<?xml version="1.0" encoding="utf-8"?>
	<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
	<title>An RSS Feed from melniklegal.com</title>
<description>melniklegal.com Blog</description>
<link>http://melniklegal.com/programs/weblog.cgi</link>
<category>e-commerce</category>
<copyright>Copyright melniklegal.com </copyright>
<language>en-us</language>
<lastBuildDate>Tue, 25 Aug 2026 23:05:46 EST</lastBuildDate>
<managingEditor>tatiana@melniklegal.com (Web Master)</managingEditor>
<pubDate>Tue, 25 Aug 2026 23:05:46 EST</pubDate>
<webMaster>tatiana@melniklegal.com (Tatiana)</webMaster>
<generator>e-commerce-inc.com sitebuilder blog press</generator>
<atom:link href="http://melniklegal.com/programs/blogrss.cgi" rel="self" type="application/rss+xml" />

			
<item>
<title><![CDATA[A Few Telemedicine Resources]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><font face="Arial">Following the release of the <i>Model Policy for the Appropriate Use of Telemedicine Technologies in the Practice of Medicine</i> by the Federation of State Medical Boards in April 2014<font size="2">[1]</font>, the Center for Connected Health Policy (CCHP) and the American Telemedicine Association (ATA) released telemedicine reports, providing insights into the state of telemedicine adoption, reimbursement barriers and physician licensing requirements throughout the United States.</font><br></div><div align="left"><br></div><style> .linkcolorchange A:link {color: #edad27; text-decoration: 
 underline}.linkcolorchange A:visited {color: #edad27; text-decoration: 
 underline}  .linkcolorchange A:active {text-decoration: underline}  
 .linkcolorchange A:hover {text-decoration: underline; color: #edad27;} 
 </style><table style="text-align: left; margin-left: auto; margin-right: auto;" class="linkcolorchange" align="left" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i></b></font><font color="#FFFFFF">These reports provide a great resource for those researching the regulatory environment surrounding telemedicine and telehealth. But, it is important to remember that the laws and policies in this area change frequently throughout the US. The three reports cover most of the same areas, although they are presented differently. The report from </font></font></font><font face="Arial"><font face="Arial"><font color="#FFFFFF">the Center for Connected Health sets out eleven policy areas that are generally crucial when providers are formulating a telemedicine based business model. The American Telemedicina Association reports provide some very helpful charts comparing the laws of the various states. It is also important to remember that other regulatory requirements impact the practice of telemedicine, such as state and federal data privacy and security laws as well as general medical practice requirements (<i>e.g.</i>, record keeping).<br><br>If you have questions regarding any telemedicine related issues, please <font color="#66FFFF"><a href="https://melniklegal.com/Contact.html">contact us</a></font> today.<br></font></font></font></td></tr></tbody></table><div align="left"><br></div><div align="left"><font face="Arial"><b><br>Center for Connected Health Policy</b><b> Report on <a href="https://cchpca.org/sites/default/files/resources/Fifty%20State%20Medicaid%20Report.09.2014_1.pdf"><i>State Telehealth Policies and Reimbursement Schedules: A Comprehensive Plan of the 50 States and District of Columbia</i></a> </b>(Sept. 2014)<font size="2">[2]</font></font><br><br><font face="Arial">In its second annual report, the CCHP looked at the Medicaid reimbursement policies and telemedicine laws in all 50 states. As CCHP notes, some "states have incorporated policies into law, while others have addressed issues such as definition, reimbursement policies, licensure requirements, and other important issues in their Medicaid Program Guidelines." This is a good reminder to those interested in operating in this space must take care to review all appropriate laws and guidance documents prior to starting their telemedicine based practice or otherwise offering healthcare services via telemedicine. For example, some technologies may seen appropriate until a board of medicine takes action against a provider. See e.g., </font><font face="arial" size="3"><b><a href="https://melniklegal.com/programs/weblog.cgi?showpage=1390610496_Telemedicine">Can Doctor’s Use Skype for Telemedicine? Not in Oklahoma.