15

So then, if we could continue on, what are now the privacy implications of the latest Dobbs opinion and overturning of Roe?

 

Rachel V. Rose  7:26

Interestingly, the word privacy doesn’t appear a lot in the Dobbs majority opinion or the dissent. But basically, there historically has been a specific guarantee in the Bill of Rights that creates a zone of privacy and this is what the dissent ordered. Now, the majority held that the right to privacy allegedly stemmed from the 1st, 5th, 9th and 14th amendments. Why is that important? Well, it’s important because this has now been overturned. But the privacy rights that are now an issue relate to HIPAA, for example, because of protected health information. It relates to the law enforcement exceptions in HIPAA which we find at 45 CFR 164.512, E and F primarily, the data the selling and marketing of PHI we find at 45 CFR 164.514 and then we start to get into the encroachment into the fiduciary relationship between a patient and a provider as well.

Under HIPAA Privacy Rule, there is that general non-disclosure requirement with certain exceptions. Again, it’s important that if the law enforcement exception is implicated, that it would be an issue with what is being requested, has the patient been notified? Is the request legally valid in terms of meeting due process? All of those issues can in fact, arise in terms of privacy and as we saw in June of 2021, the Federal Trade Commission actually brought an enforcement action successfully against Flo which is the ovulation and period tracking app for not getting patient consent, and selling or marketing that sensitive data to third party analytical vendors and entities who engage in advertising such as Google and Facebook and other entities such as that. There are a lot of different potential ramifications in terms of privacy.

 

Catherine Short  10:12

You mentioned HIPAA law enforcement exception. Can you discuss that a little bit more and then suggestions for complying with it?

 

Rachel V. Rose  10:21

Sure. As I mentioned, there are really two prongs. So the HIPAA law enforcement exception actually is not specific to reproductive health. It applies to all types of PHI. Basically, the fundamental purpose behind the law enforcement exceptions are that the Privacy Rule permits, but does not require covered entities to disclose PHI about an individual, even for law enforcement purposes, pursuant to process and otherwise required by law under certain conditions. If a covered entity such as a hospital may want to respond to a law enforcement request being made through a process, such as a court order, or a warrant, or a subpoena or a summons or an administrative agency, by disclosing only the requested PHI provided that all of the conditions specified in the Privacy Rule for permissible law enforcement disclosures are met. In the absence of a mandate enforceable in a court of law, the privacy rules permission to disclose PHI for law enforcement purposes does not permit a disclosure to law enforcement where a hospital or other health care providers workforce member chose to report an individual’s abortion or other reproductive healthcare. So the bottom line is if a an entity or a person receives a subpoena or another type of legal request, you have to make sure that again, you revert back to the two sections that I mentioned 45 CFR 164.512, E and F, because that sets forth what should be included and what the obligations are of that receiving entity. I always recommend consulting outside counsel before responding especially in today’s environment.

Catherine Short: 12:37

So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V. Rose, JD MBA Principal with Rachel V. Rose, Attorney at Law PLLC Houston, Texas on the topic of “How New Legislation Impacts Privacy”. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.

Oral contraceptives. There’re millions of women, I would say, probably taking these or have taken these. Are there any specific considerations with respect to oral contraceptives and how that fits into privacy? What are your thoughts on that?

 

Rachel V. Rose  13:33

So because the FDA has approved oral contraceptives for other purposes other than the inhibition of pregnancy, women use it for a variety of different conditions such as premenstrual dysmorphic disorder, such as endometriosis, and acne and amenorrhea to regulate the period. It’s very common in female athletes, for example, or women who are anorexic not to have regular periods. Polycystic ovarian syndrome, which is actually an autoimmune condition. All of those have ramifications not only on a woman’s cycle, but also on her fertility. That is exactly what Title X sought to establish. And that is that the women’s reproductive health be made a priority and that the preservation of reproductive health be available to women.

 

Catherine Short  14:40

What does that have to do then with Dobbs and the overturning of Roe and privacy? Could you spell that out for us a little bit more?

 

Rachel V. Rose  14:49

Well, what’s interesting is contraception could be condoms, too, right? So now you’re not only talking about female reproductive health, you’re talking about male reproductive health and as well, so that I find very interesting on that front. The other part is that as we’ve seen with conditions such as lupus and rheumatoid arthritis and cancer, at least 30 states are saying, if a woman is of reproductive age, then certain states are banning those medications. As was asked in a previous presentation, pharmacist or declining to refill them while if a prescription is coming in, it has to be for a purpose that needs medical necessity. In terms of the ramifications for oral contraceptives in particular, certain states are taking a broad brush approach that it’s not only Dobbs doesn’t only relate to abortion, it also relates to women’s reproductive health. Going back to Griswold versus the state of Connecticut, which is a 1965 Supreme Court case, that was something that fit within the zone of privacy, but also was something between a doctor and the patient to decide not the government to mandate. That’s just something that is disconcerting on a lot of fronts.

A lot of people take different medications, for different reasons. For anyone who appreciates FDA law, there actually are certain meds and I’ve read a lot of articles on this, that have a blackbox warning not to get pregnant, because the fetus will be deformed if you get pregnant while on this drug. Well, sometimes the path to hell is paved with good intentions. But the analogy here is that anything can happen. A woman might be on the pill, but she might miss it a day or a condom could break and she could end up being pregnant despite the medication saying you shouldn’t be pregnant on this medication. All of those factors need to be considered. Unfortunately, in some states, the issue of oral contraceptives and other drugs are being looped into this broad brushstroke prohibition on procedural abortion.

 

Catherine Short  17:22

Are they also including things such as IVF, and also the intrauterine device?

 

Rachel V. Rose  17:32

You’re raising a lot of good issues and IVF,  again, you need to look state by state as to what different states are saying. Interestingly, just in the beginning of August, Georgia passed a law saying that a woman who is pregnant can get certain disability or certain payments for being pregnant and have certain monetary benefits. But what’s interesting on the flip side, is that naturally, a lot of pregnancies end. The other side of that is what if the fetus is very deformed? and what happens to those babies who may then be given up for adoption or abandon or things of that nature? So I think it opens the door to a lot of issues.

IVF, I have read a couple of articles on that, and as we know, depending on the type of IVF, certain states are saying, Oh, well, the life begins when the sperm and the egg are put together. Well, what if you have eight sperm and egg that are then frozen? They are not viable because they’re frozen. So at what point does that occur? I don’t have an answer to that. I think that’s an area of bioethics and healthcare that is going to be one to watch.

 

Catherine Short  18:59

So continuing on in our discussion, what about privacy related to then raping, incest and perhaps age of patients, etc.

 

Rachel V. Rose  19:10

That’s a very sensitive and important question, because as many people know, if there’s rape or incest, oftentimes there are criminal law implications as well especially if incest occurs with a minor, a provider, whether it’s an ER nurse or a physician may have a legal obligation to report that to certain types of state agencies. That’s something to absolutely be very conscious of. Now, that’s going to vary from state to state and some states aren’t even covering abortions in the event of rape or incest. I think that the long term health implications could be more significant given and the various state laws.

 

Catherine Short  20:01

Okay, and then something that you brought up earlier was having to do with Flo, for example. So could you discuss the privacy of apps such as this? And then I started this conversation mentioning about information and then misinformation that people are hearing about. And then perhaps sometimes, like the impact of travel, you’re hearing sometimes like that people are being forbidden for traveling for health reasons. How would government officials even find out about or law enforcement even find out about that? In the first place? How do they know you’re not just going to another state for it to visit your relatives?

 

Rachel V. Rose  20:41

Well, here’s the thing, as you know, I write a lot of articles, right. If people were to look at my history, whether it was when I was writing a lot during the opioid crisis, or now with this particular situation, I look up a lot of things related to reproductive health, abortion, etc. Does it mean I’m going to get an abortion? No. And that’s where the interstate commerce and the line of cases from the Supreme Court, especially going into the late 60s, the Heart of Atlanta Motel, Inc. v. United States, 379 U.S. 241 springs to mind, where interstate commerce gets us into federal jurisdiction. So if we see too many things, situations start to happen, or too much privacy encroachment, going beyond what is,  “reproductive health”, then I think that is going to be an area of case law to absolutely watch. And again, the Senate in June, introduced a bill which is still just in the introduction phase, but it was bipartisan to prevent this type of data collection and tracking, because you don’t know if someone’s going to visit a relative or not or if there’s someone like me, who is writing an article in there googling stuff.

 

Catherine Short  22:08

You had mentioned earlier also, or we talked a little bit about HIPAA law enforcement exception. Obviously, that can cover quite a few things having to do with privacy and health law. But concerning the topic that we’re talking about, so if there was some kind of law enforcement in this case, who specifically does this type of enforcement in states where where regulation is much higher, or for abortion and things like that? Does police or is there some kind of special force? Or are regular people reporting on each other, like bounty hunters? Or? I mean, these are things you hear about. Could you talk about that a bit?

 

Rachel V. Rose  22:48

Yeah. So in Texas, they have what’s known as the snitch law. It is basically a bounty. Some states might pass a law saying that there is a requirement to report if someone comes to you, but again, going back to the HHS guidance, which was released the beginning of July, that could be a violation and a breach and could require that HHS be notified. This is an emerging area and it’s one to watch. It’s going to vary from state to state, unless, of course, we have federal law, which gets passed that basically reinstates Roe and Casey and only Congress can do that.

 

Catherine Short  23:36

So is there a way that Dobbs can be overturned?

 

Rachel V. Rose  23:40

Yes. As many people appreciate, we have three branches of our federal government that are set forth in the Constitution, we have Congress, we have the executive branch, which is the president and the executive agencies and then we have our judiciary, which is defined in article Three. Article one is Congress, Article Two is the executive branch and article Three is the judiciary. What’s important to note is that our system was set up to have checks and balances. So even though the Supreme Court did overturn Roe, importantly, Congress, if they have enough of the required votes on the House side, and then the Senate side can, in fact, pass a law that would memorialize what was permissible under Roe. Not to say that there couldn’t be another challenge down the line, but that is the only way to do that. That’s why, for example, in those executive orders, what the President and the White House can do is limited

 

Catherine Short  24:51

Such an interesting subject. I wanted to emphasize again, to our listeners, that this is a privacy issue that we’re that we’re emphasizing here and I didn’t know if you had any other thoughts that you wanted to emphasize to our to our listeners?

 

Rachel V. Rose  25:05

Catherine, this is an emotional issue regardless of the side but as an employer as a healthcare provider, one needs to step back and divorce oneself emotionally and make sure that for example, if the law enforcement exception under HIPAA is being invoked, that the organization is protecting both themselves and the patient because there could be downstream litigation that could be taken against them as well.  That’s one area to consider. Another area is the greater impact on both equal protection of women’s health, not even reproductive health. That is another item that absolutely needs to be considered. As I mentioned, condoms are contraceptives, and typically those are used by men. So it does affect men, and it does affect women. It affects families and women or men really who may be going through different types of medical treatments such as cancer, where they may freeze their sperm or their eggs to make sure that when they’re ready, there is a viable option having undergone very significant treatment that could in fact, alter cells. So those are all factors to consider and approaching things from a privacy standpoint and a clinical standpoint in the provider patient relationship, as well as obligations under laws such as HIPAA, and EMTALA should really help mitigate the emotion and just focus on the patient care and what the obligations are under the law.

 

Catherine Short  26:54

One other question. As a repercussion from some of this, do you think that possibly there might then be a diminishment of the number of providers for women of reproductive age and women who need just general gynecological care or obstetricians, and what’s your opinion on that?

 

Rachel V. Rose  27:16

So as we learned earlier, the drugs that are being impacted are not just surgical abortions, there are drugs that are used in the treatment of women’s health. So to say that I’m not going to treat a woman of reproductive age, if you think about it, that is a significant part of the population. That would lead down the road into constitutional violations as well as the potential for equal protection violations as well. So I think that’s something to be honed in on.

 

 

 

Catherine Short  27:56

All right.Well, I wanted to thank you so much. I believe that we’re just about out of time.

 

Rachel V. Rose  28:02

Catherine, always my pleasure, and I look forward to our next conversation.

 

Catherine Short  28:10

Me too.  Thank you so much and thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

The Dobbs Opinion, the Repealing of Roe, & the Impact on the Privacy & Security of Patient Information – Audio Version of the Webinar09 Aug 202201:13:45

Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely subject for us.The Dobbs Opinion repealed fifty years of precedent under Roe. The implications of the Opinion extend beyond women’s reproductive rights and impact the privacy rights of all Americans. The purpose of this webinar is to explain the key aspects of the Dobbs Opinion related to privacy from both the Majority and the Dissent’s perspective, address the current legislative initiatives, HHS Guidance, and Executive Orders, as well as appreciate the role HIPAA plays in navigating Dobbs.

This webinar will cover the following objectives:

1.Understand the privacy implications of the Dobbs Opinion, which repealed Roe.
2.Appreciate the nuances of the Majority and Dissent’s positions and the impact on the privacy of protected health information (PHI) and the role HIPAA plays, including the 18 identifying factors of PII components of PHI.
3.Learn the current initiatives taken by various federal branches of government, states, and private companies and the impact on privacy rights of all individuals.

The Insecurity of Everything: The Vital Importance of Hardware Data Security08 Aug 202200:25:40

1st Talk Compliance features guest John Shegerian, Chairman and CEO of ERI, the largest cybersecurity-focused hardware destruction and electronic waste recycling company in the United States and co-author of the cybersecurity book, “The Insecurity of Everything” on the topic of “The Insecurity of Everything: The Vital Importance of Hardware Data Security.” He will share some of the latest information about the very real problem of hardware hacking in the world of healthcare and beyond and how that issue became even more serious during the pandemic, with so many people working from home. He will also be explaining critical information for health-related businesses to help them keep their private data – and the data of their patients and customers – protected!

 

Catherine Short:  0:01

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

 

On today’s episode, we are speaking with John Shegerian, Chairman and CEO of ERI, the largest cybersecurity-focused hardware destruction and electronic waste recycling company in the United States.

 

John is the co-author of the cybersecurity book “The insecurity of everything”, and today, we will be discussing the insecurity of everything: how hardware data security is becoming the most important topic in the world. He will share some of the latest information about the very real problem of hardware hacking in the world of healthcare and beyond, and how that issue is becoming even more serious during the pandemic with so many people working from home. We will also be talking about critical information for health related businesses to help keep them and their private data and the data of their patients and customers protected.

 

Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition.

 

For this episode, we’re spotlighting Super Ninja Julie Garcia, business office manager at Coastal Vascular Center. Julie says “Coastal Vascular Center has three office locations, and yet the whole group works as a team. They all respond well to the compliance updates and changes. I am fortunate to have such a close knit caring group of professionals to work with every day”.

 

Congratulations, Julie, our team is honored to have the privilege of working with you.

 

So John, thank you so much for being with us today on First Talk Compliance.

 

John Shegerian:  2:21

It’s totally my honor. Catherine, it’s great to be back with you here today.

 

Catherine Short: 2:24

Thank you. I’m glad to have you on today, too. So John, can you tell me, how serious is the problem of hardware hacking?

 

John Shegerian:  2:34

It’s very serious, Catherine, when I got into the recycling business 17 or 17 and a half years ago, e-waste was the fastest growing solid waste stream in the world. Fast forward 17 and a half, 18 years later, it’s now the fastest growing solid waste stream by an order of magnitude of five times. So our great innovation nation has created more gadgets that connect us. With Internet of Things and wearables and nest and ring and cars are now computers on wheels. The problem of e-waste is growing, which means the problem of hardware data protection and the issue of hardware data destruction when our old electronics come to their natural end of life has grown with it. It’s a massive problem and it’s something that we need to address.

 

Catherine Short:  3:28

And so what’s the biggest factor driving that need for efficient data destruction?

 

John Shegerian:  3:35

Right. As your listeners and constituents are typically in the healthcare agency or organization world, they know the legacy laws which still exist actually, such as HIPAA and Rick [INAUDIBLE] and [INAUDIBLE] still exists around data protection and constituency protection with regards to privacy. But, in May of 2018, we had of course, GDPR passed in the EU, which was protecting corporations having to protect the data of their clients or constituents. Americans started now taking hold and being informed by what the EU did post 2018 and now America is not only passing their own federal versions of GDPR but every state is also passing their own version of GDPR, which is all around privacy and data protection, which means these many more people out there hand in the pot to regulate this, which means there’s going to be more fines and more regulators overseeing the health care agencies across the United States that’s created. The risk level, the liability level has multiplied many times over. Hardware is connecting us more than ever before. So the risk level has increased and the regulatory level has increased which creates a perfect storm of having to really take this issue seriously now more than ever.

 

Catherine Short:  5:05

Okay, so how can people in this field learn more about sustainability practices and data protection in particular?

