Dorsey Health Law
AI
The Use of AI for Autonomous Medical Decision-Making: Does Utah’s AI Prescription Renewal Pilot Program Go Too Far?
This year, Utah commenced a contract with Doctronic to pilot a medication renewal program where Doctronic’s AI system autonomously authorizes refills for certain routine medications. The contract arranged for a partnership between the Utah Office of Artificial Intelligence Policy (Office) and the Utah Department of Professional Licensing (DOPL), who agreed to refrain from regulatory enforcement during the 12-month term of the pilot program. The implementation of this type of AI pilot program in the state was made possible by the Utah Artificial Intelligence Policy Act (UAIP) which was passed in 2024. The UAIP established the Office and tasked it with creating a mechanism for companies to apply with the Office to receive 12 months of regulatory mitigation while developing a proposed AI system. This regulatory “sandbox” allows Doctronic to test its medication renewal program without professional licensing or scope-of-practice enforcement concerns. Doctronic’s program is the first state-approved AI tool that is legally permitted to participate in autonomous medical decision-making for prescription renewals. In late April, the Utah Medical Licensing Board (Medical Board) released a letter responding to the launch of the new statewide pilot program. The Medical Board criticized the state for failing to include the Medical Board in the decision-making process prior to executing the Doctronic contract, and called on the state to immediately suspend the Doctronic program. While the DOPL creates and executes professional regulations in the state, the Medical Board serves in an advisory capacity regarding practice and licensing standards in Utah. The Medical Board’s letter expressed concern that it was not given the opportunity to opine on the Doctronic pilot program despite the Medical Board’s expertise and advisory role. The Doctronic AI Prescription Renewal Tool During the course of the pilot program, patients who choose to participate will access a cloud-based web application and create a free member account which will verify their identity to have their prescription refilled. Patients must then submit photographic evidence of their current medication (prescription label or pill bottle showing medication name, dosage, and prescriber information). After identifying the patient and the prescription, the AI system will perform a secondary verification using Surescripts—a national health information network. The AI tool will then gather a medication-focused medical history from the patient and available data. Finally, the AI tool will determine if prescription renewal is appropriate and if so, will send the prescription refill order to the patient’s preferred pharmacy. The pilot program has 3 phases. Under phase one, for the first 250 patients, all AI-generated renewal decisions will undergo review by licensed physicians prior to the renewal being submitted to the pharmacy. During phase two, AI-generated renewal decisions for the next 1,000 patients will be retrospectively reviewed by licensed physicians. During the final phase, the pilot will have a structured sampling approach to quality oversight with: (i) 5-10% of all renewals reviewed monthly; (ii) quarterly analysis of escalated cases; and (iii) annual review of performance metrics and clinical outcomes. The contracted-for mitigation includes the state forgoing any enforcement action for unlawfully practicing a regulated profession, such as the practice of medicine, without a license. State Laws While Utah’s AI prescription renewal pilot program is the first of its type, its implementation reflects a nationwide legislative push to increase the use of AI technology and AI decision-making in healthcare. As of early June, over 280 bills across 44 states have been introduced this year focusing on the use of AI in health care. Eleven of these bills address autonomous clinical decision-making by AI platforms. After its Utah contract, Doctronic has confirmed it is in active discussions to implement similar “sandbox” programs with Texas, Arizona, and Wyoming. Additionally, there are several other large AI platforms on the market that are involved in, or seeking to become involved in, government sanctioned healthcare technology programs. Federal Law The use of AI in health care is also the subject of legal initiatives at the federal level. The Trump administration has issued several executive orders (EOs) meant to promote and steer the use and development of AI technologies. The 2025 “Removing Barriers to American Leadership in Artificial Intelligence” EO is notable as it directs the Assistant to the President for Science and Technology to revoke all policies, directives, regulations, orders, and other actions taken pursuant to the revoked Executive Order 14110 (Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence) in order to achieve the EO’s purported goals of encouraging development and innovation in the AI sector. Another similar and notable EO is the “Promoting Advanced Artificial Intelligence Innovation and Security” EO, which establishes a legal framework allowing AI developers to collaborate with the federal government to ensure secure AI innovation and to accelerate the deployment of the developers’ AI technologies. While this second EO primarily focuses on the development of AI tools for military use and national security, these and other AI-focused EOs from the Trump administration evidence a general desire to focus on developing and improving AI tools. In addition to many EOs, the introduction of federal legislation such as the Healthy Technology Act of 2025 demonstrates a shift towards AI decision-making in health care even at the Federal level. The Healthy Technology Act of 2025, was proposed to amend the Federal Food, Drug, and Cosmetic Act (FDCA) to clarify that artificial intelligence and machine learning technologies can qualify as a practitioner eligible to prescribe drugs if a) authorized by the law of the State involved; and b) approved, cleared, or authorized by the Food and Drug Administration. Under the FDCA certain drugs can only be dispensed pursuant to a prescription issued by a legally recognized “practitioner.” While the bill would not automatically allow AI systems to prescribe nationwide, it would allow AI systems to qualify as a “practitioner” when approved under state law. If the Healthy Technology Act were passed, Utah’s regulatory sandbox is the exact type of state-level program contemplated by the law—although, it is notable that proponents and opponents of the Utah pilot program currently disagree on whether the AI system should be considered the practitioner issuing judgment or a renewal assistant acting pursuant to delegated authority under a supervising practitioner’s license. Where states characterize an AI tool as a practitioner, the Healthy Technology Act (or similar legislation) would create a federal pathway recognizing that AI systems can be approved and recognized as prescribing practitioners, eliminating any question as to whether a prescription initiated by a state-and FDA-approved AI technology is a valid prescription under federal law. Alternatively, in states not introducing frameworks for AI systems to operate as a “practitioner,” the proposed Healthy Technology Act would have no effect. It is unclear whether Doctronic’s AI system being utilized in the Utah pilot program is operating as a “helper” or the “practitioner”. On the one hand, the tool may be characterized as a “helper” to the practitioner and not the practitioner themselves. The fact that Utah uses the named prescriber’s license number when authorizing the renewal is evidence of this “helper” characterization. Using the “helper” characterization potentially takes advantage of a regulatory loophole allowing the Utah program to avoid the question of whether—without redefining a practitioner under the FDCA—AI tools acting independently can generate a lawful prescription. On the other hand, the Doctronic contract seems to characterize the AI tool as a practitioner by saying that the AI program itself may “authorize” a renewal. The ability of states to avoid culpability for having AI tools operate as practitioners by recharacterizing the tool as a helper rather than the practitioner may have explained, in part, why the Healthy Technology Act has stalled and no similar legislation has been presented. The Act was introduced and referred to the House Committee on Energy and Commerce on the same day in January 2025 but has since had no further actions. Benefits to Autonomous AI Prescribing By utilizing AI in healthcare, both state and federal governments hope to decrease administrative burden, reduce employee burnout, and improve patient satisfaction. The stated goals of the Utah program are to improve medication adherence, address refill delays, improve healthcare access in underserved communities, and minimize practitioner time spent on routine refill requests. Criticisms of Autonomous AI Prescribing Despite the potential positive benefits of AI prescribing tools, clinicians, patients, and healthcare organizations raise significant