Disclaimer
This publication is designed to provide general information on pertinent legal topics. The statements made are provided for educational purposes only. They do not constitute legal or financial advice nor do they necessarily reflect the views of Holland & Hart LLP or any of its attorneys other than the author. This publication is not intended to create an attorney-client relationship between you and Holland & Hart LLP. Substantive changes in the law subsequent to the date of this publication might affect the analysis or commentary. Similarly, the analysis may differ depending on the jurisdiction or circumstances. If you have specific questions as to the application of the law to your activities, you should seek the advice of your legal counsel.
Privacy Policy
View our privacy policy.


Prompt Pay Discounts
/in Fraud and Abuseby Kim C. Stanger, Holland & Hart LLP
Healthcare providers sometimes offer “prompt pay” discounts to encourage patients to pay their bills within a certain period, including outstanding copayments or deductible amounts. Such programs should be structured appropriately to ensure compliance with applicable laws and payer contracts.
1. Federal Fraud and Abuse Laws. If the discount is offered to induce the patient to receive other services payable by Medicare, Medicaid, or other government programs, the discount may violate federal fraud and abuse laws. The federal Anti-Kickback Statute (“AKS”) prohibits knowingly offering any remuneration to persons to induce or reward referrals for items or services covered by federal health programs, including Medicare or Medicaid. See 42 U.S.C. § 1370a-7b. The AKS applies to discounts offered to federal program beneficiaries if the purpose of the discount is to induce referrals. See, e.g., OIG, Special Advisory Bulletin: Offering Gifts and Other Inducements to Beneficiaries (8/30/02); OIG, Special Fraud Alert regarding Routine Waiver of Part B Co-Pays and Deductibles (12/19/94). Similarly, the federal Civil Monetary Penalties Law (“CMPL”) prohibits knowingly offering anything of value to Medicare or Medicaid beneficiaries that is likely to influence the beneficiary’s selection of a particular provider of services payable by Medicare or Medicaid, including waivers or discounts of coinsurance or deductible amounts. See 42 U.S.C. § 1320a-7a(a)(5); 42 C.F.R. § 1003.102 and .103(b)(13). Read more
HIPAA Privacy Rule Modified to Permit Covered Entities to Make Certain Limited Disclosures to the National Instant Criminal Background System
/in HIPAAby Teresa Locke, Holland & Hart LLP
On Tuesday, January 6, 2016, the U.S. Department of Health and Human Services (the Department) issued a final rule, effective February 5, modifying the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule to expressly permit – but not require – certain HIPAA covered entities to disclose to the National Instant Criminal Background System (NICS) certain personal health information (PHI) related to individuals who are subject to a Federal “mental health prohibitor” that disqualifies them from shipping, transporting, possessing, or receiving a firearm. Among the persons subject to the Federal mental health prohibitor established under the Gun Control Act of 1968 and implementing regulations issued by the U.S. Department of Justice are individuals who have been: (a) involuntarily committed to a mental institution; (b) found incompetent to stand trial or not guilty by reason of insanity; or (c) otherwise determined by a court, board, commission, or other lawful authority to be a danger to themselves or others or to lack the mental capacity to contract or manage their own affairs as a result of marked subnormal intelligence or mental illness, incompetency, condition, or disease. Fearing that States might not be fully reporting relevant information to the NCIS because of actual or perceived barriers related to HIPAA, the Department enacted the revision to the Privacy Rule by adding a new category of permitted disclosures to 45 CFR 164.512(k). The new rule is narrowly tailored to appropriately balance public safety goals with important patient privacy interests to ensure that individuals are not discouraged from seeking voluntary treatment for mental health issues.