 

John Shegerian:  5:14

Think about this, how important is Shred-it or Iron Mountain to all of our lives, in the healthcare agencies in terms of shredding data that’s on paper? Now, think of all the electronics that you use on a daily basis, whether it’s your cell phones, personal or professional, your laptops, your tablets, your copier machines, your X ray machines, MRIs, everything that you touch that contains patient data is now covered by the laws the states are creating around privacy and data and the federal laws. If your constituents information is breach, and they tie it back to software breach, or on this discussion today, on a hardware hack or breach, you’re going to be held liable both by your constituents and patients who can sue you and will sue you, but also the local and state regulators and the federal regulators.

 

Catherine Short:  6:07

It kind of makes a person feel a little bit paralyzed when they think about is my electronic information being wiped, I think I’ve liked it clean, but maybe deep in the recesses, it’s not free of all my information and so should I just keep storing it all in the basement? How can a business find out if a recycler is certified, what types of certifications are necessary in terms of environmental compliance and feel safe?

 

John Shegerian:  6:36

It comes down to a couple things. Anyone can fake a website. Whoever is in charge at your organization, whether it’s a cybersecurity specialist or just a security specialist, whether it’s a CISO or Chief Technology Officer, or by the way, a Chief Sustainability Officer, because your healthcare agency or healthcare organization cannot be sustainable with regards to both software hacks and hardware hacks. Since websites can be tricked, what I highly recommend is two or three things. First of all, the right type of certifications and checking back with those certification agencies that the recycling company is part of that certifying body. For instance, on the environmental side, these two certifications that your clients and your listeners should be hearing about. One is called  e-Stewards ban.org. The other one is called R2. R2 is under the brand of Siri, and that’s a different brand. Again, R2 certification and  e-Stewards certification are the two most important certifications when it comes to environment. When it comes to data protection, the one that was created exactly for your listeners, was NAID. That was first created, national association of information destruction, was created to protect data that was on paper. That was originally created to regulate the data on paper that was going through organizations like Shred-it, and also Iron Mountain  making sure they were doing it the right way. It now also covers certified and responsible hardware data destruction, so it covers both and you can find all NAID members at naidonline.org. Now, you also want to look on the websites of the recyclers you’re speaking with, or data destruction companies you’re speaking with to make sure they’re NAID certified. They can say they’re NAID certified but not truly be on the certification list. You could back check it by going to naidonline.org.

 

Catherine Short: 9:00

What about some electronic devices that can’t be recycled? Are there any on your list that can’t?

 

John Shegerian:  9:06

No. The truth is, all electronic devices when responsibly recycled can be turned back into the commodities and all those commodities can go back for beneficiaries. Zero waste, zero landfill, zero emissions. Everything we can handle. We can handle your old MRI Machine, your old Xray machine, your desktops, your laptops, copier machines, by the way, oh my god, you want to talk about a hidden goldmine of information for the cyber criminals, copier machine hard drives, have every copy that’s ever been made on that copy machine. Every copy is on that hard drive.

 

Catherine Short: 9:40

I think about copier machines all the time. I think about oh my gosh, yeah.

 

John Shegerian  9:45

A lot of people don’t, and then it gets in the wrong people’s hands. It’s literally a goldmine for cybercriminals so please, everything that your patients or clients information is going through: copier machines, fax machines , MRIs, X ray, cell phones, anything you’re touching and using where patients information is flowing through, has to be responsibly destroyed when they come to end of life. So just pick a responsible recycler. We’re just one of many across America and there’s lots of good ones, but don’t let it go. Do not, under any circumstances, allow someone to pick up your old electronics from your healthcare agencies and say they’re doing it for free. Free is literally a four letter word for the word Sham. Free does not exist. Just like free doctors don’t exist, free nurses don’t exist, free lawyers don’t exist, free accountants don’t exist, Free recycling, legitimate, responsible recycling does not exist on this planet today.

 

Catherine Short:  10:47

Copiers are an interesting story, though, because for most businesses who have these large copying machines, they’re almost always leased. So it’s not like they’re owning them, and then having them destroyed after. They’re going back to whatever business had leased them. That always makes me feel nervous, because then they’re going back to whatever company they leased them from. I assume that they have some kind of contract that says their information is being destroyed. But I don’t know, what are your thoughts on that?

 

John Shegerian:  11:17

Catherine, you’d be shocked unless you put a special rider into that contract, in many cases, the leasing company dumps these things onto an open market, loads them on to basically containers, where they’re sold overseas and secondary and tertiary market. Here’s what I’ll tell you, the dirty little secret of the E-waste industry, the  Homeland Security and the DOJ and FBI are all clients of ours and have sat us down in our offices as executives of ERI and told us that in 2001, 2002, 2003, 2004,2005,2006 and 2007 even, the folks that were buying these old electronics off of our shores, wanted to mine the gold, the silver and the other precious metals that would contain they’re in. Now the people buying our old electronics off our shores in 2022 and beyond, in many cases, not all, but in many cases, are just buying the old electronics, pulling the hard drives, to try to do corporate espionage or breach our homeland security in America, depending on where the electronics came from, and then disposing of the carcass of the rest of the machinery into the ocean, into the desert, or they’re just simply burning them. It’s very dangerous to think that a leasing company is going to act responsibly without dictating, legally dictating in a rider to your contract, how they have to handle it and having them counter sign that in the contract. Catherine, you make a great point, this goes for rental, this goes for leased cars that are now downloading our information on the hardware of a leased car has your own information. The same thing with leased equipment that’s in a hospital or healthcare agency that does go back to the leasing company. They have no requirement to destroy that information responsibly, unless you dictate it in a legal and binding rider to your contract.

 

Catherine Short: 13:14

Okay, how do you propose to do that?

 

John Shegerian:  13:18

Well, we deal with leasing agents all the time that are doing the right thing, but only because they’re told to. So to me, you’re the CISO, or CTO, or Security Expert, or Chief Sustainability Officer from the healthcare agencies that are listening to this podcast today, every healthcare organization we deal with, and financial organization, have different people in charge of the hardware. So I’m just giving four or five examples of who can be in control of the hardware. Those people have to be shown or have to be shared the information we’re talking about today, that the dangers that are lurking within old hardware and electronics are potentially catastrophic, and that the contract should now be adjusted. This is a big shift in the industry. We have these conversations every day with our client base and it’s a growing issue because what happens then, is when agencies or healthcare organizations or other at risk organizations are lackadaisical in their approach, they start finding themselves in problems with their cybersecurity insurance contracts, which require them to take care of all these issues and if they found out they left holes open, or they haven’t taken care, it could also affect your insurance coverage in the cybersecurity and data breach sector.

 

Catherine Short:  14:41

True, true.

 

So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is John Shegerian Chairman and CEO of ERI, the largest cybersecurity-focused hardware destruction and electronic waste recycling company in the United States, and co author of the cybersecurity book, “The insecurity of everything”, on the topic of “The insecurity of everything: The vital importance of hardware data security”. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.

 

Okay, well, we have had a huge change in the world, obviously. We’ve had this COVID 19 pandemic continuing on. How has that changed the cybersecurity landscape and in your world, and in our world here with hardware hacking, and with everything going on with with you all and hence for us?

 

John Shegerian:  16:01

Yeah, that’s a great question. The quiet behind the scenes change that we saw was very evident to all of us, there was a work from home movement, because we were all on lockdown throughout 2020, and a good part of even 2021. People got used to working from home and actually liked it, and that’s okay. But what we saw that wasn’t okay and that greatly affected of the data sphere and the data breaches section that we focus on with our clients and potential clients is that once people work from home, because of different factors in a home, time crunches, children, spouses, your personal hardware that you use for your own life, started getting contaminated with your professional information and your professional hardware, also then started getting contaminated with your personal because sometimes you’re supposed to get on a zoom call, and your laptop takes a poop or is no longer available, you get on to your desktop, who belongs to somebody else in the household, your son, your daughter, or some other family member and all of a sudden you’re doing the Zoom call from that desktop and that data that was supposed to be on your hardware is now on your children’s hardware and vice versa. You’re supposed to get on a personal call, and you end up on your professional laptop and before you know it, your personal information is on your professional hardware, and your professional information, and that includes your patients and clients, their information is on your personal hardware and what you need to do is follow, if it’s a good protocol, follow the protocol of the agency or healthcare organization you work for because in terms of the destruction of the data and destruction of the hardware for all of your equipment. You don’t want to be the cause of a data breach because your personal equipment you put up on Craigslist or eBay to sell, but your professional equipment got handled the way your healthcare organization requires you to. You got to treat it all as at risk once you work from home and there’s a cross contamination. People go, Ah, I’m not part of that my information is not getting cross contaminated. Listen, I’m the CEO of our company, and I have cross contamination on my hardware at home, as does my wife, as does my children who are both lawyers. My point is, this is not calling anybody out for carelessness, it’s just what happens after you’re at home for a long enough period, and you’re using your hardware and jumping from room to room. Different times, things break down, and all of a sudden, you’ll be shocked how much cross contamination really happens and if you’re lackadaisical with your own hardware, it could be catastrophic results in your professional career and life.

 

Catherine Short:  19:07

Right. How do we make recycling electronics successful to all the new teleworkers in a post Coronavirus workforce?

 

John Shegerian:  19:15

That’s a great question Catherine. It comes up all the time with clients or potential clients. We developed in 2012, for other purposes, for one of our clients requests, a box program. We have boxes from the size of a cell phone all the way up to a pallet size box, about 17 different sizes. We can ship those boxes to anyone’s home or office by the way, and they can fill them up at their own leisure and their own timeline and convenience with as much electronics as they have, print off a label, and then UPS or FedEx will pick them up from their doorstep and reverse logistics it back to one of our eight locations nationally. Now of course there’s an expense that comes to us, but just like doctors and lawyers and nurses and accountants and Investment bankers, and everyone else you pay a fee to, real responsible recycling costs money. It costs us over $100 million to build our infrastructure and all our technology to handle the United States and beyond, our international clients and their hardware data destruction and recycling needs. We have to pay for that infrastructure, just like doctors and nurses have to pay for their infrastructure. So we charge a fee and we make it convenient for everybody at home or in their office to just make recycling super simple. Press of a button, the boxes are delivered a day or two later, and they fill them up at their own convenience, and then UPS or FedEx take them back to us and all their information will go away.

 

Catherine Short: 20:45

Well, I have a question for you. What about when you get a new phone,  you go to AT&T or Verizon or Apple or whatever and you know, it’s time to upgrade your phone and they say, okay, you’ve got to wipe your phone, and then you trade it in for a new phone. And they say, Okay, we’ll give you a discount on your phone and you trade in your old phone. And they say you have to wipe your old phone, and then you mail it into us and we have to make sure you wipe your data clean, etc. Are you actually wiping your data clean when you set it back to factory settings? Or is that kind of a lie? Are you not setting it back to factory settings? Is your information still in there?

 

John Shegerian:  21:26

Brilliant question. I don’t want to characterize it as a lie, but it’s a hopeful goal, that typically when you talk to the best hackers, and we have a lot of the great hackers that are white collar hackers that — how do I say this? white hat hackers, that know how to hack, but don’t do it for illegal purposes, they say it’s a hopeful goal that’s literally proven to fail 95% of the time. Most of us don’t know how to do it the right way, most of that information is recoverable, and again, none of them recommend it. I’m only leaning on, I’m erring on caution on advising you and your great listeners, I wouldn’t do that if you think you’re at risk, if you think you have information on your phone, or your tablet that you don’t want the bad guys to get. It’s like Oprah Winfrey’s old statement of years ago, about six or seven years ago, never text or email something that you don’t want to see on the cover of The New York Times. I believe that’s really true when it comes to the question you asked.

 

Catherine Short:  22:36

Interesting. All right. I mean, that’s what my suspicion was.

 

John Shegerian  22:40

You’re right. Your suspicion is absolutely correct.

 

Catherine Short:  22:44

Yeah. Okay. Well, I think that we’re coming up on the end of our time, do you have any other advice or thoughts that you wanted to leave with us today, there’s so many, so many things. But any other thoughts,

 

John Shegerian:  22:58

I want to leave everybody with a positive note. Responsible recycling of your old hardware is not difficult. There’s lots of great recyclers across this wonderful nation. You just have to make sure you do your homework. It’s become a bigger problem because of the technological revolution and because of the high turnover of electronics, and because we all want newer, better, faster, and that’s okay. But in our goal for newer, better, faster, let’s not overlook the dangers that lurk within. Just please responsible recycle everything that you have, that you don’t want any of that information to get out. Both professionally and personally, it will do you well, because A, you don’t want anything to happen to your career that you worked hard on and B you don’t want anything to happen to you own finances or legal issues within your own household. So just take extra care so nothing bad happens. It’s all possible to make it all go away because the technology exists with a company like mine, and many other good recyclers across this nation. There’s lots of ways to do it and all I just asked is for people to take a little extra time doing their homework, and they’ll have a great result.

 

Catherine Short:

Okay, wonderful.

 

John Shegerian:

And for all the listeners, thank you for listening. I want to make an offer. If you write to the email that Catherine Short is giving you, you can get a free copy of our book, The insecurity of everything. It will be mailed to you within a couple of weeks of your request. I’m happy to share this with you all as an education tool and I think you’ll get a lot out of it and it’ll be a great reference tool also to keep on your desk.

 

Catherine Short:  24:32

Okay, great. Thank you so much, John, I really appreciate you coming on today. So thank you so much for offering your expert advice for us today.

 

John Shegerian:  24:41

Absolutely. My pleasure. I’m happy to come back anytime Catherine and support your great organization.

 

Catherine Short:  24:46

Thank you. Thank you so much. I really, really appreciate it. Thank you and thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

 

Work Civility: A Harassment-Free Workplace vs Employees’ Right to Engage in Concerted Activity: Audio Version of the Webinar14 Jul 202200:56:22

Lauren E.M. Russell, Counsel at Young Conaway Stargatt & Taylor, LLP leads this hot-topic webinar. The National Labor Relations Board under the Biden Administration has expressed a renewed interest in expanding its influence into non-unionized work forces. This includes reviewing and–in the right circumstances challenging–employers’ use of workplace civility, confidentiality, and anti-harassment policies. Learn what you need to know to safely navigate the National Labor Relations Act while ensuring that your employees enjoy a safe and respectful work environment.

This webinar will cover the following objectives:

1. Understand the scope and application of the National Labor Relations Act
2. Learn about the National Labor Relations Board’s current enforcement priorities
3. Understand the steps available to ensure that you avoid scrutiny from the Board while also meeting your legal obligations to provide a safe and respectful work environment, free from unlawful harassment

Combatting Ransomware in Healthcare13 Jul 202200:16:07

1st Talk Compliance features guest William J McBorrough, co-Founder and Chief Security Advisor at MCGlobalTech, a D.C.-based Information Security Consulting Firm on the topic of “Combatting Ransomware in Healthcare.” William joins our host, Catherine Short to examine how ransomware attacks have impacted thousands of organizations worldwide with the healthcare sector having been the most targeted. Join us in a discussion of the state of ransomware in the healthcare sector and best practices to prepare your organization from the inevitable attacks.

Catherine Short:  0:00

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

On today’s episode, we’re speaking with William J McBorrough, Co-founder and Chief Security Adviser at MCGlobalTech, a Washington DC based information security consulting firm on the topic of combating ransomware in healthcare. We will examine how ransomware attacks have impacted thousands of organizations worldwide, with the healthcare sector having been the most targeted. Join us in a discussion of the state of ransomware in the healthcare sector in 2021, and best practices to prepare your organization from the inevitable attacks.

Before we begin, I would like to mention at First Healthcare Compliance we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Dina Green, Billing Manager at Community Link Consulting of Washington State. Congratulations, Dina, our team is honored to have the privilege of working with you.

So hello, William, thank you so much for joining me today on 1st Talk Compliance.

 

William J McBorrough: 1:52

It’s my pleasure, happy to be here.

 

Catherine Short: 1:55

Wonderful. Well, let’s get right into it. Can you explain to me what exactly is ransomware?

 

William J McBorrough:  2:03

Sure. We are all familiar with the concept of ransom, typically, within the context of a kidnapping where you hold someone until a ransom is paid, and then you release them. That is the exact same concept of how that works with ransomware attacks. Ransomware attacks are a software based attack in which an attacker restricts access or encrypts an organization’s computers, servers, files, and demand a payment. We’ve seen incredible growth and complexity of ransomware over the past few years, although ransomware has been around for about 20 years. At its core a ransomware is an attack that restricts access to an organization’s data and systems. Any incidents within an organization that impact access to data and systems is one that should be of concern. Ransomware will be one of several of those incidents.

 

Catherine Short:  3:06

Okay, great. Can you tell me who is at risk for ransomware attacks? Are we speaking of only very large systems or are smaller systems are they at risk?

