ARRA’s New Privacy and Security Requirements

I was all set to write an article Monday morning on the expanded privacy and security requirements in the American Recovery & Reinvestment Act of 2009 (ARRA) when I remembered that I was registered for a webinar presented by FairWarning (a privacy surveillance company) Monday afternoon on just that subject. I am really glad I waited to write, because this webinar provided a wealth of information on the new requirements. [By the way, you will also see this section of ARRA (Title XIII) referred to as the Health Information Technology for Economic and Clinical Health (HITECH) Act. Subtitle D contains the Privacy provisions.]

Many people and organizations have opined that EHRs will not take hold in general medical settings or in behavioral healthcare until consumers and providers trust that the EHR products and the means of transferring data are truly secure and protect the privacy of the patient. Webinar presenter Deven McGraw, of the Center for Democracy & Technology, most articulately presented the aspects of ARRA that will increase the privacy and security requirements that healthcare providers must follow. She indicated changes in four broad areas including substantive modifications to HIPAA statutory requirements, increased enforcement of HIPAA, provisions to address health information held by entitites not covered by HIPAA, and a variety of administrative changes.

The new law incorporates and expands upon the HIPAA requirements.

  • There has been an attempt to more clearly define certain terms, like just what a “breach” of privacy is.
  • Previously, covered entities where the only ones required to report breaches of privacy; now the same requirement is placed upon Business Associates.
  • HITECH strengthens the individual’s right to restrict disclosures of health information to their insurance plan and even allows the individual to “opt out” of electronic recording and sharing of their information if they pay for their services privately and in advance. Mental health services are frequently cited as  sensitive content that an individual may want left out of their electronic record.
  • The HIPAA mandate requiring that a provider not release psychotherapy notes to the insurer has been included in this act, and the Secretary of Health and Human Services (HHS) has been ordered to study whether psychological test data should be included in this exception.
  • ARRA improves upon the HIPAA “minimum necessary” standard requiring that only the minimum amount of patient information should be disclosed depending upon the specific request for information.
  • The legislation places requirements upon companies that provide Personal Health Records (PHR) for the security of the data in those records, and prohibits the sale of protected health information.
  • Most importantly, the law provides an ongoing process for setting privacy and security standards and evaluating their effectiveness. 

brief summary of these changes written by the American Psychological Association was published by Behavioral Healthcare magazine in February.

Perhaps the most important thing behavioral health providers need to realize is that the move toward mental health EHRs is happening. How exactly those records will interface with the rest of the National Health Information Network and exactly what information will be shared with other healthcare providers remains to be seen, but this endeavor is irrevocably marching forward. Where will you be in this process?

To comment on this article, click on the title and insert your comment in the box at the bottom of the page.

Mental Health and e-Health News Bits

Running a mental health practice or community organization is a demanding endeavor and probably gets in the way of reading some of the huge volumes of info out there. I just thought I would share some quick bits and pieces of information you might find useful.

1.   ICD-10 Update: Last October 31, I posted information about an October 2011 deadline for implementing the ICD-10. HHS has relented and set a new deadline of October 1, 2013 for adoption of the diagnosis and procedure system.  The code sets are complete and available for your information at the HHS web site. An informational document will give you the scoop.

(Reported in Healthcare Informatics on January 16, 2009.)

2. Community Partnership of Southern Arizona has links on their website that many will find useful. They have collected state-by-state information on the following 19 items for all 50 states: Mental Health Authority, NAMI (National Alliance on Mental Illness), Mental Health America, Protection and Advocacy,  2-1-1 Human and Emergency Services, Employment Services, Vocational Rehabilitation Services, Medicaid Authority, Housing Authority, Homeless Information, Food Bank Locator, Food Stamp Program, Resources for Individuals with Disabilities, Psychiatric Advance Directives, Suicide Prevention, Civil Commitment Statutes, National Council: Providers, National Council: State Association, Child Welfare Information, and Department of Education.

3.  Evidence Based Practice Toolkits are available from SAMHSA. Six toolkits are currently available for public use. If you have been considering implementation of EBP in your organization, these toolkits are a good place to begin.

(Reported in the January 15, NJAMHA Newswire.)

4. HIPAA: I have come upon a wonderful way to keep up with and understand all things HIPAA-related. Hipaa.com is a web site devoted to education about HIPAA and has some outstanding articles. You can subscribe to their blog and follow them on Twitter.

What would you like us to discuss in this space? Are there kinds of information that are more useful than others? Let us know which topics you find most important.

To leave your comments, click on the title of this article and enter your message in the box at the bottom of the page.

Are your passwords HIPAA secure?

Standard advice for securing computer systems is to require users to change passwords frequently. Something about this recommendation has always bothered me, but I never really thought it through. A current blog posting at Healthcare Informatics by Dale Sanders really hits the nail on the head. He points out that these change-passwords-frequently policies actually undercut password security rather than enhancing it, once you factor in human psychology. If you have to replace your password frequently, you will probably come up with something simplistic, or resort to a post-it note on the monitor, or maintain a paper list. It would be far more secure to create a single, strong password or passphrase and continue to use it for a much longer period.

To manage passwords used on the web, you can’t go wrong with Roboform. Create a strong master password (long, and using a combination of letters, numbers, and special characters), then let Robo’s password generator suggest strong passwords for individual web sites. Once you select and use a password on a web site, Robo will remember and “type” it in for you when you next visit that site. All you have to do is enter your master password once in each browser session; Robo uses that to unlock your password library and cleverly selects the right one whenever you hit a login window. There is even a version of Roboform that you can install on a USB “thumb” drive, so you can securely carry your passwords with you for use on multiple computers, or even public computers when traveling.

