Can anyone do this assignment by paying much attention to the details and by reading the instructions carefully? Has to be done in own words from scratch.
Journal of Health Care Compliance — January – February 2006 41
Bob Brown, PhD, is the director of Health Informatics, Michigan State
University Kalamazoo Center for Medical Studies.
A Look at the Hurdles HIPAA Has Had to Overcome over the Last 10 Years
I t is now 2006, marking the tenth anniversary of the passage of the Health Insurance Portability and Ac- countability Act (HIPAA), which contained the ad-
ministrative simplifi cation provisions (ASP) of HIPAA intended to “improve the effi ciency and effectiveness of the health care system, by encouraging the develop- ment of a health information system through the estab- lishment of standards and requirements for the electron- ic transmission of certain health information.”
An analysis of the costs and benefi ts of implementing the transaction standards included in the preamble to the transaction standards rule estimated $24.2 billion in net savings over 10 years. In the 10 years since HIPAA was signed into law, much has been accomplished, but how closely does the current health care system resem- ble the vision fi rst presented in 1996, and what if any health care savings have been realized?
IMPLEMENTING HIPAA TOOK LONGER THAN ANTICIPATED When HIPAA was passed in 1996, it contained a section that instructed the Secretary of Health and Human Ser- vices to carry out all the provisions of HIPAA in no more than 30 months. This turned out to be a daunting task. Congress did not appropriate additional funds to HHS for the development and implementation of all the rules mandated by the law, so the task of researching, writing, and revising the rules fell to a core group of HHS staff of no more than 10 headed up by a senior HHS advisor on health policy.
The fi rst two sets of proposed rules completed by HHS were the transaction standards and the national provider ID standards published in the spring of 1998. Then, over the summer, HHS released the proposed employer iden- tifi er and proposed security rules. The original HIPAA
HIPAA BOB BROWN
Does HIPAA Measure Up to What Was Envisioned When the Act Was First Signed Into Law?
Journal of Health Care Compliance — January – February 200642
legislation also mandated that the privacy of electronic health information contained in any electronic transaction be protected to a level specifi ed in a set of national pri- vacy standards.
At the time HIPAA was passed, no such standards existed, but Congress was work- ing on new comprehensive medical privacy legislation that covered all types of health information whether in electronic, paper, or other form. However, since the other provisions of the ASP could not be fully im- plemented without adequate privacy pro- tections in place, and since Congress could not always be counted on to pass needed legislation on a timely basis, HIPAA includ- ed language that said that in the event that Congress did not pass privacy regulation by August of 1998, the task of formulating pri- vacy rules would pass to HHS.
Congress was indeed unable to pass pri- vacy legislation by the deadline, so HHS published proposed privacy rules in No- vember 1998. By the end of 1998 HHS had published fi ve proposed rules, and every- thing seemed to be on schedule to meet the 30 month implementation timeframe con- tained in the legislation.
After this promising start, however, the HIPAA implementation process slowed down considerably. This occurred for a number of reasons. By 1998 most health care organizations realized that they had serious Y2K problems with many of their computer systems which needed to be fi xed before they could begin to make the chang- es needed to comply with the transactions standards. Payers and providers also found problems with some of the transaction standards that would have to be corrected to make them workable.
Provider organizations expressed reser- vations about the privacy rules, with many providers claiming that the rules would disrupt important patient information ex- changes among providers leading to poor- er quality patient care and increased costs. And when the fi nal privacy rules were re- leased in December 2000 with new more
burdensome provisions, including requir- ing providers to obtain written patient consent on a lengthy consent form before treatment, the protests from providers in- creased dramatically.
In addition payers and providers alike were reporting signifi cant problems imple- menting the transaction standards and pre- dicted that very few organizations would be able to meet the October 2002 deadline resulting in potentially devastating disrup- tions in payments to providers.