</a><br><br></b>CCHP observed the following major trends regarding reimbursement for live video, store-and-forward and remote patient monitoring:<br></font><ul><li><font face="arial" size="3">In comparison to forty-four states last year, currently forty-six state Medicaid programs reimburse for some form of live video. Washington DC’s Medicaid program is also now required to reimburse for live video as a result of recent legislation.</font></li><li><font face="arial" size="3">Ten state Medicaid programs offer some reimbursement for store-and-forward (states that only reimbursed for tele-radiology are not included in this count).</font></li><li><font face="arial" size="3">Thirteen state Medicaid programs offer reimbursement for remote patient monitoring compared to ten states at the time this report was first published in 2013.</font></li><li><font face="arial" size="3">Three state Medicaid programs (Alaska, Minnesota and Mississippi) reimburse for all three.</font></li></ul><font face="arial" size="3">In reviewing state telemedicine policies, the survey focused on eleven policy areas:<br></font><ul><li><font face="arial" size="3">Definition of the term telemedicine/telehealth</font></li><li><font face="arial" size="3">Reimbursement for live video</font></li><li><font face="arial" size="3">Reimbursement for store-and-forward</font></li><li><font face="arial" size="3">Reimbursement for remote patient monitoring (RPM)</font></li><li><font face="arial" size="3">Reimbursement for email/phone/fax</font></li><li><font face="arial" size="3">Consent issues</font></li><li><font face="arial" size="3">Location of service provided</font></li><li><font face="arial" size="3">Reimbursement for transmission and/or facility fees</font></li><li><font face="arial" size="3">Online prescribing</font></li><li><font face="arial" size="3">Private payer laws</font></li><li><font face="arial" size="3">Cross-state licensure</font></li></ul></div><div align="left"><font face="Arial">These policy areas are important to understand when developing a telemedicine based practice, evaluating offering services to existing patients via telemedicine, or developing a telemedicine compliance program. Physicians and physician extenders (<i>e.g.</i>, nurse practitioners, registered nurses, and others) who wish to practice across state lines must also pay close attention to the licensure requirements keeping in mind that the law is based on the physical location of the patient <i>and not the provider</i>.</font><br><br><font face="Arial" size="3"><b>American Telemedicine Association Report on <a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis--physician-practice-standards-licensure.pdf?sfvrsn=6"><i>Physician Practice Standards &amp; Licensure</i></a></b> <font size="2">[3]</font></font><br><br><font face="Arial">This report evaluated the physician licensure laws in the states for both in-state and out-of state practice. The report also looked at the physician-patient encounter requirements when using telemedicine, telepresenter requirements that may be more stringent as compared to in-person services, and informed consent requirements. The report provides a summary chart grading each state on a A - F scale. </font><br><br><font face="Arial" size="3"><b>American Telemedicine Association Report on <a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis---coverage-and-reimbursement.pdf?sfvrsn=6"><i>Coverage &amp; Reimbursement</i></a></b> <font size="2">[4]</font></font><br><font face="Arial"><br></font></div><div align="left"><font face="Arial">Payment and coverage remains one of the biggest obstacles to the widespread adoption of telemedicine. In this report, the ATA "extracts and compares telemedicine coverage and reimbursement standards for every state in the U.S." Notably, as the ATA explained:</font><br><ul><li><font face="Arial">Of the 21 states that have telemedicine parity laws for private insurance, only 15 of them and D.C. scored the highest grades indicating policies that authorize state-wide coverage, without any provider or technology restrictions. Over half of the country, 29 states, ranked the lowest with failing scores for having no parity law in place.