1 / 6100%
Thank you for a very well written post. When I first started out in nursing, I was using paper charts,
which eventually became electronic charting. Unbelievably, a year ago I worked for a surgery center
that still relied on paper charting. It was very hard to believe that they deemed electronic charting
more hectic than paper charting. They had not conformed to the 2009 Health Information
Technology for Economic and Clinical Health (HITECH) Act, which includes the Medicare and
Medicaid Electronic Health Record (EHR) Incentive Programs (Lammers & McLaughlin, 2016).
When I left surgery center, I came back to a facility that does use an EHR. What a difference it made
when charting on my patients. Effective health IT use may alleviate some waste. For example,
multiple studies have found that automated dose calculations in computerized provider order entry
(CPOE) systems produce significant reductions in medication errors, which in turn should reduce
the need for corrective care, thus yielding cost savings. Previous research has found that electronic
prescribing to Medicare beneficiaries reduces the incidence of adverse drug events (ADEs) in both
hospitals and ambulatory care settings. In addition, use of the health information exchange (HIE)
capability of health IT can contribute to reductions in redundant care (Lammers & McLaughlin,
2016).
Over the past decade, Congress has enacted laws requiring CMS to test various "pay-for
performance" initiatives to begin shifting physician payments from volume-based to quality based.
These initiatives included the Physician Quality Reporting System, the Electronic Health Record
Meaningful Use program, and the Value-Based Payment Modifier program. Each was designed to
provide incentives for physicians and groups to engage in behavior, determined by Congress and
various think tanks that would improve the quality of care and, hopefully, reduce the costs of care.
There are two pathways for participation in these new pay-for-performance programs, the series
focuses more on actions required in the Merit-Based Incentive Payment System (MIPS).
Approximately 85% of clinicians submitting Medicare Part B claims will participate in MIPS. The
remaining 15% could assume risk in return for larger incentives while carrying out improvement
activities similar to the MIPS requirements in frameworks known as
Alternative Payment Models. The new rules are intended to provide flexibility to medical providers
as to how they report on quality as well as the other three categories of improvements rather than
the "one size fits all" rules of the past. MIPS-eligible clinicians will include physicians, physician
assistants, nurse practitioners, clinical nurse specialists, certified registered nurse anesthetists, and
groups that include these providers who bill Medicare Part B services.
Eligible clinicians who do not exceed the Medicare "low volume threshold" are exempt from MIPS
reporting (Rutherford, 2017). After working in the surgery center, I now wonder how they were able
to get around the HITECH act, as well as, if they received any pay-for-performance initiatives.
The Health Information Technology for Economic and Clinical Health (HITECH) Act, enacted as
part of the American Recovery and Reinvestment Act of 2009, was signed into law on February 17,
2009, to promote the adoption and meaningful use of health information technology. Subtitle D of
the HITECH Act addresses the privacy and security concerns associated with the electronic
transmission of health information, in part, through several provisions that strengthen the civil and
criminal enforcement of the HIPAA rules.
Section 13410(d) of the HITECH Act, which became effective on February 18, 2009, revised section
1176(a) of the Social Security Act (the Act) by establishing:
Four categories of violations that reflect increasing levels of culpability;
Four corresponding tiers of penalty amounts that significantly increase the minimum penalty
amount for each violation; and
A maximum penalty amount of $1.5 million for all violations of an identical provision.
It also amended section 1176(b) of the Act by:
Striking the previous bar on the imposition of penalties if the covered entity did not know
and with the exercise of reasonable diligence would not have known of the violation (such
violations are now punishable under the lowest tier of penalties); and
Providing a prohibition on the imposition of penalties for any violation that is corrected
within a 30-day time period, as long as the violation was not due to willful neglect.
This interim final rule conforms HIPAA’s enforcement regulations to these statutory revisions that
are currently effective under section 13410(d) of the HITECH Act. This interim final rule does not
make amendments with respect to those enforcement provisions of the HITECH Act that are not
yet effective under the applicable statutory provisions.
Impact on HIPAA Privacy and Security Provisions
The Health Information Technology for Economic and Clinical Health Act (HITECH) is part of
the American Recovery and Reinvestment Act (ARRA) of 2009 and creates incentives related to
health care information technology, including incentives for the use of electronic health record
(EHR) systems among providers.
Because HITECH legislation results in an expansion in the exchange of electronic protected health
information (ePHI), it also widens the scope of privacy and security protections under the Health
Insurance Portability and Accountability Act (HIPAA), including increasing legal liability for non-
compliance and more enforcement actions. The following are highlights of key HITECH provisions
as they relate to HIPAA.