After George Bush was elected president, many in health care expected that, given his promises to reduce government regula- tions, he would take steps to block imple- mentation of the rules. Indeed, one of his fi rst acts as president was to postpone the effective date of the privacy rules while his administration reviewed them.
However, much to the chagrin of many in the health care fi eld, the Bush admin- istration announced its support for the HIPAA rules and its intention to keep to the April 2003 privacy rule deadline. A re- vised version of the privacy rule was re- leased in August 2001, mainly unchanged but without the consent requirement and with a few other changes intended to ad- dress some of the concerns of health care providers. To address the concerns that the transactions standards deadline would trig- ger a “train wreck” in the health care sys- tem, the administration induced Congress to pass a bill that granted a one year exten- sion of the transaction standards to anyone who applied.
It would be almost two more years be- fore the fi nal security standards were re- leased in February 2003, close to fi ve years after the publication of the proposed rules. HHS stated that this delay was necessary to make sure that the security rules were con- sistent with the privacy rule. HHS also used that time to get more input from security professionals and other interested groups and to modify the rules to refl ect changes in technology that had occurred since the proposed rules were published. The publi-
HIPAA
Journal of Health Care Compliance — January – February 2006 43
cation of the fi nal security rules generated much less controversy than did the fi nal privacy rule and transaction standards.
COMPLIANCE BY COVERED ENTITIES HAS BEEN SLOW It has been three years since the deadline for transaction standards, two years since the privacy rule deadline, and one year since the security rule deadline. So how well are covered entities complying with HIPAA?
Phoenix Health Systems, a health care in- formation management services and consult- ing fi rm, has been conducting a quarterly sur- vey of covered entities’ levels of HIPAA prepa- ration and compliance since the fi rst proposed rules were published. A review of the results indicates that most covered entities got off to a slow start in their compliance efforts. For ex- ample, the fall 2003 survey showed that almost one quarter of providers covered by HIPAA were not in compliance with the privacy rule six months after the April 2003 deadline. Cur- rent levels of compliance still remain far be- low 100 percent as indicated by the results of the most recent survey (Summer 2005) with fewer than half of covered providers in com- pliance with the security rule six months after the April 2005 deadline.
Some of the key fi ndings of the most re- cent survey include:
HIPAA Security Rule Seventy-four percent (74 percent) of payers indicated that they are currently compliant with the HIPAA Security Regulations. Forty-three percent (43 percent) of provid- ers have achieved security compliance.
HIPAA Transactions and Code Sets Eighty percent (80 percent) of providers and payers reported compliance. Seventy-one percent (71 percent) of pro- vider respondents are now transmitting over one-half of the HIPAA standard transactions. Sixty-eight percent (68 percent) of pay- ers are capable of conducting all of the HIPAA standard transactions.
An average of 55 percent of providers and payers indicated that there are trans- actions which their information systems are capable of producing but that are not yet being conducted, in great part be- cause their trading partners are unable to accept or transmit them.
HIPAA Privacy Seventy-eight percent (78 percent) of providers stated they are compliant with the rule. Ninety percent (90 percent) of payers stated they are compliant with the rule. Eighteen percent (18 percent) of provid- ers and six percent (6 percent) of payers reported that they remain noncompliant.
(The results of all the surveys are avail- able online at www.hipaadvisory.com).
ENFORCEMENT HAS BEEN LAX The federal agencies charged with enforc- ing the rules do not conduct routine com- pliance audits of covered entities. Although Congress established signifi cant criminal and civil penalties for noncompliance, few covered entities have been sanctioned for noncompliance. There has been only one criminal prosecution of a HIPAA vio- lation, and as we reported in this column in the September-October 2005 issue, a re- cent Department of Justice opinion makes it unlikely there will be very many more. Currently all compliance investigations are initiated by complaints.
Enforcement for HIPAA compliance is managed by CMS for the non-privacy stan- dards (transactions and code sets, security, et cetera) and by the Offi ce for Civil Rights (OCR) for the privacy standards. As of May 2005, CMS had received 334 complaints.