concerns about the technology. The Medical Board cited concerns such as the AI tool’s inability to reassess patients and apply clinical judgment to safely adjust doses, monitor for side effects, or ensure continued efficacy based on the assessment findings. Opponents note that when patients are responsible for entering their information into an AI platform, the patient could make a mistake. Additionally, patients may exclude information they don’t know is important. AI models will analyze and make decisions based on the data they receive, even if it is incorrect or incomplete and will not challenge discrepancies between a narrative and a physical presentation like a human practitioner can during a patient visit. Opponents argue that human providers are likely to have better outcomes than AI when an informed medical opinion requires both accurate patient data and assessment of the patient’s physical presentation. The critics’ argument is that a human provider can collect more accurate and complete data from a patient because they have the benefit of being able to compare what the patient is saying with the clinical picture the provider is seeing or has previously seen; allowing the provider to challenge inconsistencies—catching prescription errors or inefficiencies sooner, more often, or without needing an adverse event to alert the patient or others to an error. Other concerns include inadequate safety protocols (regulatory and within the AI itself), privacy concerns, fewer opportunities for a clinician to lay eyes on their patients as AI takes on a larger role, and scope creep—a phenomenon where, once the initial AI is reviewed and approved, the technology company can implement updates that don’t face the same level of regulatory scrutiny and thus, the technology company may expand the AI’s scope beyond medication renewals. One of the most prominent legal concerns with AI autonomous clinical decision-making is professional liability. The following are just some of the critical questions that arise when analyzing professional liability implications when AI tools exercise autonomous medication renewal decisions: Who will be responsible if there is an erroneous prescription renewal? AI developer, prescribing practitioner, the pharmacy, the state? As AI become more autonomous, will hospitals need to credential it? Must it be incorporated into privileging processes? How does peer review apply? Do existing corporate practice laws create obstacles? Does the reliance on AI establish a new standard of care? In other words, could failure to use AI eventually become evidence of negligence? Whether the numerous concerns about AI will dampen the adoption of autonomous AI decision-making in healthcare remains to be seen. Instead, the concerns may drive developers, regulators, and proponents to creating stronger safeguards, oversight mechanisms, and regulatory frameworks, in response. What is clear is that AI developers are moving AI tools beyond those that simply perform administrative functions and into tasks traditionally reserved for licensed healthcare professionals. As states continue to experiment with regulation and legislative bodies consider expanding AI’s role in clinical care, healthcare organizations should closely monitor developments involving liability, scope-of-practice requirements, privacy protections, and standards of care. The answers to these questions and concerns may ultimately determine how AI is used in healthcare, the extent to which patients and providers are willing to trust healthcare AI programs, and whether organizations choose to incorporate AI programs into their clinical practices.
June 29, 2026
HIPAA’s 2024 Reproductive Health Rule is Vacated Nationwide – One Year After Going Into Effect
On June 18, 2025, a Texas court issued a ruling that vacated, on a nationwide basis, the HIPAA Privacy Rule to Support Reproductive Health Care Privacy (the “Reproductive Health Rule”), just one year after the rule went into effect. In Purl v. United States Department of Health and Human Services, No. 2:24-CV-228-Z (N.D. Tex. June 18, 2025), plaintiffs, Dr. Carmen Purl and her medical clinic, challenged the validity of the Department of Health and Human Services (“HHS”) Reproductive Health Rule on the grounds that the rulemaking exceeded HHS’ statutory authority and unlawfully restricted state-mandated reporting obligations, particularly in the context of child abuse investigations. The plaintiffs argued that federal law 42 U.S.C. § 1320d-7(b) provides that "[n]othing in [HIPAA] shall be construed to invalidate or limit the authority, power, or procedures established under any law providing for the reporting of disease or injury, child abuse, birth, or death, public health surveillance, or public health investigation or intervention." Dr. Purl and her medical clinic argued that the Reproductive Health Rule did just that: it unlawfully impeded Texas’ state-mandated reporting of child abuse and public health investigations—in contravention of 42 U.S.C. § 1320d-7(b)—by interfering with health care providers’ ability to make such reporting if the reporting involved the broadly defined term “reproductive health care”. As the court noted, the Administrative Procedure Act states: courts must "hold unlawful and set aside" agency actions that are "not in accordance with law" or are "in excess of statutory jurisdiction, authority, or limitations, or short of statutory right" (5 U.S.C. § 706(2)(A), (C)). Accordingly, the court held that HHS acted outside of the bounds of its statutorily delegated authority and in contravention of federal law because the Reproductive Health Rule 1) "unlawfully 'limits' state public health laws," 2) "impermissibly redefines 'person' and 'public health,' in contravention of Federal law and 'in excess of statutory authority,'" and 3) was adopted without authority expressly delegated by Congress. The Reproductive Health Rule went into effect on June 25, 2024, with a compliance deadline of December 23, 2024. The Reproductive Health Rule amended the Health Insurance Portability and Accountability Act (“HIPAA”) regulations by adding a class of protected health information (“PHI”) that carried heightened protection, called “reproductive health information”. The Reproductive Health Rule was issued by HHS in reaction to the U.S. Supreme Court case, Dobbs v. Jackson Women's Health Organization, 597 U.S. 215 (2022), which overturned the federal right to an abortion, returning authority to regulate abortion to the states. Given widespread concerns that state abortion restrictions could interfere with individuals’ willingness to seek reproductive health care, HHS responded to Dobbs by amending HIPAA’s Privacy Rule to limit the circumstances under which “reproductive health information” could be disclosed for certain non-healthcare purposes. Specifically, under the Reproductive Health Rule, HIPAA-regulated entities were not allowed to disclose “reproductive health information” for the following purposes: (i) To conduct a criminal, civil, or administrative investigation into or impose criminal, civil, or administrative liability on any person for the mere act of seeking, obtaining, providing, or facilitating reproductive health care, where such health care is lawful under the circumstances in which it is provided; or (ii) The identification of any person for the purpose of conducting such investigation or imposing such liability. HIPAA-regulated entities were required to obtain a written attestation from persons requesting PHI related to reproductive healthcare in situations involving health oversight, judicial or administrative proceedings, law enforcement and disclosures regarding decedents such as disclosures to coroners and medical examiners. Compliance with the Reproductive Health Rule entailed HIPAA-regulated entities adopting new policies and procedures, conducting internal training, and often required education of any third parties who were presented with an attestation in response to their requests for PHI. With the ruling in Purl, just one year after the Reproductive Health Rule went into effect, HIPAA-regulated entities that implemented new policies and procedures in accordance with the Reproductive Health Rule can now terminate those policies and procedures immediately, with the exception of a future compliance obligation related to a separate topic that was included as part of the Reproductive Health Rule: patient notification about substance use disorder treatment records. Notably, the Reproductive Health Rule also requires that HIPAA-regulated entities amend their Notice of Privacy Practices (“NPP”) by February 16, 2026 to reflect changes in the uses and disclosures of substance use disorder treatment records in light of changes in federal substance use disorder regulations at 42 C.F.R. Part 2 (the “Part 2 NPP Requirement”). The Purl decision severed the Part 2 NPP Requirements from its order vacating the Reproductive Health Rule, and therefore, HIPAA-regulated entities are still required to amend their NPPs pertaining to substance use disorder regulations by February 16, 2026. Please contact this author or your regular Dorsey & Whitney LLP attorney to discuss this legal development.