</font></li></ul><ul><li><font face="Arial">Forty-seven state Medicaid programs have some type of coverage for telemedicine. Only five states and D.C. scored the highest grades by offering more comprehensive coverage, with few barriers for telemedicine-provided services . Connecticut, Hawaii, Idaho, Iowa, Nevada, Rhode Island, Utah and West Virginia ranked the lowest with failing scores in this area.</font></li></ul><ul><li><font face="Arial">One disappointing observation includes the lack of coverage and reimbursement for telemedicine under state employee health plans. Eighty-two percent of the country is ranked the lowest with failing scores including Arkansas which will only cover the use of store-and-forward for diabetic retinopathy screening, and Nebraska which requires their plans to cover autism treatment via telemedicine.</font></li></ul><ul><li><font face="Arial">Regarding Medicaid regulations, states are slowly moving away from the traditional hub-and-spoke model and allowing a variety of technology applications. Twenty-three states and D.C. do not specify a patient setting or patient location as a condition for payment of telemedicine. Aside from this, 21states recognize the home as an originating site, while 13 states recognize schools and/or school-based health centers as an originating site. Utah ranks the lowest with only one eligible originating site </font></li></ul><ul><li><font face="Arial">South Dakota has the highest ranking for Medicaid operations because its program covers telemedicine when providers use interactive audio-video, store-and-forward, remote patient monitoring, e-mail, fax, or phone mail. Fifty-seven percent of the country ranked the lowest with failing scores either because they only cover synchronous only or provide no coverage for telemedicine at all. Idaho, Missouri, North Carolina and South Carolina prohibit the use of cell phone video to facilitate a telemedicine encounter.<font size="2">[5]</font></font><br></li></ul><br><font face="Arial">-------------------------------------------</font><br><font face="Arial" size="2">[1] Federation of State Medical Boards, Model Policy for the Appropriate Use of Telemedicine Technologies in the Practice of Medicine (April 2014), <i>available at </i><a href="https://www.fsmb.org/Media/Default/PDF/FSMB/Advocacy/FSMB_Telemedicine_Policy.pdf">https://www.fsmb.org/Media/Default/PDF/FSMB/Advocacy/FSMB_Telemedicine_Policy.pdf</a>.</font><br><br><font face="Arial" size="2">[2] Center for Connected Health Policy, State Telehealth Policies and Reimbursement Schedules: A Comprehensive Plan of the 50 States and District of Columbia (Sept. 2014), <i>available at</i> <a href="https://cchpca.org/sites/default/files/resources/Fifty%20State%20Medicaid%20Report.09.2014_1.pdf">https://cchpca.org/sites/default/files/resources/Fifty%20State%20Medicaid%20Report.09.2014_1.pdf</a>.</font><br><br><font face="Arial" size="2">[3] American Telemedicine Association, Physician Practice Standards &amp; Licensure (Sept. 2014), <i>available at</i> <a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis--physician-practice-standards-licensure.pdf?sfvrsn=6">https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis--physician-practice-standards-licensure.pdf?sfvrsn=6</a>.</font><br><br><font face="Arial" size="2">[4] </font><font face="Arial" size="2"><font face="Arial" size="2">American Telemedicine Association, Coverage &amp; Reimbursement (Sept. 2014), <i>available at</i> </font><a href="https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis---coverage-and-reimbursement.pdf?sfvrsn=6">https://www.americantelemed.org/docs/default-source/policy/50-state-telemedicine-gaps-analysis---coverage-and-reimbursement.pdf?sfvrsn=6</a>.</font><br><br><font face="Arial" size="2">[5] <i>Id</i>. at 2-3.</font><br><font face="Arial">-------------------------------------------<br></font><br><font face="Arial"><font face="Arial"><font size="2">Posted by Tatiana Melnik on October 28, 2014.<br><br><br></font></font><br></font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1414554679_Telemedicine.html</link>
<guid>http://melniklegal.com/weblog/1414554679_Telemedicine.html</guid>
<pubDate>Tue, 28 Oct 2014 23:51:19 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Eligible Professionals May Apply for a Hardship Exception from Meaningful Use Penalties]]></title>
<description><![CDATA[
 
