<?xml version="1.0" encoding="utf-8"?>
	<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
	<title>An RSS Feed from melniklegal.com</title>
<description>melniklegal.com Blog</description>
<link>http://melniklegal.com/programs/weblog.cgi</link>
<category>e-commerce</category>
<copyright>Copyright melniklegal.com </copyright>
<language>en-us</language>
<lastBuildDate>Mon, 05 Oct 2026 17:18:44 EST</lastBuildDate>
<managingEditor>tatiana@melniklegal.com (Web Master)</managingEditor>
<pubDate>Mon, 05 Oct 2026 17:18:44 EST</pubDate>
<webMaster>tatiana@melniklegal.com (Tatiana)</webMaster>
<generator>e-commerce-inc.com sitebuilder blog press</generator>
<atom:link href="http://melniklegal.com/programs/blogrss.cgi" rel="self" type="application/rss+xml" />

			
<item>
<title><![CDATA[Eligible Professionals May Apply for a Hardship Exception from Meaningful Use Penalties]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><div><table border="0"><tbody><tr><td align="left" valign="top"><font face="Arial">As part of the American Recovery and Reinvestment Act of 2009 (ARRA), Congress mandated that payment adjustments be applied to Medicare eligible professionals (EPs) who are not meaningful users of Certified EHR Technology under the Medicare EHR Incentive Programs.<br><br>Medicare EPs who are not meaningful users will be subject to a payment adjustment beginning on January 1, 2015.<br><br>But, exceptions are available under certain limited circumstances.<br></font></td><td valign="top"><img src="https://melniklegal.com/images/Meaningful_Use_Hardship.jpg"><br></td></tr></tbody></table><font face="Arial"><b><br>Which practitioners are subject to MU payment adjustments and when do the payment adjustments begin?</b></font><br></div><div><ul><li><font face="Arial">EPs who participate in the Medicare EHR Incentive Program.</font></li><li><font face="Arial">EPs who can participate in <i>either</i> the Medicare or Medicaid EHR Incentive Programs.</font></li><li><font face="Arial">These payment adjustments will be <font color="#006600"><b>applied beginning on January 1, 2015</b></font>, for Medicare EPs.</font></li></ul></div><div><font face="Arial"><b>Which practitioners are NOT subject to MU payment adjustments?</b></font><br><ul><li><font face="Arial">Medicaid EPs who can only participate in the Medicaid EHR Incentive Program and do not bill Medicare.</font></li></ul><p><b><font face="Arial">How much are the payment adjustments and how are they applied?</font></b></p><p><font face="Arial">The payment adjustment will be applied to the Medicare physician fee schedule (PFS) amount for covered professional services furnished by the EP during the year (including the fee schedule amount for purposes of determining a payment based on the fee schedule amount). <br></font></p><p><font face="Arial">The payment adjustment is 1% per year and is cumulative for every year that an EP is not a meaningful user. Depending on the total number of Medicare EPs who are meaningful users under the EHR Incentive Programs after 2018, the maximum cumulative payment adjustment can reach as high as 5%.</font><br></p></div><font face="Arial">For additional details on MU payment adjustments, <a href="https://melniklegal.com/av/PaymentAdj_HardshipExcepTipSheetforEP_2013.pdf">please see the Payment Adjustments and Hardships Exceptions Tipsheet for Eligible Professionals released by CMS</a>.<br><br><b>Are there any </b></font><font face="Arial"><b><b><font face="Arial">payment adjustment </font></b>exceptions available for Medicare EPs who cannot meet MU deadlines?</b><br><br><b>Yes</b>. EPs who cannot meet MU deadlines may be eligible to receive a hardship exception from CMS. But, CMS has explained that </font><font face="Arial"><font face="Arial">these exceptions will be granted only under specific circumstances and only if </font></font><font face="Arial"><font face="Arial"><font face="Arial">CMS determines that providers have demonstrated that those circumstances pose a significant barrier to their achieving meaningful use.<br><br>Hardship exceptions are available in the following categories:<br></font></font></font><div><ul><li><font face="Arial"><b>Infrastructure </b>- EPs must demonstrate that they are in an area without sufficient internet access or face insurmountable barriers to obtaining infrastructure (e.g., lack of broadband).</font></li><li><font face="Arial"><b>New EPs</b> - Newly practicing EPs who would not have had time to become meaningful users can apply for <u><i>a 2-year limited exception</i></u> to payment adjustments. Thus EPs who begin practice in calendar year 2015 would receive an exception to the penalties in 2015 and 2016, but would have to begin demonstrating meaningful use in calendar year 2016 to avoid payment adjustments in 2017.</font></li><li><font face="Arial"><b>Unforeseen Circumstances</b> - Examples may include a natural disaster or other unforeseeable barrier.</font></li><li><font face="Arial"><b>Patient Interaction</b> - Lack of face-to-face or telemedicine interaction with patients; Lack of follow-up need with patients.</font></li><li><font face="Arial"><b>Practice at Multiple Locations</b> - Lack of control over availability of CEHRT for more than 50% of patient encounters</font><br></li></ul></div><font face="Arial"><font face="Arial"><font face="Arial">CMS will be providing additional details on the requirements and application process in the future.</font></font><br><br><br><br><br></font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1387148396_Meaningful-Use.html</link>
