<?xml version="1.0" encoding="utf-8"?>
	<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
	<title>An RSS Feed from melniklegal.com</title>
<description>melniklegal.com Blog</description>
<link>http://melniklegal.com/programs/weblog.cgi</link>
<category>e-commerce</category>
<copyright>Copyright melniklegal.com </copyright>
<language>en-us</language>
<lastBuildDate>Tue, 15 Sep 2026 02:19:27 EST</lastBuildDate>
<managingEditor>tatiana@melniklegal.com (Web Master)</managingEditor>
<pubDate>Tue, 15 Sep 2026 02:19:27 EST</pubDate>
<webMaster>tatiana@melniklegal.com (Tatiana)</webMaster>
<generator>e-commerce-inc.com sitebuilder blog press</generator>
<atom:link href="http://melniklegal.com/programs/blogrss.cgi" rel="self" type="application/rss+xml" />

			
<item>
<title><![CDATA[Will the HHS Release of the Medicare Treasure Trove Lead to More Healthcare Fraud Lawsuits?]]></title>
<description><![CDATA[
 
 
 
 
   <font face="Arial">It's likely. Reuters reports that attorneys specializing in whistleblower healthcare fraud cases are mining the data for clues about potential fraud. <br><br>Using data mining techniques to find fraud is not new. The Medicare Fraud Strike Force has been using these analysis techniques - along with trend evaluation and modeling - for some time. During a speech </font><font face="Arial"><font face="Arial">at the Los Angeles Health Care Fraud Prevention Summit </font>in 2010, for example, Lanny A. Breuer, Assistant Attorney General for the Criminal Division, told the audience that:<br></font><blockquote><blockquote><div align="left"><font face="Arial" size="3">In 2007, the Criminal Division of the Justice Department refocused our approach to investigating and prosecuting health care fraud cases. <i><b>Our investigative approach is now data driven</b></i>: put simply, our analysts and agents review Medicare billing data from across the country; identify patterns of unusual billing conduct; and then deploy our "Strike Force" teams of investigators and prosecutors to those hotspots to investigate, make arrests, and prosecute. And as criminals become more creative and sophisticated, we intend to use our most aggressive investigative techniques to be right at their heels. Whenever possible, we actively use undercover operations, court-authorized wiretaps and room bugs, and confidential informants to stop these schemes in their tracks.</font><font face="Arial" size="2">[1]</font><br></div></blockquote></blockquote><font face="Arial">And the big data analysis techniques are working. In 2012, several individuals allegedly involved in a </font><font face="Arial"><font face="Arial">$375 million</font> home health fraud scheme were indicted in the Northern District of Texas. </font><font face="Arial"><font face="Arial">HHS Inspector General Daniel Levinson commented that</font> they were discovered by the use of "data analysis [allowing the investigators to] target suspicious billing spikes." Levinson explained that, “[i]n this case, our analysts discovered that in 2010, while 99 percent of physicians who certified patients for home health signed off on 104 or fewer people Dr. Roy certified more than 5,000."<font size="2">[2]</font><br><br>But, with the release of the Medicare billing data to the public, now plaintiffs' lawyers have access to the data as well. Given the possible recoveries, it's no surprise:<br></font><blockquote><blockquote><font face="Arial">A whistleblower who prevails gets up to 30 percent of whatever the government recovers, and 40 percent of that reward typically goes to the whistleblower's lawyer.<br><br>Whistleblower cases can result in huge settlements, such as the $3 billion GlaxoSmithKline paid in 2012 to resolve claims that it promoted drugs for unapproved uses and failed to report certain safety data.<font size="2">[3]</font></font><br></blockquote></blockquote><font face="Arial">As explained by Reuters, the whistleblower lawyers are doing the same thing that the government is doing in it's analysis - looking for doctors whose billing practices are outside the norm to bolster existing cases:<br></font><blockquote><blockquote><font face="Arial">By Thursday, Pennsylvania lawyer Marc Raspanti was having a ball. Raspanti said he spent six hours combing through the data. He has several Medicare fraud lawsuits pending against pharmaceutical companies alleging kickbacks to certain doctors.<br><br>Raspanti is analyzing the data, he said, to see if doctors are prescribing an unusually high amount of the pharmaceutical company's products. If so, he said, that could bolster allegations that something is amiss.