There are a number of tools on the market to assist covered entities (CE) and business associates (BA) in addressing their compliance needs. Solutions range from large governance, risk, and compliance programs to tools that assist in the development of a compliance program. When it comes to ongoing compliance management, Ostendio's My Virtual Compliance Manager™ (MyVCM™) offers a solution that is more than just a tool for an occasional look at the compliance stance of an organization.
HIPAA originally recognized the business associate (BA) as a contractor of a covered entity (CE), but did not mandate direct accountability to the regulations. This put the onus on a CE to ensure, contractually, that its BAs met applicable requirements and supported their CE clients' compliance. When the Privacy and Security Rules first became effective, many CEs accepted BA contracts (BAC) (sometimes also called BA agreements [BAA]) from their BAs. Some BAs were actually quite adamant about having the CE sign their BAC. Although it was the obligation of a CE to initiated the BAC and the CE was liable under the law for compliance, in most cases, BAs offered a BAC that met the legal requirements and often looked like the model offered by HHS. If this was not the case or if either party wanted additional provisions, the CE and the BA negotiated a contract. No provisions required by HIPAA could be removed or changed, but other provisions could be added.
Q: Is it permissible to write down a patient's pending exams (e.g., MRI, ultrasound) on the patient boards located by the patient's bed in his or her room even if that patient has a roommate?
The 2-midnight rule may get a little tweak if the proposals in CMS' 2016 OPPS proposed rule comes to fruition. The rule proposes that physicians now be granted a little more flexibility when it comes to ordering inpatient admissions, even when the stay is expected to be less than two midnights?provided of course that the stay is justifiable from a medical standpoint and the physician clearly documents his or her thinking on the case.
A few days after Briefings on APCs conducted the interview that appeared in last month's issue with W. Jeff Terry, MD, an AMA delegate from Mobile, Alabama, the AMA and CMS announced an accord regarding ICD-10.
In a joint announcement, the organizations said that CMS would not audit or deny Part B physician fee schedule claims for one year after ICD-10-CM implementation due to lack of specificity. While physicians will still be responsible for meeting medical necessity and LCD and NCD requirements, valid ICD-10-CM codes that include the appropriate first three characters will be sufficiently specific for Medicare claims.
One of the biggest challenges to the provider community, including hospitals and critical access hospitals (CAH), is keeping up to date with current regulatory requirements, particularly when it comes to rules on coverage, coding, billing, and payment for services provided to beneficiaries under federal healthcare programs, including Medicare and Medicaid. For those of you who have taken one of our hospital or CAH Medicare Boot Camps, you probably remember discussing this early during the week, when we identified the major official sources of authority on Medicare rules, as well as some tips about how to efficiently keep yourselves up to date.