The Saga Over The Privacy of Medicare Claims Data Continues . . .

Guest post by Michele Grinberg, my colleague in the Health Care Practice Group at Flaherty, Sensabaugh Bonasso PLLC.

Through indirection find direction out? With apologies to William Shakespeare, the U.S. Court of Appeals for the11th Circuit and D.C. circuit say: NO, not this time.

In Jennifer D. Alley, Real Time Medical Data, LLC v. U.S. Dept. of Health and Human Services, issued Dec. 18, 2009, the Court held that plaintiffs Alley & Real Time Data cannot obtain certain Medicare data for procedures performed in Florida, Georgia, Mississippi and Tennessee by AMA physicians and for all Florida physicians (the certified class). Specifically, Medicare Part B raw claims data that could easily be matched to a particular physician and then aggregated to calculate the total annual Medicare payment by physician cannot be disclosed to Alley. Alley had sought the information through filing a federal Freedom of Information Request (FOIA).

The reason? Because the Florida District Court in 1979 issued a permanent injunction in Florida Medical Assn. v. Dept. of Health Education & Welfare, prohibiting DHHS (then HEW) from disclosing “any list of annual Medicare reimbursements…for any years, which would personally and individually identify those providers of services …. Any such disclosure of annual Medicare reimbursement amounts, for any years, in a manner that would personally and individually identify the providers….is contrary to federal law.” (quoted in Alley)

Judge Carnes in a well-authored opinion (for those of you, like me, who care about good writing) enjoys the irony of hearing argument that sounds much like the health policy arguments heard in the mid-1970s. His second sentence reads: “The present national debate over health care rhymes a lot with one that took place three decades ago.” But whether it’s still good policy or not, Judge Carnes holds that plaintiffs cannot collaterally attack the 1979 injunction by arguing it does not apply to the data sought or the context has shifted in favor of disclosure or the reimbursement methodology has changed. Rather, if plaintiffs believe the injunction is no longer valid, their recourse is to go back to the court where the injunction issued and challenge it there.

In a footnote, the 11th Circuit references a recent 2009, United States of Court of Appeals D.C. Circuit, decision: Consumers’ Checkbook, Center For Study of Services. v. U.S. Department of Health and Human Services. The lower court’s holding in this case was discussed in this blog in 2008 (Consumers' Checkbook v HHS Update). In the 11th Circuit footnote (No.9), the court observes that in a factually similar case, the D.C. Circuit has held that FOIA exemption 6 permits DHHS to not disclose the requested Medicare data. FOIA exemption 6 protects from disclosure government agency files that constitute “a clearly unwarranted invasion of personal privacy.”

What we have then are two cases: one that upholds a 1979 injunction which enjoins DHHS from providing Medicare data that can be manipulated to identify annual reimbursements to individual physicians and other providers but which injunction reaches only the certified class of providers (identified above); and a second case that holds that providing similar Medicare data that can be tied to individual providers is protected from disclosure by a FOIA exemption. Thus, data elements which might indirectly seem disclosable are not if they lead to a resulting disclosure which invades personal privacy. We will see what changes health insurance reform brings, if any.

The AMA provides additional analysis of the decision in a story posted January 11, 2010, Appeals court rejects effort to sell Medicare physician claims data. Also, Law.com reports on the decision in its article, Mark Twain Lives On in Federal Judge's Ruling on Release of Medicare Data.

2010 AHLA Hospitals and Health Systems Law Institute: Hot 2010 Health Law Legal Topics

Although it is cold today in West Virginia - I'm hoping it will be hot in Florida in February.

I thought I would take a moment on this cold wintry day to write about the hot health topics that will be discussed at the American Health Lawyers Association (AHLA) Hospitals and Health Systems Law Institute scheduled for February 25-26, 2010 at the Doral Golf Resort & Spa in Miami, Florida (Conference Brochure PDF).

I will be speaking at the Hospitals Law Institute along with my colleague, Jody Joiner, Assistant Operations Counsel at Sisters of Charity of Leavenworth Health System. Our topic scheduled for Friday, February 26 is Hospital’s Friend or Foe: The Age of Social Media and Health 2.0 where we plan to cover:
  • The social media technology tools used by health care providers and hospitals
  • Pros/cons and legal implications of social media and health 2.0 services such as blogs, wikis, social networking, podcasting, video sharing, etc.
  • Best practices and development of policies and procedures which address staff and employees using social media
In addition to our session there will be variety of "hot" health law legal topic covered at the conference that will interest hospital administrators and their legal counsel, including sessions on government data mining to identify hospital compliance, understanding the recent ARRA HITECH developments impacting HIPAA and EHR, hospital/physician collaboration and relationships, best practices in hospital practitioner credentialing, peer review and privileging, voluntary disclosure strategies, hospital clinical research issues, and much more.

The AHLA Hospital and Health System Law Institute overlaps with the AHLA Physicians and Physician Organizations Law Insitute which will be held on February 24-25.The Physician Law Insitute will include "hot" physician topics on on call payments, Accountability Care Organizations, HITECH, disruptive physician behavior intervention, Stark issues for physicians, hospital/physician mergers, FMV for physician compensation and much more.