 

William J McBorrough:  3:22

I think it’s really a matter of scale. Basically, any computer or any computing device that is connected to the internet is at risk of a ransomware attack. From a college student at home doing distance learning to a large healthcare organizations with hundreds of hospitals. Typically, what you find is that for single individuals or very small organizations, they’re really victims of opportunity. A lot of these attacks are automated, they’re scanning the internet and if they identify one, they attempt to perpetrate this attack. There has been increased sophistication in these attacks over the past few years, that are targeting large organizations, including healthcare organizations that are really sophisticated attacks that are planned by the cyber gangs. So everyone is at risk.

 

Catherine Short:  4:21

Why would a cyber criminal go after a smaller entity when they could go for a bigger fish?

 

William J McBorrough:  4:28

That is a great question because I get this a lot. Hey, we’re a small company, no one knows us. Why would anyone attack us? Typically what you find, on the smaller end, you’re not being targeted at all. A lot of these attacks are sort of automated, you happen to be vulnerable. You happen to be connected to the internet. So yes, you are going to get caught up in this wide net. Typically they’re going to ask you for a not insurmountable amount of pay because again, the whole goal of a ransomware is to get the rest. The large entities with the ability to pay millions of dollars in ransom, are the ones being targeted by using more sophisticated attack that takes months of research, focus and attention and the level of effort is greater. Everyone is potentially impacted, because attackers have the ability to automate these attacks and they’re able to scan the wider internet and just find you if you’re vulnerable, and encrypt your systems. So again, it’s sort of an equal opportunity attack.

 

Catherine Short:  5:38

okay, can you tell me what the signs are of a ransomware attack? Are they super obvious?

 

William J McBorrough:  5:46

I mean, the primary sign is super obvious. If your system is compromised, it will get locked up. You will get a screen in your browser or on your computer desktop that is saying, we have encrypted your system, pay ransom of this amount, by this means, by this date, or else. But another ways that you can find the indicators of a ransomware attack is that when your files are actually encrypted, there’s an additional extension added to the file name,  file.exe, file.dll file.docx, file.pdf, typically, there will be an additional extension added to it and when you open up the file, all you will see is gibberish, right? Why? Because the data in the file has been encrypted, and that’s a primary indicator that you are the victim of a ransomware attack.

 

Catherine Short:  6:46

Okay, so how should users respond to a ransomware attack? And when I’m asking about users, how should users at perhaps a entity as opposed to perhaps an individual respond?

 

William J McBorrough:  7:02

That’s a great question, Catherine because with the entities, you should have processes and procedures that your users and employees are trained to follow. I think that what a lot of organizations lack is the fact that their employees aren’t really trained on what to do. Typically it’s running a three step process that organizations to train their employees. First,  if you suspect your system has been compromised by any type of malware, including ransomware rule one is disconnect that system from the network. So unplug the cable that connects it to the internet jack, disable the Wi Fi. If you’re on some type of mobile device, reset the device in airplane mode, disable the Wi Fi or disable the Bluetooth. The goal here is to prevent the spread. Typically ransomware within an organization wants to compromise one system, move to the next compromise that system, and so on, and so forth. Step number two is disconnect any external devices. If you have USB sticks, if you have phones or cameras attached to it, if you have external hard drives of some kind, you want to disconnect that, again, these are things you do to limit the spread of the compromise. And notify your IT organization, notify your security organization, notify your management. Users and employees should be trained and given easy access to how do you notify IT when you suspect a compromise of any kind? That will essentially be the step one, two and three.

 

Catherine Short:  8:51

Okay, good. And what if you are perhaps an employee at home and maybe something happens to your individual computer? What should you do then?

 

William J McBorrough:  9:01

The first two steps still apply and get help. I mean, there are a lot of resources that have been made available by the US [INAUDIBLE] by the FBI, what us as citizens should do if we were the victim of a ransomware attack. There’s resources that can be made available to help us at no cost, decrypt our system. You should have access to some means or some individual to help you manage your computer system, and that could mean even if you have a MacBook, take it to the Apple store. After you have disconnected, take it over to the Apple store and say hey, I suspect that my computer has been compromised. Can you help me? Seek help. The last thing you want to do is to leave your computer connected to the network where you are able to infect other computers that are on the same network.

 

Catherine Short:  10:01

okay, great advice. What should organizations do to protect against ransomware attacks happening in the first place?

 

William J McBorrough:  10:11

So some basic best practices here. First, the primary vector, or ransomware attack is through phishing emails. And when you have to have a security awareness training program that provides consistent reinforcement of a good security behavior. Once a year, check the box training does not work, has never worked. Two, in a way that ransomware spreads within an organization and ultimately compromises system are due to underlying vulnerabilities because your systems are not properly updated and patched.  Keep all of your systems updated, and patched. There are services available to help you monitor that. That’s part of what we do at our managing security services. Three, again, you need to protect access to your data in your systems. If your data and systems are impacted, you need the ability to recover from that impact. You have to implement data backups. Maintain, potentially online but most definitely offline backups of all of your critical files and system and test your ability to recover from them. Next, you must install security software on all of your computers in service, not just antivirus, make sure that the firewalls are updated, make sure that you have in town malware and make sure that we have the capability to monitor that those security software are actually functioning. Next, email filtering, very important. Again, the number one vector within organizations for ransomware is email. So you must have the capability to filter all of your inbound and outbound email. The only thing better than having a user who is trained to see a phishing email and not click on it is to prevent that email from entering that users inbox. There are filtering tools, we can help organizations identify which ones work best for them. Next, implement two factor authentication to access the systems in your application. Passwords are dead. They have been there for a long time. A lot of applications today, a lot of cloud systems today have built in capability for multifactor authentication. Now typically the way how this works is you enter your username and your  password and then you connect it either via a token or via a one time password  sent to you mobile device or via a one time password sent to the email there are many different options available today for multifactor authentication. Lastly, within an organization, you want to implement segmentation. Segment your network. Separate your end users from your servers if you have servers on site, because you have to be able to limit the spread within the organization. Lastly, you got to have security policies and procedures to guide user behavior. What to do when. What not to do when. Policies and procedures that must be made available to your employees, they must be trained on those policies and you must have plans. Business continuity plans or disaster recovery plans, incident recovery plans, what should we do when the inevitable happens? Very important. And lastly, you have to test all of these controls. One of the things that we do on a regular basis for our clients is we test the security programs. Where are the weaknesses? You want to identify where you are vulnerable and address that vulnerability.

 

Catherine Short:  13:57

Great advice. So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is William J McBorrough, Co founder and Chief Security Adviser at MCGlobalTech, a Washington DC based information security consulting firm on the topic of combating ransomware in healthcare. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also find us on all other social media.

So William, what are the most common avenues of ransomware attack?

 

William J McBorrough:  14:49

Well Catherine, as I’ve said before, I’ve mentioned multiple times emails, emails, phishing emails. Phishing emails are the primary vector for ransomware attack. They are the primary vector for most cyber attacks within organizations today. They account for more than a third to close to a half of the cyber incidences within businesses large and small. Phishing emails are used primarily to trick users into opening then downloading attachments of malicious content that then compromises the underlying systems. The second most common vector that has been established over the past few years is the fact that you now have a lot of organizations that are opening up their network to allow remote users to connect to systems within the network and not doing it securely. One of the most common ways that is done is the built in functionality within the Microsoft operating system, or remote desktop. Remote desktop gives you the ability to connect from one system to the desktop of another system across the internet. There are more secure means of achieving this within the organization, but what you find is that because of COVID-19, with the sort of vast migration of workers from the office to the home, a lot of organizations open up the network to allow workers to continue to work and that has led to a great increase in successful ransomware infections.

 

Catherine Short:  16:36

What are some possible impacts of a ransomware attack? If one happens, then what is the impact?

 

William J McBorrough:  16:45

Typical impacts are temporary, and sometimes permanent loss of sensitive information. A lot of times even after the ransom is paid, you don’t get full access to all your files. Two, disruption to business operations. We have had cases over the past year in which healthcare organizations have lost access to their IT systems for weeks and trying to sort of recover the data and recover their systems. Another impact would be the financial losses due to all of that downtime and recovery efforts. And lastly, the potential harm to the organization’s reputation. You don’t want to be on the front page of CNN or some other news outlet to be the next victim of a ransomware. That  hit to your reputation as an organization does have a long lasting impact,

 

Catherine Short:  17:47

How much could a ransomware attack cost?

 

William J McBorrough: 17:52

What we’ve found is that over the course of 2020 to 2021, the average ransomware payment is close to $50,000. However, what we’ve seen is that with more focus being placed on larger organizations, we’ve seen successful ransomware a payments of close to four, five, $6 million to  an organization’s IT systems. We had a client once, a very small medical practice, where they were the victim of a ransomware attack. They contacted us because the attacker was demanding a payment of $6,000. Now, in the grand scheme of things $6,000 have an impact, but it’s not an insurmountable amount of money. But again, there’s a very wide range with an average of over $100,000

 

Catherine Short:  18:47

Do you recommend paying the ransom? Or what do you recommend?

 

William J McBorrough:  18:51

Referring back to sort of guidance, out of FBI, and out of the US Department of Health and Human Services, typically, this is a business decision that organizations should make. What I recommend is that an organization should do what is necessary to prepare for a ransomware attack. If you have implemented, some of the best practices that I mentioned before, you can find from many different sources, including,  the SBA, the FBI, the Department of Homeland Security, if you’ve implemented those best practices, then you have the ability to recover, right? If an attacker encrypts your files and you have a functioning backup of those files, then you don’t have to pay. That’s the position you want to be in. But if you don’t have any other means to recover your information, paying up the ransom, is generally encouraged because that is the easiest way to get access to your files and regain access to your systems. But we add a caveat to that. One of the things that we’ve seen is that only 60 to 70% of organizations that pay the ransom, get full access to 100% of their files. So the best course of action here is to prepare to be able to withstand a ransomware attack, because even if you pay, there is no guarantee that you are going to recover all of your files. Be prepared.

 

Catherine Short:  20:32

Okay, actually, that was my next question. Does paying the ransom guarantee you get access to all of your data?

 

William J McBorrough:  20:40

In many cases, that is not the case.  Sometimes you get access to your files, and sometimes the files that you do get access to are so corrupted that they’re, sort of not really usable for you. We’ve had instances where once the files were decrypted, because the organization paid, they were not fully decrypted, so they were not able to get access to all of their patient’s health information to be able to file insurance claims. Paying does not guarantee that you are going to get access to all your files. The only way to guarantee access is to have a working, functioning backup of those files, there are many different affordable means to be able to do that.

 

Catherine Short:  21:26

Is there insurance that covers ransomware attacks? Does that exist?

 

William J McBorrough:  21:32

Yes. There’s insurance that covers sort of the impact of ransomware attacks. The organization has to do a couple of things. They have to of quantify costs of the financial loss due to business operations, as well as due to a recovery efforts and there are insurance policies that covers that. Typically, what you find is that a lot of insurance providers won’t want you to be able to demonstrate that you have performed your due diligence in trying to protect the information, similar to insurance companies wanting you to have a safe driving record. There are a lot of different types of policy options that are available to cover both direct and indirect cost of security incidents, and those options are available and the market is still growing. There will be more options for that in the future. However, being as prepared as possible, helps limit that liability.  Whereas a cyber liability insurance can help you recoup some of your losses, it is never going to be able to recoup 100% of the impact to the organization.

 

Catherine Short:  22:47

That makes perfect sense. Yeah, that you would need to demonstrate that you have done as much as possible on your side to be able to have insurance and then to also just be protecting yourself just in general. So thank you so much, William, I think we’re just about out of time but do you have any other advice that you wanted to leave with us today that perhaps we didn’t cover or touch on?

 

William J McBorrough:  23:10

Sure. One thing that I will leave you all with is I speak to a lot of organizations and typically there’s  a sense of being overwhelmed by yet another cybersecurity thing to worry about. Ransomware, although it is top of mind for a lot of organizations today, have been around for over 20 years, and is growing in sophistication. But it’s just another cyber attack that impacts your data and your systems. So all of the best practices that we talked about are things that you should implement. It’s not religious sort of a ransomware mitigation exercise. Those are things that you should implement to protect the business, to protect your data, protect your systems, you can withstand a ransomware attack, it is possible and you can do that with limited impact to the organization. You just have to be prepared.

 

Catherine Short:  24:05

Okay, well, thank you so much again, for speaking with us today. This has been extremely enlightening. And also you’ve made cybersecurity very easy to understand and very much appreciate that. So thank you so much, William very much appreciate that. Thanks to our audience as well for tuning in today to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

 

 

How to Handle Document Retention & Destruction13 Jun 202200:14:35

1st Talk Compliance features guest Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX, on the topic of “HIPAA and Beyond: Documentation Retention & Legal Holds.” Rachel joins our host, Catherine Short to review a multitude of laws, including HIPAA, requires certain types of documents be kept for a certain period of time. How does document retention play out for public companies subject to SOX and what should companies do in the event of a legal hold or a preservation request? This presentation addresses laws that are relevant to healthcare industry participants, as well as compliance suggestions, and steps to take when either a legal hold or a preservation request arrives.

 Catherine Short:  0:00

Welcome and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality, complimentary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel. On today’s episode, we are speaking with Rachel V. Rose JD MBA, a principal with Rachel V. Rose Attorney at Law PLLC in Houston, Texas, on the topic of HIPAA and beyond: document retention and legal holds.

A multitude of laws including HIPAA requires certain types of documents to be kept for a certain period of time. How does document retention play out for public companies subject to SOX and what companies do in the event of illegal hold or preservation request. This presentation addresses laws that are relevant to healthcare industry participants, as well as compliance suggestions and steps to take when either a legal hold or preservation request arrives.

Before we begin, I would like to mention at First Healthcare Compliance we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Julie Garcia, Business Office Manager at Coastal Vascular Center. Julie says “Coastal Vascular Center has three office locations, and yet the whole group works as a team, they respond well to the compliance updates and changes. I’m fortunate to have such a close knit and caring group of professionals to work with every day”. Congratulations Julie, our team is honored to have the privilege of working with you.

So hello, Rachel, thank you so much for joining me today on 1st Talk Compliance.

 

Rachel V. Rose:  2:18

Hi, Catherine, thank you for having me today, as part of First Talk Compliance. I think the issue that we’re going to be addressing is timely and important.

 

Catherine Short:  2:29

Thank you. I do too. So my first question has to do with electronic media and also all other forms of documents. My question is, do PNPs apply only to electronic media or all forms of documents? And so could you explain to our audience first what PNP is, what does that mean? And then tell us about electronic media versus paper and any other form?

 

Rachel V. Rose:  2:57

First and foremost, PNP simply means policies and procedures. For those of you who have been in the healthcare industry for quite some time, you’re very familiar with the requirements under HIPAA, that policies and procedures are required in order to address a variety of different items which are present both within the HIPAA Privacy Rule, which was initially published in the Federal Register in December of 2000, as well as the Security Rule, which was published in the Federal Register in February of 2003, and became effective in 2005. So if we think about protected health information in general, there are two primary forms of protected health information there is PHI, which is stated in the HIPAA Privacy Rule, and is inclusive of all written paper, oral and electronic forms of PHI. By way of contrast, the security rule, specifically addresses electronic PHI, or ePHI. So examples of ePHI include not only emails and cloud types of storage, but also VPNs and voice over processing, which is a tool that is utilized by many organizations today.

Along those lines, Catherine in terms of PNPs and what needs to be addressed, it’s imperative to parse out the Privacy Rule from the Security Rule. Whenever you start looking at your document retention and destruction items, first, identify what types of PHI need to be retained and for what periods of time. A second prong of that is to look at how documents are being retained in electronic, if they are paper are they kept in a locked file cabinet in a separate room? All of those are included in policies and procedures. Now, when you get to the document destruction, they can shred those and it should be shredded automatically just people walk over and they put those documents in the shredding bin. From there, the third party comes and picks it up, they unlock the block and they release the documents into a huge typically a mobile shredding device from there a certificate is given and that’s important in terms of making sure that your organization is compliant. Oftentimes, a certificate is emailed and it allows an organization to easily file those into a sub folder and keep a record of the type of shred that was produced. And that’s important, the PHI cannot be pieced back together and that’s why the confetti shredder is important. Now for electronic protected health information, how you delete that is going to be a discussion between you and your IT provider in terms of the software that you need to use and the schedule that can be set up a term of destruction, a server or a laptop, or other types of information, it needs to be completely sanitized, or destroyed.  I always refer my clients to NIST, and to make sure that they are adhering to the appropriate guidelines, as well as making sure that the data is completely deleted so that you don’t have a situation for example, and this actually was a HIPAA violation, where a Xerox copier was returned, but it had not been sanitized. So just like the paper shredding, companies give a certificate of shredding, so should it third party give a certificate that the data has been sanitized completely, and then you file that certificate away.

 

Catherine Short: 7:35

Often companies, of course lease these copiers from places such as Xerox or, or other companies like that. So does the company itself like the law firm or the the hospital or whatever, do they have to sanitize the copiers themselves? Or they have it with the third party?