</font><font face="Arial" size="2">[4]</font></blockquote></blockquote><font face="Arial">In undertaking this analysis, however, attorneys are likely find new cases. Additionally, practice managers, pharmaceutical sales managers, nurse practitioners, and others who have a suspicion that something may be amiss in a practice, with their employer, with a pharmaceutical relationship, can now themselves use the database to investigate. This data release will likely lead to additional healthcare fraud cases and bolster whistleblower claims.<br><br>----------------------------------------<br><font size="2">[1] Press Release, Department of Justice, Assistant Attorney General for the Criminal Division Lanny A. Breuer Speaks at the Los Angeles Health Care Fraud Prevention Summit, Speech, Aug. 26, 2010,<i> available at</i> <a href="https://www.justice.gov/criminal/pr/speeches/2010/crm-speech-100826.html">https://www.justice.gov/criminal/pr/speeches/2010/crm-speech-100826.html</a> (last visited April 19, 2014).<br><br>[2] Press Release, Department of Justice, Dallas Doctor Arrested for Alleged Role in Nearly $375 Million Health Care Fraud Scheme, Feb. 28, 2012, <i>available at</i> <a href="https://www.justice.gov/opa/pr/2012/February/12-crm-260.html">https://www.justice.gov/opa/pr/2012/February/12-crm-260.html</a> </font></font><font face="Arial"><font size="2"><font face="Arial"><font size="2">(last visited April 19, 2014).<br><br>[3] Terry Baynes, Lawyers Start Mining the Medicare Data for Clues to Fraud, Reuters, April 14, 2014, <a href="https://www.reuters.com/article/2014/04/14/us-data-idUSBREA3D05820140414">https://www.reuters.com/article/2014/04/14/us-data-idUSBREA3D05820140414</a>.<br><br>[4] Id.<br><br><br><br></font></font></font></font><br><font face="Arial"><font size="2">Posted by Tatiana Melnik April 19, 2014.</font></font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1397881440_Big-Data.html</link>
<guid>http://melniklegal.com/weblog/1397881440_Big-Data.html</guid>
<pubDate>Sat, 19 Apr 2014 00:24:00 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Fact Dispute Regarding Disclosure of HIV Test Results Causes Nebraska Supreme Court to Reverse Lower Court]]></title>
<description><![CDATA[
 
 
 
 <div align="left"><font face="Arial">On March 14, 2014, the Nebraska Supreme Court reversed a lower court decision granting Prairie Fields Family Medicine PC summary judgment on claims for intentional and negligent infliction of emotional distress related to the alleged improper release of HIV test results of C.E., a patient of the practice.<br><br>Plaintiff C.E. sued Prairie Fields and Kristy Stout-Kreikemeyer, an employee of the practice, alleging claims of invasion of privacy, intentional infliction of emotional distress, and negligent infliction of emotional distress based on the improper disclosure of the results of an HIV test.<br><br>Brief summary of the facts as set out by the Court:<br></font><ul><li><font face="Arial" size="2">In 2010, C.E. went to a diagnostic laboratory in Omaha, Nebraska, to have a physical examination for a life insurance application and the lab drew a blood sample.</font></li><li><font face="Arial" size="2">The lab sent the blood sample to another lab for testing, and the lab sent the results to C.E.'s physician at Prairie Fields.</font></li><li><font face="Arial" size="2">Sometime in September 2010, C.E. went to see her physician. "When C.E. arrived <b>on a Thursday</b> <b>at about 3 or 4 p.m.</b>, Kristy Stout-Kreikemeyer, whom C.E. knew from high school, showed C.E. to a room. C.E. said that when she asked about her test results, Stout-Kreikemeyer looked in C.E.’s file, flushed, and responded that she could not say anything."<br></font></li><li><font face="Arial" size="2">"C.E. testified that <b>the next day, Friday, at about 7 p.m.</b>, Jonathan Karr, the father of one of C.E.’s daughters, called her or sent text messages to ask how she was because he had heard from his friend Jamie Goertz that she had 'Aids, full blown-out Aids.' C..E. said Karr sent her the text message that he had received from Goertz."</font></li><li><font face="Arial" size="2">C.E. was not sure who disclosed the information, but was certain the information was disclosed by someone from the practice because of the way the information was handled by the labs.</font></li><li><font face="Arial" size="2">C.E. believed that the information may have been disclosed by Kristy Stout-Kreikemeyer "because she had seen a social contact between her and Goertz on an Internet social media service." <font color="#336666"><i><u><b>[Notice the use of social media evidence here.]