Enforcement
Historically, HIPAA was not rigorously enforced, but the adoption of the final rule [PDF] in
2013 clarified and strengthened enforcement activities. Both covered entities and business
associates are subject to penalties for violations.
Civil money penalties for "willful neglect" are increased.
Although an individual can't bring a cause of action against a provider for violations under
HITECH, a state attorney general can bring an action on behalf of a state's residents.
The Department of Health and Human Services (HHS) is required to conduct periodic
audits of covered entities and business associates.
Notification of Breach
HITECH imposes data breach notification requirements for unauthorized uses and disclosure of
unsecured or unencrypted PHI.
Electronic Health Record Access
For providers that have implemented an EHR system, individuals have a right to obtain their PHI in
an electronic format. Only a fee equal to the labor cost can be charged for an electronic request.
Business Associates (BA) and Business Associate Agreements (BAA)
HITECH now applies HIPAA provisions to business associates, thus requiring business
associates to comply with the HIPAA security rule.
Most, if not all, software vendors providing EHR systems will clearly qualify as business
associates.
Business associates must report security breaches to covered entities consistent with
notification requirements.
Business associates are subject to civil and criminal penalties, just as the covered entities are
subject to these penalties.
Business associates and providers will now share more joint responsibilities than they have
previously.
HITECH Act Summary
The HITECH Act encouraged healthcare providers to adopt electronic health records and improve
privacy and security protections for healthcare data. This was achieved through financial incentives
for adopting EHRs and increased penalties for violations of the HIPAA Privacy and Security Rules.
The HITECH Act contains four subtitles (A-D). Subtitle A concerns the promotion of health
information technology and is split into two parts. Part 1 is concerned with improving healthcare
quality, safety, and efficiency. Part 2 is concerned with the application and use of health information
technology standards and reports.
Subtitle B covers testing of health information technology, Subtitle C covers grants and loans
funding, and Subtitle D covers privacy and security of electronic health information. Subtitle D is
also split into two parts. Part 1 is concerned with improving privacy and security of health IT and
PHI, and Part 2 covers the relationship between the HITECH Act and other laws.
HITECH Act Compliance Date
The HITECH Act introduced a number of challenges for Covered Entities, Business Associates,
and enforcement agencies such HHS´ Office for Civil Rights and the Federal Trade Commission
which, under HITECH, is required to enforce the breach notification regulations for vendors of
personal health apps and other organizations not covered by HIPAA.
Consequently, the compliance dates for HITECH were staggered. Some HITECH Act provisions
such as the authority for State Attorney generals to bring a civil action were effective upon
enactment (February 2009), while other provisions had effective dates 60 and 180 days after the
passage of HITECH or by the end of the year.
The requirement for Business Associates to comply with HIPAA was scheduled to take effect in
February 2010; but, as with many provisions of Subtitle D, some HITECH Act compliance dates
were delayed until the publication of the HIPAA Final Omnibus Rule in 2013. Consequently, there
is no single HITECH Act compliance date.
The Meaningful Use Program
The Department of Health & Human Services (HHS) was given a budget in excess of $25 billion to
achieve the goals of the HITECH Act. The HHS used some of that budget to fund the Meaningful
Use program a program that incentivized care providers to adopt certified EHRs by offering
monetary incentives. Certified EHRs are those that have been certified as meeting defined standards
by an authorized testing and certification body.
Certified EHRs had to be used in a meaningful way, such as for issuing electronic prescriptions and
for the exchange of electronic health information to improve quality of care. The program aimed to
improve coordination of care, improve efficiency, reduce costs, ensure privacy and security, improve
population and public health, and engage patients and their caregivers more in their own healthcare.
The financial incentives were initially significant and increased with each year of the program as new
requirements were introduced at each of the three stages of the Meaningful Use program. However,
from 2015 onwards, Medicare-eligible professionals that did not comply with the HITECH EHR
requirements saw the reimbursement of Medicare claims penalized by 1%. In 2017, the penalty for
failing to demonstrate the adoption and use of a certified EHR increased to 3%.
Regardless of what some may say, I believe God wants us to use technology as long as it is to further
his purposes. In other words, I do not believe He’s entirely for or against technology. But this
doesn’t mean that God is okay with however we decide to use technology. He calls us to use
technology for his glory and our good (1 Cor. 10:31)not for the destruction of his creation or
people.
References
Lammers, E. J., & McLaughlin, C. G. (2016). Meaningful use of electronic health records and
Medicare expenditures: Evidence from a panel data analysis of U.S. health care markets, 2010-
2013. Health Services Research, 52(4), 1364-1386. https://doi.org/10.1111/1475-6773.12550
Students also viewed