 

Rachel V. Rose:  7:55

That’s an excellent question, Catherine and it comes down to two documents. The first document is the Business Associate Agreement, which as many people know in one section of that it will define how the information is to be returned or destroyed. Another part of that should be in the services agreement contract. If it’s in the services agreement contract that the physician’s office, for example, is responsible for wiping the drive on that, then that’s something that they would be responsible for. If they’re not, then they need to get assurances to make sure that that is being done. The process for that is taking it to the secure bin in the office dropping it in there and then the third party, which we’ve contracted with, and then you insert the third party in the contract, contact information comes up, picks it up and gives us a certificate. The last part of that procedure would be the certificates are filed with whoever gets those certificates. It could be IT, it could be HR, it could be your HIPAA compliance person. So the same thing should happen for electronic media. And if you’re unsure of the vendor, then just put that you will contact your IT person and or an attorney in order to ascertain an appropriate third party to wipe the median clean.

 

Catherine Short:  9:36

Okay. My next question has to do with spoliation. First, what is spoliation? And then what is the best way to avoid spoliation?

 

Rachel V. Rose:  9:48

That’s an excellent question. Spoliation basically is the destruction of evidence. Spoliation can be intentional or non intentional. In fact, there are two states and one territory, Illinois, Florida and the District of Columbia, which actually recognize a tort for negligence spoliation of evidence. Now spoliation of evidence may occur prior to a case commencing, it can occur during a legal proceeding. A couple of items to note there are that courts have the authority to sanction both the lawyers and their counsel for spoliation of evidence. If we harken back to 2002, with the Enron and WorldCom type cases and scandals, that led to the passage of the Sarbanes-Oxley Act, also known as SOX, and abbreviated as S O X. Section 802 of Sox was implemented for auditors, accounting firms and publicly traded companies primarily to prevent the destruction and or alteration of evidence. That same concept applies with spoliation. How can it happen, and what are the best ways to avoid it from happening? Your first line of defense is training your workforce. Your second line of defense is having adequate policies and procedures on retention and destruction of various types of information. The last policy and procedure which is critical is what’s known as a legal hold policy. With that, you should have a template that is already available and you would insert the date of the request of the legal hold or anticipated litigation, and then if you’ve received a subpoena or another form of a litigation hold, such as a preservation letter from a government agency, things of that nature, you need to document exactly what was asked of you to set aside and then you set it aside in an appropriate secure manner and make sure that nobody touches it. It should serve as a check and a balance so that one person completes the checklist, another person makes sure that all the information is gathered, and then lastly, someone rechecks the work of the person who is gathering that information.

 

Catherine Short:12:44

Okay. What are technical, physical and Administrative Safeguards that are the most relevant to protecting PHI and sensitive PII in relation to retention and deletion of this material?

 

Rachel V. Rose:  13:04

That’s an excellent question. As we know, cyber security is a focal point of all facets of our government. After the federal courts were attacked as a result of the solar winds attack, the Administrative Office of the Courts set out a statement and all of the individual courts issued requirements that needed to be followed. In light of that, we have the White House issuing an executive order in May of 2021, indicating a need for increased collaboration between the public and private sectors in order to make the overall cyber environment secure.  That came really in the wake of the Colonial Pipeline, cyber attack. Then we have various laws being considered and passed both at the state and the federal level. So it’s A, a focus; B, with the rise of ransomware attacks in the sophistication of cyber criminals, this is only going to become more and more important, and that’s why your policies and procedures related to retention and deletion as well as the business continuity and disaster recovery plans are vital. That’s because those technical, administrative and physical safeguards are a key component to ensuring that organizations are keeping backups that are not accessible by the same method of attack. It also ensures that in the event in original is lost, that a legal backup or legal copy can be reproduced to a court, to a government agency, or another type of legal proceeding. An example of a technical safeguard, which is relevant to document retention and deletion would be making sure that you have identified an appropriate vendor for the sanitization of media, such as the copiers that we mentioned earlier or laptops, and making sure that you get a certificate. Lastly, in terms of physical safeguards, keeping information in a secure area, so if everything’s housed on your servers or in a data center, look for two factor identification in order for people to access that item, as well as keeping a log as to when that room was accessed.

 

Catherine Short:16:01

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality, complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V. Rose, JD, MBA, Principal with Rachel V. Rose Attorney at Law PLLC in Houston, Texas, on the topic of HIPAA and beyond: document retention and legal holds. Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us and subscribe on all forms of social media.

Rachel, what are key items to include in document preservation PNPs?

 

Rachel V. Rose:  16:54

So some key items to include in document preservation PNPs, or your legal hold policy are as follows. First and foremost, you want to have definitions so that your workforce understands exactly what a preservation is, or a legal hold is. Then you want to identify scenarios which a legal hold might be necessary to implement, such as anticipated litigation, it could be the result of a preservation request, typically in the form of a written letter from a government agency, it can be by court order, such as by a subpoena. So in all of these circumstances, you want to make sure that your workforce understands the potential seriousness of not complying with any of these requests. Along those lines, you want to then identify types of information, you need to identify who in the organization would implement or sound the alarm for that legal hold. It’s important to note that it’s really on a need to know basis, and by saying that, you don’t need to send out an alert or an email to everybody in an organization, it needs to be very specific to documents which may be under certain people’s control, and you need to alert them that they are not to delete anything. By the same token, larger entities or business associates or a third party, IT can begin to round up that information and set it aside, if you will, in a separate folder, or offline on a separate hard drive. From there, you want to make sure that you’re including a checklist and that will vary somewhat from organization to organization, or industry to industry. Lastly, you want to have a chain of custody letter to show when the initial information was compiled, where it was compiled to. Finally, it’s important to note that the individuals who are passing the information off will need to sign that chain of custody letter.

 

Catherine Short: 19:30

Okay, great. Rachel, what are the most effective ways to delete evidence legally and to destroy it in accordance with HIPAA?

 

Rachel V. Rose:  19:43

Well, first and foremost, you want to make sure that you’re not deleting anything that’s required to be preserved. If you know it’s to be preserved, then deleting evidence is just not acceptable in any way, shape or form and that can lead to spoliation, which we talked about earlier. In terms of regularly deleting certain types of documents or information, first and foremost, you need to look at the general laws and for HIPAA, you need to look at the state laws because federal HIPAA recommend six years, but the state laws are typically longer. And most states require a seven year retention period for PHI. However, if there are minors involved, typically organizations need to keep that until the person reaches 18, plus about two to four years.  We say that because that is the timeframe, and you need to check your state laws individually, for a statute of limitations of when certain lawsuits can be brought. So along those lines, you need to identify everything in your policies and procedures as to the who, what, when, where, why, and how, regarding how information that is not subject to any legal hold type of requirement may be appropriately destroyed on an ongoing basis. How you appropriately destroy that, again goes back to the requirements of NIST, the National Institute for Standards and Technology, and the HIPAA security rule or the Privacy Rule. If it is paper protected health information, use some form of a confetti cut shredder.

 

Catherine Short: 21:45

Okay, great advice. And speaking of I think we are just about out of time, but do you have any other advice or things that you wanted to mention to our audience, before we wrap up,

 

Rachel V. Rose:  21:59

I would just recommend approaching any HIPAA or document retention in terms of cultivating an overall culture of compliance. It’s important to appreciate that there are ramifications and consequences for not adhering to legal holds and in the event it comes about as a criminal proceeding, if you’re not retaining the documents that the United States Government or another government entity has asked you to preserve and retain, that could end up being a legal action against your organization for potential obstruction of justice. So it’s something to take very seriously. There can be sanctions or we know under HIPAA, people, and I mentioned the sanitization of the Xerox machine earlier but also, there was a truck full of medical records, and the entity was fined for not appropriately disposing of those and that occurred within the last four years. So paper is still around, and it’s important to adhere to the retention and destruction requirements for all forms.

 

Catherine Short:  23:18

Rachel, thank you for being on our program today and for going over this important information with us.

 

Rachel V. Rose:  23:25

Catherine, it’s my pleasure. Thank you for the thoughtful questions, and the follow up questions. I truly appreciate it and always enjoy collaborating with First Healthcare Compliance.

 

Catherine Short:  23:37

Thank you. Well, the pleasure is ours and I always enjoy speaking with you, Rachel, and thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on healthcarenowradio.com and then your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

 

 

 

How to Prevent Employee Snooping and Insider Threats – Audio Version of the Webinar11 May 202201:02:23

Raymond Ribble is the CEO and Founder at SPHER, Inc. a market-leading compliance analytics, cyber-security solution addressing: HIPAA compliance, State Privacy Laws, and ePHI security threats and our presenter for this webinar. Snooping and Insider threats are exactly why user monitoring and ePHI access strategies are vital to the security of sensitive patient information and data protection. While it is an unsettling thought, not all cybersecurity incidents are traced from employee negligence. With so much attention and money surrounding cybersecurity in the healthcare industry, malicious employees may decide to purposefully disclose patient information. Since employees and contractors may have knowledge of your network setup, vulnerabilities, and access codes, snooping employees with malicious intent hold the key to exposing your organization to a series of unwanted risks and threats.

This webinar will cover the following objectives:

1. Identify roots signs of Employee and Contractor Unauthorized Access
2. Provide guidelines to prevent Snooping
3. Provide Insight and procedures to detect Insider Threats

Medical Error & Patient Advocacy – How Can We Have More Candor?09 May 202200:14:32

1st Talk Compliance features guest Kathleen W. McNicholas, MD, JD, CHC, CCEP, Consultant and Patient Advocate with Medical Legal Patient Advocacy Inc., on the topic of “Medical Error & Patient Advocacy – How Can We Have More Candor?” Kathleen joins our host, Catherine Short to review medical error and provide an approach to harmed patients. The CANDOR program of Communication and Optimal Resolution will be explained. CANDOR is well established and has been successfully adopted by many medical centers.

Catherine Short:  0:04

Welcome, and let’s 1st Talk Compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality, complimentary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

 

On today’s episode, we are speaking with Kathleen W McNicholas, MD, JD, CHC, CCEP. Consultant and Patient Advocate with Medical Legal Patient Advocacy Inc, on the topic of medical error, CANDOR, and patient advocacy. We will review medical error and provide an approach to harmed patient. The CANDOR program of communication and optimal resolution will be explained. CANDOR is a well-established program and has been successfully adopted by many medical centers. With CANDOR in place, patients may benefit from the use of the principles and the help of a Board-certified Patient Advocate.

 

Before we begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our Compliance Super Ninja recognition. For this episode, we’re spotlighting Super Ninja Julie Garcia, Business Office Manager at Coastal Vascular Center. Julie says “Coastal Vascular Center has three office locations and yet the whole group works as a team. They all respond well to the compliance updates and changes. I’m fortunate to have such a close-knit caring group of professionals to work with every day”. Congratulations, Julie, our team is honored to have the privilege of working with you.

 

So hello, Kathleen, thank you so much for joining me today on first talk compliance.

 

Kathleen W McNicholas:  2:22

Thank you, Catherine. It’s a great pleasure.

 

Catherine Short  2:25 

So what skill set is required to be a board-certified patient advocate?

 

Kathleen W McNicholas: 2:32

We have to have real competence, proven competence, in our field, in mine its surgery, relationships to get us credibility. It also is important to have humility. With my career and my background, I got a healthy dose of humility. I feel that I’m fairly competent to do that, but it’s an ethical relationship and it’s a pleasure for me to be able to extend my career and service.

 

Catherine Short:  3:02

What made you become a Board-certified Patient Advocate?

 

Kathleen W McNicholas:  3:06

That’s a very interesting background story. I had a very special friend, I was part of his family essentially, and he had a very bad outcome, due to a medical error. I was involved in that in the late 1990s and saw the anguish and the suffering that the family went through. And a little quote that I’ve used from René Leriche: “Every surgeon has a small cemetery, and they go there frequently to pray”. I think that really was the impetus in my case, to a lot of my changes in my career and transitions. When I saw that happen, I thought that there had to be a way, a better way. I’ve subsequently spent a lot of time in that cemetery thinking about what we could do differently, to make M’s death not in vain and to make it really a pivotal point in at least my career. It was happening at the same time that the medical errors, medical liability was becoming a big issue and I just kind of got caught, thankfully, in a great wave. When my career as a cardiac surgeon ended, I continued as a surgeon, but just didn’t operate, which is an unusual surgeon. I then was able to do patient safety and leadership and work in performance improvement at an excellent institution and learned a lot about patient safety risk management.

 

I had spent some time in my transition. I found that I was pretty boring, didn’t have a hobby, and thought I’d go to law school. A couple other things happened to me which I kind of put in the background, but law school was pretty eventful, and not because of my experience in law, but I had a myocardial infarction in 2002 followed by stents 2003 I had a coronary artery bypass grafting. I retired from cardiac surgery in 2008. This experience with my friend, son and my friend really prompted me to become more involved in patient safety. I’d also met Tim McDonald, who started the CANDOR program in the University of Illinois, and it all kind of just came together. When I saw something called board certification and patient advocacy, I thought that was perfect. I really enjoy patient work. I still enjoy patients.

 

Catherine Short:  5:34

This next question has to do with CANDOR, which is all capitalized. Could you explain to our listeners what the program of CANDOR is, and then what concept support CANDOR and healthcare and who has ownership with this.

 

Kathleen W McNicholas:  5:52

CANDOR is an acronym for Communication and Optimal Resolution. This is a process that was started in the early 2000s. It was led by Richard Boothman at the University of Michigan and Tim McDonald from University of Illinois, Chicago. AHRQ threw a big grant in their way to pilot this program, and to make a toolkit so we could share. The important thing in medicine is you don’t have to do everything yourself that other people can do some things and form a toolkit, and you do things uniformly. So CANDOR was instituted. CANDOR is an amazingly good process in a response to harm caused by medical error. So this has to be recognized, reported, and really intense review and then after a review, and a consensus decides that this is appropriate, there was harm caused by medical error, resolution comes about. Resolution can be monetary, it can be of course, waiving the fees because you don’t want to charge for useless service and certainly medical error will be considered useless service. You don’t want to go down that rabbit hole. So if you want to look at that in hold the bills, hold future bills. Then some families want to be part of the process in that at University of Illinois has been worked into it and they have a wonderful patient, advocacy group that goes with them. It is difficult, it’s a heavy lift. It’s a big process, it works well when it works well. What I have done is taken the large caps and made them small caps, just to get the usual word candor. The whole process is geared towards finding resolution for families and finding it in a timely fashion. You don’t want to go through a four-year legal process, which is the alternative. If you can’t accept and you don’t understand and you need to find information, you go to the next best source, which is the legal process, you get experts, then you have a battle of experts. Then if you get a settlement well, that’s pretty disappointing, too because that’s a shallow victory.

 

Catherine Short:  8:23

Okay, so how are ethics of medicine, patient safety and patient advocacy aligned?

 

Kathleen W McNicholas:  8:31

The ethics of medicine are the basic ethics do good, and that we learned in kindergarten before, do no evil, do no harm. Then justice, be fair. The other thing is autonomy: treat patients with respect, respect their decisions, respect their positions, respect where they are, their status. That’s pretty easy. Medical practice came along, and we kind of amplified them and changed them. Patient safety ethics are also very, very interesting and I think focus on something that I focused a lot on and was able to develop programs and work around things. It’s pretty intuitive, but it’s also pretty powerful. You have that vigilance. I had a brief career as a pilot.  I won’t say it was very successful. I didn’t crash but I came close and I did have a problem finding airports, but you have to be vigilant. You have to look out for what could happen. Mindfulness is something I wish I had a little more of, and we all have to kind of block out the other things and be mindful. Compliance, I mean, I thought we were compliant just because we were doing well and doing things the way we thought was correct and there was a whole body of information there, of law and compliance. Compliance is key to making the ship run and have a commonality. The biggest part really and the part that appeals to me is humility. Humility is really difficult. I should say resilience too but nobody did tack [INAUDIBLE] because we really do come and go with our patients. People asked me how I remember my patients and I asked them how you could forget them. The most important thing in CANDOR is communication and optimal resolution. Therefore, the acronym CANDOR.

 

Catherine Short: 10:26

Can you describe in four words, the basic skills required for patient advocacy?

 

Kathleen W McNicholas:  10:33

You have to have empathy of the patients and the patient’s families. I had my own little experience on the opposite side of the sternal retractor when I had my bypass surgery. That’s something that people have, some people have naturally, some people acquire, and some people have it amplified.

 

You have to have trust. If you can’t trust someone, you can’t work with them. I think trust is a very important thing to have, and to have the ability to develop and to nurture.

 

You have to have credibility. Got to have been there, you’ve got to have walked in the shoes. I tried to arm myself pretty well. I considered law a hobby but that was five years of intense study and as I told everybody that asked me what I did, I told them I was a technician. When they told me what hard days I had, I said, well, did anyone die? And they said, No, I said you had a good day.