</b></u></i></font></font></li><li><font face="Arial" size="2">"C.E. then learned through a discovery request that Sara Sorensen worked at Prairie Fields as a medical transcriptionist. Sorensen was Goertz’ former wife, and C.E. believed that Sorensen had disclosed the test results to him. Prairie Fields stipulated that Sorensen had transcribed C.E.’s medical records."</font></li><li><font face="Arial" size="2">"C.E. testified that she did not tell anyone about the test result because she believed that the test result was a false positive. She believed this because her doctor had told her that other antibodies could cause a false positive result and because she had a family history of autoimmune conditions."</font></li></ul></div><p align="left"><font face="Arial">The lower court granted summary judgment in favor of Prairie Fields because, according to the lower court, the medical practice "introduced substantial competent evidence to establish a prima faci[e] showing that there is a lack of causation by [Prairie Fields] or its agents related to any claim for damages made by [C.E.] in this case." The lower court then looked to C.E. and said that C.E. did not provide evidence that Prairie Fields of its agents were "somehow negligent and that said negligence caused some type of damage/injury to [C.E.]" (The parties agreed to dismiss Kristy Stout-Kreikemeyer from the case and the invasion of privacy claim was time barred.)</font></p><p align="left"><font face="Arial">In reversing the lower court decision, the Nebraska Supreme Court stated that, "giving C.E. the benefit of all reasonable inferences [as the Court is required to do in deciding on a Summary Judgment motion], the circumstantial evidence that she presented was sufficient to support an inference in her favor" and therefore, "Prairie Fields was not entitled to judgment as a matter of law." The Court further ruled that, the lower court "erred by concluding C.E. presented no competent evidence that a Prairie Fields employee had disclosed her diagnosis. Moreover, the court incorrectly stated that her evidence must show it was more likely than not that a Prairie Fields employee had disclosed her diagnosis. A court does not weigh the evidence at the summary judgment."</font></p><p align="left"><font face="Arial">The decision is <a href="https://melniklegal.com/av/2014_CE_v_Prairie_Fields_Family_Medicine_Neb_S_Ct.pdf"><i>C.E. v. Prairie Fields Family Medicine PC</i></a>, 287 Neb. 667 (Mar. 14, 2014). </font></p><p align="left"><font face="Arial"><u><b>A Few Take-a-Ways</b></u></font></p><div align="left"><ul><li><font face="Arial">The disclosure occurred sometime in or about September 2010. C.E. filed suit in February 2012. The lower court issued its decision in or about May 2013. This Court issued the decision discussed above in March 2014. The case will now go back to the lower court and the litigation, unless it is settled, will proceed. These cases, like any litigation, take years.</font></li></ul><ul><li><font face="Arial">It is imperative that providers train their staff on protecting medical information because the provider will be drawn into the litigation. Providers treating patients in small towns, multiple family members, the provider's employees, and so forth may consider taking special precautions to ensure that information is secure and to segregate duties as needed.</font></li></ul></div><div align="left"><ul><li><font face="Arial">In the scheme of protected health information, information related to HIV/AIDS and other sexually transmitted diseases</font><font face="Arial">, mental health, substance abuse, and abortions occupies a special class of information -- often called highly sensitive information -- because of the stigma and other repercussions improper disclosure may case. As such, this highly sensitive information generally receives special protections under either (or both) federal and state law and individuals who suffer data breaches involving this kind of information may have more legal remedies (and higher jury verdicts).</font></li></ul><ul><li><font face="Arial">This case was decided under Nebraska state law. HIPAA does not provide for a private right of action. So, cases involving the unauthorized disclosure of healthcare records, substance abuse records, and so forth, are brought under state law. But, several courts have ruled that HIPAA may be used to set a 'standard of care.' Providers may consider reviewing their practices to see whether they could meet this standard of care.<br></font></li></ul><font face="Arial"><br></font></div>
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1396407470_Privacy-Litigation.html</link>
<guid>http://melniklegal.com/weblog/1396407470_Privacy-Litigation.html</guid>