<guid>http://melniklegal.com/weblog/1387148396_Meaningful-Use.html</guid>
<pubDate>Sun, 15 Dec 2013 17:59:56 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Florida Governor Signs New Data Breach Law Requiring All Businesses to Implement Security Controls]]></title>
<description><![CDATA[
 
 
 
 
     <font face="Arial">After being unanimously passed by the Florida legislature on April 30, 2014, on June 20, 2014, Florida's Governor Rick Scott signed the Florida Information Protection Act of 2014 (Act or FIPA). This Act repeals and wholly replaces Florida's existing data breach law (at Flat. Stat. Section 817.5681) with new Section 501.171. <b>FIPA takes effect on July 1, 2014.</b><br></font><br><table style="text-align: left; margin-left: auto; margin-right: auto;" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i> </b></font><font color="#FFFFFF">This statute is a relatively sweeping change for Florida and raises the bar for other states. It applies to <u><i><b>every</b></i></u> business that handles "personal information" of Florida residents and requires these businesses to take proactive "reasonable measures" to secure data. But, like many other data breach and data security statutes, FIPA fails to define what it means to take "reasonable measures." In general, this means that companies need to follow industry best practices. As a starting point, businesses should conduct a risk analysis to better gauge their risks. FIPA also implements a records disposal requirement.<br><br>Given the increased liability brought about by this statute, Florida-based businesses that share data with other entities should review their contracts to ensure that data breach notification requirements are included together with appropriate cyberliability (<i>i.e.</i>, data breach) insurance requirements, damages caps, and indemnification language. Non-Florida based businesses that handle "personal information" of Florida residents should be aware that they too may be subject to the requirements can be pulled into court under the Florida Long-Arm Statute.<font size="2">[1]</font><br></font></font></font></td></tr></tbody></table><br><font face="Arial"><b>What Steps Should Companies Take?<br></b>Companies should consider taking a few proactive steps to gauge their risks and liabilities in light of the proactive requirement to take security measures, shortened deadline to provide data breach notification, and notification requirements for down-stream entities (e.g., business associates, vendors, contractors, etc.).</font><br><ul><li><font face="Arial">Under take a <font color="#993399"><u><b>risk analysis</b></u></font> to better assess potential risks and vulnerabilities to the confidentiality, integrity and availability of all personal information handled by the company</font></li></ul><ul><ul><li><font face="Arial">For a good starting point for a risk analysis, consider looking to the HIPAA materials and the NIST guidance documents</font></li></ul></ul><ul><li><font face="Arial">Review existing <font color="#993399"><u><b>privacy and security policies and procedures</b></u></font> and update as needed</font></li></ul><ul><ul><li><font face="Arial">Policies should reflect what the organization actually does and not what it would do in an ideal world. Policies that are in place but are not followed may demonstrate willful negligence and be the proverbial "smoking gun" in litigation</font></li></ul></ul><ul><li><font face="Arial">Develop an <font color="#993399"><u><b>incident response plan</b></u></font>, which should include a data breach notification plan</font></li></ul><ul><ul><li><font face="Arial" size="3">This plan should be called an "incident response plan" because <u><i>not</i></u> every incident is a breach. By calling something a "breach" your team may be attributing a legal meaning to an event that is merely a potential security incident. Keep in mind that the term "breach" is defined in the statue.</font><font face="Arial" size="3"> </font><br></li></ul></ul><ul><ul><li><font face="Arial">Any security incident is a stressful event. Having a plan in place, that at the very least contains important phone numbers for contacts who can assist you through the process will ease the stress a bit. Your attorney should be the first call because you never know what you are going to find.