In the August 17, 2000 Final Rule for Standards for Electronic Transactions, direct data entry was defined as “direct entry of data (for example, using dumb terminals or web browsers) that is immediately transmitted into a health plan’s computer.” [65 Federal Register 50367] An exception for direct data entry was articulated in the August 17, 2000, Final Rule: A health care provider electing to use direct data entry offered by a health plan to conduct a transaction for which a standard has been adopted under this part must use the applicable data content and data condition requirements of the standard when conducting the transaction. The health care provider is not…
Categories 5010Leave a commentContingency Plan: Data Backup-What to Do and How to Do It
In our series on the HIPAA Administrative Simplification Security Rule, this is the first implementation specification for the Administrative Safeguard Standard (Contingency Plan). This implementation specification is required. As HIPAA.com has noted in earlier postings, with enactment of the American Recovery and Reinvestment Act of 2009 (ARRA) on February 17, 2009, business associates also will be required to comply with the Security Rule standards, effective February 17, 2010. What to Do Establish and implement procedures to create and maintain retrievable exact copies of electronic protected health information. How to Do It Covered entities must backup electronic protected health information on a regular basis. When a computer system fails, it may…
Categories SecurityLeave a commentContingency Plan: Sample Policy and Procedures
This is the seventh Administrative Safeguard Standard of the HIPAA Administrative Simplification Security Rule. It has five implementation specifications: Data backup plan; Disaster recovery plan; Emergency mode operation plan; Testing and revision procedures; and Applications and data criticality analysis. The first three are required; the last two are addressable. Addressable does not mean optional. Rather, an addressable implementation specification means that a covered entity must use reasonable and appropriate measures to meet the standard. Further, as HIPAA.com has noted earlier, business associates also will be required to comply with the Security Rule standards, effective February 17, 2010. HIPAA.com will outline What to do and How to do it for each…
Categories SecurityLeave a commentContingency Plan-What This HIPAA Security Rule Administrative Safeguard Standard Means
This is the seventh Administrative Safeguard Standard of the HIPAA Administrative Simplification Security Rule. It has five implementation specifications: Data backup plan; Disaster recovery plan; Emergency mode operation plan; Testing and revision procedures; and Applications and data criticality analysis. The first three are required; the last two are addressable. Addressable does not mean optional. Rather, an addressable implementation specification means that a covered entity must use reasonable and appropriate measures to meet the standard. Further, as HIPAA.com has noted earlier, business associates also will be required to comply with the Security Rule standards, effective February 17, 2010. If a fire swept through a covered entity’s facility, the covered entity would…
Categories SecurityLeave a commentBusiness Associate To-Do List
What are Business Associates Required to Do to Meet HIPAA Requirements? With passage of the American Recovery and Reinvestment Act (ARRA), privacy and security compliance increased significantly with business associates immediately required to comply directly with many of HIPAA’s rules. It also dramatically expanded other remedial actions (such as increasing federal government audits; granting attorneys fees in some HIPAA lawsuits; and allowing a method for individuals to recover penalties under HIPAA). Business associates also are subject to civil and criminal penalties , including a provision that allows individuals to receive financial compensation for the violation. If you are a business associate, your “To-Do” list looks similar to the list the…
Categories American Recovery and Reinvestment ActLeave a comment5010/D.0 Effective Date Tuesday, March 17, 2009; Compliance Date January 1, 2012
The version modification to the HIPAA Administrative Simplification transaction standards becomes effective Tuesday, March 17, 2009. Here are several critical things to know, drawn directly from the final rule published in the Federal Register on January 16, 2009. The final rule is available for download on the HIPAA.com site. Effective Date: The effective date [March 17, 2009] is the date that the policies set forth in this final rule take effect, and new policies are considered to be officially adopted. [74 Federal Register 3302] Compliance Date: On January 1, 2012, all covered entities will have reached Level 2 compliance, and must be fully compliant in using Versions 5010 and D.0…
Categories 5010Leave a commentNew Director of Office of Recovery Act Coordination
Dennis Williams has been selected to be HHS’ Deputy Assistant Secretary for Recovery Act Coordination. Mr. Williams most recently served as Health Resources and Services Administration’s (HRSA) Deputy Administrator, a post he held from 2002-2009. Prior to joining HRSA, Williams served as acting Assistant Secretary in HHS’ Office of the Assistant Secretary for Management and Budget (OASMB, currently ASRT) from 2001 to 2002. From 1985-2001 he served as Deputy Assistant Secretary for Budget in OASMB. The Office of Recovery Act Coordination, which reports to the Assistant Secretary for Resources and Technology (ASRT), will ensure that the Act’s requirements and OMB’s guidance are followed, including: » Making sure that reporting due…
Categories Health IT and HITECHLeave a commentOne Week from Today: 5010/D.0 Final Rule Effective Date
They’re coming: the Ides of March (the 14th); NCAA Basketball Tournament Announcement (the 15th); St. Patrick’s Day (the 17th); and 5010/D.0 Final Rule Effective Date (the 17th). If you are a covered entity, Level 1 testing begins Tuesday, March 17, 2009. Here are five things you need to do to start. Conduct a Gap Analysis. What do I need to do to become compliant on January 1, 2012? That date sounds far off, but it will be here before you know it. Unlike previous transaction contingency periods for covered entities and their trading partners, HHS has indicated that there will be no tolerance for those not ready. Read the final…
Categories 5010Leave a commentMedicare Incentives for Physicians
Amounts shown are per physician. To participate in the incentives, you must be a meaningful user. Incentive Year Adopted 2011 2012 2013 2014 2015+ 2011 $18,000 — — — — 2012 $12,000 $18,000 — — — 2013 $8,000 $12,000 $15,000 — — 2014 $4,000 $8,000 $12,000 $12,000 __ 2015 $2,000 $4,000 $8,000 $8,000 0 2016 0 $2,000 $4,000 $4,000 0 2017 0 0 0 0 0 Total $44,000 $44,000 $39,000 $24,000 0 Health Shortage Area + 10%$48,400 + 10%$48,400 +10%$42,900 +10%$26,400 As defined by the HITECH Act, a physician meaningful user is one using software that supports computerized provider order entry, uses ePrescribing, submits information to HHS on clinical quality…
Categories Health IT and HITECHLeave a commentCMS Confirms 5010 and ICD-10 Rules’ Effective Dates
In notification to the U.S. House and Senate on Thursday, March 5, 2009, Don Johnson, Acting Director, Office of Legislation of the Centers for Medicare & Medicaid Services (CMS), notified the Congress that “[i]n accordance with the White House Chief of Staff’s memorandum of January 20, 2009 entitled ‘Regulatory Review,’ a determination has been made that the effective date will not be extended and the comment period will not be reopened for either of these rules.” The effective date for each of the rules is March 17, 2009. The memorandum CMS sent to Congress follows. Beginning next Monday, March 9, HIPAA.com will have a posting daily through March 17, 2009,…
Categories 5010, Transactions & Code SetsLeave a comment
