Health care accountability, portability on horizon

Health-care providers and insurers have had the federal Health Insurance Portability and Accountability Act (HIPPA) on their radar screens for years. Most are now developing strategies to upgrade their information systems in advance of the sweeping new regulations.

But what about employers? Industry experts say that human resources personnel and office managers will need to acquaint themselves with at least some basic principles of HIPAA to make sure they’re in compliance.

Building a Strong Data Foundation in the Age of AI

Artificial intelligence (AI) has become a key priority in the boardroom and across management —…

Learn More

“If you’re an employer and you either create or receive individually identifiable health information, you’ve got an issue,” said Stephen D. Zubiago, a health-care attorney at Nixon Peabody LLP in Providence.

HIPAA regulations are aimed at simplifying the administration of health insurance through electronic transmission of patient records. Passed by Congress in 1996, the law creates stringent new requirements for the protection of patient information, set to go into effect in April 2003.

- Advertisement -

It’s unlikely that even big companies will have a thorough grasp of the intricacies of HIPAA, Zubiago told a group of HR managers, accountants and others during a seminar at ITEC, a technology conference Nov. 13-14 at the Providence Convention Center. He held up a 3-inch thick binder that contained just half of HIPAA’s privacy regulations, which are subject to change before they go into effect.

But there are rules that any employer should know, he said. First, any “individually identifiable” health information that is “maintained or transmitted by electronic media or any other form” is strictly protected, according to the legislation.

“In other words, basically anything,” Zubiago said. The interpretation of protected health information, or PHI, even includes an employee who brings documentation from a doctor’s office to an employer showing why he or she missed work.

Sending or receiving any PHI will require written consent from the patient, whether the information is in electronic form or on paper. Zubiago recommends employers draft generic consent forms – as broadly defined as possible – for employees to sign in case health information needs to be disclosed for any reason.

And employers must also abide by what’s called a “minimum necessary” rule, which essentially mandates that disclosure of PHI be done only on a “need-to-know” basis. Businesses that could be most affected by HIPAA regulations are companies that self-insure their workforce, which tend to be medium-and large-sized firms.

Although those companies usually outsource the oversight of employee health benefits to third-party administrators, there is a greater likelihood that they could come into contact with patient information.

“Having a third-party administrator (handling health benefits) may get around the HIPAA issue for self-insured companies,” Zubiago said. “But it depends. Some companies are much more hands-on about managing their health benefits and could create or receive (employee health information) that way.”

Small businesses have less to worry about, he said, although they should have a system set up for handling any private health information that comes through the door.

“From an HR perspective, it may require us to reexamine how we document and store any health-benefits information,” said JK Nicholas, president and CEO of NorthPoint Domain, a Boston developer of Internet portals for physicians.

But perhaps the overarching rule regarding HIPAA requirements right now is that none of the rules is set in stone, and interpretation of them is subject to debate.

“There is no case law or guidance out there,” Zubiago said. “It’s very much a moving body of law right now.”

No posts to display