 
 
 
     <div align="left"><div><table border="0"><tbody><tr><td align="left" valign="top"><font face="Arial">As part of the American Recovery and Reinvestment Act of 2009 (ARRA), Congress mandated that payment adjustments be applied to Medicare eligible professionals (EPs) who are not meaningful users of Certified EHR Technology under the Medicare EHR Incentive Programs.<br><br>Medicare EPs who are not meaningful users will be subject to a payment adjustment beginning on January 1, 2015.<br><br>But, exceptions are available under certain limited circumstances.<br></font></td><td valign="top"><img src="https://melniklegal.com/images/Meaningful_Use_Hardship.jpg"><br></td></tr></tbody></table><font face="Arial"><b><br>Which practitioners are subject to MU payment adjustments and when do the payment adjustments begin?</b></font><br></div><div><ul><li><font face="Arial">EPs who participate in the Medicare EHR Incentive Program.</font></li><li><font face="Arial">EPs who can participate in <i>either</i> the Medicare or Medicaid EHR Incentive Programs.</font></li><li><font face="Arial">These payment adjustments will be <font color="#006600"><b>applied beginning on January 1, 2015</b></font>, for Medicare EPs.</font></li></ul></div><div><font face="Arial"><b>Which practitioners are NOT subject to MU payment adjustments?</b></font><br><ul><li><font face="Arial">Medicaid EPs who can only participate in the Medicaid EHR Incentive Program and do not bill Medicare.</font></li></ul><p><b><font face="Arial">How much are the payment adjustments and how are they applied?</font></b></p><p><font face="Arial">The payment adjustment will be applied to the Medicare physician fee schedule (PFS) amount for covered professional services furnished by the EP during the year (including the fee schedule amount for purposes of determining a payment based on the fee schedule amount). <br></font></p><p><font face="Arial">The payment adjustment is 1% per year and is cumulative for every year that an EP is not a meaningful user. Depending on the total number of Medicare EPs who are meaningful users under the EHR Incentive Programs after 2018, the maximum cumulative payment adjustment can reach as high as 5%.</font><br></p></div><font face="Arial">For additional details on MU payment adjustments, <a href="https://melniklegal.com/av/PaymentAdj_HardshipExcepTipSheetforEP_2013.pdf">please see the Payment Adjustments and Hardships Exceptions Tipsheet for Eligible Professionals released by CMS</a>.<br><br><b>Are there any </b></font><font face="Arial"><b><b><font face="Arial">payment adjustment </font></b>exceptions available for Medicare EPs who cannot meet MU deadlines?</b><br><br><b>Yes</b>. EPs who cannot meet MU deadlines may be eligible to receive a hardship exception from CMS. But, CMS has explained that </font><font face="Arial"><font face="Arial">these exceptions will be granted only under specific circumstances and only if </font></font><font face="Arial"><font face="Arial"><font face="Arial">CMS determines that providers have demonstrated that those circumstances pose a significant barrier to their achieving meaningful use.<br><br>Hardship exceptions are available in the following categories:<br></font></font></font><div><ul><li><font face="Arial"><b>Infrastructure </b>- EPs must demonstrate that they are in an area without sufficient internet access or face insurmountable barriers to obtaining infrastructure (e.g., lack of broadband).</font></li><li><font face="Arial"><b>New EPs</b> - Newly practicing EPs who would not have had time to become meaningful users can apply for <u><i>a 2-year limited exception</i></u> to payment adjustments. Thus EPs who begin practice in calendar year 2015 would receive an exception to the penalties in 2015 and 2016, but would have to begin demonstrating meaningful use in calendar year 2016 to avoid payment adjustments in 2017.</font></li><li><font face="Arial"><b>Unforeseen Circumstances</b> - Examples may include a natural disaster or other unforeseeable barrier.</font></li><li><font face="Arial"><b>Patient Interaction</b> - Lack of face-to-face or telemedicine interaction with patients; Lack of follow-up need with patients.</font></li><li><font face="Arial"><b>Practice at Multiple Locations</b> - Lack of control over availability of CEHRT for more than 50% of patient encounters</font><br></li></ul></div><font face="Arial"><font face="Arial"><font face="Arial">CMS will be providing additional details on the requirements and application process in the future.</font></font><br><br><br><br><br></font></div>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1387148396_Meaningful-Use.html</link>
<guid>http://melniklegal.com/weblog/1387148396_Meaningful-Use.html</guid>
<pubDate>Sun, 15 Dec 2013 17:59:56 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Ponemon Study Finds Increase in Healthcare Data Breaches]]></title>
<description><![CDATA[
 
 
 
 <font face="Arial, Helvetica, sans-serif" size="3">The costs of data 
 breaches continue to rise. According to a December 2012 study by the 
 Ponemon Institute, the average economic impact of a healthcare data 
 breach over the past two years was $2.4 million, which was an increase 
 of more than $400,000 over 2010. More organizations continue to have 
 multiple data breaches, with 45% of organizations reporting that they 
 have had more than 5 data breaches over the past two years.<br><br>Resources:<br></font><div align="left"><ul><li><a href="https://www.ponemon.org/library/third-annual-patient-privacy-data-security-study"><font face="Arial">Ponemon Institute Third Annual Bechmark Study on Patient Privacy and Data Security (Dec. 2012)</font></a><font face="Arial"> (downloadable from IDExperts with free registration)</font><br></li></ul></div>
   
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1381603080_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1381603080_Data-Breach.html</guid>
<pubDate>Sat, 12 Oct 2013 14:38:00 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[OCR Reminds Covered Entities to Choose Friends Carefully]]></title>
<description><![CDATA[
 