</font></li></ul></ul><ul><li><font face="Arial"><u><font color="#993399"><b>Encrypt personal information</b></font></u> to the extent possible and <b><i>definitely</i></b> <font color="#CC0000"><u><b>encrypt all mobile devices</b></u></font></font></li></ul><ul><ul><li><font face="Arial">The loss and theft of laptops is one of the leading causes of data breaches. Laptops should have hard drive encryption (as opposed to a separate drive that each employee should use to store personal information). If your company is using a Windows based product, check to see if BitLocker is available on the version you're using because it comes preinstalled in some Windows products and only needs to be enabled.</font></li></ul></ul><ul><ul><li><font face="Arial">Employee owned mobile devices that have access to "personal information" should be enrolled in a mobile device management system and the company should have <i>written authorization</i> from the employee to wipe the device, copy the device, seize it in the event of litigation, etc. <br></font></li></ul></ul><ul><ul><li><font face="Arial"><b>Encryption is particularly important because it pulls the information out of the definition of "personal information" and therefore also pulls it out of the breach notification requirement</b>.</font></li></ul></ul><ul><li><font face="Arial"><font color="#993399"><u><b>Identify all vendor and business relationship that impact "personal information" and review the existing contracts</b></u></font> to ensure that your business will receive timely notification in the event of an incident as well as cooperation during the investigation<br></font></li></ul><div align="left"><font face="Arial"><b>A Few Highlights from the New Law</b></font><br><ul><li><font face="Arial">Arguably, every organization is covered under the law because the definition of "covered entity" is quite broad: <br></font></li></ul><blockquote><blockquote><font face="Arial">“Covered entity” means a sole proprietorship, partnership, corporation, trust, estate, cooperative, association, or other commercial entity that <i><b>acquires</b></i>, <b><i>maintains</i></b>, <i><b>stores</b></i>, or <i><b>uses</b></i> personal information. For purposes of the notice requirements . . ., the term includes a governmental entity.</font><font face="Arial"><br></font></blockquote><font face="Arial">Those in the healthcare space will be familiar with the term "covered entity" but note that this provision covers every organization that </font><font face="Arial"><i><b>acquires</b></i>, <b><i>maintains</i></b>, <i><b>stores</b></i>, or <i><b>uses</b></i> personal information.</font></blockquote><ul><li><font face="Arial">The definition of personal information is quite broad and includes social security numbers, healthcare information, health insurance policy number, credit card numbers, and "a user name or e-mail address, in combination with a password or security question and answer that would permit access to an online account."</font></li></ul><ul><li><font face="Arial">There is a shorter timeline to notify affected Florida individuals - Under Florida's previous law, organizations were required to notify within 45 days. Now, it is "no later than 30 days after the determination of a breach or reason to believe a breach occurred" unless there is a law enforcement delay or "if, after an appropriate investigation and consultation with relevant federal, state, or local law enforcement agencies, the covered entity reasonably determines that the breach has not and will not likely result in identity theft or any other financial harm to the individuals whose personal information has been accessed.</font></li></ul><ul><li><font face="Arial">As noted above, covered entities must take proactive measures to protect the personal information. "Each covered entity, governmental entity, or third-party agent shall take reasonable measures to protect and secure data in electronic form containing personal information."</font></li></ul></div><ul><li><font face="Arial">There is no private right of action. But, a "violation of this section shall be treated as an unfair or deceptive trade practice in any action brought by the [Department of Legal Affairs (i.e., the Florida Attorney General)] under s. 501.207 against a covered entity or third-party agent." Civil penalties are not to exceed $500,000 and will go into the General Revenue Fund.</font></li></ul><ul><li><font face="Arial">FIPA includes a data records disposal provision. "Each covered entity or third-party agent shall take all reasonable measures to dispose, or arrange for the disposal, of customer records containing personal information within its custody or control when the records are no longer to be retained. Such disposal shall involve shredding, erasing, or otherwise modifying the personal information in the records to make it unreadable or undecipherable through any means." <br></font></li></ul><p><font face="Arial">The text of the new law is available here - <a href="https://laws.flrules.org/2014/189">https://laws.flrules.org/2014/189.