 

And then humility. I’m not the most humble person in the world, though I certainly should be and I tried to be and it should come naturally, but I think that’s an important quality. I would say in short, it would be empathy, trust, credibility, and humility and integrity would go in there too. You have to be a solid person on solid ground.

 

Catherine Short:  11:53

Right. I agree. So you pursued a legal education. What impact did your career in medicine have on you pursuing a legal education?

 

Kathleen W McNicholas: 12:07

It was would be very difficult, I could imagine, if I lived long enough to practice medicine at the intensity that I did. So I was looking for a hobby. I went to law school thinking it would be a casual experience, it was anything but. I had to go to law school and actually finish it. I love the body of knowledge I got. I did not become a lawyer. I do not want to become a lawyer, I don’t want to practice law, but I love the theory and I love the way lawyers think.

 

Catherine Short:  12:36

Well, what impact did your experience with law have on your career then as a patient advocate?

 

Kathleen W McNicholas:  12:44

My experience of law was really an academic experience. It was important for me to be with people who were pursuing that line of work and to see how they think and to read the cases, to see how they were judged, to critique them, to apply my knowledge- there were a couple really pivotal cases, one I was involved with. It was not a malpractice, but it was a court judgment on a Christian Science child. It’s a life of service, I really want to be useful and I’m trying. My heart is to continue to appreciate the fact that my health had declined, and I have an excellent cardiologist that rescued me. So I’ve got a new lease on life that I’m trying to enjoy, that I am enjoying.

 

Catherine Short:  13:32

Wonderful! So if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources, we help create confidence among compliance professionals throughout the United States. My guest today is Kathleen W, McNicholas MD, JD, CHC, CCEP, Consultant, and Patient Advocate with Medical Legal Patient Advocacy, Inc, on the topic of medical error, CANDOR, and patient advocacy.

Please show your support by taking a few minutes to provide a review of First Healthcare Compliance on Google or Facebook. You can also follow us on other social media.

So Kathleen, what was your contribution to patient safety?

 

Kathleen W McNicholas:  14:25

I co-lead the CANDOR program at a major local institution, which is an outstanding institution and I think that has to be the highlight. I also worked on Just Culture, which is a new way of approaching error in dealing with individuals and the choices they make. I had a lot of interest in working with people after events because I think that’s the hardest time for them and that’s the time when they really lose confidence in themselves and the suffering is unbearable. I set up a program of post event debriefs, which we held at variable times during the day, as soon as we could, after the event and with the support of absolutely tremendous Patient Safety Department. We could do this, we invite all people that were involved in the event that we knew of, and it was really a very diverse group of people and people would know that they alone were not responsible, which at the beginning, they all thought they were, and this was not punitive. In the old days, we had a very simple system, it was ABC assess, blame and crucify. This is the polar opposite of that, where you take the wisdom of the group, and you support them. The fact that they’re supportive makes them realize that they are really valued professionals, that they see a safety problem, they will be the ones to report it. The reporting system has outstanding, near misses, good catches, crash events, and try to learn from them. I really enjoy looking at problems and seeing how people fix it and getting other people’s perspectives. I hope that answered your question.

 

Catherine Short:  16:06

Yes. I have a question about something called Human Factors, capital H, capital F. So can you explain what that means? Human Factors? And then what has been the contribution of Human Factors to patient safety.

 

Kathleen W McNicholas:  16:23

I wouldn’t even begin to assess the contribution. It is huge. And when you’re blessed as the institution where I worked at, a value Institute, and they had a whole section of people who were experts in Human Factors, they would come and look at a problem to say, what made it so simple for that accident to happen? What made it so not avoidable that you fall into that trap? How can we improve this? How can we change it? Their minds, it was a psychology but it goes back to Deming in trying to figure out why bad things happen. When you get a group of people and somebody that’s a specialist in Human Factors, they can cut through what you are all looking at and show you what the defect was, or what the potential harm was, that was laying there behind the scenes that allowed this to happen. How the drain got stuffed up it wouldn’t work, how the door to the bathroom had a handle that if you pushed it, it would just release and you could have [INAUDIBLE]. We looked at [INAUDIBLE], we looked at all major events and we could see how these things happen. The labeling, the storage, the tall man letter labeling, there were so many fantastic things.

 

This group of people is sitting there trying to help us to make it harder to make an error, and easier to do that right. I think that is a talent and that’s a science that has incredible application and it’s one that you don’t think of normally. Here when I’d always insist that we’d get somebody from Human Factors, people would think that was a little silly and a little out of the field. Why could they help? But they could help because they could cut through, they have a different way of thinking and a different way of looking and it’s all of us how we look at the problem and how we come up with solutions or improvements.

 

Catherine Short:  18:22

So Human Factors is how humans are influencing errors. Something happened by accident and this seems to be happening over and over again because humans are doing the same thing over and over again. And how can we fix this, that kind of thing?

 

Kathleen W McNicholas:  18:38

It’s a latent defect that makes it easy to do it wrong. We want to put a layer of prevention. If somebody notices a small defect in what we’re doing, how we’re thinking, and it gets people in the operating room to announce their names to say who they are, they speak, you hear their voice. If something goes wrong, they could speak up and say, excuse me, I want to double check this, or I have a question. That’s listened to, and that comes from aviation, and the read backs, there’s so many things that Human Factors professionals can tell us, if you put this in your system, you will improve the performance. It’s small things but then you get to communicate it and you amplify, you magnify the value of patient safety experts. The meetings we have with the people who have really devoted a lot of their time and education to getting it right is just overwhelmingly beneficial. It’s great. I’m enthusiastic about it because it’s how we’re getting to the safety culture and it is a culture of safety. You have to understand that an error could be catastrophic. Therefore the vigilance, therefore the mindfulness, therefore the compliance, therefore be humble and admit to yourself ‘I can make an error’. If it’s going to happen one out of 1000 times, it’s going to happen to someone. Someone’s going to be that one out of 1000 and you want to prevent that.

 

Catherine Short:  20:10

Okay, so here is another difficult question, then what culture is the most important in healthcare?

 

Kathleen W McNicholas:  20:17

Well, it’s pretty easy. It’s a culture of safety, which is the umbrella culture. All the rest are molded in and become part of the fabric of the patient safety. If you look at it as big quilt, the just culture, the CANDOR program, the care for the caregiver program. If you find a need, you plug it up, and you plug it up safely and it’s under the rubric of the culture of safety. A hospital that has a great culture of safety is a great hospital. Patients are going to understand when you’re doing so much to do things so well.

 

Catherine Short:  20:51

Well, that leads into another question that I had. Is CANDOR adopted universally? And if it’s not, why is that?

 

Kathleen W McNicholas:  21:02

It can be because of the intensity. You really need a powerful culture of safety and you need a support group for that, and that’s a patient safety department or section or some group within the hospital. You have to have attorneys within the hospital and outside the hospital in the community, who will agree to this and who don’t just say it’s kerfuffle, which, you know, we had several other terms people throw around, but you have to get the buy in. The industry is important, but the people are more important.

 

Catherine Short:  21:40

Kathleen, what about care for the caregiver? Do you need a CANDOR program to provide care for caregiver? I know that there’s a lot of need for the caregiver as well.

 

Kathleen W McNicholas: 21:52

No, you do not. Silent victim is no longer the silent victim. I think hospitals and everyone recognized it. Even talking about my friend and when he had an echocardiogram when he had the EKG, everybody that touched him that knows the outcome is overwhelmed with grief. So I think that everybody’s out there and everybody’s seeking it or nobody goes and wants to admit that they’re weak, or they’re nonprofessional. Well, professionals are the ones that need care. And the professionals are the ones that are giving care. So AHRQ, the same same group that has CANDOR, and the care for the caregiver is another program with another toolkit, but it’s a part that is really beneficial to move in right away and talk with the group, find out who was affected, and open yourself up and have professional people, it appears their colleagues, that can go in find out how the person’s doing and provide more care, suggest or recommend more care if it’s necessary. That syndrome of burnout, you know, this is human being with little parts of their souls being removed, in effect, that you cannot shake it off, you do not take off your ID tag and become a different person when you go home. You carry it with you. Everybody has this little area of their soul and we have to make sure it’s nurtured, it’s healed and it just happened together. We have to look at it as far as the just culture goes, and assure them that we’re humans, things happen. We have to take care of them because they’re absolutely, totally valuable to the institution and their value has to be cared for. It has to be nurtured.

 

Catherine Short:  23:40

Well, Kathleen, I think we’re just about out of time but I wanted to ask you, do you have some other thoughts or things that you wanted to leave with us today?

 

Kathleen W McNicholas:  23:48

Oh, yes! We’re all evolving. I think I’ve evolved, and I think that we all have to be open and just look for opportunity, and look to be useful. For patients, there’s always somebody out there and when they’re searching, a patient advocate is a wonderful person to search for. I’ve been a patient advocate all my life and it’s kind of silly, now I have a nonprofit, because I really can’t see burdening people with anything more when they’re already so stressed. It’s really so difficult, but they need to speak and they need to speak with a person and they need to speak with their families and the communication thing is really the key. if he could if they could promote that and make family peace. I tell you that suffering I just can only imagine my friends went through with the loss of the beautiful, beautiful son, it’s overwhelming it really fills that cemetery and there are little plots around it where you see them all sitting in breathing in there, they’re still breathing to this day so you really want to find peace and resolution. That’s why I’ve kind of moved to in my life from the aggressive cardiac surgeon to the patient advocate in a different form just a surgeon who doesn’t operate anymore except in my dreams.

 

Catherine Short:  25:19

Absolutely. Well, thank you, Kathleen, thank you so much for coming on to 1st Talk Compliance today very, very much appreciate it.

 

Kathleen W McNicholas:  25:29

Thank you, Catherine. It really was a privilege in the display some of my passion towards this field. And again, I should thank my colleagues who worked very hard with me to make our institutions safer, and really make them places I have tremendous pride in and want to maintain that.

 

Catherine Short:  25:52

We’re grateful to you. Thank you so much, and thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about our show on the program’s page on healthcarenowradio.com and to lend your voice to the conversation on Twitter @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind!

 

 

 

 

 

 

 

Employment and Labor Law Digest11 Apr 202200:26:54

1st Talk Compliance features guest Catherine Walters, a partner at BYBEL RUTLEDGE LLP and management-side labor and employment attorney representing employers of all sizes, on the topic of “Employment and Labor Law Digest.”  Catherine joins our host, Catherine Short to update employers and human resources professionals on recent employment and labor law developments and discuss specific hot topics.

Catherine Short: 0:01

Welcome and let’s 1st talk compliance. I’m Catherine Short, Manager of Virtual Education at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality complementary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook, or iTunes. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

 

On today’s episode, we are speaking with Catherine Walters, Partner at Bybel Rutledge LLP, where she is a management side labor and employment attorney representing employers of all sizes on the topic of employment and labor law digest. This program will provide a quick update of 2021’s most important developments and forecast what employers can expect for 2022. We will update employers and human resource professionals on recent employment and labor law developments, discuss specific hot topics of interest to employers and human resource professionals, and provide ideas regarding anticipated changes in the labor and employment law arena for 2022.

 

Before we begin, at First Healthcare Compliance, we serve as a trusted resource for compliance professionals and celebrate their hard work and dedication with our compliance Super Ninja recognition. For this Super Ninja, our team is turning the spotlight on Mindy Mayberry, Practice Administrator at ENT Specialists. Mindy says “I have the best group of physicians and staff. We have a close-knit team at ENT Specialists PC that we consider family.” Congratulations Mindy our team is honored to have the privilege of working with you.

 

Thank you, Catherine, for joining me on 1st Talk Compliance. It’s a pleasure to have you on

 

Catherine Walters: 2:10

My pleasure to be here Catherine, I enjoy working with you.

 

Catherine Short:  2:14

Great, I do too. It’s always nice to have you and your insights. So Catherine, we have a broad range of topics to discuss here today. Can we go through some of your top concerns for employers in 2022?

 

Catherine Walters:  2:30

Absolutely. You know, I have a lot of concerns for employers, but trying to put them in a specific order is a good idea because I think that some of them are much more imminent than others. If we want to get started, I can talk about COVID issues. It remains top of mind because there are no consistent standards for employers to follow. I am unusually in favor of the Occupational Safety and Health Administration, OSHA. I am a defense attorney so I really represent employers, but I do think that OSHA does a marvelous job of attempting to create safe workplaces, and a safe workplace is the best kind of workplace you can have. With COVID, we’ve not been able to get any consistent standards for employers to follow not for lack of trying by OSHA, but really because the OSHA standards keep getting kicked around, batted down, and finally shot down by the US Supreme Court. Ultimately, OSHA tried to put together an emergency temporary standard that dealt with vaccination and testing for employers with 100 or more employees and the long and the short is that emergency temporary standard has been shot down by the US Supreme Court as of January 13 of this year and as a result, employers have been left with no consistent standards to follow. If you look at the United States, it’s a patchwork of different state laws, different municipal laws, just a patchwork of differing things that employers have to try to abide by. Some of the laws prevent employers from enforcing certain types of rules and others require the enforcement of certain kinds of rules. So an employer really is between a rock and a hard place without some type of consistent national standard.

 

Catherine Short:  4:40

Well, onto another issue. The OFCCP issues. If you can explain what the OFCCP is, first of all, and discuss issues concerning this.

 

Catherine Walters:  4:54

Sure. The OFCCP means Office of Federal Contract Compliance Programs. It’s basically considered to be the federal watchdog with respect to federal contractors who receive federal monies to perform work or provide products. The OFCCP enforces a number of laws as to employers. Primarily it enforces Executive Order 11246, which requires affirmative action on behalf of minorities and females. Then there’s the Rehabilitation Act, Section 504 of the Rehabilitation Act, which requires employers to provide affirmative action and equal opportunity to individuals with disabilities. Then there’s also the Vietnam Veterans, VEVRAA. OFCCP enforces the Vietnam Veterans law as well, and it requires affirmative action on behalf of protected veterans. It’s not just Vietnam veterans at this point, affirmative action is typically applicable to federal contractors with varying sizes of federal contracts, and numbers of employees 50 or more employees, and you have to have a written plan. What we see on an annual basis is employers who must update their affirmative action plans. So every year, a federal contractor will update those plans. The OFCCP is the one that not only monitors those plans but accepts charges of discrimination and investigates those. They’re really focused on discrimination and much of their focus is on systemic discrimination, as opposed to individual discriminations. What you’ll have in many situations is what we call disparate treatment versus disparate impact. Disparate treatment is where you treat one person differently from another or one group or class of employees differently from another.

 

 

Catherine Walters:  7:06

There’s the new SAM requirements. SAM, is the System for Award Management database. Federal contractors have to sign up with that portal in order to qualify for government contracts. This has never happened in the past, but we have a new affirmative action plan reporting requirement that will go into effect. In essence, under the SAM declarations page, contractors are going to have to begin affirming that they have developed and maintained affirmative action programs at each establishment as applicable. This is an initiative that is commencing now. By March 31, contractors shall be able to access that portal to certify their affirmative action planning compliance. By June 30, contractors must certify whether they have developed and maintained their affirmative action program for each establishment or functional unit as might apply to them. This was where the OFCCP lacked teeth. In many instances, in the past, employers were able to get away with not having their programs in place or updating their plans on a regular basis. A lot of contractors think they have an affirmative action plan and it’s in some dusty binder on some dusty shelf in some closet somewhere. It’s an annual exercise and it has to be done at least annually and be done even more regularly. You can have short plans, but you can’t have a plan that goes beyond 12 months. This will require people to give more thought to making these certifications, because to make a certification is very important. Under SAM, if you lie about it, you could be disbarred.

 

I would say then that this will enable OFCCP to select people for audit. Once selected for audit, the contractors would actually submit their plans through the portal. It’s going to be interesting to see how many contractors decide that they want to continue being federal contractors. I think we’ll lose some people as a result of these new certifications because a lot of contractors that don’t have huge amounts of government contracts, they consistently look at whether they want to continue being federal contractors and some of them decided against doing it because there are too many overlays, other legal overlays, particularly on the employment side of things and that’s just one of the affirmative action. So many times you’ll see contractors reassess their status and decide to pull out. Those who stay in it are going to make these certifications, they have to be accurate. So we’re going to see more of an uptick in employers actually working on their affirmative action plans.

 

For a number of other things going on too at OFCCP, for example, they are targeting non discrimination in hiring and compensation. They’ve always done that but they’re using another approach to it. Basically, compliance with affirmative action. It’s really just the beginning of meeting OFCCP obligations. The executive order adds other non discrimination obligations. I think that we’re going to see a real heightened scrutiny of application screening. Right now, a lot of employers use artificial intelligence to screen applicants. They have online applications, and they get thousands upon thousands of applicants for a couple of positions, in good times. What the OFCCP plans to do, both on its own and in conjunction with the EEOC, is to look more closely at the contractors who use these routine application screening tools. Are they screening for race, or sex, or LGBTQ status or disability? Are they screening for it and then screening them out? Basically, these are tools that can be misused, even unintentionally. They screen for certain words, or certain indicators, and those people are often simply eliminated from the applicant pool without more. So, to the extent contractors use these tools beyond their intended purpose, and they’re not monitoring any potential disparate impact, contractors will be at risk of becoming targets of the OFCCP’s audit and enforcement approaches. If I were using one of these software programs, or even several of them to work my way through applicants for employment, I would take a really good look at them. I know your vendors will typically provide validation studies, but you want to take a look at how you’re using them and what you’re screening for. It’s just a quick reminder to employers that use these tools that they should pay more attention to them because the OFCCP and the EEOC are going to be looking closely at that in the coming year or two.

