YOUR BUSINESS AUTHORITY
Springfield, MO
Michael Cordonnier and Tina Fowler are attorneys with Lathrop & Gage LC in Springfield.
Every employer that offers health benefits or health services to its employees is affected by regulations under the Health Insurance Portability and Accountability Act Administrative Simplification Rules. While many in the health care industry have been forced to comply with HIPAA privacy requirements for more than a year, small health plans with annual receipts of $5 million or less (health plans with either $5 million in receipts or $5 million in claims) faced their first deadline for compliance with the Privacy Rule on April 14.
Many employers ignored this deadline, assuming that the rule applied only to entities within the health care industry, or assuming that having a third-party administrator protected them from any obligations under the rule. Neither assumption is correct.
For employers offering fully insured plans, discuss the following with your insurance company:
the need to amend plan documents to describe privacy protection of health information maintained and created by the plan and the appropriate separation between the plan and the employer;
the need to certify compliance with plan separation activities;
the need to coordinate with the health insurance issuer regarding employee requests for access to health plan documents;
any issues regarding access to necessary information by the employer's health plan brokers or other agents; and
if the employer wishes to assist employees with claims issues, the need for tying exchanges of information between the plan and the employer to an employee's authorization.
Employers with self-insured plans with a third-party administrator (or fully insured plans receiving more than summary health information) should designate a privacy official to oversee, develop and implement the employer's privacy plan; and amend plan documents to establish the permitted and required uses and disclosures of protected health information. The plan documents must be amended to state that the plan sponsor/employer has agreed to:
not use or further disclose protected health information - or PHI - other than as permitted or required by the plan documents or by law;
ensure that any agents provided PHI from the plan agree to the same restrictions and conditions that apply to the employer;
not use or disclose the information for employment related activities and decisions, or in connection with any other benefit or plan;
report to the plan any use or disclosure of information inconsistent with the uses or disclosures provided for in the plan documents;
make PHI available to beneficiaries who request access;
make PHI available for amendment and incorporate amendments;
make available any information required by the plan to provide an accounting of disclosures to a plan beneficiary;
make its internal practices, books and records relating to the use and disclosure of PHI received from the plan available for purposes of determining the plan's compliance with HIPAA;
if feasible, return or destroy PHI received from the plan when no longer needed for the purpose for which the disclosure was made, or if such destruction or return is not feasible, limit uses and disclosures to those purposes that make the return or destruction infeasible; and
ensure the plan documents show adequate separation between the employer and the plan.
These employers also should:
provide certification by the employer that plan documents have been amended to the Third Party Administrator (keep a copy of such certification in applicable health plan documentation);
ensure that plan agreements mirror the changes made to the plan documents and allow the employer access to PHI as outlined in the plan document;
develop a Notice of Privacy Practices for distribution to plan participants;
designate certain employees or classes that can receive, maintain and retrieve PHI from the plan (limit access to the designated employees and create policies and procedures to enforce such limitations through disciplinary action);
ensure business associate agreements are in place and are signed by all business associates of the plan, such as third-party administrator or brokers;
ensure similar restrictions such as those in the business associate agreement are in place for agents or subcontractors who may receive PHI from the employer;
train work force employees with access to PHI regarding their obligations under the Privacy Rule and the employer's policies and procedures; and
develop policies and procedures related to HIPAA compliance.
Covered health plans that fail to comply risk enforcement action by the Department of Health and Human Services. Entities may be fined up to $100 for each individual violation, with a maximum fine of $25,000 for violations of a single standard. If violations were known, fines can reach $50,000 and violators can face jail time of up to one year.
This installment of Springfield Business Journal’s Architects & Engineers Project Report showcases 26 endeavors by area design and engineering professionals.
Banker pleads guilty to fraud scheme
Longtime employee sues Ozarks Tech, alleges retaliation
Cavender’s opens hat shop in southeast Springfield
Caterpillar to acquire John Fabick Tractor Co.
Eric Schmitt introduces Modern Skies Act
Springfield airport to cut the ribbon on $35M in construction projects