</a></font></p><font face="Arial"><font size="2">---------------------<br>[1] Interestingly, the Florida legislature addressed the possibility of this in the "Bill Analysis and Fiscal Impact Statement" as follows:<br></font></font><blockquote><font face="Arial"><font size="2">Although the bill does not specifically provide that the covered entity must be conducting business in this state, the Florida Long-Arm statute may provide courts with the authority to assert personal jurisdiction over a nonresident covered entity. The statute enumerates a number of actions that a person or his or her representative may take that would submit that person to the jurisdiction of Florida courts. Those actions include, among other things, operating, conducting, engaging in, or carrying on a business venture in this state or having an office or agency in this state; committing a tortious act within this state; or breaching a contract in this state by failing to perform acts required by the contract to be performed in this state. A person may also become subject to the jurisdiction of a Florida court if the person is engaged in substantial and not isolated activity within Florida.</font></font><br></blockquote><font face="Arial"><font size="2">Florida Senate, </font></font><font face="Arial"><font size="2"><font face="Arial"><font size="2">Bill Analysis and Fiscal Impact Statement</font></font>: CS/SB 1524, April 1, 2014, <a href="https://www.flsenate.gov/Session/Bill/2014/1524/Analyses/2014s1524.pre.rc.PDF">https://www.flsenate.gov/Session/Bill/2014/1524/Analyses/2014s1524.pre.rc.PDF</a>.<br></font></font><font face="Arial"><font size="2"><br></font></font><font face="Arial"><font size="2"><font face="Arial"><font size="2">---------------------<br></font></font></font></font><br><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">Posted by: Tatiana Melnik on June 27, 2014</font></font><br></font></font></font> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1403923293_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1403923293_Data-Breach.html</guid>
<pubDate>Fri, 27 Jun 2014 22:41:33 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[OIG Proposes Rules to Expand Exclusion and CMP Authorities]]></title>
<description><![CDATA[
 
 
 
 
    <div align="left"><font face="Arial"><font size="2"></font></font><table border="0"><tbody><tr><td align="left" valign="top"><font face="Arial"><font face="Arial">Over the last several years, the Federal Governments enforcement efforts have continued to bear fruit. On February 26, 2014, the Departments of Justice (DOJ) and Health and Human Services (HHS) announced that the "government’s health care fraud prevention and enforcement efforts recovered a record-breaking $4.3 billion in taxpayer dollars in Fiscal Year (FY) 2013, up from $4.2 billion in FY 2012."<font size="2">[1]</font> Further, "[o]ver the last five years, the administration’s enforcement efforts have recovered $19.2 billion, up from $9.4 billion over the prior five-year period.&nbsp; Since the inception of the program in 1997, the HCFAC Program has returned more than $25.9 billion to the Medicare Trust Funds and treasury."<font size="2">[2]</font></font>&nbsp; </font></td><td align="left" valign="top"><font face="Arial"> </font><font face="Arial"><img src="https://melniklegal.com/images/handcuffs.png"></font><br></td></tr></tbody></table><font face="Arial"><br>The Affordable Care Act (ACA) greatly expanded the OIGs authority to exclude individuals and entities from the Federal health care programs and expanded the grounds for which civil monetary penalties (CMPs) could be issued. The OIG published proposed rules on each of May 9 and May 12 to incorporate these changes.<br><br>On May 9, 2014, the HHS's Office of Inspector General (OIG) published a proposed rule that would significantly expand the exclusion regulations applicable to individuals or entities receiving funds, directly or indirectly, from federal health care programs. <font size="2">[3]</font> "OIG’s exclusion authorities are intended to protect the Federal health care programs and their beneficiaries from untrustworthy health care providers, i.e., individuals and entities who pose a risk to program beneficiaries or to the integrity of these programs." <font size="2">[4]</font> The OIG's authorities include both mandatory exclusions (section 1128(a) of the Act) and permissive exclusions (section 1128(b) of the Act).<br><br>In this Proposed Rule, the OIG incorporates the changes from the ACA and the Medicare Prescription Drug, Improvement, and Modernization Act of 2003 (MMA). The ACA expanded the OIG’s authority for exclusion and established a new authority at Section 1128(f)(4) of the Act for the OIG to issue testimonial subpoenas in investigations of exclusion cases. In this Proposed Rule, the OIG incorporates these statutory changes, revises certain definitions applicable to exclusions, proposes early reinstatement procedures for individuals excluded as a result of loosing their licenses, and provides for a number of other proposed policy changes related to exclusions.