<pubDate>Tue, 01 Apr 2014 22:57:50 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[CMS Announces Hospice Quality Reporting Program]]></title>
<description><![CDATA[
 
 
 
 
     <font face="Arial"> </font><div align="left"><font face="Arial">On April 8, 2014, CMS announced in the Federal Register that it is establishing a new System of Records (SOR) to support the collection of data required for the Hospice Quality Reporting Program. The Notice was published pursuant to the requirements of the Privacy Act of 1974.<br><br>CMS is establishing a new SOR titled, “Hospice Item Set (HIS) System,” System No. 09-70-0548. The new system will support the collection of data required for the Hospice Quality Reporting Program (HQRP) pursuant to Section 3004(c) of the Patient Protection and Affordable Care Act of 2010 (ACA) (Pub. L. 111-148), which amended the Social Security Act (the Act) (42 U.S.C. 1814(i)).<br><br>HIS is a standardized, patient-level data collection vehicle consisting of data elements confirming that the appropriate assessments were made and inquiries or concerns were addressed for each patient at the time of admission for the following domains of care: (1) Pain; (2) Respiratory Status; (3) Medications; (4) Patient Preferences; and (5) Beliefs Values.<br><b><br>Hospices will begin using the HIS on July 1, 2014</b>. As discussed further below, hospices will be reporting on seven National Quality Forum measures. Data will be collected on all patients - whether or not they are Medicare beneficiaries.</font><font face="Arial"><br><br></font><table border="0"><tbody><tr><td align="left" valign="top"><br><font face="Arial"><img src="https://melniklegal.com/images/data_analytics.png">&nbsp; <br></font></td><td align="left" valign="top"><font face="Arial"> </font><font face="Arial"><b>CMS intends to use and share the data to fight waste, fraud and abuse.</b> <br><br>CMS will share the data with other federal agencies as well as state and government agencies, who will then use their data analysis&nbsp; tools to spot waste, fraud and abuse. Such data analytics programs already exist within a number of federal and state agencies.<br><br>With this data reporting requirement, hospice owners and operators should consider taking this opportunity to evaluate whether additional internal compliance programs are needed. Specifically, operators should consider implementing internal data analytics programs -- and using their 'big data' -- to find potential waste, fraud and abuse prior to CMS discovering potential issues. Such programs can also be used to find trends and other quality improvement and cost savings opportunities.<br><br>There are a number of software vendors on the market providing data analytics software to healthcare providers.</font></td></tr></tbody></table><font face="Arial">As explained by CMS:<br></font><blockquote><font face="Arial">Section 3004(c) of the ACA directed the Secretary of HHS to establish a quality reporting program for hospices for the purpose of collecting, compiling and eventually publishing data measuring the quality of care provided to patients receiving hospice care. The quality measure data is required to be valid, meaningful, and feasible to collect, and to address symptom management, patient preferences and care coordination. Although CMS administers the HIS, information is also collected on hospice patients who may not be Medicare beneficiaries.<br></font></blockquote><blockquote><font face="Arial">. . .<br><br>The HIS was developed specifically for use by hospices and contains data elements that can be used by CMS to collect the patient-level data required for seven National Quality Forum—(NQF) endorsed quality measures and a modification of one NQF-endorsed measure. <b>These measures include</b>: <br></font><blockquote><font face="Arial">(1) Hospice and Palliative Care—Pain Screening (NQF #1634); <br><br>(2) Hospice and Palliative Care—Pain Assessment (NQF #1637); <br><br>(3) Hospice and Palliative Care—Dyspnea Screening (NQF #1639);<br><br>(4) Hospice and Palliative Care—Dyspnea Treatment (NQF #1638);<br><br>(5) Patients Treated With an Opioid who are Given a Bowel Regimen (NQF #1617);<br><br>(6) Hospice and Palliative Care—Treatment Preferences (NQF #1641); and<br><br>(7) Beliefs/values addressed (modified version of the NQF #1647 measure).<br></font></blockquote></blockquote><div><font face="Arial"><b>When will hospices begin using the Hospice Item Set (HIS) System and what are they submitting?