June 23, 2025
Trump Administration 2.0: Legal Updates Impacting Health Care
Federal Grant and Loan “Temporary Pause” to Have a Significant Impact on the Health Care Industry
UPDATE - January 29, 2025: The Trump Administration rescinded the OMB memorandum ordering the federal grant and loan pause on January 29, 2025. UPDATE - January 28, 2025: The federal grant and loan pause described in this blog post has been temporarily enjoined by a U.S. District Court until February 3, 2025 for funds that were already set to be disbursed. We will continue to monitor the status of the pause on federal assistance. UPDATE - January 28, 2025: Following a widespread lock out to Medicaid portals in all 50 states, the White House Press Secretary issued a statement on X that Medicaid would not be impacted by the OMB spending freeze memo and the Medicaid portal should be back online soon. A memorandum from the Office of Management and Budget (“OMB”) on January 27, 2025 notified heads of federal agencies of a temporary pause on all disbursements of federal grants and loans, effective at 5pm Eastern on January 28, 2025. The OMB memorandum requires federal agencies to submit detailed information on programs, projects, or activities subject to the pause by February 10, 2025 so that OMB can evaluate their alignment with the Administration’s priorities for federal spending which have been revealed in part through recent Executive Orders. There is some uncertainty as to how broadly the pause in federal funding will apply, as the OMB memo permits OMB to grant exceptions on a case-by-case basis, and notes that the pause is subject to what is “permissible under applicable law.” The memo states that the pause does not impact direct federal assistance to individuals, and therefore should not disrupt the flow of Medicare reimbursement to health care providers, or impact Social Security payments. Many in the health care industry will be impacted, however, as the pause will impact federal funding disbursed by the Department of Health and Human Services, which is the largest grant-making agency in the U.S. Access to Medicaid payment portals was cut off in all 50 states as of January 28, 2025, creating uncertainty about the pause’s applicability to Medicaid and Medicaid beneficiaries’ ability to access care. The federal funding pause will likely impact every state-federal cooperative program which receives funding through the federal government For example, health centers providing family planning, HIV treatment/prevention and other services which are paid for through federal funding, including impacting these clinics’ ability to make payroll and keep the centers open for patient care. The pause will also have an impact on federal research and loans to research institutions, as well as to universities and other private organizations. The pause raises questions regarding the President’s ability to override spending decisions made by Congress and compliance with a federal statute called the Impoundment Control Act. The first lawsuit challenging the pause, which includes health care industry plaintiffs, was filed on January 28, 2025. For additional guidance on steps for recipients of federal grant and loan funding to take now, please see this post by our Dorsey colleagues. An important first step is to seek clarification from your grants management official regarding permissible activities under the grants during this period of time covered by the pause. Then, continue to follow up and monitor any changes to that advice as the issues continue to play out over the coming days, weeks and months. Dorsey attorneys are actively monitoring Executive Orders and other activities of the new Administration and will continue to publish updates and analysis on the impacts of these actions in health care.