<br><br><font color="#000099"><b>Comments on the May 9 Proposed Rule are due July 8, 2014</b></font>. <br><br>Separately, on May 12, the OIG published a proposed rule to implement the expanded CMP authorities set forth in the ACA.<font size="2">[5]</font> The ACA provided for CMPs, assessments, and exclusions for:<br></font><ul><li><font face="Arial">failure to grant OIG timely access to records; <br></font></li><li><font face="Arial">ordering or prescribing while excluded; <br></font></li><li><font face="Arial">making false statements, omissions, or misrepresentations in an enrollment application; <br></font></li><li><font face="Arial">failure to report and return an overpayment; and <br></font></li><li><font face="Arial">making or using a false record or statement that is material to a false or fraudulent claim. <br></font></li></ul><font face="Arial">This Proposed Rule addresses a number of issues, including (1) when and how these CMPs are applied, (2) an alternate methodology for calculating the penalties and assessments for employing excluded individuals in positions in which the individuals do not directly bill the Federal health care programs for furnishing items or services, and (3) the liability guidelines under other OIG authorities, including the Civil Monetary Penalties Law (CMPL), the Emergency Medical Treatment and Labor Act (EMTALA), section 1140 of the Act for conduct involving electronic mail, Internet, and telemarketing solicitations, and section1927 of the Act for late or incompletereporting of drug-pricing information. <br><br><font color="#990000"><b><font color="#000099">Comments on the May 12 Proposed Rule are due by July 11, 2014</font></b></font>.<br><br>The ACA also made some enforcement easier because it changed the scienter standard with respect to the Anti-Kickback Statute. Under this change a provider does not need to have actual knowledge of the Anti-Kickback section or specific intent to commit a violation of the Anti-Kickback Section to find intent. This change will make it easier for the government to prosecute health care fraud cases.<br><br><font size="2">---------------------------------------<br>[1] Press Release, Departments of Justice and Health and Human Services Announce Record-Breaking Recoveries Resulting from Joint Efforts to Combat Health Care Fraud, HHS (Feb. 26, 2014), <a href="https://www.hhs.gov/news/press/2014pres/02/20140226a.html">https://www.hhs.gov/news/press/2014pres/02/20140226a.html</a>.<br></font><font size="2">[2] Id.</font> <br><font size="2">[3] HHS OIG, Medicare and State Health Care Programs: Fraud and Abuse; Revisions to the Office of Inspector General’s Exclusion Authorities, 79 FR 26810 (May 9, 2014), <a href="https://www.gpo.gov/fdsys/pkg/FR-2014-05-09/pdf/2014-10390.pdf">https://www.gpo.gov/fdsys/pkg/FR-2014-05-09/pdf/2014-10390.pdf</a>.</font><br><font size="2">[4] Id.<br>[5] </font><font size="2">HHS OIG, Medicare and State Health Care Programs: Fraud and Abuse; Revisions to the Office of Inspector General’s Civil Monetary Penalty Rules, 79 FR 27080 (May 12, 2014), <a href="https://www.gpo.gov/fdsys/pkg/FR-2014-05-09/pdf/2014-10390.pdf">https://www.gpo.gov/fdsys/pkg/FR-2014-05-09/pdf/2014-10390.pdf</a>.</font><font size="2"><br>---------------------------------------</font><br><font size="2"><br>Posted by Tatiana Melnik on May 26, 2014</font><br></font></div>  
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1401118313_Healthcare-Fraud.html</link>
<guid>http://melniklegal.com/weblog/1401118313_Healthcare-Fraud.html</guid>
<pubDate>Mon, 26 May 2014 11:31:53 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[A Few Telemedicine Resources]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><font face="Arial">Following the release of the <i>Model Policy for the Appropriate Use of Telemedicine Technologies in the Practice of Medicine</i> by the Federation of State Medical Boards in April 2014<font size="2">[1]</font>, the Center for Connected Health Policy (CCHP) and the American Telemedicine Association (ATA) released telemedicine reports, providing insights into the state of telemedicine adoption, reimbursement barriers and physician licensing requirements throughout the United States.</font><br></div><div align="left"><br></div><style> .linkcolorchange A:link {color: #edad27; text-decoration: 
 underline}.linkcolorchange A:visited {color: #edad27; text-decoration: 
 underline}  .linkcolorchange A:active {text-decoration: underline}  
 .linkcolorchange A:hover {text-decoration: underline; color: #edad27;} 