 

There’s some other things that are going on, that I think are important to mention as well at the OFCCP. I think that we’re going to see more use again, or a reversion to the OFCCP’s use, of statistical methods to assess whether pay equity has been compromised in a contractor’s workforce. We’re going to see that basically detailed pay equity assessments. One of the other things that is really concerning, at least it should be concerning, to subcontractors and suppliers is that the Department of Labor’s full regulatory agenda proposed a new rule that would add provisions to the regulations that implement Executive Order 11246 and require contractors to provide notice to the OFCCP when they actually award supply and service contracts or subcontracts. This doesn’t exist as the rule right now but the OFCCP is looking at implementing this. I don’t know if it will happen or when it will happen, but this combined with the SAM portal certification requirements suggests that the OFCCP is going to use the contractors themselves to drill down and identify potential new meat to go after in terms of audit and investigation because a lot of the subcontractor and supplier subcontractors, they don’t meet their affirmative action obligations even though they have them and there’s almost no way that that the OFCCP will be aware of them without having audited the primary contractor or without any of those subcontractors identifying themselves on their EEO-1 forms as federal contractors.

 

Catherine Short:   14:53

If you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality, complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Catherine Walters partner at Bybel Rutledge on the topic of employment and labor law digest. Please show your support by taking a moment to provide a review of First Healthcare Compliance on Google or Facebook, you can also follow us and subscribe on all forms of social media.

 

Catherine Short:

I don’t think that I had ever heard the words affirmative action used outside of perhaps a college or university setting. Is this synonymous with how we hear diversity and inclusion and the workplace?

 

Catherine Walters:  15:46

I wouldn’t say it’s synonymous, but they definitely dovetail with each other. Remember that affirmative action is really focused on federal contractors, although a lot of employers have what we call voluntary plans, and then there are some constitutional plans out there for public sector employers. You mentioned the college affirmative action programs. There’s one out there right now before the Supreme Court, has to do with Harvard, that focuses on race conscious recruiting or admissions in order to diversify the campus, right? To diversify the people on the campus. There’s a little bit of a difference between the way the colleges and universities do it. Their focus is, it had originally been, on providing opportunities to underrepresented communities, and giving them a leg up, then it has morphed more into how to diversify your campus life. When we look at that in comparison with employers, on the one side of things, you’ve got recruitment and hiring, which really relates to federal contractors, whereas you’ve got diversity and inclusion, more of the bent of the campus ones. In between that are the employers that may not have affirmative action plans, but they are focused on diversity and inclusion in their workforces. The difference between affirmative action employers, and diversity and inclusion, where the employer doesn’t necessarily have an affirmative action plan, is that diversity inclusion is about minorities and females and individuals with disabilities and veterans and everybody else who’s a protected class, getting them in the door, but it’s more about retention. How do we retain people? How do we integrate them into our workforce? How do we benefit within our workforce from the diversity that each of these individuals brings to us? The more differences you bring into your workplace, the more everybody learns, and the more evolved your workforce gets.

 

Catherine Short:     18:13

Okay, no, that helps a lot. Thank you for the explanation. I appreciate that. Is remote work here to stay?

 

Catherine Walters:  18:21

In a word? Yes. At least for employers who can accommodate remote work. As I indicated earlier, I think that there are a lot of employers that can’t accommodate remote work. Of course, there’s the hybrid type where some workers must be in person and others can be remote. I do think to the extent an employer is able to have remote work, I think it’s here to stay. Some of the big issues really are about adapting your employment processes to this new normal. We look at every employment process that an employer uses and try to assess, how does that apply where the person isn’t really here? So we focus on recruiting and virtual recruiting and interviews and how do we really assess a person if we can’t see them in person? It’s not so bad on Zoom or Teams meetings at this point. I think we’re all accustomed to doing that now. But still, there’s nothing like that in person meeting. So again, how do we make accommodations and adapt for virtual or remote recruiting? And then onboarding that person once you’ve decided to hire them, how do we go about onboarding them? We can send them all the employee handbooks and things to sign that we want, but how do you introduce them to your team? How do you make them an integral part of a team and collaborating colleague? There’s all kinds of fun stuff to consider here. And then of course performance, we really are reverting over to performance as the measure of how we judge their performance. Productivity is the key. How do we judge performance? That gets you into rewriting your job descriptions and reassessing expectations for remote employees and how much work that they need to produce. Is it volume? Is it substance? What is it that you’re seeking from your employees? It gets back to productivity as opposed to how many hours they’re working, or what time of day they’re working. Are they producing the work that they’re supposed to be producing? Is it working? Now, of course, we have these behavioral issues, when we do have meetings, we’ve got people with their little side chats, or they’re making fun of other people on screen, they’re making nasty comments. Those are just minor issues but then, of course, you’ve got the people who are going to find new ways of harassing their coworkers. When you’re in person, it’s one thing. You can say things, you can be physical. When you’re remote, there’s just a whole raft of new things that we’re seeing. New creative behaviors to harass your colleagues. So we’ve got to identify those and determine how to identify and how to stop those because even though everybody’s remote, it doesn’t stop an employer from having obligations to prevent harassment and discrimination in the workplace. And then, of course, that leads you to the concept of, you know, how do we apply discipline to people? How do you know if somebody hasn’t shown up for work? How do you know if they’ve done something that you would typically discipline them for during an in person work day? That gets you back, of course, to the concept of productivity. So we have to reassess discipline. And of course, there’s everything else, whether it’s discharge or performance reviews, or any of the other things that an employer puts into assessing its employees and building those relationships, career advancement, discipline, all the things that go into having an employer employee relationship, have to be rethought, reassessed in light of the concept of remote work. I think it’s a big ask for a lot of employers, and it’s something that everyone has to do, and I’m hopeful that everyone can do it successfully now that we’re well into remote work.

 

Catherine Short:   22:36

Okay, the next area I want to ask about was enhanced Department of Labor enforcement.

 

Catherine Walters:  22:43

If we start with government contractors, I would say that both federal and state agencies are going to be moving forward with enhanced enforcement. So, we’ll continue to see the OFCCP transitioning back into an enforcement posture with the EEOC. We’re going to continue to see a rise in retaliation charges and other types of sex discrimination charges. And then of course, with online or remote work, we’re going to see a rise in online harassment charges. I think the EEOC, because it’s going to be working in conjunction with the OFCCP and the National Labor Relations Board to do sharing of information, we’re going to see all of those agencies banding together to identify potential employers that they identify as committing more violations than others. We’re going to see broader, more holistic or whole employment audits and investigations. It won’t just be looking at whether somebody’s engaged in disparate treatment. I think that analysis of the investigation or the analysis of discrimination will go broader to see whether there’s a systemic mistreatment or disparate impact or whether classes of people as opposed to just individuals are being treated differently from each other.

 

Catherine Short:   24:18

All right, great. Can you speak briefly about restrictive covenants?

 

Catherine Walters:  24:22

Certainly. Restrictive Covenants include things like non-competition agreements, non-solicitation agreements, non-interference and non-contact and so forth. Typically, employers use them to prevent valued employees from leaving them and going and competing with them at another workplace. In recent years, we’ve seen a lessening of the use of the noncompetition restriction, meaning that that person can go work somewhere else, but still, a use of non-solicitation, meaning that even though you can go to a competitor, you may not solicit clients or other customers that you had when you worked for me, and you can’t reach out to our employees and ask them to come with you. Basically, you can’t interfere with my relationships that I had, either before you were here, or while you were here, and you can’t do it for a year or two. Of course, that dovetails with confidentiality agreements, and the protection of confidential information and trade secrets for employers. With respect to restrictive covenants, some states in the United States have legislation against restrictive covenants in the employment field. It’s clear that restrictive covenants prevent employees from moving around, and this inability to move around or go to a competing employer prevents them from increasing wages and benefits as quickly as they might otherwise be able to do and it prevents them from growing in their careers in many cases. Restrictive covenants, while they’re legislated in many states, they aren’t legislated in others. So, there’s no consistent legislation about restrictive covenants in the United States. Some states, you can use them to your heart’s content, other states you can use them in very limited fashion, and in other states, they’re prohibited.

 

 

Catherine Short:   26:32

Well, thank you very much Catherine. Did you have any other words of advice you’d like to leave with us today?

 

Catherine Walters:  26:39

I think I’ve said just about everything there is to say, except buckle up. My concept is adapt or die. Everybody’s learned during COVID. If you can’t adapt, then you’re not going to make it and I think that employers just have to remain vigilant, they have to remain flexible, and they have to remain in the know as to what’s changing and happening around them so that they can swing with it and stay ahead of the curve. I say change is the key word, and for the next couple of years, just change, and buckle up for change.

 

Catherine Short:   27:18

Very good. Well, I wanted to thank you for being here today, it was our pleasure. So, thank you.

 

Catherine Walters:  27:24

Always a pleasure to work with you, Catherine, and all the other folks at First Healthcare Compliance, I can’t think of a nicer group of people to work with. Thank you for having me.

 

Catherine Short:   27:34

Very happy to have you here. I wanted to let our listeners know that Catherine is going to be one of our presenters at our Healthcare Compliance Symposium which is coming up on April 28. Make sure you get your tickets for that. Find those through our website and you can hear Catherine speaking at that event.

 

Thanks to our audience for tuning in to 1st Talk Compliance. You can learn more about the show on the program’s page on Healthcarenowradio.com and to lend your voice to the conversation on Twitter at @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@1sthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind

 

 

 

 

 

DMEPOS – CMS Compliance and Requirements Updates: Audio Version of the Webinar07 Apr 202201:06:57

Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX presents this very timely subject for us. Durable medical equipment, prosthetics, orthotics and supplies (DMEPOS) includes an “entity or individual, including a physician or a Part A provider, which sells or rents Part B covered items to Medicare beneficiaries.” There are special payment rules associated with DMEPOS. DMEPOS products have to meet quality standards, DMEPOS suppliers need to be accepted by Medicare to participate (similar to providers), and are subject to fraud, waste, and abuse laws. The purpose of this webinar to provide an overview of participation and quality requirements, relay the latest compliance and requirements updates, and address False Claims Act cases involving DMEPOS companies.

This webinar will cover the following objectives:

1. Appreciate the requirements for DMEPOS entities and products
2. Learn about the latest compliance updates
3. Understand that a consequence of non-compliance, as well as submitting false and fraudulent claims, is a potential False Claims Act case and/or government enforcement action

Reporting Requirements with OCR for Breaches: Audio Version of the Webinar24 Mar 202201:05:38

First Healthcare Compliance hosts C. Trey Scott, Coordinating Attorney at Kennedy, Attorneys & Counselors at Law, for an interactive discussion on “Under Pressure: Reporting Requirements with OCR for Breaches.” Attendees will learn the reporting requirements for a data breach of a healthcare provider.

This webinar will cover the following objectives:

1. Attendees will learn the different timelines for reporting breaches

2. Attendees will learn the definition of a breach

3. Attendees will learn how to complete a breach reporting form from the Office of Civil Rights

Healthcare and Technology Negotiations17 Mar 202200:27:45


Catherine Short converses with Rachel V. Rose, JD, MBA, principal with Rachel V. Rose – Attorney at Law, P.L.L.C., Houston, TX and Bruce J. Lynskey, Co-Founder at ePrevenir, on the topic of “Negotiations in Healthcare and Technology.” Negotiating occurs in every facet of business and law. From contractual negotiations through settlement negotiations, it is a delicate dance. There are a variety of classic negotiation techniques, which include extreme posturing and “anchoring”. Healthcare and cybersecurity present unique challenges because of the looming exposure to a government investigation and either a civil and/or criminal action, even if a settlement is reached between two private parties. Here we will discuss approaches when negotiating contracts, settlements, and other items, which arise in healthcare and the cybersecurity industries.

Catherine Short:

Welcome and let’s first talk compliance. I’m Catherine Short, partnership Marketing Manager at First Healthcare Compliance. Thanks for tuning in.

 

This show is brought to you by First Healthcare Compliance as part of our commitment to provide high-quality, complementary educational resources. We help create confidence among Compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can follow us on Instagram, Twitter, and subscribe to our YouTube channel.

 

On today’s episode, we are speaking with Rachel V. Rose, JD, MBA, Principal with Rachel V. Rose – Attorney at Law PLLC, Houston, Texas, and Bruce Lynskey, Co-founder at ePrevenir Inc., an intelligent cloud-based point and click decision support tool used by providers with diabetic patients on negotiations in healthcare and technology. Negotiating occurs in every facet of business and law. From contractual negotiations through settlement negotiations, it is a delicate dance. There are a variety of classic negotiation techniques, which include extreme posturing and anchoring. Healthcare and cybersecurity present unique challenges because of the looming exposure to a government investigation, and either a civil and or criminal action, even if a settlement is reached between two private parties. Here we will discuss approaches when negotiating contracts, settlements, and other items which arise in healthcare and the cybersecurity industry.

 

Before I begin, I would like to mention at First Healthcare Compliance, we strive to serve as a trusted resource for compliance professionals, and every month we celebrate their hard work and dedication with our compliance Super Ninja recognition. For this episode, we are spotlighting Super Ninja Julie Garcia, Business Office Manager at Coastal Vascular Center. Julie says “Coastal Vascular Center has three office locations and yet the whole group works as a team. They all respond well to the compliance updates and changes. I am fortunate to have such a close-knit caring group of professionals to work with every day.” Congratulations, Julie! Our team is honored to have the privilege of working with you.

 

Hello, Rachel and Bruce, thank you so much for joining me today on First Talk Compliance.

 

Rachel V. Rose:  2:33

Thank you, Catherine. We’re delighted to be here.

 

Catherine Short:  2:37

Thank you. I’m so glad you both are here. So what are some important general takeaways that you have learned from various types of negotiations?

 

Rachel V. Rose:  2:48

Bruce, do you want to begin from how you approach negotiations and then the key takeaways from the ending?

 

Bruce Lynskey:  2:58

Sure, thank you, Rachel. Some general takeaways. First, the types of negotiation. You will do ongoing negotiations that will take place over an extended period of time, let’s say extended period of time meaning greater than two weeks. It could be a multifaceted contract that you’re working on and you will negotiate bit by bit with the other parties. Others are short and sweet and negotiations. Those take place quickly, sometimes without much advance warning. Some general takeaways that I learned over a number of years from doing negotiations is first and foremost, be prepared. You usually have some advanced warning that negotiation is going to take place. If it’s an extended negotiation, for example, the contract that I cited, you have plenty of time to prepare, you understand who is going to be sitting at the other side of the table, and you have time to learn about that person if you don’t already know them. The most important rule is be prepared. Do your homework when you show up for the negotiation. Otherwise, you’re at a significant disadvantage from which you won’t recover. Rachel, do you have any?

 

Rachel V. Rose:  4:27

I would just add, Bruce, to get yourself as a negotiator into a mindset, and building on what you articulated in terms of anticipating who your opposing parties are. It’s critical to have someone in the bullpen so to speak or identify that person upfront so that you’re not necessarily walking into a situation where you have a room full of people just against you as an individual.

 

Bruce Lynskey: 4:59

Right. If I can add another takeaway, ultimately, you’re going to be negotiating with every type of person you could ever imagine having met. The golden rule is no matter with whom you’re negotiating, stick to your business demeanor. Some people you negotiate with will try to be very informal, others will probably be emotional, and they could even get personal in the negotiations, no matter what, the rule of thumb is stick to the business. By doing so, you are letting the other person do the acting or acting up in the negotiation and you’re there for the real reason. Stick to the business. Here’s the next thing we need to discuss, let’s begin, and so forth. If the other person is full of energy and histrionics and emotional, you’ll eventually tire them out by sticking to the business. Just let them know what a boring person you are, and that the reason you’re here is to get the business done, period.

 

Catherine Short: 6:11

If you could explain, for our listeners who are perhaps new to negotiations, what are the different types of negotiations?

 

Bruce Lynskey: 6:22

You’re always negotiating. Even outside of business, you’re negotiating, whether you realize it or not, it’s part of coexisting with other people. In the business environment, it’s typically agreements. Agreements are captured in contracts. Within agreements, you could be negotiating who’s responsible for what, you’re doing a business agreement, there’s obviously a business partner, you could be pricing services that you are selling to the business partner, you could be bartering with the business partner too. That’s what usually is. As part of the negotiation, there will be something about liability and it’s typically releasing yourself as much as possible from any liability having to do with what you’re negotiating.