 
 
 
     <font face="Arial"> <i><b>Lack of Technical Controls Leads to Two Settlements with OCR for $4.8M.</b></i> <br><br>On May 8, 2014, the Office of Civil Rights (OCR) announced a settlement with New York and Presbyterian Hospital (NYP) and Columbia University (CU) involving allegation of violations of the HIPAA Privacy and Security Rules. Under the Resolution Agreements, NYP will pay $3 million and CU will pay $1.5 million to settle the investigations.<br></font><br><table style="text-align: left; margin-left: auto; margin-right: auto;" border="0"><tbody><tr><td style="border: 1px solid #edad27; padding:3px;" color="#FFFFFF" size="3" bgcolor="#001c31" valign="top"><font face="Arial"><font face="Arial"><font color="#FFCC00"><b><i>A few preliminary comments....</i> </b></font><font color="#FFFFFF">This settlement is a good reminder that covered entities, business associates, and subcontractors must choose their partners carefully. As more organizations implement data sharing agreements, form strategic healthcare IT partnerships (e.g., those involving big data, analytics, etc.), and otherwise store their data with vendors, data breach issues are inevitable. Healthcare providers and vendors must carefully review their agreements to ensure that each party bears the appropriate amount of risk. Provisions related to indemnification, limitation of liability, damages caps, and insurance requirements should be reviewed with special attention.</font></font></font><br></td></tr></tbody></table><br><font face="Arial">NYP and CU are separate covered entities, but have an affiliation - generally called New York Presbyterian Hospital/Columbia University Medical Center - where CU faculty members serve as attending physicians at NYP.&nbsp; Under this arrangement, "NYP and CU operate a shared data network and a shared network firewall that is administered by employees of both entities. The shared network links to NYP patient information systems containing ePHI."[1]<br><br>NYP and CU filed a joint breach report in September 27, 2010 (<b>yes, 2010</b> - compare that to the 2014 settlement date!) following notification that the information of 6,800 patients, including patient status, vital signs, medications, and laboratory results, was available online. Specifically, according to the OCR Press Release:<br></font><blockquote><font face="Arial">The investigation revealed that the breach was caused when a physician employed by CU who developed applications for both NYP and CU attempted to deactivate a personally-owned computer server on the network containing NYP patient ePHI.&nbsp; Because of a lack of technical safeguards, deactivation of the server resulted in ePHI being accessible on internet search engines.&nbsp; <b>The entities learned of the breach after receiving a complaint by an individual who found the ePHI of the individual's deceased partner, a former patient of NYP, on the internet</b>.</font></blockquote><font face="Arial">OCR notified each of the entities on November 5, 2010 that it would launching an investigation. According to the Resolution Agreement with each of the entities, the OCR found the following conduct problematic:<br><br></font><table style="border: 1px solid #000000;" cellpadding="5" cellspacing="5"><tbody><tr><td align="center" valign="top"><font face="Arial"><b>New York Presbyterian Hospital</b></font></td><td align="center" valign="top"><font face="Arial"><b>Columbia University Medical Center<br></b></font></td></tr><tr><td align="left" valign="top"><div align="left"><font face="Arial">a. NYP impermissibly disclosed the ePHI of 6,800 patients to Google and other Internet search engines when a computer server that had access to NYP ePHI information systems was errantly reconfigured.</font><br><br><font face="Arial">b. NYP failed to conduct an accurate and thorough risk analysis that incorporates all IT equipment, applications, and data systems utilizing ePHI.</font><br><br><font face="Arial">c. NYP failed to implement processes for assessing and monitoring all IT equipment, applications, and data systems that were linked to NYP patient databases prior to the breach incident, and failed to implement security measures sufficient to reduce the risks and vulnerabilities to its ePHI to a reasonable and appropriate level.</font><br><br><font face="Arial">d. NYP failed to implement appropriate policies and procedures for authorizing access to its NYP patient data bases, <u>and it failed to comply with its own policies on information access management</u>.<font size="2">[2] (emphasis added)<br><br></font></font><div align="left"><font face="Arial"><font color="#993399"><b>NYP settlement: $3 million</b></font>.<br></font></div></div><font face="Arial"></font></td><td align="left" valign="top"> <font face="Arial">a. CU failed to conduct an accurate, and thorough risk analysis that incorporates all IT equipment, applications and data systems utilizing ePHI, including the server accessing NYP-ePHI.<br><br>b. CU failed to implement processes for assessing and monitoring IT equipment, applications and data systems that were linked to NYP patient data bases prior to the breach incident and failed to implement security measures sufficient to reduce the risks of inappropriate disclosure to an acceptable level.<font size="2">[3]<br><br></font></font><font face="Arial"><font color="#993399"><b>CU settlement: $1.5 million</b></font>.