You can register for one or both. As an AHLA Member I regularly attend the Physician/Hospital Law Institutes every year or so because of quality and breadth of health law related materials for those who work in the health care industry. More information, along with how to register, can be found at the AHLA website:
Hospitals and Health Systems Law Institute
Physicians and Physician Organizations Law Insitute

CMS and ONC Issue Rules on Proposing a Definition of Meaningful Use and Setting Standards for EHR Incentive Program

Yesterday the Centers for Medicare & Medicare Services (CMS) and the Office of the National Coordinator for Health Information Technology (ONC) issued two regulations laying the foundation for improving quality, efficiency and safety through meaningful use of certified electronic health record (EHR) technology.

The two regulations are part of the implementation of the EHR incentive programs for physicians and hospitals enacted under the HITECH provisions of the American Recovery and Reinvestment Act of 2009 (ARRA). CMS issued a proposed rule outlining the proposed provisions governing the EHR incentive programs, including defining the central concept of “meaningful use” of EHR technology. ONC issued an interim final regulation setting forth the initial standards, implementation specifications, and certification criteria for EHR technology.

For more details see the following CMS Press Release. Also, CMS has issued Fact Sheets on the proposed regulations:
Below are links to complete copies of the rules. Once they are published in the Federal Register I will update with the specific Fed Reg details. Some light reading for the New Year!
Medicare and Medicaid Programs; Electronic Health Record Incentive Program
AGENCY: Centers for Medicare & Medicaid Services (CMS), HHS.
ACTION: Proposed rule.
SUMMARY: This proposed rule would implement the provisions of the American Recovery and Reinvestment Act of 2009 (ARRA) (Pub. L. 111-5) that provide incentive payments to eligible professionals (EPs) and eligible hospitals participating in Medicare and Medicaid programs that adopt and meaningfully use certified electronic health record (EHR) technology. The proposed rule would specify the-- initial criteria an EP and eligible hospital must meet in order to qualify for the incentive payment; calculation of the incentive payment amounts; payment adjustments under Medicare for covered professional services and inpatient hospital services provided by EPs and eligible hospitals failing to meaningfully use certified EHR technology; and other program participation requirements. Also, as required by ARRA the Office of the National Coordinator for Health Information Technology (ONC) will be issuing a closely related interim final rule that specifies the Secretary’s adoption of an initial set of standards, implementation, specifications, and certification criteria for electronic health records. ONC will also be issuing a notice of proposed rulemaking on the process for organizations to conduct the certification of EHR technology.

Health Information Technology: Initial Set of Standards, Implementation Specifications, and Certification Criteria for Electronic Health Record Technology
AGENCY: Office of the National Coordinator for Health Information Technology,
Department of Health and Human Services.
ACTION: Interim final rule.
SUMMARY: The Department of Health and Human Services (HHS) is issuing this interim final rule with a request for comments to adopt an initial set of standards, implementation specifications, and certification criteria, as required by section 3004(b)(1) of the Public Health Service Act. This interim final rule represents the first step in an incremental approach to adopting standards, implementation specifications, and certification criteria to enhance the interoperability, functionality, utility, and security of health information technology and to support its meaningful use. The certification criteria adopted in this initial set establish the capabilities and related standards that certified electronic health record (EHR) technology will need to include in order to, at a minimum, support the achievement of the proposed meaningful use Stage 1 (beginning in 2011) by eligible professionals and eligible hospitals under the Medicare and Medicaid EHR Incentive Programs.

Tweet By Hospital Employee: What information is considered PHI?

Interesting Tweet HIPAA Breach story coming out of Mississippi involving Governor Haley Barbour. The incident involved a response to Governor Barbour's tweet by a University Medical Center employee.

Ves Dimov, M.D. at Clinical Cases and Images Blog posts about the story - Single tweet by hospital employee to Mississippi Governor allegedly violates HIPAA, forces her to resign.

The incident will provide a good case study for health privacy lawyers who regularly consider the question of what information is and is not protected health information (PHI) under 45 CFR 160.103. PHI is defined under HIPAA as:

The Privacy Rule protects all "individually identifiable health information" held or transmitted by a covered entity or its business associate, in any form or media, whether electronic, paper, or oral. The Privacy Rule calls this information "protected health information (PHI)."

“Individually identifiable health information” is information, including demographic data, that relates to:

  • the individual’s past, present or future physical or mental health or condition,
  • the provision of health care to the individual, or
  • the past, present, or future payment for the provision of health care to the individual,

and that identifies the individual or for which there is a reasonable basis to believe it can be used to identify the individual. Individually identifiable health information includes many common identifiers (e.g., name, address, birth date, Social Security Number).

Thanks for the tip @RLBates and @EdBennett.