January 28, 2025
Immigration
ICE in your Healthcare Facility? No Need to Freeze
For over a decade, agents with U.S. Immigration and Customs Enforcement (“ICE”) were instructed pursuant to official policies to refrain from conducting law enforcement actions in or near various “sensitive locations” or “protected areas,” such as healthcare facilities, schools, and churches. Exceptions existed in the policies for exigent circumstances, such as when the enforcement action involved a national security threat or there was an imminent risk of death, violence, or physical harm to a person. But the exceptions and the policies are no more: One of President Trump’s first actions in his second term was to rescind the policies, first put in place in 2011 and reiterated in 2021. In the following days, hospitals and other previously protected places began to report the presence of ICE agents conducting enforcement actions involving searches, interviews, and arrests. Because of this abrupt change in policy, many hospitals and other healthcare facilities are understandably unfamiliar with what to do and expect when ICE agents arrive at your door. But fear not, below is a short list of “dos” and “do nots” to follow when (and even before) ICE agents arrive at your facility. This guidance is intended to help your staff balance cooperating with federal agents and protecting patient privacy. Do: Prepare a written policy and standard operating procedure for interacting with immigration agents (which should accompany policies for interacting with law enforcement authorities in general). Identify an internal resource (in-house counsel or other representative with education and training on dealing with law enforcement), whether a single person or a team, who is well-versed in the rules for interacting with ICE agents. Identify an external resource, such as outside counsel, who can support your response when immigration agents arrive. Contact your internal and external resources immediately when immigration agents arrive. Instruct your front desk staff to inform the ICE agents that they must speak with your internal or external resource, and make arrangements to do so. While making those arrangements, direct the ICE agents to a conference room away from patients in order to avoid causing patient concern/disruption. Identify the ICE agent and inquire whether any government lawyer is aware of their activities. Understand that ICE agents are allowed in public spaces like a hospital waiting room, parking lots, and cafeterias, but to enter any private patient care areas they need a valid warrant or your permission (which you may withhold, unless there is a judicial warrant). Understand that any warrants or subpoenas served by immigration agents may be judicial (issued by a federal or state court judge) or administrative (issued by the government agency, including an immigration judge), and that agents do not have the authority to enter private areas with an administrative warrant or subpoena. Have in-house or outside counsel review all warrants and subpoenas to determine their validity, and cooperate with agents that present valid judicial warrants or subpoenas. Generally speaking, any judicial search warrants should: Be signed by a judge. Specify the name of the hospital, the time period for executing the warrant (and the current time is within that stated time period) and describe the scope of the search. If there is no judicial warrant or subpoena, but the ICE agents are armed with an administrative warrant or subpoena, or otherwise describe an exigent circumstance (e.g., their actions are necessary to avoid imminent harm to the public, national security, or your staff/other patients), evaluate the circumstances. It is important to balance protection of patient privacy with cooperating in an investigation that appears necessary to protect individuals/the public. Have at least one facility representative accompany each ICE agent around the facility. Note any staff or patients interviewed or items/records seized. Staff may videotape the ICE agents. Protect patient privacy in accordance with HIPAA and applicable state law. HIPAA generally does not allow disclosure of patient information (protected health information) including patient names or immigration status unless an exception under HIPAA is satisfied. Your lawyer can help to evaluate whether an exception applies to any requested disclosure. This may include objecting to a search that is outside of a valid warrant. Employees, patients, and visitors have the right to remain silent and they can be advised on that right. Be aware the ICE agents may not be in the facility for surveillance or investigation, but instead may be there to deliver an I-9 audit. It is important to develop policies and procedures to appropriately respond to an I-9 audit. The facility will have three business days to produce the requested I-9 forms. It is important to contact the facility’s attorney immediately if you receive an I-9 audit. Understand that immigration agents visiting your facility may be with ICE, or with US Customs and Border Protection (“CBP”), or with the United States Citizenship and Immigration Services (“USCIS”). For example, USCIS officers may be conducting a Fraud Detection and National Security (FDNS) site visit to confirm the veracity of a nonimmigrant (H-1B, L-1, TN, etc.) petition. Cooperation with this type of site visit is not mandatory, but it is beneficial to provide officers with requested information so that they are able to make a finding with a full record. Do Not: Do not allow ICE agents into patient care areas without the input of your internal and/or external resources, and confirmation that they have valid authority or your permission. The front desk staff can tell the ICE agents that they are not allowed to let them into private patient care areas without talking to the facility’s lawyer. Do not give statements to ICE agents without consulting with an attorney. Do not direct employees or patients to refuse to speak to ICE agents when questioned. Do not hide patients or employees or assist them in leaving the premises. Do not provide false information or destroy records. Do not leave patient information visible from public areas. Even without a search warrant, ICE agents in public areas can look at things that are in plain view, such as papers and computer screens. So, reasonable safeguards should be implemented to cover patient information that is in public spaces, such as covering papers or shielding computer screens or taking any conversations into private spaces to avoid any inadvertent disclosure. Do not allow the presence of ICE agents to interfere with patient access to health care. Dorsey attorneys are actively monitoring activities of the new Administration and will continue to publish updates and analysis on the impacts of these actions in health care. Contact your regular Dorsey attorney or the authors for further guidance.
January 28, 2025
Iowa Fetal Heartbeat Law to Go Into Effect on July 29, 2024
Iowa’s fetal heartbeat law, House File 732, which was signed into law by Governor Kim Reynolds in 2023, will go into effect on Monday, July 29, 2024. This blog post gives a brief background and summary to help hospitals and providers understand their obligations under the law. The fetal heartbeat law has been temporarily enjoined from enforcement since July 2023. However, a 4-3 decision from the Iowa Supreme Court in June 2024 in Planned Parenthood of the Heartland, Inc. v. Reynolds ex rel. State, 2024 Iowa Sup. LEXIS 74, 2024 WL 3209943, and a subsequent order from District Court Judge Jeffrey Farrell dissolving the temporary injunction, will allow the fetal heartbeat law to go into effect on July 29. The fetal heartbeat law bans abortions, with exceptions for rape, incest, non-viability of the fetus and medical emergencies, after a fetal heartbeat can be detected. A fetal heartbeat can be detected as early as six weeks into a pregnancy. In order to be effective as an exception to the law, the rape and incest exceptions require reporting to law enforcement, a public health agency, or doctor within 45 days for rape, and 140 days for incest. With regard to the medical emergency exception, some have read the Iowa Supreme Court in Planned Parenthood of the Heartland, Inc., to interpret this exception narrowly. Under this narrow reading, “medical emergency” (which permits an abortion after fetal heartbeat detection), would include neither “psychological conditions, emotional conditions, familial conditions, or the woman’s age” or, “when continuation of the pregnancy will create a serious risk of substantial and irreversible impairment of a major bodily function of the pregnant woman.” Id. at 6. This interpretation would mean that unless a woman has a life-threatening condition, an abortion is not permitted in order to preserve the health of the mother – even if the mother’s health would be at risk of substantial and irreversible impairment of a major bodily function. However, federal law, known as the Emergency Medical Treatment and Labor Act (EMTALA), currently preempts Iowa law to the extent that Iowa law conflicts with EMTALA. EMTALA defines “emergency medical condition” to encompass health-jeopardizing, and not merely life-threatening conditions. Therefore, if the treating physician determines that an abortion is necessary to stabilize a women’s emergency medical condition, then EMTALA would control the decision under those circumstances. While this potential conflict between state and federal law will come to the forefront in Iowa starting on July 29th, the issue of EMTALA pre-emption of a state abortion restriction was already addressed in June 2024 by the U.S. Supreme Court. In that case, the U.S. Supreme Court allowed an order by a federal judge in Idaho to remain in place that temporarily blocks the State of Idaho from enforcing an abortion ban (which is similar to Iowa’s fetal heartbeat law) to the extent that the Idaho law conflicts with EMTALA. This means that Idaho doctors currently have the discretion to perform emergency abortions if a provider determines that an abortion is necessary in order to stabilize a woman’s medical emergency. It is likely that other cases will come before federal courts across the country to test EMTALA pre-emption of abortion restrictions in the context of medical emergencies, so hospitals and providers should continue to monitor the status of these cases. In order to better understand their EMTALA obligations, hospitals and physicians should review the CMS guidance which addresses the EMTALA obligations of hospitals and physicians in light of new state laws prohibiting or restricting access to abortion. It is important to note that in addition to the fetal heartbeat law, there are other requirements in Iowa related to providing an abortion. For example, Iowa Code Chapter 146A includes a number of prerequisites that a physician performing an abortion must complete. These prerequisites include a written certification from the pregnant woman 24 hours prior to the abortion that she has undergone an ultrasound, an opportunity to view the ultrasound and hear a description of the ultrasound and heartbeat, and has been provided information regarding alternative options to abortion, risks associated with abortion and materials developed by the State. Notably, the Iowa Code Chapter 146A abortion prerequisites do not apply in the event of an abortion performed in a medical emergency. We will continue to monitor the progress of these laws and provide updates in this blog. If you have any questions about these laws’ impact on you or your organization, please contact the authors or your regular Dorsey attorney.