</font></td></tr></tbody></table><font face="Arial"><br></font><font face="Arial"><font face="Arial">As is the usual course, each Resolution Agreement includes a Corrective Action Plan. Each of the parties must take the following steps:</font></font><br><font face="Arial"><font face="Arial"><br></font></font><table style="border: 1px solid #000000;" border="0" cellpadding="5" cellspacing="5"><tbody><tr><td align="center" valign="top"><font face="Arial"><b>New York Presbyterian Hospital</b></font></td><td align="center" valign="top"><font face="Arial"><b>Columbia University Medical Center<br></b></font></td></tr><tr><td align="left" valign="top"><font face="Arial"><b>Modify Existing Risk Analysis Process.</b><br>. . . NYP shall conduct a comprehensive and thorough risk analysis of security risks and vulnerabilities that incorporates all electronic equipment, data systems, and applications controlled, administered or owned by NYP, its workforce members, and affiliated staff that contains, stores, transmits or receives NYP ePHI. NYP shall develop a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI which will then be incorporated in its Risk Analysis. . . . <br><br><b>Develop and Implement a Risk Management Plan</b>.<br>Within ninety (90) calendar days of the completion of the Risk Analysis . . . , NYP shall develop an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities found in its risk analysis. The plan shall include a process and timeline for implementation, evaluation, and revision. The plan shall be forwarded to HHS for its review . . . <br><br><b><br>Review and Revise Policies and Procedures on Information Access Management. </b><br>. . . NYP shall review, and to the extent necessary, revise its internal policies and procedures for authorizing access to NYP ePHI. The revised policies and procedures shall include a specific process to be followed by workforce members and affiliated staff for requesting authorization to access NYP ePHI (including criteria for granting such access), obtaining approval of such request, documenting such request, and conducting periodic monitoring of ePHI usage. NYP shall forward its policies and procedures for authorizing access to all NYP ePHI to HHS for its review . . . <br><b><br><br>Implement Process for Evaluating Environmental and Operational Changes.</b><br>. . . NYP shall develop a process to evaluate any environmental or operational changes that affect the security of NYP ePHI.<br><br><b>Review and Revise Policies and Procedures on Device and Media Controls.</b><br>. . . NYP shall review, and to the extent necessary, revise its policies and procedures related to the use of hardware and electronic media including, but not limited to laptops, servers, tablets, mobile phones, USB drives, external hard drives, DVDs and CDs that may be used to access, store, download, or transmit NYP ePHI. The revised policies shall identify criteria for the use of such hardware and electronic media and procedures for obtaining authorization for the use of personal devices and media that utilize NYP ePHI systems. The policies shall also address security responsibilities, including disposal and reuse of personal devices and media and regular compliance monitoring. NYP shall forward its policies and procedures to HHS for its review . . .<br><br><b>Develop an Enhanced Privacy and Security Awareness Training Program.</b><br>1. . . NYP shall augment its existing mandatory Health Information Privacy and Security Awareness Training Program (for workforce members and affiliated staff that have access to protected health information including ePHI, to train on the necessity and existence of prohibitions on the purchase, use or administration of computer equipment that accesses NYP ePHI, except under the explicit management of NYP IT personnel ("the Training Program"). As before, the Training Program shall also include general instruction on compliance with the HIPAA Privacy, Security, and Breach Notification Rules and NYP health information security policies and procedures, and shall also include training on new policies and procedures, if any, developed as required by . . . this CAP.<br><br>2. Under the Training Program, NYP shall provide training to all workforce members and affiliated staff as soon as possible but no later than one year of the Effective Date and yearly thereafter. Any workforce member or affiliated staff that commences working for NYP, or that are given access to ePHI, after the development of the Training Program shall be trained within thirty (30) calendar days of the commencement of their employment or affiliation with NYP.<br><br>3. Each individual who is required to attend training shall certify, in writing or in electronic form, that he or she has received the required training and the date training was received. NYP shall retain copies of such certifications for no less than six years following the date training was provided.<br><br>4. NYP shall review the Training Program, including all training materials developed as part of the program, annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments.</font><br></td><td align="left" valign="top"><b> </b><font face="Arial"><b>Conduct a thorough Risk Analysis.</b><br>. . . CU shall conduct a comprehensive and thorough risk analysis of security risks and vulnerabilities that incorporates all electronic equipment, data systems and applications controlled, administered or owned by CU, its workforce members that contains, stores, transmits or receives CU ePHI. CU shall develop a complete inventory of all electronic equipment, data systems, and applications that contain or store ePHI which will then be incorporated in its Risk Analysis. . . .