Lorman Medical Records Law Seminar: March 18, 2010

On March 18, 2010 I will be speaking on Medical Records Law at a seminar in Charleston, West Virginia. The seminar is sponsored by Lorman Educational Services. Joining me for the day long seminar will be three very knowledgeable health care colleagues:
  • Michael T. Harmon, MPA, CIPP/G, Compliance Specialist for the West Virginia Mutual Insurance Company, a Medical Professional Liability Insurance Company
  • Sallie H. Milam, J.D., CIPP/G, Executive Director of the West Virginia Health Information Network and Chief Privacy Officer for the West Virginia State Government
  • James W. Thomas, Esq., Manager of the Charleston, West Virginia Business Law Department of Jackson Kelly PLLC whose practice focuses primarily upon health care matters of a business, regulatory and operational nature
Additional information about the seminar and how to register can be found at Lorman Educational Services. Following is the full seminar agenda:

8:30 am – 9:00 am


Registration




9:00 am – 9:15 am


Overview




9:15 am – 10:30 am


HIPAA Compliance: Reality and Perspective



— Michael T. Harmon, MPA, CIPP/G



  • Overview
  • Enforcement
  • Complaints
  • Case Examples
  • Summary of HITECH Changes




10:30 am – 10:45 am


Break




10:45 am – 12:00 pm


HITECH Financial Incentives for Implementation of HIT



— James W. Thomas, Esq.



  • Qualifying an Electronic Health Record System
  • Available Financial Incentives




12:00 pm – 1:00 pm


Lunch (On Your Own)




1:00 pm – 2:00 pm


Health Information Exchange in West Virginia: Impact on Patient Records



— Sallie H. Milam, J.D., CIPP/G




2:00 pm – 2:15 pm


Break




2:15 pm – 3:30 pm


Consumer Driven Health Care: HITECH, Health 2.0, Social Media and Personal Health Records



— Robert L. Coffield, Esq.



  • HITECH Breach Notification Requirements
  • Impact of Health 2.0 and Social Media Technology on the Future of Health Care
  • Development and Adoption of Personal Health Records
  • Discuss the Legal Implications of Emerging Technology




3:30 pm – 4:30 pm


Panel Discussion



— Robert L. Coffield, Esq., Michael T. Harmon, MPA, CIPP/G, Sallie H. Milam, J.D., CIPP/G and James W. Thomas, Esq.

West Virginia State Bar and Office of Disciplinary Counsel News

The West Virginia State Bar announced today that the Office of Disciplinary Counsel has a new website. Also, the West Virginia State Bar has redesigned its website design..

The new Office of Disciplinary Counsel website contains information about the disciplinary complaint process the function of the Lawyer Disciplinary Board, the Rules of professional Conduct and the disciplinary complaint process. The website also has links to all Legal Ethics Opinions issued by the Lawyer Disciplinary Board and recent disciplinary decisions issued by the Supreme Court of Appeals of West Virginia.

Also, the West Virginia State Bar announces that the West Virginia Supreme Court of Appeal has entered order with a proposed amendment to Rule 8, Rules for Admission Pro Hac Vice. The proposed amendment increases the fee pad to the West Virginia State Bar for each individual applicant for pro hac vice admission from $250 to $350. Public comment on the proposed rule is being received through January 25, 2010.
A copy of the proposed order:
Request for Comments on Proposed Amendment to Rule 8.0 Admission pro hac vice, of the West Virginia Rules of Admission to the Practice of Law

UPDATE (3/16/10):

The West Virginia State Bar's Unlawful Practice of Law Committee released Advisory Opinion 10-001, relating to questions from attorneys regarding its interpretation of Rule 8 of the West Virginia Rules of Admission to the Practice of Law, relating to admissions pro hac vice.

Advisory Opinion 10-001 addresses the following issues:

1. Whether the requirement in Rule 8 of of admission pro hac vice extends to matters in which no action, suit or proceeding is pending;

2. To what extent is the responsible local attorney required to participate in proceedings involving the attorney admitted pro hac vice;

3. Whether presiding judicial officers can "excuse" local counsel form participation or "waive" the requirement of participating; and

4. What limitations exist for attorneys seeking to be admitted pro hac vice, particularly their ability to be admitted on a frequent basis, or in multiple or consolidated actions.

Drug and Device Law: Herrmann's Farewell Post

Farewell and congratulations go out to fellow health law blogger, Mark Herrmann, (formerly) co-author of the Drug and Device Law Blog and author of The Curmudgeon's Guide to Practicing Law.

In Mark's Farewell Post he announced that he is leaving Jones Day after 20 years to become the VP and Chief Counsel - Litigation at Aon Corporation. Fellow co-author, James Beck, has this to say (Long Live the Blog) about Mark's departure. He also announces 3 new lawyers joining the blogging team to replace Mark. Wow! 3 lawyers to replace 1. What a complement.

Although not much of my practice focuses on drug and device work, I have been a periodic reader since the early years of blogging. Why? Because I've always loved the tone of their posts - informal, practical and lighthearted. Great to see Beck link to a post that I remember reading (and liking) about why big firms don't blog well. Great advice for any law blogger.

Thanks to the Likelihood of Confusion post that tipped me on Mark's departure.