In the course of providing technical support on our billing and EMR software, I am exposed to the password selections of many of our users. It is amazing how rare it is to find anyone using serious passwords. Names, almost surely loved ones or pets, are the most common, but way too frequently I see passwords that are identical to user IDs, or non-passwords like “123” and “password”. Although we have optional rules in our products that would require strong password choices if enabled, they rarely are used.

Coming up with an easily remembered, secure, master password is not really all that hard. Just think up a short sentence that includes punctuation and some numbers. You can check the quality of your choice using Microsoft’s password checker.

Here’s an example: “Turning 60! soon.” This easily remembered phrase is actually more secure than “3-vO$aLKG7”, which conforms to all the standard password creation advice.

Maintaining medical privacy is serious business. Current HIPAA rules provide for serious penalties when medical information is not properly secured. Are you guilty of password negligence yourself?

Seth Krieger

To comment on this article, click on the title and enter your comment at the bottom of the article.

Mental Health Billing and the ICD-10

Back in August, the U.S. Department of Health and Human Services (HHS) posted a proposed rule requiring the implementation of the portion of HIPAA that mandates use of the ICD-10 by October 2011. The International Classification of Diseases-10 was endorsed by the 43rd World Health Assembly in 1990 and was implemented by many World Health Organization (WHO) member states as early as 1994. The United States is 14 years behind the curve on use of this updated version of the ICD, the list of diagnoses used in all medical billing. As more healthcare organizations implement electronic medical records (EMRs) ICD diagnostic codes are used ever more widely, but at present payment for health services is still the most important function of these codes in the U.S.

There was an immediate outcry from provider and payer organizations that the 2011 date was too soon. The Medical Group Management Association, the American Medical Association and America’s Health Insurance Plans registered objections with HHS over the implementation date indicating that the costs would be too great for providers and payers, especially given the recently completed and very costly implementation of the NPI (National Provider Identifier).  But now, the American Hospital Association has supported the 2011 date suggesting that the potential gains from use of the ICD-10 are too great to wait any longer to implement the new codes.

We know the pain that has been experienced by customers of Synergistic Office Solutions in adopting the NPI and continuing to get paid for services rendered. Our software has been able to handle the NPI since early 2007, but some of our customers still struggle with the confusion caused by this transition.  While software can be made ready for the ICD-10 without very much difficulty, we are concerned about how this change will be handled in the real world by psychologists and psychiatrists and social workers who are accustomed to using the DSM-IV and ICD-9 for diagnoses for mental health conditions.

What do you think about a move to ICD-10? Do you expect this next round of changes required by HIPAA to be simple? to be problematic? What do you expect the impact will be for your organization and how do you plan to handle it? What is the best way for vendors of mental health billing software and medical billing software, medical EMRs and behavioral health EMRs to assist providers in implementing the new ICD-10 codes? Let us know what you think. We want to help make this new transition as smooth as possible.

HIPAA Privacy Rule: Communicating with Family and Friends

New guidance about communicating with a patient’s family, friends or caretakers was released by the U.S. Department of Health and Human Services, Office of Civil Rights. This is the office entrusted with education about and enforcement of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy Rule. They have created two documents which lay out details about sharing information about a patient, one for providers of care and one for patients or consumers of care.

 

As I read these two documents, I found myself recalling my internship training in a Community Mental Health Center. We were clearly instructed that we were not even to acknowledge that a person was a client of the Center if someone telephoned about them. Family or friends accompanying them to their visit were not invited into the session unless the patient asked that they be included. Even minor adolescents and children were granted the privacy of the therapy session unless a clear agreement including parents or caretakers was reached. Obviously, the therapeutic relationship in the behavioral health field is a more sensitive matter than in many physical health settings. My experience is that mental health providers have always been more concerned and responsible about securing a patient/client/consumer’s privacy than anyone providing physical health care I have ever met.

 

In this electronic world in which we live, I have seen some of that care diminished; and we have begun to bump into this matter in technical support at SOS. HIPAA provides that a Covered Entity (a health care provider who electronically transmits certain transactions including electronic claims) must assure the security and privacy of their patient information. It also requires that Covered Entities educate people and organizations who provide services to them about the necessity of protecting the health information of their patients. In fact, it requires that Covered Entities maintain a Business Associate Agreement (BAA) with each person or organization with whom they do business who might in the course of doing business be exposed to the Protected Health Information (PHI) of their clients. If you have any doubt about whether you are, or are not, a Covered Entity, it would seem prudent to assume that you are and to execute a BAA with anyone to whom you reveal PHI.

 

When implementation of the Privacy Rule was first mandated in April 2003, we were asked to execute BAA’s by a very small proportion of our customers. During the five years since then, we have almost never been asked to sign such a document. Since service to our customers is a big part of who we are, we have made available a BAA that makes it very easy for a Covered Entity to assure that SOS is handling their data in an appropriate fashion if we ever have access to it (http://www.sosoft.com/fod/doc105-sosbaa.pdf ). Even given the ease of accomplishing this agreement, we still have difficulty getting provider organizations to do so.

 

What is your take on the HIPAA Privacy Rule and how it is implemented in your organization? Were you on top of this in 2003 and 2004 but not as likely to educate staff and your computer and software vendors in 2008? Do you see a difference between how psychology, psychiatry and other behavioral health organizations handle the Privacy Rule and how physical health providers do so? Has the rule kept you from filing your claims electronically so you would not become a Covered Entity?