<br><br><b><br>Develop and Implement a Risk Management Plan.</b><br>Within ninety (90) calendar days of completion of the Risk Analysis . . . , CU shall develop an organization-wide risk management plan to address and mitigate any security risks and vulnerabilities found in its risk analysis. The plan shall include a process and timeline for implementation, evaluation, and revision. The plan shall be forwarded to HHS for its review . . .<br><br><b>Review and Revise Policies and Procedures on Information Access Management.</b><br>. . . CU shall review and to the extent necessary revise its internal policies and procedures for authorizing access to CU ePHI. The revised policies and procedures shall include a process to be followed by workforce members for requesting authorization to access CU ePHI (including criteria for granting such access), obtaining approval of such request, documenting such request, and conducting periodic monitoring of ePHI usage. CU shall forward its policies and procedures for authorizing access to all CU ePHI to HHS for its review . . . <br><br><br><b>Compliance with Evaluation Standard.</b><br>. . . CU shall develop a process to evaluate any environmental or operational changes that affect the security of CU ePHI. <br><br><b><br>Review and Revise Policies and Procedures on Device and Media Controls.</b><br>. . . CU shall review and to the extent necessary, revise its policies and procedures related to the use of hardware and electronic media including, but not limited to laptops, servers, tablets, mobile phones, USB drives, external hard drives, DVDs and CDs that may be used to access, store, download or transmit CU ePHI. The revised policies shall identify criteria for the use of such hardware and electronic media and procedures for obtaining authorization for the use of personal devices and media that utilized CU ePHI systems. The policies shall also address security responsibilities, including disposal and reuse of personal devices and media and regular compliance monitoring. CU shall forward its policies and procedures to HHS for its review . . . <br><br><b>Develop a Privacy and Security Awareness Training Program.</b><br>1. . . . CU shall develop a mandatory Health Information Privacy and Security Awareness Training Program (the Training Program) for workforce members that have access to protected health information including ePHI. The Training Program shall include instruction on compliance with the HIPAA Privacy, Security, and Breach Notification Rules and CU health information security policies and procedures, and shall particularly include training on the policies and procedures developed as required by . . .&nbsp; this CAP.<br><br>2. Under the Training Program, CU shall provide training to all workforce members as soon as possible but no later than one year of the Effective Date and yearly thereafter. Any workforce member that commence working for CU after the development of the Training Program shall be trained within thirty (30) calendar days of the commencement of their employment with CU.<br><br>3. Each individual who is required to attend training shall certify, in writing or in electronic form, that he or she has received the required training and the date train ing was received. CU shall retain copies of such certifications for no less than six years following the date training was provided.<br><br>4. CU shall review the Training Program, including all training materials developed as part of the program, annually, and, where appropriate, update the training to reflect changes in Federal law or HHS guidance, any issues discovered during audits or reviews, and any other relevant developments. </font><br></td></tr></tbody></table><font face="Arial"><br>For a chart summary of the OCR fines as well as other HIPAA related litigation, please see<a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html"> </a></font><font face="Arial"><a href="https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html">https://melniklegal.com/list_of_HIPAA_fines_and_penalties.html</a>. <br><br><font size="2">---------------------<br>[1] Press Release, Office of Civil Rights (May 8, 2014), <i>available at</i> <a href="https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/jointbreach-agreement.html">https://www.hhs.gov/ocr/privacy/hipaa/enforcement/examples/jointbreach-agreement.html</a>.<br><br>[2] <a href="https://melniklegal.com/av/2014_OCR-ny-and-presbyterian-hospital-settlement-agr.pdf">Resolution Agreement between HHS Office of Civil Rights and </a></font></font><font face="Arial"><font size="2"><a href="https://melniklegal.com/av/2014_OCR-ny-and-presbyterian-hospital-settlement-agr.pdf"><font face="Arial">New York and Presbyterian Hospital</font></a><font face="Arial"> (agr. undated, press release from May 8, 2014).</font><br><br>[3] <a href="https://melniklegal.com/av/2014_OCR-columbia-university-resolution-agr.pdf">Resolution Agreement between HHS Office of Civil Rights and Columbia University</a> (agr. undated, press release from May 8, 2014).<br></font></font><font face="Arial"><font size="2"><font face="Arial"><font size="2">---------------------<br></font></font></font></font><br><font face="Arial"><font size="2"><font face="Arial"><font size="2"><font face="Arial"><font size="2">Posted by: Tatiana Melnik on May 8, 2014</font></font><br></font></font></font> </font>    
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1399561833_Data-Breach.html</link>
<guid>http://melniklegal.com/weblog/1399561833_Data-Breach.html</guid>
<pubDate>Thu, 08 May 2014 11:10:33 EST</pubDate>
</item>
			