July 24, 2024
Data Privacy and Security
HIPAA on the Horizon in the New Year: Important Lessons from an Active 2023 and Regulatory Initiatives to Watch for in 2024
2023 marked 20 years since the first compliance deadline under the Health Insurance Portability and Accountability Act’s (“HIPAA”) privacy rule. Despite the two decades of experience with HIPAA, compliance continues to remain a challenge for HIPAA-covered entities as well as for their business associates. 2023 brought a large number of important HIPAA-related developments and lessons-learned that privacy/security officials and health care attorneys should be aware of when planning for HIPAA compliance activities in 2024. This article features lessons learned in some of the most significant HIPAA-related enforcement actions and guidance documents from the U.S. Department of Health and Human Services’ Office for Civil Rights’ (“OCR”) in 2023, and ends with a summary of some of the ongoing OCR regulatory initiatives to monitor in 2024. OCR’s First Enforcement Action Related to a Phishing Attack On December 7, 2023, the OCR announced a $480,000 settlement with Lafourche Medical Group (“LMG”), a Louisiana-based medical group specializing in emergency medicine, occupational medicine, and laboratory testing. The settlement marks the first time that OCR resolved a phishing attack under HIPAA. According to OCR Director Melanie Fontes Rainer, phishing is “the most common way that hackers gain access to health care systems to steal sensitive data and health information.” In March 2021, a staff member of LMG was the victim of a phishing attack that compromised the staff member’s email account containing the electronic protected health information (“PHI” or “ePHI”) of as many as 34,000 patients. LMG reported the incident to OCR in May 2021, and OCR began its investigation in January 2022. After OCR investigated the breach, it determined that LMG had failed to comply with the following basic HIPAA requirements: (i) conducting a risk analysis to determine vulnerabilities to PHI, and (ii) creating and maintaining policies and procedures to regularly review information system activity and to safeguard PHI against cyberattacks. As a result of these findings, LMG entered into a resolution agreement with OCR on November 3, 2023, which requires LMG to pay a $480,000 penalty to OCR and implement a two-year corrective action plan (“CAP”) to address the HIPAA violations identified in OCR’s investigation. As part of the CAP, LMG has agreed to undertake HIPAA compliance activities that are required of health care providers: Establish and implement security measures to reduce security risks and vulnerabilities; Develop, maintain, and revise written policies and procedures as necessary to comply with HIPAA; and Provide training to all staff members who have access to patient PHI on HIPAA policies and procedures. OCR’s report of this first-of-a-kind settlement noted that in 2023 (through November), based on data breaches reported to it, over 89 million individuals had been affected by large data breaches (those involving 500 or more individuals). This was up from 2022, in which over 55 million individuals were affected by these large data breaches. To drive home the significance of OCR’s enforcement action, OCR noted in its press release about the settlement, “Phishing attacks can result in identity theft, financial loss, discrimination, stigma, mental anguish, negative consequences to the reputation, health, or physical safety of the individual or to others identified in the individual’s protected health information.” Lesson learned: Covered entities should regularly update and review the risk analysis and ensure the organization has adopted business grade security measures to protect ePHI. Covered entities should also routinely review and update written HIPAA privacy and security policies and procedures, and, most importantly, deliver frequent staff training to ensure staff remain vigilant and skeptical of any suspicious emails or other contact, and report the emails or other contact immediately to the privacy and security officers. Staff training is a critical line of defense against phishing attacks. Embedded Tracking Technologies- HIPAA Covered Entities and Business Associates Should Carefully Review Their Websites In December 2022, OCR issued a bulletin that warned HIPAA covered entities and business associates against the use of embedded tracking technologies that could track individually-identifiable health information on the covered entities’ or business associates’ websites. OCR defined “tracking technology” as “a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app.” While some covered entities track online user activity internally, many covered entities contract with third-party analytics companies to track and analyze the data about the individual users’ access to and interaction with the covered entity’s website. Common third-parties used to track website use data include: Meta Pixel, Google Analytics and Adobe Analytics. Tracking technologies allow the covered entity to gain insights about users’ online activities for marketing purposes, and to help improve patient experience on the website and to improve patient care, among other reasons. However, the third-parties who track the data are also able to use the data to target ads and to otherwise profile the users. The guidance points out that individually identifiable health information (such as a person’s appointment date, home or email address, or IP address) is “protected health information” that is governed by HIPAA, even if the individual does not have a pre-existing relationship with the covered entity and even if the information does not include sensitive information like treatment information, diagnosis or billing data. As OCR noted in its guidance, the risk that the data being tracked is HIPAA-protected PHI is highest on those portions of a covered entity’s website that have user-authenticated pages (where the individual logs in) because the information on those pages are more likely to include sensitive health information like diagnosis, prescription and other treatment information. OCR’s bulletin warned that the use of individually identifiable health information that is tracked on a covered entity’s website must be in compliance with HIPAA’s privacy and security rules. This means, for example, that any third-party data tracker/analyst who the covered entity engages must have a written business associate agreement in place with the covered entity. Prior to, and after OCR’s bulletin, twenty or more class action lawsuits were filed against hospitals and health systems across the U.S. based on allegations that the hospitals were inappropriately sharing patient data with companies like Google, Facebook, Adobe and others for marketing purposes. Some of the cases have settled and others are ongoing. In response to the OCR bulletin, hospitals and health systems expressed alarm due to the proliferation of the use of website data trackers in use at nearly every hospital in the nation. Some have joined a legal challenge against the OCR bulletin. In November 2023, the American Hospital Association, the Texas Hospital Association and others filed suit against OCR claiming that the OCR bulletin improperly imposes HIPAA restrictions on information that is not “protected health information” as that term is defined under HIPAA. In February 2023, the Federal Trade Commission (“FTC”) began enforcing a lesser-known law called the FTC Health Breach Notification Rule (the “HBN Rule”) against companies that use website-embedded tracking technologies and disclose the data being tracked through these technologies to third-party tracking companies. The HBN Rule applies to non-HIPAA covered entities that are vendors of personal health records (or who are a related entity or service provider of a vendor of personal health records). The HBN Rule requires that a breach notification be filed with the FTC if there is an unauthorized disclosure of personal health information, such as to a third party that has embedded tracking technologies on the company’s website. Under this law, the FTC took enforcement action against well-known companies such as BetterHelp, GoodRx and Premom, requiring the payment of large civil money penalties and requiring that the companies adopt and enforce internal prohibitions on sharing user health data with third parties for advertising purposes. Additionally, the FTC issued industry guidance as a warning to others who use embedded tracking technologies on their websites. In July 2023, the OCR and FTC teamed up and issued a joint letter to 130 hospitals and telehealth providers about the risks and concerns regarding the use of the website tracking technologies, and issued a press release with a general warning to the hospital system