 

Rachel V. Rose:  7:17

Bruce, you brought up a great point, and also an interesting scenario in the healthcare forum and cybersecurity, check forum as well. But with your experience with Veran Medical Technologies and now ePrevenir. In my experience in healthcare, one contract that comes up quite a bit is the Business Associate Agreement between a covered entity and a business associate, or a business associate and its subcontractor, which is required under HIPAA. The fundamental premise of that particular contract is that both parties are setting forth that they have the requisite technical, administrative, and physical safeguards in place in order to protect the confidentiality, availability, and integrity of that data. One item that you just mentioned in terms of liability often comes in the form of an indemnification provision. In approaching indemnification provisions, I always advise my clients in relation to the following. First, have you done business with this entity before? That is a crucial question because if you have a course of dealing with someone, that’s very different than entering into an agreement with an organization or a person that you have no frame of reference of doing business with before. Secondly, you don’t want to assume liability unnecessarily, and you don’t want to make it one-sided. Whenever I do indemnification, I always make sure that it’s mutual, meaning that both parties are absolving, if you will, the other party of the same types of liability. Also, what I’ve been doing more and more lately is carving out a limitation in terms of cybersecurity breaches of any type, meaning that if it is the breaching party, then they are responsible for paying for the notices to the patients, for the notices to the media. There’s only one other thing that I’ve negotiated in there, and it depends on who I’m negotiating with. Basically, just the fundamental requirements of any statute in terms of notification. What that does is that the next sentence says that the parties will pay for their own legal fees, any forensics that they have done, etc. Right off the bat, both parties know what they’re in for in the event of a breach. I think that type of negotiation is critical.

 

Catherine Short  10:10

Something that comes up and every single day I’m all over the world, whether it’s a healthcare, entity, or otherwise, are cyber-attacks. What is usually negotiated when a cyber-attack occurs, and with whom?

 

Bruce Lynskey:  10:24

Let me preface this by saying, from my high technology background, there’s no such thing as being 100% safe from a cyber-attack. Any responsible organization dealing with this matter has to assume there’s going to be a cyber-attack and then go from there as far as figuring out how we’ll deal with it.

 

Rachel V. Rose:  10:47

No, you’re exactly right, Bruce. Building on that as well as Catherine’s question, in today’s landscape, there are a lot of different laws to deal with. First and foremost, in the event of a cyber-attack, which ends up being a reportable breach, there are potentially a multitude of government entities that need to be notified and then down the line, a lot of those entities you will be negotiating with individually. On a worldwide scale that is very significant. In terms of who else you’ll be negotiating with, it will be a government entity, typically, it will be counsel for the entity that has been harmed, it could be individuals, for example, if we take one of the retail cyber-attacks such as Target or Neiman Marcus or Home Depot, oftentimes those cases go to court so then you have to set up a claims administrator, there’s either a class action or a multi-district litigation scenario, which ensues, so there could be negotiations down that line as well. The one area that you want to avoid negotiations in is direct negotiations with the entity that perpetrated the cyber-attack and the biggest reason for that actually, is because you don’t always know who is behind the wall, so to speak, or who you are dealing with. In the fall of 2020, the Office of foreign asset control, which is under the US Department of the Treasury, issued two bulletins that encouraged people to contact law enforcement first, because some of the state actors that are involved in the cyber-attacks are actually precluded from doing business with the United States or United States citizens. That could in turn open yourself or your company up to criminal liability for different financial transactions that occur over typically a wire scenario.

 

Catherine Short:  13:01

If you’re just tuning in, you’re listening to first talk compliance brought to you by First Healthcare Compliance as part of our commitment to provide high-quality, complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Rachel V. Rose, JD MBA principal with Rachel V. Rose Attorney at Law PLLC, Houston, Texas, and Bruce J. Lynskey co-founder ePrevenir, on the topic of negotiations in healthcare and technology. Please show your support by taking a few minutes to provide a review of healthcare compliance on Google. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

As far as negotiations go, what are your most utilized techniques in healthcare or cybersecurity or any type of negotiations for that matter?

 

Bruce Lynskey:  13:59

Okay, something I’ve mentioned that I like is, always do your homework. We’ve said that. Do your homework thoroughly. Understand with whom you’re dealing with. What are the key points in the negotiation? Which of the two parties is going to gain the most value from this negotiation? Typically, in a negotiation, someone approached the other party. Negotiations don’t occur spontaneously. Someone has something to gain from a successful negotiation. Understand that terrain. A technique that I use when possible is, of course, I try to always remain businesslike, but I do act a little bit and I try to come across as a bit naive or green to the situation, or not really in control of understanding all the different components, and you watch intently the other party to see if they’ve picked up on that and start to take advantage of it. You let them take advantage of the situation because they don’t believe that you understand all the details of what you’re negotiating. That usually ends up putting you in a superior position, assuming that you understand everything.

 

Rachel V. Rose:  15:35

To build on what Bruce said, the two techniques that I like to utilize are: I like to prepare mentally, as well as doing the homework. So the emotional component. I’m a huge advocate of meditation both before and during, and I advise my clients the same, but perhaps more importantly, because it gives you different opportunities during negotiation is to always have a partner. A. there’s safety in numbers, B. you can deploy the good cop, bad cop type situation, or C. one person might be the primary driver, if they’ve established a good rapport, and the other person is taking notes and observing everyone else in the room. Those are the defaults that I always go to. Bruce?

 

Bruce Lynskey: 16:29

Those are very good. The idea that Rachel mentioned of having a partner is terrific provided that you can do it, you usually can. In a negotiation, it’s just known from the outset that that’s how it’s going to take place from your side. An advantage to having a partner in the picture is, if you need to use the technique called good cop, bad cop. There is someone who’s going to take the blame for the bad aspects of this negotiation or the undesirable features in the agreement you’re trying to conclude. It’s very convenient to have one of the two of you take the role of the bad cop who absorbs all the bad karma that is happening in the negotiation, and the other one appears to be the good cop, the hero, and the one who will be able to get it done to the agreement of both sides and so forth. That’s a shrewd technique. Chances are, if you’re going to negotiate something that is quite involved or complicated, it’s probably good practice at the outset, to bring two of you into the picture right from the beginning so that you have the opportunity if you need, to play the good cop, bad cop role.

 

Catherine Short:  17:57

So besides good cop, bad cop, what about other mental components of negotiations, whether it’s reverse psychology, feigning boredom, appealing to emotions, false demands, genuineness or bullying techniques? What’s your perspective and what is your reaction to negotiating opposite the two major types of people in negotiations, unreasonable people versus people who are genuine and reasonable? What do you think?

 

Rachel V. Rose  18:30

Bruce, this one is all you. I think the genuine reasonable people from my perspective, I’ve literally been on a phone with someone and said, walk with me, right? And we were able to flush things out over the phone within 20 minutes. Tell me where your hang-ups are, I’ll let you know. And let me know a number that you’re comfortable with. I think one of the key issues in any negotiation is that very, very, very rarely does a person get everything that they are asking for, and I think you need to prepare yourself and your client that you’re not going to get everything that you are asking for in this negotiation. So that trends itself now to what Bruce is going to delve into how to deal with unreasonable people, which I think answers a lot of the feigning, the bullying and the tactics that are less than desirable to have to deal with Bruce.

 

Bruce Lynskey:  19:31

Okay. Thank you, Rachel. Rachel just mentioned, the high importance of doing your homework before you open the negotiations. A key part of that homework is understanding your base minimum that you’re willing to take because as Rachel pointed out in a negotiation, it is rare for either of the two parties to get absolutely everything that’s they want. Therefore, it’s up to you to know in advance what your minimum is that you will accept, what the best possible scenario is, the maximum you would love to have. I always make it a mental point to understand possibly two other steps in between. So we end up with four possibilities, the minimum, the maximum and two intermediate possibilities that are ordered in priority or about you. I know that walking in, if you read the other party you knew already, or they turn out to be a completely unreasonable person, and there are plenty of those out there, they’ll be ready for them. An unreasonable person is someone who appears to completely believe they have to have everything or nothing, and they are not willing to negotiate. They are excitable, they get histrionic, they get very emotional, and they can certainly get personal. So you wonder how in the world can I get anything done with this person?

One tactic to apply with this kind of person is try sticking to the business, let them perform, but just stay on course with the business. Indicate by your your total business like manner, and almost boredom with what’s going on, that you’re strictly in there for the business, you don’t care what they think of you, you don’t care how emotional they’re getting, it’s having no effect on you. That’s a tack to try. The worst case scenario, and it can happen, it hasn’t happened much but it will, every now and then, and that is the walk away. You understand two things going in there, you understand what the minimum is that you will accept because you did your homework, you also will read a situation, you need to be way more patient than the other side is. The other side’s being completely unreasonable. You’re exercising total patience, and you’re sticking to the business. But if no progress is being made whatsoever, you need to walk away. When you walk away, that’s it, that’s the end of this negotiation. You let the other party approach you in the aftermath. You never approach the other party to resume this. So when you make the decision to walk away, that’s a serious decision. It could be fatal in the sense that this is the end of any negotiation and that’s not going to resume. Understand that the walkaway is not something you casually use to get control of the negotiation. But I’ve had to do that a few times and of the times I had to do it, half of those times the other party eventually returned.

 

Catherine Short: 23:06

How about the role of silence? How does silence play in effective negotiations? Is it effective? Or does it stop negotiations?

 

Bruce Lynskey: 23:19

Silence is a great technique provided you know how to use it. Trying silence without understanding how to use it is like putting a gun into the hands of someone with no training. The appropriate time to use silence and when there was something that we refer to as the pregnant pause, both of you have paused, and now you’re waiting for someone to resume. In a negotiation situation, this will happen. If you’re dealing with a good negotiator, this will happen a lot because they currently have the upper hand and they are silent. They are pausing. What you need to do is remain silent and that’s really hard to do. But you need to remain silent. What the two of you are doing is essentially facing off with each other with your silence. The first one who speaks is going to be the one who likely ends up at the lower end of the deal.

 

Rachel V. Rose: 24:26

Right. There’s an article that MIT Sloan, that’s MIT Business School, published on silence, and to Bruce’s point, it can be exceptionally effective for a lot of different reasons. One reason is that it gives you time to think and that pregnant pause also makes people feel uncomfortable on the other side. If you want to try and see if someone will fill the air, just shut your mouth. It’s amazing what can come out. But to this point on the other side, it could be like two cats in a room, just staring each other down, and the first person who speaks is the least likely to prevail.

 

Catherine Short: 25:16

But this is an incredibly interesting and fascinating conversation. I believe that we’re just about out of time, though. So do either one of you have any other great advice for us or things that you’ve thought about? During our conversation that you wanted to share with our listeners?

 

Bruce Lynskey: 25:35

Yes, I’ll share something. Everyone is going to be involved in negotiations. That is part of business. It’s also part of life. You should look at negotiation as an art as well as a science. It’s a highly desirable skill, but you should grasp onto and plunge into it, relish it because it’s a very valuable skill. Just realize it’s an art and a science. The art is the subtleties that are so effective in negotiation. The science is the different tactics you can use, when you should use them, and so on. But it’s a mixture of the two.

 

Rachel V. Rose: 26:15

I concur with what Bruce said. One negotiates in life all of the time. The more you can hone those skills in an informal versus a formal setting, I think it will be very beneficial. I would just reiterate that it’s very important to prepare yourself emotionally and mentally, use techniques such as breathing, and also be able to grab a partner so that you have more options available to you during the negotiations.

 

Catherine Short:  26:54

Perfect. I wanted to thank you both for being here today on first talk compliance, so thank you so much.

 

Bruce Lynskey:  27:01

My pleasure.

 

Rachel V. Rose:  27:02

Thank you, Katherine, for having us.

 

Catherine Short:  27:05

Thank you to our audience for being here as well and for tuning in to First Talk Compliance. You can learn more about the show on our program’s page on Healthcarenowradio.com and lend your voice to the conversation on Twitter at @1sthcc or #1sttalkcompliance. You can also email me at catherineshort@firsthcc.com. I’m Catherine Short of First Healthcare Compliance. Remember, Compliance is the key to achieving peace of mind

 

 

 

 

2022 Forecast of Employment and Labor With Other HOT Topics: Audio Version of the Webinar16 Feb 202201:36:04

First Healthcare Compliance hosts Catherine Walters, Esq., Partner at BYBEL RUTLEDGE LLP a management-side labor and employment attorney representing employers of all sizes, for an interactive discussion on “Employment and Labor Law Round-up With 2022 Forecast and Other HOT Topics.” During 2021 as the COVID pandemic raged on and the new Administration faced unprecedented challenges, extensive changes occurred in the employment and labor law landscape, and even more extensive changes are anticipated for 2022.  This program will provide a quick update of 2021’s most important developments and forecast what employers can expect in 2022.  Attend this program to catch up on the Biden Administration’s progress on its labor agenda, relevant Supreme Court decisions and how they affect employers, DOL agency activities, issues to worry about in 2022 and other hot topics, including OSHA, vaccination rules/policies, wage and hour issues, remote workplace tips, cannabis, restrictive covenants, to name a few.  

This webinar will cover the following objectives:

1. Update employers and human resources professionals on recent employment and labor law developments

2. Discuss specific hot topics of interest to employers and human resources professionals

3. Provide ideas regarding anticipated changes in the labor and employment law arena in 2022

Fraud, Healthcare, COVID-19 and the False Claims Act14 Feb 202201:02:25


Catherine Short speaks with Shauna Itri, Partner at Seeger Weiss LLP on the topic of “Fraud, Healthcare, COVID-19 and the False Claims Act.” A whistleblower or qui tam action can provide financial rewards to individuals who have information that a company/individual has committed fraud. The primary statutes under which this relief may be sought are the federal and state False Claims Acts (“FCAs”). In addition to the FCAs, there are other statutes which apply to tax fraud, securities fraud, and in California, fraud on private insurance companies. This episode will provide an overview of the False Claims Acts, the knowledge and skills to be able to recognize a potential whistleblower case, and understand the unique procedures utilized in filing whistleblower cases/tips. We will also delve into recent trends in cases brought (or that could be brought) under the False Claims Act including cases involving mined data and potential fraud related to COVID-19.  

 Catherine Short:

Welcome and let’s 1st Talk Compliance. I’m Catherine Short Partnership Marketing Manager at First Healthcare Compliance. Thanks for tuning in. This show is brought to you by First Healthcare Compliance as part of our commitment to provide high quality, complimentary educational resources. We help create confidence among compliance professionals throughout the United States. Please show your support by taking a moment to provide a review on Google, Facebook or iTunes. You can follow us on Instagram, Twitter, or subscribe to our YouTube channel.

 

On today’s episode, we are speaking with Shauna Itri, Partner at Seeger Weiss LLP, on the topic of fraud, health care COVID-19 and the False Claims Act. A whistleblower or key term action can provide financial rewards to individuals who have information that a company or individual has committed fraud. The primary statutes under which this relief may be sought are the federal and state False Claims Act or FCS. In addition to the FCS there are other statutes which apply to tax fraud, securities fraud, and in California, fraud on private insurance companies. This episode will provide an overview of the False Claims Act the knowledge and skills to be able to recognize a potential whistleblower case and understand the unique procedures utilized in filing whistleblower cases and tips. We will also delve into recent trends in cases brought or that could be brought under the False Claims Act including cases involving mind data and potential fraud related to COVID 19.

 

Before we begin, I would like to mention at first healthcare compliance we strive to serve as a trusted resource for compliance professionals and every month we celebrate their hard work and dedication with our compliance super ninja recognition. For this episode, we’re spotlighting Super Ninja Jessica Berg, Business Manager at Wayne Radiologists, who says that she enjoys most about working with Wayne Radiologists “is that I get to be involved in all aspects of the daily operations from financials and human resources to the daily IT and clinical operations. This has given me the opportunity to learn various skill sets and develop close relationships with all the employees and physicians within the organization”. Congratulations, Jessica, our team is honored to have the privilege of working with you. So hello, Shauna, thank you so much for joining me today on 1st Talk Compliance.

Shauna Itri:  2:38

Hi, Catherine. Thank you for having me and thank you to first healthcare compliance as well.

Catherine Short:  2:44

Thank you. So why are there not so many successful False Claims Act cases where the government has not intervened?