 </style><table style="text-align: left; margin-left: auto; margin-right: auto;" class="linkcolorchange" align="left" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i></b></font><font color="#FFFFFF">These reports provide a great resource for those researching the regulatory environment surrounding telemedicine and telehealth. But, it is important to remember that the laws and policies in this area change frequently throughout the US. The three reports cover most of the same areas, although they are presented differently. The report from </font></font></font><font face="Arial"><font face="Arial"><font color="#FFFFFF">the Center for Connected Health sets out eleven policy areas that are generally crucial when providers are formulating a telemedicine based business model. The American Telemedicina Association reports provide some very helpful charts comparing the laws of the various states. It is also important to remember that other regulatory requirements impact the practice of telemedicine, such as state and federal data privacy and security laws as well as general medical practice requirements (<i>e.g.</i>, record keeping).<br><br>If you have questions regarding any telemedicine related issues, please <font color="#66FFFF"><a href="https://melniklegal.com/Contact.html">contact us</a></font> today.<br></font></font></font></td></tr></tbody></table><div align="left"><br></div><div align="left"><font face="Arial"><b><br>Center for Connected Health Policy</b><b> Report on <a href="https://cchpca.org/sites/default/files/resources/Fifty%20State%20Medicaid%20Report.09.2014_1.pdf"><i>State Telehealth Policies and Reimbursement Schedules: A Comprehensive Plan of the 50 States and District of Columbia</i></a> </b>(Sept. 2014)<font size="2">[2]</font></font><br><br><font face="Arial">In its second annual report, the CCHP looked at the Medicaid reimbursement policies and telemedicine laws in all 50 states. As CCHP notes, some "states have incorporated policies into law, while others have addressed issues such as definition, reimbursement policies, licensure requirements, and other important issues in their Medicaid Program Guidelines." This is a good reminder to those interested in operating in this space must take care to review all appropriate laws and guidance documents prior to starting their telemedicine based practice or otherwise offering healthcare services via telemedicine. For example, some technologies may seen appropriate until a board of medicine takes action against a provider. See e.g., </font><font face="arial" size="3"><b><a href="https://melniklegal.com/programs/weblog.cgi?showpage=1390610496_Telemedicine">Can Doctor’s Use Skype for Telemedicine? Not in Oklahoma.</a><br><br></b>CCHP observed the following major trends regarding reimbursement for live video, store-and-forward and remote patient monitoring:<br></font><ul><li><font face="arial" size="3">In comparison to forty-four states last year, currently forty-six state Medicaid programs reimburse for some form of live video. Washington DC’s Medicaid program is also now required to reimburse for live video as a result of recent legislation.</font></li><li><font face="arial" size="3">Ten state Medicaid programs offer some reimbursement for store-and-forward (states that only reimbursed for tele-radiology are not included in this count).</font></li><li><font face="arial" size="3">Thirteen state Medicaid programs offer reimbursement for remote patient monitoring compared to ten states at the time this report was first published in 2013.</font></li><li><font face="arial" size="3">Three state Medicaid programs (Alaska, Minnesota and Mississippi) reimburse for all three.</font></li></ul><font face="arial" size="3">In reviewing state telemedicine policies, the survey focused on eleven policy areas:<br></font><ul><li><font face="arial" size="3">Definition of the term telemedicine/telehealth</font></li><li><font face="arial" size="3">Reimbursement for live video</font></li><li><font face="arial" size="3">Reimbursement for store-and-forward</font></li><li><font face="arial" size="3">Reimbursement for remote patient monitoring (RPM)</font></li><li><font face="arial" size="3">Reimbursement for email/phone/fax</font></li><li><font face="arial" size="3">Consent issues</font></li><li><font face="arial" size="3">Location of service provided</font></li><li><font face="arial" size="3">Reimbursement for transmission and/or facility fees</font></li><li><font face="arial" size="3">Online prescribing</font></li><li><font face="arial" size="3">Private payer laws</font></li><li><font face="arial" size="3">Cross-state licensure</font></li></ul></div><div align="left"><font face="Arial">These policy areas are important to understand when developing a telemedicine based practice, evaluating offering services to existing patients via telemedicine, or developing a telemedicine compliance program. Physicians and physician extenders (<i>e.g.</i>, nurse practitioners, registered nurses, and others) who wish to practice across state lines must also pay close attention to the licensure requirements keeping in mind that the law is based on the physical location of the patient <i>and not the provider</i>.