and telehealth industry against the use of embedded tracking technologies. Lesson learned: HIPAA covered entities should carefully review their websites to ensure that any third party with embedded tracking technologies has signed a HIPAA-compliant business associate agreement, and to ensure that the use or disclosure of any data gleaned from tracking access to the company website is compliant with the HIPAA privacy rule. See our prior articles on this topic here and here. Rights of Access Initiative- Still a Top Priority for OCR In 2023, the OCR reached several new resolution agreements with entities alleged to have violated patients’ rights to timely access of their medical records. Under HIPAA, covered entities, like health care providers and payors, have a maximum of 30 days (which OCR describes as an “outer limit”) to provide patients with a copy of their medical record upon request. The “Right of Access Initiative” became an enforcement priority for OCR at the end of 2019, in an attempt to address patient complaints about difficulties they encountered in obtaining timely copies of their medical records. In fact, OCR’s final resolution agreement of 2023 in the amount of $80,000 marked OCR’s 46th such settlement in a little over three years. In response to what OCR views as a widespread issue of non-compliance, OCR has published guidance for covered entities’ implementation of this individual HIPPA right to access. Lesson learned: Review and audit the administrative processes your organization has in place for responding to requests for patient records to ensure they meet HIPAA’s requirements. Major Source of Risk: Covered Entity and Business Associate Failure to Conduct Enterprise-Wide Security Risk Analysis In May and June 2023, OCR entered into resolution agreements with two separate business associates who, in similar fact patterns, were found to have lacked a sufficient enterprise-wide risk analysis of their security function, leading to the breach of hundreds of thousands of patient records. In one situation, the business associate provided billing, coding and IT services to health care providers and, through a compromise in the business associate’s systems, the PHI of hundreds of individuals was exfiltrated from an unsecured server by an unauthorized person. In the other situation, a business associate that provides practice management, practice analytics and revenue cycle management services to health care providers inadvertently allowed a file transfer protocol (“FTP”) server containing hundreds of thousands of individuals’ data to be openly accessible on the internet. OCR also cited a covered entity for non-compliance with the risk analysis standard. In February 2023, OCR entered into a resolution agreement with a large health system in order to resolve a data breach impacting 2.81M individuals following a hacking incident. When OCR investigated the incident, it found that the health system lacked a risk analysis to determine the risks and vulnerabilities to its patients’ ePHI. OCR also found a number of important security rule violations that stemmed from the initial failure to conduct risk analyses, including failing to implement an authentication process, failing to monitor the activity of users on the system, and failure to have security measures in place for ePHI that was being transmitted electronically. In September 2023, OCR and the Office of the National Coordinator for Health Information Technology (“ONC”) published an updated version of a do-it-yourself security risk assessment tool, intended for small and medium-sized covered entities. The updated tool is intended to make it easier for covered entities and business associates to assess the security risk to ePHI and to mitigate that risk. Lesson learned: In resolution agreements, OCR routinely cites companies for failing to complete an enterprise-side security rule risk analysis. In fact, this is one of the most common sources of HIPAA violations that lead to subsequent settlement agreements with OCR. The bottom line is that there is no substitute for an enterprise-wide security rule risk analysis. This type of risk analysis should be conducted routinely by covered entities and by their business associates in order to identify and mitigate the security risks to all repositories of electronic PHI. Another lesson that comes out of this pair or resolution agreements in 2023 is that covered entities should carefully vet and audit the HIPAA compliance program and practices of their potential and current business associates. In the end, although business associates have their own liability under HIPAA, the patient data and patient relationships at risk are those of the covered entity served by the business associate. Even Small Breaches Can Result in Liability In 2023, OCR settled two cases that contained fact patterns OCR has addressed in guidance and settlement agreements repeatedly: snooping and social media breaches. Notably, these cases each also involved a small number of patients, and the enforcement actions signal to covered entities and business associates that even small breaches can result in liability. One resolution agreement was with a hospital related to its security staff snooping in patient records. The other resolution agreement was with a physician practice that responded to a negative review on Google in a way that acknowledged the patient relationship and disclosed patient information. Lessons learned: Ongoing staff training regarding impermissible uses and disclosures of patient information is a critical element of a provider’s HIPAA compliance activities. Include basic reminders in HIPAA workforce training through, for example, use of the resolution agreements in the way that OCR intends them to used- as an example for others to help prevent similar conduct in the future. COVID-19 HIPAA Enforcement Discretion Ends and OCR Emphasized its Enforcement Priority and Strategy for Cybersecurity In August 2023, years of HIPAA-related enforcement discretion by OCR related to the COVID-19 pandemic came to an end. The enforcement discretion that OCR exercised throughout the early days of the COVID-19 pandemic related to matters such as the use of non-HIPAA compliant telehealth technologies, and non-HIPAA compliance related to COVID-19 vaccine patient scheduling, public health and health oversight disclosures, and community based testing sites. OCR published notifications and guidance to the public to prepare HIPAA covered entities and business associates for an end to the waiver of enforcement discretion. OCR also announced the development of a new enforcement division at OCR, called the Health Information Privacy, Data and Cybersecurity Division, which will focus on OCR’s work and role in cybersecurity. Additionally, citing a 93% increase in large data breaches due to cybersecurity events between 2018-2022 (with a 278% increase in large breaches involving ransomware), the Department of Health and Human Services published a concept paper outlining the Department’s cybersecurity strategy for health care providers. The strategy calls for new voluntary health care-specific cybersecurity goals; developing incentives and supports with Congress that will be used to help hospitals improve cybersecurity; and strategies for increasing accountability and coordination within the health care sector. Ongoing OCR Regulatory Initiatives- Changes are Coming OCR has introduced several HIPAA regulatory initiatives that are still under consideration by the agency, and many of which may become finalized in 2024. It is important for privacy/security officials and health care counsel to be familiar with the proposed regulations in order to understand OCR’s perspective because that helps in steering internal compliance protocols, training and accountability at the organization: Reproductive Health Care OCR issued a Notice of Proposed Rulemaking (“NPRM”) on April 12, 2023 to prohibit the use or disclosure of PHI to identify, investigate, prosecute, or sue patients, providers, and others involved in the provision of legal reproductive health care, including abortion. The public comment period closed on June 16, 2023 and OCR received over 25,000 comments. A final rule has not yet been published. Substance Use Disorder (“SUD”) Treatment Records In coordination with the Substance Abuse and Mental Health Services Administration (SAMHSA), OCR issued a NPRM on November 28, 2022 to align certain aspects of 42 CFR part 2 (Part 2) with HIPAA. Part 2 protects patient records maintained in connection with substance abuse education prevention, training, treatment, rehabilitation or research in order to ensure privacy for SUD patients. The public comment period closed on January 31, 2023 and OCR received over 200 comments. A final rule has not yet been published. HITECH Request for Information (“RFI”) Regarding Mitigating Security Practices and the Sharing of Monetary Settlements with Individuals Harmed OCR published a RFI on April 6, 2022, seeking public input on portions of the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The RFI specifically requests input on: (i) recognized security practices that OCR will consider when determining potential fines, audit results, or other remedies for resolving potential violations of HIPAA; and (ii) the methodology under which an individual harmed by a potential HIPAA violation may receive a percentage of a monetary penalty/settlement collected with respect to such violation. The public comment period closed on June 6, 2022. OCR has yet to announce further action on this RFI. HIPAA Privacy Rule Updates OCR issued a NPRM on January 1, 2021 to modify the HIPAA Privacy Rule to encourage patient engagement in health care, remove barriers to coordinated care, and decrease regulatory burden. The public comment period closed on May 6, 2021 and OCR received over 1,300 comments. A final rule has not yet been published. The proposed new rules, if finalized, would require some significant changes at HIPAA covered entities and business associates, such as: allowing patients to inspect their PHI in person and take notes or photographs of their PHI; changing the maximum time to provide access to PHI from 30 days to 15 days; new rules about costs for records including certain circumstances when ePHI must be provided at no cost, requirements to provide estimates of fees for copies, and requirements to post fee schedules for records access on the website; individuals will be permitted to request that their PHI be transferred to a personal health application or direct ePHI to be send to another covered entity; covered entities will be required to inform individuals that they have the right to obtain or direct copies of their PHI to a third-party when a summary of PHI is offered instead of a copy; the requirement for HIPAA-covered entities to obtain written confirmation that a Notice of Privacy Practices has been provided will be removed; covered entities will be allowed to disclose PHI to avert a threat to health or safety when harm is “seriously and reasonably foreseeable” (as opposed to the current, more stringent standard that only allows such disclosure when harm is “serious and imminent," and expansion of permissible uses and disclosures by covered entities based on care coordination, case management and based on a good faith belief that the disclosure it is in the best interest of the individual. While the pending HIPAA updates are intended to ease the administration burden on HIPAA-covered entities in the long run, there will be a significant short term burden associated with changes to policies and procedures, changes related to notices of privacy practices, changes to medical record access processes and others. The authors will continue to monitor these initiatives for updates and changes in 2024. If you have any questions about HIPAA, cyber-attacks, OCR investigations, or regulatory changes, reach out to your regular Dorsey attorney or to any member of the Dorsey & Whitney LLP Healthcare Transactions and Regulations practice group.
January 3, 2024
HHS OCR Settles HIPAA Investigation with Business Associate for $350,000
Over the past decade, the number of health care data breaches reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) has increased dramatically. From 2009 to 2022, over 5,000 data breaches affecting 500 or more records were reported to OCR, accounting for the exposure of over 380 million health care records. More and more often, these breaches have involved business associates performing third-party services for covered entities. This year, some of the largest business associate breaches have involved Cerebral, Inc. (> 3 million individuals affected), NationsBenefits Holdings, LLC (> 3 million individuals affected), and NextGen Healthcare (> 1 million individuals affected). The latest business associate settlement with OCR, involving MedEvolve, Inc., provides important lessons for both business associates and covered entities. The HIPAA Fundamentals The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) creates rules for the privacy and security of individually identifiable health information held by covered entities and business associates (the “HIPAA Rules”). A “covered entity” is a health plan, a health care provider that electronically transmits health information in connection with certain financial and administrative transactions, or a health care clearinghouse. A “business associate” is a person or entity that provides services to a covered entity that involve creating, receiving, maintaining, or transmitting protected health information (“PHI”). Any subcontractor of a business associate that creates, maintains, or transmits PHI on behalf of that business associate is also a business associate. All arrangements between covered entities and business associates, including between business associates and subcontractors, must involve a business associate agreement (BAA) which outlines each party’s obligations to protect PHI and report any data breaches. OCR is the office tasked with enforcement of the HIPAA Rules. Under the HIPAA Rules, covered entities are required to notify affected individuals, OCR, and in some cases, the media, following the discovery of a breach of unsecured PHI. Business associates are also required to notify covered entities following the discovery of a breach. OCR investigates written complaints and conducts compliance reviews and audits to enforce the HIPAA Rules. If violations of HIPAA are discovered, OCR can enter into a resolution agreement with the violating entity. Resolution agreements often require the entity to complete a corrective action plan (CAP) and pay a settlement amount. OCR’s Settlement with MedEvolve, Inc. On May 16, OCR announced a settlement of potential violations of the HIPAA Rules with MedEvolve, Inc. (MedEvolve), a business associate that provides practice management, revenue cycle management, and practice analytics software services to covered health care entities. The alleged HIPAA violations occurred in 2018, when MedEvolve suffered a data breach exposing the PHI of more than 200,000 individuals. Specifically, one of MedEvolve’s servers containing PHI such as patient names, billing addresses, and phone numbers was reported as openly accessible to the internet. As OCR investigated the breach, it determined that MedEvolve had failed to: (i) conduct a risk assessment to determine vulnerabilities to PHI, and (ii) enter into a BAA with a subcontractor. Pursuant to the resolution agreement, MedEvolve has paid a $350,000 penalty to OCR and agreed to implement a corrective action plan (CAP) to address potential violations of the HIPAA Rules. As part of the CAP, MedEvolve has agreed to: Conduct a risk analysis to determine vulnerabilities; Implement a risk management plan; Revise its written HIPAA policies and procedures; and Provide HIPAA training for employees with access to PHI. Additionally, OCR will monitor MedEvolve for a period of two years to ensure compliance with the HIPAA Rules. Lessons for Covered Entities and Business Associates While covered entities have historically reported the largest number of data breaches, the number of business associate data breaches continues to increase. Hacking/IT incidents accounted for 79% of the large data breaches reported to OCR in 2022, and network servers were the most common targets in these incidents. Thankfully, both covered entities and business associates can take precautions to strengthen their cybersecurity practices and lower the risk of a breach. Steps that should be taken include: Covered entities should conduct due diligence on any vendor that will handle PHI. This should include investigating the vendor’s: (i) IT security measures employed to protect data, (ii) employee training used to ensure staff understands how to protect PHI; and (iii) processes in place for responding to incidents. Covered entities and business associates should have a BAA in place and understand their reporting obligations under the BAA. The BAA should govern a business associate’s reporting obligations to the covered entity. When a breach is reported to the government, OCR will have questions about the BAA and the parties’ reporting obligations. Employees pose the biggest risk to an employer’s security. Employees should be trained to recognize and avoid phishing attempts and to report concerns immediately when they suspect a breach has occurred. When it comes to cybersecurity, an ounce of prevention is worth a pound of cure. Dorsey’s health care attorneys strongly recommend regularly reviewing your HIPAA compliance and updating your policies and procedures to reflect current best practices.
