On the Regulatory Radar Screen

         

What We are Tracking

 Regulatory Radar Map Graphic

 

Issue 

Date published or expected  

MEDICARE

CMS  final rule on outpatient PPS and ambulatory surgical centers for CY 2010

Released Nov. 20; Effective Jan. 1

CMS final rule on physician fee schedule changes for CY 2010

Released Oct 30; Effective Jan. 1

National rollout of Medicare Recovery Audit Contractor program Contractors are implementing the program in all 50 states

CMS notice on proposed changes to the hospital cost report

Published July 2; Effective for cost reporting periods beginning Feb. 1

CMS proposed rule on revised conditions of participation related to emergency preparedness and response

Expected this month; Effective TBD

CMS proposed rule on policy and technical changes to the Medicare Advantage and the Medicare Prescription Drug Benefit Program

Published Oct. 22; Effective TBD

CMS proposed rule on end-stage renal disease PPS for CY 2011

Released Sept. 29; Effective Jan. 1, 2011

MEDICAID

CMS proposed rule to eliminate federal funding of Medicaid GME

Published May 23, 2007; "Sense of Congress" resolution in the "American Recovery and Reinvestment Act" (ARRA) urged HHS secretary not to issue a final rule

CMS final rule on intergovernmental transfers, certified public expenditures and upper payment limits Published May 29, 2007, but needs to be reissued; Sense of Congress resolution in ARRA urged HHS secretary not to issue a final rule
OTHER
DoD final rule on Tricare critical access hospital payments Published Aug. 31; Effective Dec. 31
Proposed rule from the departments of HHS, Labor and Treasury on implementing mental health parity legislation Expected by January
HHS proposed rules on the definition of "meaningful user" as a requirement for hospitals to receive health IT stimulus funding beginning in FY 2011 Expected soon
Department of Labor rule on requirements for federal contractors to post notices of employees' rights under federal labor law  Final rule pending
HHS electronic health record technical standards to permit compliance with HITECH's new accounting of disclosures requirements  Expected this month

HHS interim final rule on "breach notification for unsecured protected health information"

Final rule pending

 

HOT TOPIC

HOT TOPIC

RAC program rolls out across the country

The four contractors for Medicare's Recovery Audit Contractor (RAC) program now are reviewing hospital and physician claims across the nation. Diversified Collection Services, based in Livermore, CA, is auditing claims in Region A, which includes Connecticut, Delaware, the District of Columbia, Maine, Maryland, Massachusetts, New Hampshire, New Jersey, New York, Pennsylvania, Rhode Island and Vermont. CGI Technologies and Solutions, Inc., of Fairfax, VA., is conducting audits in Region B, consisting of Indiana, Michigan and Minnesota. Illinois, Kentucky, Ohio and Wisconsin. Connolly Consulting audits claims in Region C, targeting physicians and hospitals in South Carolina, Alabama, Arkansas, Colorado, Florida, Georgia, Louisiana, Mississippi, North Carolina, New Mexico, Oklahoma, South Carolina, Tennessee, Texas, Virginia, West Virginia, Puerto Rico and the U.S. Virgin Islands. HealthDataInsights, Inc., of Las Vegas, audits claims in the Region D states of Alaska, Arizona, California, South Dakota, North Dakota, Hawaii, Idaho, Iowa, Kansas, Missouri, Montana, Nebraska, Nevada, Oregon, Utah, Washington and Wyoming. The program is expected to be operating in all 50 states in 2010. For information on RAC advocacy and education resources, visit www.aha.org/rac.

Diversified Collection Services, Livermore, CA, covers Region A.; CGI Technologies and Solutions, Fairfax, VA, covers Region B; Connolly Consulting Associates, Wilton, CT, covers Region C; and HealthData-Insights, Las Vegas, covers Region D.

RAC Map 

 

AHA supports “risk of harm” trigger in breach notification rule

The AHA recently weighed in on the Department of Health and Human Services' (HHS) interim final rule on health data breach notification, urging the department to retain its “risk of harm” standard when it issues a final rule.

The interim final rule, which took effect on Sept. 23, seeks to flesh out the federal data breach notification provisions in the 2009 American Recovery and Reinvestment Act. The regulation states that an organization needs to notify individuals of a breach of protected health information only if it determines the breach poses significant harm to affected individuals.

In a recent comment letter to HHS, the AHA stated that “notifying individuals of an unauthorized acquisition, access or disclosure of their PHI serves no useful purpose when a covered entity, through investigation, has determined that there is no reasonable likelihood of harm to the individuals.” The risk of harm standard is consistent with the statutory language of the HITECH Act, as well as with state laws and federal agency policies, the AHA observed.

The AHA generally supports the interim final rule requiring hospitals and other entities covered by the Health Insurance Portability and Accountability Act to notify individuals when a breach of their unsecured personal health information occurs. But the association said “further improvements are needed to ensure the rule effectively serves its purpose.”

For example, the AHA calls on HHS to identify additional situations in which a health data breach does not compromise privacy and security and so would not warrant notification. The AHA also encourages the department to rescind its guidance that covered entities must determine whether their business associates are agents in order to understand when a business associate's knowledge of a breach will be imputed directly to covered entities. Among other recommendations, the AHA urges HHS to develop a system for covered entities to electronically notify the department of breaches affecting fewer than 500 people.

For more on the AHA's comments, go to “Letters” under the “Advocacy” section of www.aha.org and click on “AHA Comments on Breach Notification Interim Final Rule.”