Legal Aspects of Health Insurance add Reimbursement

Chapter 5: Legal Aspects of Health Insurance and Reimbursement

This chapter discusses various legal aspects concerning health insurance and reimbursement, focusing on important legislation and regulatory frameworks, particularly the Health Insurance Portability and Accountability Act (HIPAA) of 1996.

5.1 NCCI Edits in OCE Software

Table 5-1: Partial Listing of NCCI Edits
  • Edit code 12348: Invalid diagnosis code

    • Description: Diagnosis and age conflict

    • Disposition of Claim: Return to provider

  • Edit code (unassigned): Diagnosis and legal sex conflict

    • Disposition of Claim: Return to provider

  • Edit code (unassigned): Claims coding issues needing modifiers

    • Disposition of Claim: Denied

  • Medicare Secondary Payer Alert: Code pairs disallowed by NCCI even if appropriate modifier is present.

Notes
  • Courtesy of the Centers for Medicare & Medicaid Services (CMS)

  • MCE: Medicare Code Editor is utilized for inpatient hospital claims.

5.2 Overview of HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996 to improve functionalities and protections associated with health insurance.

Primary Objectives
  • Enhance portability and continuous coverage in healthcare

  • Establish national standards for electronic healthcare transactions

  • Protect patient privacy and security of health information

  • Implement regulations to combat healthcare fraud and abuse

  • Promote the use of medical savings accounts

  • Improve access to long-term care services and coverage

Provisions of HIPAA
  1. Title I: Health Care Access, Portability, and Renewability

    • Limits exclusions for pre-existing conditions.

    • Provides rights for enrolling in health coverage after losing previous coverage.

    • Prohibits discrimination in premiums based on health status.

  2. Title II: Preventing Health Care Fraud and Abuse, Administrative Simplification, and Medical Liability Reform

  3. Title III: Tax-Related Health Provisions

  4. Title IV: Application and Enforcement of Group Health Plan Requirements

  5. Title V: Revenue Offsets

Civil Penalty Structure for HIPAA Violations
  • Tier 1: Lack of knowledge

  • Tier 2: Reasonable cause

  • Tier 3: Willful neglect, violation corrected in time

  • Tier 4: Willful neglect, violation not corrected

  • Annual maximum fine: Over $2 million for organizations.

Patient Information Privacy

Protected Health Information (PHI) includes information identifiable to individuals such as names, addresses, telephone numbers, etc. HIPAA mandates that authorized consent is obtained before disclosing an individual's health information. The Privacy Rule ensures PHI confidentiality and security.

Incident Response

Providers must notify patients about breaches in a timely manner, specifically within 60 days of discovery.

5.3 Fraud and Abuse Definitions under HIPAA

  • Fraud: Intentional deception/misrepresentation for unauthorized payment.

  • Abuse: Actions inconsistent with sound medical practices leading to unnecessary costs.

Table 5-2: Fraud Examples and Outcomes

Examples of Fraud

Possible Outcomes

Soliciting bribes or kickbacks

Administrative sanctions

Altering claims for increased reimbursement

Civil monetary penalties

Billing unprovided services

Exclusion and sanctions

Submitting false certifications

Criminal penalties

Healthcare Fraud and Abuse Control (HCFAC) Program

Packaged programs to combat fraud through coordinated federal-state-local law enforcement. Successful litigation has led to significant recoveries for the government and victims.

OIG Advisory Opinions

The Office of Inspector General (OIG) provides guidance, including advisories on compliance with anti-kickback statutes.

5.4 Administrative Simplification under HIPAA

Regulations streamline healthcare-related transactions, emphasizing standardization to enhance efficiency. All entities conducting electronic transactions must comply with these standards.

Unique Identifiers
  • Health Plan Identifier (HPID): Assigned to third-party payers, now rescinded.

  • National Provider Identifier (NPI): Unique ID for providers.

  • Employer Identification Number (EIN): Unique ID for employers.

Electronic Health Transactions

HIPAA mandates standard electronic data interchange for healthcare claims and other transactions. Key formats include:

  • ANSI ASC X12N 837: Claim submissions standard for institutional and professional services.

    • Institutional services: UB-04 Flat file

    • Professional services: CMS-1500 Flat file

5.5 Privacy and Security Standards

Provisions enforce safeguarding of patients' PHI. Organizations must implement security plans to protect both electronic and physical health information.

Patient Consent Requirements

Providers must secure patient authorization before disclosing PHI for treatment, payment, or operations. The requirement still applies even if HIPAA does not explicitly necessitate it.

Identity Theft Protection

HIPAA regulations assert the need for draft measures against identity theft in healthcare settings, ensuring protection of patient records and privacy.

5.6 Release of Information (ROI) Processes

Authorization from patients is necessary for release. Special care must be taken to secure PHI, managing risks associated with unauthorized disclosure, including healthcare-related faxes and electronic transmissions. The release of records must adhere to strict compliance protocols, ensuring privacy/security throughout.

Overview of HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) was enacted in 1996 to improve functionalities and protections associated with health insurance.

Primary Objectives
  • Enhance portability and continuous coverage in healthcare

  • Establish national standards for electronic healthcare transactions

  • Protect patient privacy and security of health information

  • Implement regulations to combat healthcare fraud and abuse

  • Promote the use of medical savings accounts

  • Improve access to long-term care services and coverage

Provisions of HIPAA
  1. Title I: Health Care Access, Portability, and Renewability

    • Limits exclusions for pre-existing conditions.

    • Provides rights for enrolling in health coverage after losing previous coverage.

    • Prohibits discrimination in premiums based on health status.

  2. Title II: Preventing Health Care Fraud and Abuse, Administrative Simplification, and Medical Liability Reform

  3. Title III: Tax-Related Health Provisions

  4. Title IV: Application and Enforcement of Group Health Plan Requirements

  5. Title V: Revenue Offsets

Compliance Requirements

To ensure compliance with HIPAA, organizations must:

  • Implement security measures to protect both electronic and physical health information.

  • Secure patient authorization before disclosing PHI for treatment, payment, or operations.

  • Develop and maintain security plans that address risks associated with unauthorized disclosure of PHI.

  • Conduct regular risk assessments to identify vulnerabilities and mitigate them accordingly.

  • Train employees on HIPAA regulations and the importance of confidentiality and security of patient data.

  • Maintain compliance records, policies, and procedures to demonstrate adherence to HIPAA guidelines.

Patient Information Privacy

Protected Health Information (PHI) includes information identifiable to individuals such as names, addresses, and telephone numbers. HIPAA mandates that authorized consent is obtained before disclosing an individual's health information. The Privacy Rule ensures PHI confidentiality and security.

Incident Response

Providers must notify patients about breaches in a timely manner, specifically within 60 days of discovery, to ensure accountability and transparency in safeguarding patient information.

Civil Penalty Structure for HIPAA Violations
  • Tier 1: Lack of knowledge

  • Tier 2: Reasonable cause

  • Tier 3: Willful neglect, violation corrected in time

  • Tier 4: Willful neglect, violation not corrected

  • Annual maximum fine: Over $2 million for organizations.

Conclusion

HIPAA compliance is critical in safeguarding patient rights and ensuring the integrity of health information. Organizations must prioritize and regularly evaluate their compliance measures to protect patients' health information effectively.