			
			
<item>
<title><![CDATA[Is the HIPAA EMR/EHR Mandate Required by ALL Medical Providers?]]></title>
<description><![CDATA[
 
 
 
 
  <title>Is the HIPAA EMR/EHR Mandate Required by ALL Medical 
 Providers?</title>  <div align="left"><div><font face="Arial"><b>Recently, an interesting question was posed to 
 me by a colleague regarding a so-called 'HIPAA EMR/EHR mandate' and 
 whether all medical providers are required to comply, or only those 
 providers that accept Medicare and/or Medicaid.</b> 
 </font><br></div><font face="Arial"><br></font><font face="Arial">To the 
 best of my knowledge, <u><b>there is no such thing as a 
 "HIPAA EMR/EHR mandate."</b></u></font><font face="Arial"> This question seems to be conflating the HIPAA privacy,
  security, and breach notification requirements with the EHR Incentive 
 Program. Under the Medicare EHR Incentive Program, providers are 
 required to initiate participation by 2014 to avoid Medicare payment 
 adjustments that begin in 2015. See here for a timeline - <a href="https://www.cms.gov/Regulations-and-Guidance/Legislation/EHRIncentivePrograms/downloads/EHRIncentProgtimeline508V1.pdf
  
 ">https://www.cms.gov/Regulations-and-Guidance/Legislation/EHRIncentivePrograms/downloads/EHRIncentProgtimeline508V1.pdf
  </a>(excerpted below). Similarly, under the Medicaid Incentive 
 Program, providers are required to initiate participation by 2016. There
  are no payment adjustments for providers who are only eligible for the 
 Medicaid program.<br>&nbsp;<br></font><div align="center"><font face="Arial"><img src="https://melniklegal.com/images/CMS_EHR_Milestones.jpg"></font><br></div><font face="Arial"><br><br></font><div><font face="Arial">Further, there is no mandate for medical providers to 
 participate in the EHR Incentive Program. To the extent that a provider 
 accepts Medicare, the provider can take the adjustment. A number of 
 small medical providers have opted to take the adjustment because the 
 EHR subsidy is not enough to cover the cost of EHR implementation. 
 Alternatively, the provider can stop accepting Medicare and transition 
 his or her practice to a cash-only, concierge style practice, or private
  insurance only practice.</font><br><font face="Arial">&nbsp;</font><br><font face="Arial">How a provider is paid has no impact on whether a 
 provider is subject to HIPAA compliance. All medical providers that 
 transmit protected health information electronically are required to 
 comply with HIPAA.</font><br><br><br><div align="left"><font face="Arial"><font size="2">Posted by 
 Tatiana Melnik May 5, 
 2014.</font></font><br></div></div></div><font face="Arial">  </font>  
 
 
   
 
 
 
 
 
 ]]></description>
<link>http://melniklegal.com/weblog/1399311464_FAQ.html</link>
<guid>http://melniklegal.com/weblog/1399311464_FAQ.html</guid>
<pubDate>Mon, 05 May 2014 13:37:44 EST</pubDate>
</item>
			
			
</channel>
</rss>