</b></font></div><blockquote><font face="Arial">Hospices will begin using the HIS for all patients beginning July 1, 2014. <br><br>Hospices will be required to submit two HIS records for each patient admitted to their organization:<br></font><ul><li><font face="Arial"><i>HIS-Admission record</i> - contains both administrative items for patient identification and clinical items for calculating the seven quality measures; and<br></font></li></ul><ul><li><font face="Arial"><i>HIS-Discharge record</i> - a limited set of administrative items used for patient identification, as well as discharge information, which will be used primarily to determine patient exclusions for some of the seven quality measures.</font></li></ul></blockquote><font face="Arial"><b>Categories of Individuals Covered by the System:</b><br></font><blockquote><font face="Arial">The system will contain information about the following categories of individuals who participate in or are involved with the HQRP: <br></font><blockquote><font face="Arial">(1) Hospice patients and Medicare beneficiaries, who receive health care services coordinated and managed by hospices; and, <br><br>(2) any individual providers and/or any contact persons for a hospice whose personal information (such as, home or personal contact information, or Social Security Number (SSN) if used for business purposes) is provided as business-identifying information on the collection instrument.<br></font></blockquote></blockquote><font face="Arial"><b>Categories of Records in the System:</b><br></font><blockquote><font face="Arial">Information in the HIS about hospice patients includes but not limited to information related to condition, selected covariates about the condition, and patient/beneficiary demographic records containing the patient/beneficiary's name, gender, beneficiary's Health Insurance Claim Number (HICN), SSN, Medicaid number (MA number), race, and date of birth. Information collected about providers who work in hospices considered to be PII includes records containing the provider's name, address, National Provider Identifier (NPI), and CMS Certification Number (CCN), personal contact information, tax identification number, and SSN if used for business purposes.<br></font></blockquote><font face="Arial"><b>Entities Who May Receive Disclosures Under Routine Use</b><br></font><blockquote><font face="Arial">These routine uses specify circumstances, in addition to those provided by statute in the Privacy Act of 1974, under which CMS may release information from HIS without the consent of the individual to whom such information pertains. Each proposed disclosure of information under these routine uses will be evaluated to ensure that the disclosure is legally permissible, including but not limited to ensuring that the purpose of the disclosure is compatible with the purpose for which the information was collected. We propose to establish the following routine use disclosures of information maintained in the system:<br></font></blockquote><blockquote><blockquote><font face="Arial">1. To support Agency contractors, consultants, or CMS grantees who have been engaged by the Agency to assist in accomplishment of a CMS function relating to the purposes for this collection and who need to have access to the records in order to assist CMS.<br><br>2. To assist another Federal Agency, agency of a State government, an agency established by State law, or its fiscal agents with information that is necessary and/or required in order to perform the statutory functions of the HQRP;<br><br>3. To provide hospices with information they need to meet any statutory requirements of the program, assist with other reports as required by CMS, and to assist in the implementation of quality standards;<br><br>4. To support an individual or organization for research, as well as evaluation or epidemiological projects related to end of life care, or for understanding and improving payment projects;<br><br>5. To support Quality Improvement Organizations (QIOs) in connection with review of claims, or in connection with studies or other review activities conducted pursuant to Part B of Title XI of the Act, and in performing affirmative outreach activities to individuals for the purpose of establishing and maintaining their entitlement to Medicare benefits or health insurance plans;<br><br>6. To assist national accrediting organization(s) whose accredited providers are presumed to meet certain Medicare requirements (e.g., the Joint Commission for the Accreditation of Healthcare Organizations, the Community Health Accreditation Program (CHAP), or the Accreditation Commission for Health Care (ACHC);<br><br>7. To provide information to the U.S. Department of Justice (DOJ), a court, or an adjudicatory body when (a) the Agency or any component thereof, or (b) any employee of the Agency in his or her official capacity, or (c) any employee of the Agency in his or her individual capacity where the DOJ has agreed to represent the employee, or (d) the United State Government, is a party to litigation or has an interest in such litigation, and by careful review, CMS determines that the records are both relevant and necessary to the litigation and that the use of such records by the DOJ, court, or adjudicatory body is compatible with the purpose for which the agency collected the records;<br><br>8. To assist a CMS contractor (including, but not limited to Medicare Administrative Contractors, fiscal intermediaries, and carriers) that assists in the administration of a CMS-administered health benefits program, or to a grantee of a CMS-administered grant program, when disclosure is deemed reasonably necessary by CMS to prevent, deter, discover, detect, investigate, examine, prosecute, sue with respect to, defend against, correct, remedy, or otherwise combat fraud, waste or abuse in such program;<br><br>9. To assist another Federal agency or to an instrumentality of any governmental jurisdiction within or under the control of the United States (including any state or local governmental agency), that administers or that has the authority to investigate potential fraud, waste or abuse in a health benefits program funded in whole or in part by Federal funds, when disclosure is deemed reasonably necessary by CMS to prevent, deter, discover, detect, investigate, examine, prosecute, sue with respect to, defend against, correct, remedy, or otherwise combat fraud, waste or abuse in such programs;<br><br>10. To disclose records to appropriate Federal agencies and Department contractors that have a need to know the information for the purpose of assisting the Department's efforts to respond to a suspected or confirmed breach of the security or confidentiality of information maintained in this system of records, and the information disclosed is relevant and necessary for that assistance; and<br><br>11. To assist the U.S. Department of Homeland Security (DHS) cyber security personnel, if captured in an intrusion detection system used by HHS and DHS (e.g., pursuant to the Einstein 2 program).<br></font></blockquote></blockquote><font face="Arial">The Federal Register Notice is available here: <a href="https://federalregister.gov/a/2014-07552">https://federalregister.gov/a/2014-07552</a><br><br></font><div><font face="Arial"><b>Details:</b><br></font><blockquote><font face="Arial" size="2"><b>Publication Date</b>: Tuesday, April 08, 2014</font><font face="Arial" size="2"><br><b>Agencies</b>: Department of Health and Human Services and Centers for Medicare &amp; Medicaid Services<br><b>Entry Type</b>: Notice<br><b>Action</b>: Notice of a New System of Records (SOR).<br><b>Document Citation</b>: 79 FR 19341<br><b>Page</b>: 19341 -19344 (4 pages) <br><b>Document Number</b>:</font><font face="Arial" size="2"> 2014-07552</font><font face="Arial"><br></font></blockquote></div></div><font face="Arial"> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1396969740_Big-Data.html</link>
<guid>http://melniklegal.com/weblog/1396969740_Big-Data.html</guid>
<pubDate>Tue, 08 Apr 2014 11:09:00 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Interest in Cyber Security of Financial Services Firms Continues to Increase]]></title>
<description><![CDATA[
 
 
 
  
  
  
  
  
     <table align="left" border="0"><tbody><tr><td align="left" valign="top"><font face="Arial"><font face="Arial">As news of data breaches continue to mount, federal and state regulators are becoming increasingly interested in the steps companies are taking to secure the information entrusted to them by consumers as well as other companies. This year we have seen an increased focus on the financial services sector, which suffered large losses in the wake of the data breach at Target. This was then followed by data breaches at Neiman Marcus, Michaels, PF Changs, among many many others.</font></font></td><td align="left" valign="top"><font face="Arial"> </font><font face="Arial"><img src="https://melniklegal.com/images/1407508517.jpg"></font><br></td></tr></tbody></table><div align="left"><br><font face="Arial">Some of the recent examples include:</font><br><ul><li><div><font face="Arial"><b>FFIEC</b> - The Federal Financial Institutions Examination Council has launched a pilot program to assess the cyber security preparedness of 500 community banks. This announcement coincides with the launching of a web page on <font color="#009900"><b>June 24, 2014</b></font> on cyber security, which is meant to serve as "a central repository for current and future FFIEC-related materials on cyber security."