</font><br><br><font face="Arial" size="3"><b>American Telemedicine Association Report on <a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis--physician-practice-standards-licensure.pdf?sfvrsn=6"><i>Physician Practice Standards &amp; Licensure</i></a></b> <font size="2">[3]</font></font><br><br><font face="Arial">This report evaluated the physician licensure laws in the states for both in-state and out-of state practice. The report also looked at the physician-patient encounter requirements when using telemedicine, telepresenter requirements that may be more stringent as compared to in-person services, and informed consent requirements. The report provides a summary chart grading each state on a A - F scale. </font><br><br><font face="Arial" size="3"><b>American Telemedicine Association Report on <a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis---coverage-and-reimbursement.pdf?sfvrsn=6"><i>Coverage &amp; Reimbursement</i></a></b> <font size="2">[4]</font></font><br><font face="Arial"><br></font></div><div align="left"><font face="Arial">Payment and coverage remains one of the biggest obstacles to the widespread adoption of telemedicine. In this report, the ATA "extracts and compares telemedicine coverage and reimbursement standards for every state in the U.S." Notably, as the ATA explained:</font><br><ul><li><font face="Arial">Of the 21 states that have telemedicine parity laws for private insurance, only 15 of them and D.C. scored the highest grades indicating policies that authorize state-wide coverage, without any provider or technology restrictions. Over half of the country, 29 states, ranked the lowest with failing scores for having no parity law in place.</font></li></ul><ul><li><font face="Arial">Forty-seven state Medicaid programs have some type of coverage for telemedicine. Only five states and D.C. scored the highest grades by offering more comprehensive coverage, with few barriers for telemedicine-provided services . Connecticut, Hawaii, Idaho, Iowa, Nevada, Rhode Island, Utah and West Virginia ranked the lowest with failing scores in this area.</font></li></ul><ul><li><font face="Arial">One disappointing observation includes the lack of coverage and reimbursement for telemedicine under state employee health plans. Eighty-two percent of the country is ranked the lowest with failing scores including Arkansas which will only cover the use of store-and-forward for diabetic retinopathy screening, and Nebraska which requires their plans to cover autism treatment via telemedicine.</font></li></ul><ul><li><font face="Arial">Regarding Medicaid regulations, states are slowly moving away from the traditional hub-and-spoke model and allowing a variety of technology applications. Twenty-three states and D.C. do not specify a patient setting or patient location as a condition for payment of telemedicine. Aside from this, 21states recognize the home as an originating site, while 13 states recognize schools and/or school-based health centers as an originating site. Utah ranks the lowest with only one eligible originating site </font></li></ul><ul><li><font face="Arial">South Dakota has the highest ranking for Medicaid operations because its program covers telemedicine when providers use interactive audio-video, store-and-forward, remote patient monitoring, e-mail, fax, or phone mail. Fifty-seven percent of the country ranked the lowest with failing scores either because they only cover synchronous only or provide no coverage for telemedicine at all. Idaho, Missouri, North Carolina and South Carolina prohibit the use of cell phone video to facilitate a telemedicine encounter.<font size="2">[5]</font></font><br></li></ul><br><font face="Arial">-------------------------------------------</font><br><font face="Arial" size="2">[1] Federation of State Medical Boards, Model Policy for the Appropriate Use of Telemedicine Technologies in the Practice of Medicine (April 2014), <i>available at </i><a href="https://www.fsmb.org/Media/Default/PDF/FSMB/Advocacy/FSMB_Telemedicine_Policy.pdf">https://www.fsmb.org/Media/Default/PDF/FSMB/Advocacy/FSMB_Telemedicine_Policy.pdf</a>.</font><br><br><font face="Arial" size="2">[2] Center for Connected Health Policy, State Telehealth Policies and Reimbursement Schedules: A Comprehensive Plan of the 50 States and District of Columbia (Sept. 2014), <i>available at</i> <a href="https://cchpca.org/sites/default/files/resources/Fifty%20State%20Medicaid%20Report.09.2014_1.pdf">https://cchpca.org/sites/default/files/resources/Fifty%20State%20Medicaid%20Report.09.2014_1.pdf</a>.</font><br><br><font face="Arial" size="2">[3] American Telemedicine Association, Physician Practice Standards &amp; Licensure (Sept. 2014), <i>available at</i> <a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis--physician-practice-standards-licensure.pdf?sfvrsn=6">https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis--physician-practice-standards-licensure.pdf?sfvrsn=6</a>.</font><br><br><font face="Arial" size="2">[4] </font><font face="Arial" size="2"><font face="Arial" size="2">American Telemedicine Association, Coverage &amp; Reimbursement (Sept. 2014), <i>available at</i> </font><a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis---coverage-and-reimbursement.pdf?sfvrsn=6">https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis---coverage-and-reimbursement.pdf?sfvrsn=6</a>.</font><br><br><font face="Arial" size="2">[5] <i>Id</i>. at 2-3.</font><br><font face="Arial">-------------------------------------------<br></font><br><font face="Arial"><font face="Arial"><font size="2">Posted by Tatiana Melnik on October 28, 2014.<br><br><br></font></font><br></font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1414554679_Telemedicine.html</link>