The new category of permitted disclosures is very limited in scope, applying only to a specific subset of HIPAA covered entities who, under narrow circumstances, may provide discrete personal health information to the NICS. Specifically, the new rule is limited in three ways. First, it applies only to covered entities involved in ordering involuntary commitments or other adjudications that make an individual subject to the Federal mental health prohibitor. It does not apply to disclosures about individuals who are subject to state-only mental health prohibitors. Moreover, the Federal mental health prohibitor does not apply to individuals in a psychiatric facility for observation or who have been admitted voluntarily. Thus, the new rule does not create a permission for most treating providers to disclose PHI about their own patients for these purposes. The Department recognized that encouraging voluntary treatment is critical to ensuring positive outcomes for individuals’ health as well as the public’s safety. The new rule was designed to balance that goal with public safety interests served by the NICS. Read more
Physician Timeshare Arrangements: New Stark Option for Sharing Space with Visiting Specialists and Others
/in Fraud and Abuseby Kim C. Stanger, Holland & Hart LLP
Recent Stark law amendments will make it easier for physicians to share space, and for hospitals to provide space, equipment, and services to visiting specialists and other physicians on a non-exclusive, “as-needed” basis. Hospitals and physicians may want to review their current lease arrangements to determine whether the new exception is a better fit for their current or future relationships and, if so, structure their arrangements accordingly.
Prior Law. The federal Ethics in Patient Referrals Act (“Stark”) generally prohibits physicians from referring patients for certain designated health services (“DHS”) payable by Medicare to entities with which the physician has a financial relationship unless the relationship is structured to fit within a regulatory safe harbor. (42 USC 1395nn; 42 CFR 411.353). Providing space or equipment to a referring physician generally creates a financial relationship that triggers Stark1; consequently, such arrangements generally needed to be structured to satisfy Stark safe harbors for leases of space or equipment. Unfortunately, those safe harbors required, among other things, that the physician enter a formal lease that provided for exclusive use of the leased premises or equipment during defined lease terms (42 CFR 411.357(a)-(b)); the physician and lessor were generally not permitted to share space or equipment during the lease term, nor could the lease be on an “as needed” basis. Traditional timeshare arrangements in which physicians share space or equipment on a non-exclusive basis did not satisfy Stark, thereby forcing physicians and their landlords to enter formal, inefficient, and sometimes impractical lease arrangements. Read more
Responding to HIPAA Breaches
/in HIPAAby Kim C. Stanger, Holland & Hart LLP
HIPAA privacy and security breaches can result in fines of $100 to $50,000 to covered entities (including healthcare providers and health plans) and their business associates. (45 CFR 160.404). If the violation resulted from “willful neglect”, the Office for Civil Rights (“OCR”) must impose a mandatory fine of $10,000 to $50,000. (45 CFR 160.404). To make matters worse, covered entities and their business associates must self-report breaches of unsecured protected health information (“PHI”) to the affected individual and to HHS (45 CFR 164.400); failure to do so may constitute “willful neglect” resulting in additional fines. The good news is that the OCR may not impose a fine so long as the covered entity or business associate did not act with “willful neglect” and corrected the problem within 30 days. (45 CFR 160.410(b)).
Responding to Possible Breaches. Given the potential consequences, it is critical that covered entities and business associates respond appropriately to potential HIPAA breaches to avoid or minimize their liability. Below are steps that you may follow to help you identify and timely respond to HIPAA breaches. Read more
Complying With HIPAA: A Checklist for Business Associates
/in HIPAAby Kim C. Stanger, Holland & Hart LLP
The HIPAA Privacy, Security, and Breach Notification Rules now apply to both covered entities (e.g., healthcare providers and health plans) and their business associates. A “business associate” is generally a person or entity who “creates, receives, maintains, or transmits” protected health information (PHI) in the course of performing services on behalf of the covered entity (e.g., consultants; management, billing, coding, transcription or marketing companies; information technology contractors; data storage or document destruction companies; data transmission companies or vendors who routinely access PHI; third party administrators; personal health record vendors; lawyers; accountants; and malpractice insurers).1 With very limited exceptions, a subcontractor or other entity that creates, receives, maintains, or transmits PHI on behalf of a business associate is also a business associate.2 To determine if you are a business associate, see the attached Business Associate Decision Tree.
Business associates must comply with HIPAA for the following reasons: Read more