  As the FFIEC explains, "Regulators are particularly focusing on risk 
 management and oversight, threat intelligence and collaboration, 
 cyber security controls, service provider and vendor risk management, and
  cyber incident management and resilience."<font size="2">[1]</font></font></div></li></ul><ul><li><div><font face="Arial"><b>New York Department of Financial Services</b> - In <font color="#009900"><b>May 2014</b></font>, the New York Department of Financial Services (NYDFS) issued a "Report on Cyber Security in the Banking Sector." 
 The Report notes that, "Although large-scale denial-of-services attacks 
 against major financial institutions generate the most headlines, 
 community and regional banks, credit unions, money transmitters, and 
 third-party service providers (such as credit card and payment 
 processors) have experienced attempted breaches in recent years."<font size="2">[3]</font> After conducting a preliminary survey of 154 financial services institutions in 2013, the Department now "plans to expand its IT examination procedures to focus more fully on cyber security." These "revised
  examination procedures will include additional questions in the areas 
 of IT management and governance, incident response and event management,
  access controls, network security, vendor management, and disaster 
 recovery." Those providing services to these entities should also expect to see more questions regarding cyber security now that regulators are becoming more interested in vendor practices.</font><br></div></li></ul><ul><li><font face="Arial"><b>SEC</b> - Cyber security has been a focal point at the Securities and Exchange Commission for a few years. But, the SEC's Office of Compliance Inspections and Examinations announced in a Risk Alert on <font color="#009900"><b>April 15, 2014</b></font> that it is undertaking cyber security examinations of more than 50 registered broker-dealers and registered investment advisers.</font><font face="Arial"><font face="Arial"><font size="2">[2]</font></font> The OCIE will be focusing on the entity’s cyber security governance, identification and assessment of cyber security risks, protection of networks and information, risks associated with remote customer access and funds transfer requests, risks associated with vendors and other third parties, detection of unauthorized activity, and experiences with certain cyber security threats.</font><br></li></ul></div><div align="left"><br><font face="Arial"><font face="Arial"><font size="2">---------------------------------------</font></font></font><br><font face="Arial"><font size="2">[1] Press Release, FFEIC, FFIEC Launches Cybersecurity Web Page, Promotes Awareness of Cybersecurity Activities, June 24, 2014, <a href="https://www.ffiec.gov/press/pr062414.htm">https://www.ffiec.gov/press/pr062414.htm</a>.</font></font><br><br><font face="Arial"><font size="2">[2] SEC, National Exam Program Risk Alert, Vol. IV, Iss. 2 (April 15, 2014), <a href="https://www.sec.gov/ocie/announcement/Cybersecurity+Risk+Alert++%2526+Appendix+-+4.15.14.pdf">https://www.sec.gov/ocie/announcement/Cybersecurity+Risk+Alert++%2526+Appendix+-+4.15.14.pdf</a></font></font>.<br><br><font face="Arial" size="2">[3] NY State Department of Financial Services, </font><font face="Arial" size="2"><font face="Arial">Report on Cyber Security in the Banking Sector (May 2014),</font> <a href="https://www.dfs.ny.gov/about/press2014/pr140505_cyber_security.pdf">https://www.dfs.ny.gov/about/press2014/pr140505_cyber_security.pdf</a></font>.<br><font face="Arial"><font size="2">---------------------------------------</font></font><br><br><font face="Arial"><font size="2">Posted by Tatiana Melnik on August 8, 2014</font></font><br></div>
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1407508168_Financial-Services.html</link>
<guid>http://melniklegal.com/weblog/1407508168_Financial-Services.html</guid>