The majority of complaints fell into three categories: compliant transactions rejected, noncompliant transactions sent, and exces- sive telecommunication fees by trading partner. One hundred-fi fty two of the com- plaints have been closed. CMS monitors all corrective action plans and has determined
HIPAA
Journal of Health Care Compliance — January – February 200644
that most complaints fi led are resolved by the involved parties before reaching the point of issuing a corrective action plan.
OCR reports that through the end of April 2005 the number of privacy complaints totaled 12,542 of which 65 percent were closed. The majority of the complaints deal with health information uses, disclosures, and safeguards. Access to information con- tinues to garner a number of complaints followed by complaints of the minimum necessary standards and violations of the authorization standards and notice. Most complaints are fi led against provider groups such as private physician practices, general hospitals, pharmacies and outpatient clin- ics, and group health plans. OCR has made 200 referrals to the Department of Justice.1
A perceived low level of enforcement by federal agencies may be responsible for low levels of compliance among covered entities. In the discussion of the results of its latest compliance survey, Phoenix Health Systems noted that “…for the fi rst time in the Survey’s six-year history, … many healthcare organizations have sim- ply chosen not to implement many, if not all, HIPAA requirements. The two most re- ported ‘roadblocks’ to HIPAA compliance in the Summer 2005 Survey were ‘no pub- lic relations or brand problems anticipated with non-compliance’ and ‘no anticipated legal consequences for non-compliance.’”2
RETURN ON INVESTMENT HAS YET TO BE REALIZED “Based on our 17 months of HIPAA experi- ence so far…in terms of the administration simplifi cation we have not seen any return on investment as of yet.”3
In testimony at National Committee on Vital and Health Statistics (NCVHS) hear- ings held in April 2005 on the status of HIPAA, representatives of covered enti- ties reported that HIPAA implementation had proved more costly than anticipated, and no one reported any cost savings as a result of HIPAA compliance. In addition, covered entities reported that the extend-
ed transaction standards implementation process required maintaining dual systems for processing both old format and new for- mat electronic transactions adding greatly to the cost of implementation.
Participants also noted that although there was a high level of adoption of the required standard transaction formats, the rule still allowed considerable variation in how these were used. So, whereas before HIPAA there were an estimated 400 for- mats used for electronic health care trans- action standards, now, after HIPAA there was one format with over 1000 variations.
In spite of these disappointing results, how- ever, NCVHS reported that there was support for pushing ahead with the HIPAA transac- tion standards in the hopes that the work cur- rently underway to reduce the variation in the standards will continue to simplify the process. The report concludes that “…testi- mony from physician and provider groups, WEDI [Workgroup for Electronic Data Inter- change], and health information technology (HIT) vendors and clearinghouses generally supported the correlation between improved ROI and the full or improved implementa- tion of HIPAA transactions.” 4
SO IS HIPAA A FAILURE? It is clear that the dramatic cost savings and improvements in effectiveness and effi ciency envisioned in the HIPAA legis- lation and proposed rules have not been realized and that a signifi cant number of health care organizations have done little to implement HIPAA requirements. How- ever, there have been signifi cant develop- ments in the adoption of health informa- tion technology since HIPAA was passed. These include:
Signifi cant increases in the utilization of electronic medical record systems (EMRs): In a survey conducted by the Healthcare Information and Management Systems Society (HIMSS) and Superior Consult- ing Company in 1998 only 2 percent of health care organizations reported us- ing an electronic medical record system
HIPAA
Journal of Health Care Compliance — January – February 2006 45
while in the 2004 survey, 17 percent re- ported having fully implemented EMRs with another 37 percent in the process of implementing one and 23 percent ac- tively planning implementation of an EMR. Only 21 percent of health care pro- viders reported that they had no plans to implement an EMR.5