<guid>http://melniklegal.com/weblog/1414554679_Telemedicine.html</guid>
<pubDate>Tue, 28 Oct 2014 23:51:19 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[98% of OCR Employees Furloughed with Government Shutdown]]></title>
<description><![CDATA[
 
 
 
 <div align="left"><font face="Arial">As the federal government shutdown continues, people are starting to see more clearly all of the healthcare related services that are performed by the various Department of Health and Human Services agencies.</font><br><br><font face="Arial">Two federal entities having particular influence the healthcare information technology space include the Office of Civil Rights (OCR), which investigates HIPAA violations and undertakes enforcement efforts, and the Office of the National Coordinator for Health Information Technology (ONC), which coordinates nationwide efforts to implement health information technology and the electronic exchange of health information. The current shutdown has had a particularly negative impact on these two agencies because 98% of their employees have been furloughed. According to HHS's Contingency Staffing Plan for Operations in the Absence of Enacted Annual Appropriations:</font><br><ul><li><font face="Arial"><u><b>OCR</b></u></font></li><ul><li><font face="Arial">Number of employees as of Oct. 1, 2013: <b>221</b></font></li><li><font face="Arial">Total number of staff to be retained: <b>5</b></font></li><li><font face="Arial">Number of staff to be furloughed: <b>216</b></font></li><li><font face="Arial">Percent furloughed: <b>98%</b></font></li></ul></ul><ul><li><font face="Arial"><u><b>ONC</b></u></font></li><ul><li><font face="Arial">Number of employees as of Oct. 1, 2013: <b>184</b></font></li><li><font face="Arial">Total number of staff to be retained: <b>4</b></font></li><li><font face="Arial">Number of staff to be furloughed: <b>180</b></font></li><li><font face="Arial">Percent furloughed: <b>98%</b></font></li></ul></ul></div><p align="left"><font face="Arial">During the furlough, it appears that HIPAA/HITECH investigative and enforcement activities undertaken by OCR will be non-existent due to staffing levels. Additionally, the OCR Complaint Portal, which allows individuals to file complaints, is down with a message stating that, "<i>Due to the absence of either an FY 2014 appropriation or Continuing Resolution for the Department of Health and Human Services, this site will not be accepting new submissions.&nbsp; When either an FY 2014 appropriation or Continuing Resolution for the Department of Health and Human Services is passed, this site will again accept submissions. Thank you for your patience.</i>"<br></font></p><p align="center"><font face="Arial"><img src="https://melniklegal.com/images/OCR_complaint_portal_down.jpg"><br></font></p><p align="left"><font face="Arial">Similarly, ONC will be unable to continue the Standards and Interoperability Framework activities as well as related standards and testing activities; policy activities such as privacy, security, and clinical quality measure development; and administration of the Certified Health IT Product List.</font></p><div align="left"><font face="Arial">HIMSS reports that while about half of the CMS staff is furloughed, those staff members working on the HITECH program are not affected. "Meaningful use attestation can still occur and payments can still be processed, although the timeline for those payments to be distributed is still in question."</font><br><br><font face="Arial"><b>Resources and Supporting Documents</b></font><ul><li><font face="Arial">Department of Health and Human Services, Fiscal Year 2014, <a href="https://melniklegal.com/av/fy2014contingency_staffing_plan-rev2.pdf">Contingency Staffing Plan for Operations in the Absence of Enacted Annual Appropriations</a> (PDF)<br></font></li><li><font face="Arial">HIMSS Article on <a href="https://www.himss.org/News/NewsDetail.aspx?ItemNumber=22810">Impacts of Government Shutdown on Federal Agencies</a> (Oct. 11, 2013)<br></font></li></ul></div>
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1381770937_HIPAA.html</link>
<guid>http://melniklegal.com/weblog/1381770937_HIPAA.html</guid>
<pubDate>Mon, 14 Oct 2013 13:15:37 EST</pubDate>
</item>
			
			
</channel>
</rss>