<pubDate>Fri, 08 Aug 2014 10:29:28 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Eligible Professionals May Apply for a Hardship Exception from Meaningful Use Penalties]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><div><table border="0"><tbody><tr><td align="left" valign="top"><font face="Arial">As part of the American Recovery and Reinvestment Act of 2009 (ARRA), Congress mandated that payment adjustments be applied to Medicare eligible professionals (EPs) who are not meaningful users of Certified EHR Technology under the Medicare EHR Incentive Programs.<br><br>Medicare EPs who are not meaningful users will be subject to a payment adjustment beginning on January 1, 2015.<br><br>But, exceptions are available under certain limited circumstances.<br></font></td><td valign="top"><img src="https://melniklegal.com/images/Meaningful_Use_Hardship.jpg"><br></td></tr></tbody></table><font face="Arial"><b><br>Which practitioners are subject to MU payment adjustments and when do the payment adjustments begin?</b></font><br></div><div><ul><li><font face="Arial">EPs who participate in the Medicare EHR Incentive Program.</font></li><li><font face="Arial">EPs who can participate in <i>either</i> the Medicare or Medicaid EHR Incentive Programs.</font></li><li><font face="Arial">These payment adjustments will be <font color="#006600"><b>applied beginning on January 1, 2015</b></font>, for Medicare EPs.</font></li></ul></div><div><font face="Arial"><b>Which practitioners are NOT subject to MU payment adjustments?</b></font><br><ul><li><font face="Arial">Medicaid EPs who can only participate in the Medicaid EHR Incentive Program and do not bill Medicare.</font></li></ul><p><b><font face="Arial">How much are the payment adjustments and how are they applied?</font></b></p><p><font face="Arial">The payment adjustment will be applied to the Medicare physician fee schedule (PFS) amount for covered professional services furnished by the EP during the year (including the fee schedule amount for purposes of determining a payment based on the fee schedule amount). <br></font></p><p><font face="Arial">The payment adjustment is 1% per year and is cumulative for every year that an EP is not a meaningful user. Depending on the total number of Medicare EPs who are meaningful users under the EHR Incentive Programs after 2018, the maximum cumulative payment adjustment can reach as high as 5%.</font><br></p></div><font face="Arial">For additional details on MU payment adjustments, <a href="https://melniklegal.com/av/PaymentAdj_HardshipExcepTipSheetforEP_2013.pdf">please see the Payment Adjustments and Hardships Exceptions Tipsheet for Eligible Professionals released by CMS</a>.<br><br><b>Are there any </b></font><font face="Arial"><b><b><font face="Arial">payment adjustment </font></b>exceptions available for Medicare EPs who cannot meet MU deadlines?</b><br><br><b>Yes</b>. EPs who cannot meet MU deadlines may be eligible to receive a hardship exception from CMS. But, CMS has explained that </font><font face="Arial"><font face="Arial">these exceptions will be granted only under specific circumstances and only if </font></font><font face="Arial"><font face="Arial"><font face="Arial">CMS determines that providers have demonstrated that those circumstances pose a significant barrier to their achieving meaningful use.<br><br>Hardship exceptions are available in the following categories:<br></font></font></font><div><ul><li><font face="Arial"><b>Infrastructure </b>- EPs must demonstrate that they are in an area without sufficient internet access or face insurmountable barriers to obtaining infrastructure (e.g., lack of broadband).</font></li><li><font face="Arial"><b>New EPs</b> - Newly practicing EPs who would not have had time to become meaningful users can apply for <u><i>a 2-year limited exception</i></u> to payment adjustments. Thus EPs who begin practice in calendar year 2015 would receive an exception to the penalties in 2015 and 2016, but would have to begin demonstrating meaningful use in calendar year 2016 to avoid payment adjustments in 2017.</font></li><li><font face="Arial"><b>Unforeseen Circumstances</b> - Examples may include a natural disaster or other unforeseeable barrier.</font></li><li><font face="Arial"><b>Patient Interaction</b> - Lack of face-to-face or telemedicine interaction with patients; Lack of follow-up need with patients.</font></li><li><font face="Arial"><b>Practice at Multiple Locations</b> - Lack of control over availability of CEHRT for more than 50% of patient encounters</font><br></li></ul></div><font face="Arial"><font face="Arial"><font face="Arial">CMS will be providing additional details on the requirements and application process in the future.</font></font><br><br><br><br><br></font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1387148396_Meaningful-Use.html</link>
<guid>http://melniklegal.com/weblog/1387148396_Meaningful-Use.html</guid>
<pubDate>Sun, 15 Dec 2013 17:59:56 EST</pubDate>
</item>
			
			
</channel>
</rss>