Major efforts to adopt clinical reporting and messaging standards: In 2002 the federal government began The Consol- idated Health Informatics (CHI), a col- laborative effort to adopt health informa- tion interoperability standards, particu- larly health vocabulary and messaging standards, for implementation in federal government health systems. Establishment of a federal health infor- mation technology offi ce: In 2004 Presi- dent Bush announced the formation of the Offi ce of the National Coordinator for Health Information Technology to provide leadership for the development and nationwide implementation of an interoperable health information tech- nology infrastructure to improve the quality and effi ciency of health care and the ability of consumers to manage their care and safety. Development of national health informa- tion network prototypes: In 2005 HHS awarded contracts to four groups of health care and health information technolo- gy organizations to develop prototypes for a nationwide health information net- work (NHIN) architecture. The contracts awarded to these four consortia will move the nation toward the president’s goal of personal electronic health records by cre- ating a uniform architecture for health care information that can follow consum- ers throughout their lives. We can’t attribute the increase in health
care information technology to HIPAA alone. Many other factors are also driving the adoption of HIT. Factors such as the re- lease in 2001 of the Institute of Medicine report “Crossing the Quality Chasm: A New
Health System for the 21st Century,” which promoted the use of HIT to improve health care quality and reduce medical mistakes or new standards published by health care accreditation organizations such as JCAHO and CARF that encourage the use of HIT as an effective means for complying with ac- creditation standards have also stimulated health care organizations to adopt HIT.
However, HIPAA has certainly played an important role in this ongoing transition. For many organizations, compliance with the transaction standards was the impetus to replace aging practice management sys- tems with newer technologies that includ- ed integrated EMR components. When the fi nal privacy rule expanded the scope of privacy protections to all personal health information (PHI) regardless of the medi- um in which it was kept, many covered en- tities realized that compliance with impor- tant privacy standards governing the use and disclosure of PHI could be greatly fa- cilitated by implementing electronic medi- cal record systems with advanced security and auditing features.
With payers required to accept and re- spond to standard electronic eligibility sta- tus inquiries, many provider organizations have been able to implement real-time benefi t checking that allows them to ac- curately calculate reimbursements before services are provided and reduce loses for providing unreimbursed services.
HIPAA hasn’t failed. But, the Congressio- nal staff who authored the legislation and the HHS staff charged with promulgating the standards underestimated the diffi culty of the tasks when they set their ambitious timeframes. Ten years later there is still much to be done by HHS to complete the regulatory framework required by the leg- islation; and even more to be done by cov- ered entities to make the changes required by the new regulations. And only when we have fully implemented and fi netuned all the HIPAA rules will we be likely to see large scale improvements in the effective-
HIPAA
Journal of Health Care Compliance — January – February 200646
ness and effi ciency of the health care sys- tem along with the accompanying cost sav- ings. Until then, HIPAA is still very much a work in progress.
Endnotes: 1. National Committee on Vital and Health Statistics,
Seventh Annual Report to Congress on the Implementation of the Administrative Simplifi cation Provisions of the Health Insurance Portability and Accountability Act of 1996 Report to Congress, September 8 2005.
2. US Healthcare Industry HIPAA Compliance Survey Results: Summer 2005 (http://www.hipaadvisory.
com/action/surveynew/results/Summer2005.htm). 3. Joseph Smith, vice president of private programs
and chief information offi cer for Arkansas Blue Cross and Blue Shield, in “Transcript of the April 6, 2005 NCVHS Subcommittee on Standards and Security Hearings” (http://ncvhs.hhs.gov/050406tr.htm).
4. National Committee on Vital and Health Statistics, Seventh Annual Report to Congress on the Implementation of the Administrative Simplifi cation Provisions of the Health Insurance Portability and Accountability Act of 1996 Report to Congress, September 8 2005.
5. From the 9th (1998) and 15th annual (2004) HIMSS Leadership Survey, cosponsored by HIMSS and Superior Consultant Company. Survey reports available at http://www.himss.org.
HIPAA