Medical Informatics Engineering, Inc., an Indiana-based medical records service has agreed to a $100,000 settlement with OCR and a $900,000 multi-state settlement with 16 state attorney general offices for a HIPAA breach that compromised the protected health information of approximately 3.5 million people.
Q: We have a patient who received a pancreas transplant for the treatment of diabetes. The patient was later admitted to the hospital for treatment of an unrelated kidney stone. Would I still need to assign the ICD-10-CM code for diabetes as a chronic condition based on the patient’s medical history?
Commercial and government payers track chronic conditions using Hierarchical Condition Category (HCC), and providers can track HCCs to better monitor and project reimbursement and compliance.
Q: I have heard that HIPAA says covered entities must keep data backups a minimum of five miles away from the original site where the data was collected. Is this correct? Are there any restrictions or guidance about the location of data backups?
Q: I work for a behavioral health recovery center, and many of our programs fall under 42 CFR Part 2, as we provide substance use services. Sometimes a referring agency follows up to ask if a client has scheduled an appointment. Can we confirm that a patient has made an appointment? Do referral appointments like this fall under PHI?