Shauna Itri:  2:54

Well, just to give some background, I think 15%, generally speaking, of cases that are brought by whistleblowers are intervened in by the government and most of those cases are settled. Out of 100 cases, I think 15 of those will be successful, it will intervene, and they’ll be successful about 85 — I think there’s a two part answer to this question. And the first part is, why are those 15 cases most likely to be successful and settle? and the second part is, of those other 85 cases why are those cases most likely not to be successful? The first reason for the first question is, because 15 cases — I think we have to remember the power of the government. The government has a lot of resources behind it, and mainly they have exclusion power. When I mean exclusion powers, they have the power to tell a company, if you continue to do this, if you don’t settle this case, we’re going to exclude you from seeking and obtaining reimbursement from Medicare and Medicaid. For a lot of healthcare companies, that’s a big deal, because a lot of money that they — a lot of patients that they treat are Medicare and Medicaid beneficiaries and that basically means hey, you can’t treat these beneficiaries and a large part of that company’s income is then gone. So, there’s a lot of incentives for companies to settle cases when the exclusion power is on display. And not only that, out of those 100 cases, the government has resources, but they also don’t have unlimited resources, so they pick very carefully which cases they want to bring. Those cases are cases that have a clear theory of liability, those cases have a lot of documentary support, a lot of witnesses to support. So those cases tend to be very, very good cases.

Now for the second part about what happens with those 85 cases. They’re very complex, and they cost a lot of money to litigate. When the government declines, they usually give a reason why they’re declining. Sometimes it could be, hey, we don’t have the resources to pursue this. Sometimes it could be, hey, we interviewed witnesses, they didn’t support the allegations of the complaint, or we talked to our agency, and they don’t really support this complaint or this case. In those cases, the whistleblower attorney is not going to pursue it. In some cases, maybe the government doesn’t pursue it because the company they’re suing isn’t big enough or they’re not solvent. Depending on the reason why the government is declining, a lot of those cases are not continued. Also, even if a case is good, even if a case there’s liability and there’s great facts, and the government says, hey, this cases here, we just don’t have the resources, it takes a lot of resources for private attorney to bring those cases near, they’re going to have to pay for the entire discovery, the entire litigation. So, without the government’s backing, an attorney might not want to pursue it, and maybe it was or can’t afford to pay the attorney’s fees. There’s a lot of reasons why those 85 cases will not be brought there. Some of those cases, I’d say about 10 of those cases, are brought and they are litigated and a lot of those cases are successful. But for the most part, the cases that the government brings us 15% of the cases and they intervene, those cases are more likely to be successful, because they’re the cream of the crop, and there’s the government exclusion power.

Catherine Short:  6:24

Okay. In 2020, so much government money was pumped into the economy through COVID relief funds. Why are there less recoveries under the False Claims Act then from 2020?

Shauna Itri:   6:38

Yeah, if you look at the stats, DOJ post stats every year online, if you look at the stats, there has been a definite decline in successful False Claims Act cases from 2019 to 2020. I think a part of that is because everything slowed down. I know in March, for a period of three months, the whole economy was shut down. The courts were shut down the courts, attorneys’ offices are shut down. I think we have learned to work remotely and been quite successful doing it, but because of that stall, cases were all put on hold, the government was having problems doing investigations, because at the time, it was really unclear about how the COVID-19 virus spread and in person communications were definitely not encouraged. Everything slowed down, government investigations slowed down, therefore, any sort of litigation slowed down. I think that was a big reason why you’ll see a lower amount of cases from 2019 to 2020 being settled or recoveries being gained.

 

I also think, the reason why we haven’t seen a lot of recovery, despite the fact that COVID-19 money has been pumped into the economy is because it’s in the future. National crisis, unfortunately fraud surrounds national crisis. It takes some time for fraudulent schemes to develop, number one, it takes some time for the government to pump the money into the economy, it takes some time for those fraudulent schemes to be uncovered and once the case is filed, the False Claims Act filed, it’s under seal, so we don’t hear a lot about it. So, despite the fact that so much money was pumped into the economy in 2020, it’s going to be a little bit of a delay, fraud delay, and it’s going to take some time. I don’t think we’ll really see an increase due to COVID 19 funding until 2022 and beyond, just because of the reasons I said. It just takes time.

 

Catherine Short:  8:37

So you think it will be coming kind of a rev up back but it’s just going to take time for us to see?

 

Shauna Itri:   8:43

I do Catherine. Trillions of dollars have been pumped into the economy and if you see it, if you look at statistically, I mean, the False Claims Act was enacted in 1863 during the Civil War, when there was a national crisis. The Union army was getting defrauded by third parties. And then you’ll see every time there’s a natural disaster, the government pumps money to recover from the national disaster and two years later, you’ll see a bunch of fraud related to that money that was pumped into the economy. The 2008 financial crisis, the TARP funds, money was pumped in. You didn’t see a lot of TARP fraud in 2008 but you sure did in 2010. The money is continuing to get pumped into the economy for these COVID-19 relief funds. You’ll see the fraud start to develop, the fraud start to get uncovered and then a few years, you’ll see the whistleblower cases come forward.

Catherine Short:  9:34

I think you’re right. So, there’s another question I have here, can you file a false claims act anonymously?

Shauna Itri:  9:42

I get a lot of requests from clients to file anonymously because when you file a case there are some risks involved and there’s a potential for someone to get blackballed. You don’t want to be known as a whistleblower, especially a whistleblower with an unsuccessful case and there’s no guarantee your case is going to be successful no matter how good it is. So whistleblowers would prefer to remain anonymous and in fact, the SEC whistleblower statute allows whistleblowers to remain anonymous, but it’s not an option really, for the False Claims Act. I have seen people try to get around it by filing John Doe complaints, and I have done it myself. There has been a recent DOJ policy to, even if the case is declined and in fact going forward to, unseal the name of the whistleblower so that the defendant has the right to know who they’re being sued, on public policy grounds. There also have been attorneys that have been successful, forming an LLC and having the LLC being the whistleblower, but there’s ultimately a possibility that the members of the LLC will be disclosed in discovery. So, while I guess technically it’s possible, there’s a desire, there’s some attorneys working to make it happen, I never promise a client that they can remain anonymous, I just never do because anything really could happen, and their identity can get disclosed.

Catherine Short:  11:01

Okay, what are counterclaims a company can file against a whistleblower who brings a False Claims Act case?

Shauna Itri:  11:10

There are several counterclaims and they’re usually combated, and I would say unsuccessful, but the threat of a counterclaim is still there. And some of the counterclaims are, hey, this person stole documents and therefore violated confidentiality, this person stole documents and violated HIPAA, and PHI (Protected Health Information) was subsequently disclosed and violated trade secrets. There’s a lot of campaigns that can and have been brought. Now, these are litigated. What the whistleblower attorney would say is that there’s an exclusion or exemption for fraud. Typically, counterclaims are unsuccessful. I know, one counterclaim that has been successful and that’s a case out of New Jersey where a client brought a whistleblower case. In the ordinary course of her business, she came across these the file, Redweld of documents, and she brought the whole Redweld. She got sued for a counterclaim, for taking documents that she wasn’t entitled to, and the court ended up granting the counterclaim and saying she brought a whole Redweld of documents when all she needed was a manila folder full of documents and those were the ones that supported her claim and by bringing the whole Redweld she didn’t need those documents, and so therefore, she stole documents. But generally speaking, I always advise clients, if they come across documents in the ordinary course of business, they’re not breaking into file cabinets, they’re not accessing databases that they don’t have access to normally, if the file comes across their desk, they take a picture of it, they take a copy of it, and the defendant sues on a counterclaim, that document specifically supports the fraud that the whistleblower’s alleging, a counterclaim against that whistleblower for taking that document will likely not be successful because there’s an exemption to disclose fraud to the government.

Catherine Short:  13:08

Okay, if you’re just tuning in, you’re listening to 1st Talk Compliance brought to you by First Healthcare Compliance as part of our commitment to provide high quality complimentary educational resources. We help create confidence among compliance professionals throughout the United States. My guest today is Shauna Itri, partner at Seeger Weiss LLP, on the topic of fraud, health care, COVID-19 and the False Claims Act. Please show your support by taking a few minutes to provide a review of first healthcare compliance on Google or Facebook. You can also follow us on Instagram, Twitter, and subscribe to our YouTube channel.

So Shauna in the challenges of data mining False Claims Act cases based on the public disclosure bar, what is the whistleblowers response to the data being determined news media?

Shauna Itri  14:06

That’s a complex question and I’m going to break it down a little bit and just give you a little bit of background. Under the False Claims Act, there’s a bar to recovery, if the information has been publicly disclosed. This was put into place because during World Two, I’m going to bring it way back here, there was amendments to the False Claims Act, because what was happening was people are reading newspapers, articles, getting information in newspaper articles, and then using that information and filing a False Claims Act case in order to get a recovery, and Congress wanted to eliminate that. So, they invented the public disclosure Bar In 1986 the public disclosure bar was amended and it says if information, and I’m summarizing here, if information is disclosed in these enumerated sources, one of them being “news media”, then in order to not violate the public disclosure bar, the whistleblower needs to be “original source”. It’s a real issue and it has been used by defendants and False Claims Act cases regularly and cases have been dismissed because news media is, you know back in 1986 we didn’t have things such as the Internet, and so news media could have been defined as a newspaper. But now with the internet, courts have construed news media TV very broadly, to include anything on the internet. So, there could be a random blog, there could be, an OIG report that’s been published that rather discusses fraud, and that could technically be considered a public disclosure.

With that background information in these data mining cases, which are cases brought by companies or individuals that are mining data that they have purchase, or that’s publicly available, to bring cases, there have been challenges to the ability for the later to collect based on this public disclosure bar. I should mention also that the reasoning behind the public disclosure bar is to prevent predatory lawsuits. They don’t want people looking at the newspaper and bringing a case based on information the government has already known. The whistleblower in response and briefing, they have encouraged courts instead of taking a broad view of news media to take a more narrow view of news media and actually, there’s been several groups lobbying for an amendment to the False Claims Act to more plainly describe what specifically news media includes and what it does not include. I think this public disclosure bar has been used by defendants and companies to eliminate relators and in an unfair way and has broadly construed the work term news media to include any sort of disclosure of information and has used that disclosure against the relator. So relators response is, hey, this news media needs to be more narrowly construed. And it needs to be looked on a fact by fact basis.

 

Catherine Short:  17:02

That’s very interesting. What are some of the challenges to bringing a False Claims Act case for fraud related to PPP funds?

 

Shauna Itri  17:12

So, a lot of money has been pumped into the economy for this COVID-19 release, and one of the ways is through PPP funds and that is giving companies money if they’ve kept a certain percentage of their staff. First, let me take a step back to talk about what types of fraud I think will come about for these PPP cases. One of the types of fraud is, in order to receive these PPE funds, the persons or the companies need to sign certifications that they’ve met certain requirements and if they’ve signed these certifications, and they have not met these requirements, but have received the funds, that could be a potential False Claims Act case. These PPP regulations can be unclear and I think they were intended to do so because they just wanted to pump money into the economy and so a big argument is that they did not lie that, hey, we didn’t know what this regulation meant. We thought it meant X, you thought it meant Y it’s a fair interpretation for it to mean X and so we didn’t violate any sort of certification.  I think that’s gonna be one of the main barriers to bring these cases, is how vague these PPP regulations are, and the fact that they are purposely vague because the government at that point of time, really just wanted a bunch of money to be pumped into the economy.

 

Catherine Short:  18:34

Okay. Can you talk about some examples of successful False Claims Act cases related to clinical trials, specifically good commercial manufacture practice violations?

 

Shauna Itri:  18:47

Sure. First some background again, it’s always helpful to understand what are these good commercial manufacturing practices, also called CGMPs. After a drug is approved by the FDA or a device, and they manufacture the drug, there are certain regulations called CGMPs that a manufacturer has to comply with to make sure that the drug is made per the specification, is made in accordance with the FDA approval. And if you violate CGMPs, it could be potentially a False Claims Act case. We know this because years ago, GSK was sued. The background to this case is quite interesting. There’s a woman by the name of Cheryl Eckard, it is actually a 60 Minutes Episode and I would highly recommend googling it and see if you can pull up a copy of that 60 minutes, but she was a compliance officer. There were issues with GSK’s manufacturing plant in Puerto Rico. She complained about it, she flew down there, she checked it out. She wrote a memo, no one was listening. She continued to press it, she sent a memo to the CEO, the executives, I think they sent a response team down there but didn’t include her. Later, it turns out that they didn’t fix the problems. She was eventually fired. A False Claims Act case was brought on her behalf. I think it might have been 10 years later, millions of dollars in litigation fees later, the case ended up settling for the $700 million. And Cheryl Eckard became a millionaire. I think she got a $90 million relator share or whistleblower fee. The specific violations were something like, certain doses of drugs were intermixed. So, say there’s a five dose bottle there, five milligrams in there, and also 10 milligrams. I think one of the other allegations was that there was a vat of antibacterial lotion that was unsanitary. Those are the types of violations of manufacturing practices that I think deserve attention, you know, some minor flaw that was fixed is not going to be a good False Claims Acts case. But this particular case was egregious and was very successful, but it was after years and years of litigation.

 

Catherine Short: 20:56

Okay, can someone be retaliated against for filing a false claims act? And are there any specific protections?

 

Shauna Itri:   21:05

So yes, so Cheryl Eckard, I just I mentioned, she was retaliated against for exposing fraud. A lot of times employee are minimized, harassed or eventually fired. And under the False Claims Act, there is a section H, that’s the statute that allows for an addition to a subsequent complaint on behalf of the government, Section H is an add on claim for the specific whistleblower if they have suffered retaliation for engaging in “whistleblower conduct”. So, the whistleblower case doesn’t even have to be successful, but the person has to have engaged in whistleblowing conduct. And there’s also some damages associated that if the claim is successful, that was for overseas damages. In addition to Section H under the False Claims Act, there are also robust state employment statutes, and some administrative statutes that can be pursued in conjunction with or parallel litigation as to the False Claims Act. So, a lot of times, I end up working with employment lawyers hand in hand for suing these cases on behalf of our client.

 

Catherine Short:  22:11

Okay, so what if there is fraud, but it doesn’t involve Medicare or Medicaid, but rather, private insurance?

 

Shauna Itri:   22:22

In order to be a case, under the False Claims Act, or the state False Claims Act, the Federal and State false claims acts, it needs to be Medicare money, or Medicaid money, or it can be TRICARE or veterans’ money, it just has to come from the government. If there’s no government money, you can’t bring a False Claims Act case. However, there is a specific statute in California that is underutilized and it’s a California Insurance Fraud Prevention Act. It allows an individual whistleblower to bring a case on behalf of private insurance companies. It acts in the same way that the False Claims Act procedurally does and substantively does, it’s modeled after the False Claims Act and it’s underutilized. There’s not a ton of case law out there, there have been a handful of successful cases and when it is litigated, the courts tend to follow the case law on the False Claims Act cases. So it’s very, very similar. That was the long answer. The short answer is, under the False Claims Act, you’re going to have a hard time, you really can’t bring a case. But under this California Insurance Prevention Act, if the California Insurance companies are being defrauded, then you could bring a claim.

 

Catherine Short:  23:31

Okay, this is a question I’ve been wondering about. Why is there are a seal put in place, and what if that is breached?

 

Shauna Itri:  23:39

A seal is put in place, and when you filed the complaint by letter seal, and only served upon the government. The court obviously has a copy of it. The reason is because the government needs time to investigate the claims without the defendant knowing. It’s really to protect the government’s investigation. They can then disclose to the defendant that they’re investigating, but they don’t disclose that there’s been a whistleblower case and it’s really to protect their investigation. If the seal is breached, the case law has come out more recently that’s more favorable, but if the seal is breached, a relator can potentially be barred from recovering when you breach it. It’s kind of a gray area these days, ever since the Supreme Court case came out where, depending on the extent of the breach, like if you tell your spouse is a lot different than if you broadcast it to a major news station. So, it’s a little bit of a gray area, but a seal breach is problematic, and I always tell my clients don’t tell anybody.

 

Catherine Short:  24:39

Okay, very good. Well, I wanted to thank you Shauna. Do you have any other advice for us today as we wrap up?

 

Shauna Itri:  24:47

It’s going to be interesting to see how everything unfolds, given the amount of money that has been funneled into the economy for this COVID Relief Fund. I think it’d be interesting. There’s a lot of information out there publicly. It would be interesting to keep your eye on it and see what happens with these funds and the interesting ways fraud occurs but other than that, I look forward to seeing what happens. I want to thank you and first healthcare compliance again for having me. It’s been a blast, and I hope to talk soon.

 

Catherine Short:  25:18

Thank you. Thank you so much. And we it’s been a real pleasure to have you on here as well. So, thank you so much again Shauna.

 

Shauna Itri:  25:27

Thank you.

 

Catherine Short:  25:29

Okay, and thanks to our audience for tuning into 1st Talk Compliance. We always appreciate you as well. You can learn more about the show on our program’s page on Healthcarenowradio.com and lend your voice to the conversation on Twitter at @1sthcc or #1sttalkcompliance. You can also email me at Catherine Short at First Healthcare Compliance. I’m Catherine Short of First Healthcare Compliance. Remember, compliance is the key to achieving peace of mind.

 

 

 

 

© My Podcast Data · Independent project · Data from Apple & Spotify