May 19, 2023
COVID-19
Covid-19 Requirements for Healthcare Employers: A Recap of Where Things Stand
There is a lot going on right now for healthcare employers. The first phase of CMS’s vaccine mandate is in full effect nationwide (now including Texas), the CDC has changed masking guidance in some circumstances, and it has been two months since OSHA let the Health Care Emergency Temporary Standard expire. To help you navigate where things stand, we’ve provided an update on each of those topics below. CMS Vaccine Mandate On November 4, 2021, CMS enacted an Interim Final Rule (“IFR”) requiring staff at certain Medicare or Medicaid providers and suppliers (“Covered Healthcare Employers”) to be fully vaccinated against COVID-19 unless they qualify for a medical or religious exemption. That rule was temporarily enjoined in 25 states on November 29, 2021. On January 13, 2022, the Supreme Court lifted the temporary injunction. Thus, Covered Healthcare Employers nationwide have an obligation to ensure that staff (defined broadly by the IFR) are vaccinated against COVID-19 or risk citation from CMS. See our prior blog post on this topic for more details about the IFR. The IFR broadly defines the term “staff” to include “facility employees; licensed practitioners; students, trainees, and volunteers; and individuals who provide care, treatment, or other services for the facility and/or its patients, under contract or other arrangement.” The fact that care may not be provided in a formal clinical setting does not relieve staff from the mandate. How frequently a person physically enters a Covered Healthcare Employer’s setting is also irrelevant. Only those staff who perform 100 percent of their work remotely (for example, telehealth or payroll) are fully exempt from the vaccine mandate. Note that the IFR’s definition of “staff” includes those providing services “under contract or other arrangement.” That means, to demonstrate compliance with the IFR, Covered Healthcare Employers must be able to establish that contract staff (for example, from agencies or locum providers) are fully vaccinated against COVID-19 or have approved medical or religious exemptions from the vaccine. Covered Healthcare Employers must have access to documentation regarding the vaccinations of the contract employees, or approved exemptions, during a compliance survey. CMS has previously stated that Covered Healthcare Employers are not expected to maintain on-site physical copies of proof of vaccination or exemption for contractors. Because of that, some Covered Healthcare Employers used attestation forms to verify the vaccination status of contracted employees or included vague language in contracts such as, “Agency will provide vaccinated employees to provider organization.” CMS has clarified that, if used, an attestation must be specific, and a blanket attestation will not be sufficient. CMS provided the following examples: Acceptable: “Staff X is fully vaccinated against COVID-19” or “Staff Y has been granted an exemption that meets the requirements of the rule.” Unacceptable: “Contracting organization X will send to provider organization Y only staff who are either fully vaccinated or who have been granted an exemption that meets requirements of the rule.” Because all Covered Healthcare Employers must be able to obtain and submit to surveyors proof of vaccination status and information regarding exemptions and accommodations for all staff (as defined by the IFR) upon request, Covered Healthcare Employers should include COVID-19 vaccination language in new contracts and amend existing contracts to include such language. Changes to the CDC’s Masking Guidance On February 25, 2022, the CDC (once again) revised its masking guidance. Now, regardless of vaccination status, individuals are advised to consult the CDC’s COVID-19 Community Level data to help guide masking decisions. That guidance, however, does not apply in healthcare settings. Rather, healthcare entities should continue to use the COVID Data Tracker. Specifically, the CDC states: CDC’s new COVID-19 Community Levels recommendations do not apply in healthcare settings, such as hospitals and nursing homes. Instead, healthcare settings should continue to use community transmission rates and continue to follow CDC’s infection prevention and control recommendations for healthcare settings. This has caused a bit of whiplash for healthcare employers, who may have employees asking why masks are still required if community levels are “Low.” The simple explanation is that the COVID Data Tracker utilizes different metrics, so even though community levels may be “Low,” community transmission may be “High,” thus requiring continued masking in healthcare settings. We anticipate clarification and/or further changes may be coming from the CDC, but for now, healthcare entities must continue to follow the masking guidance based on the COVID Data Tracker. Expiration of the OSHA Emergency Temporary Standard OSHA’s ETS expired on December 21, 2021. On December 27, 2021, OSHA issued a statement that included the following explanation: OSHA announces today that it intends to continue to work expeditiously to issue a final standard that will protect healthcare workers from COVID-19 hazards, and will do so as it also considers its broader infectious disease rulemaking. However, given that OSHA anticipates a final rule cannot be completed in a timeframe approaching the one contemplated by the OSH Act, OSHA also announces today that it is withdrawing the non-recordkeeping portions of the healthcare ETS. The following are the recordkeeping portions of the healthcare ETS that covered employers must still follow: establishing and maintaining a COVID–19 log to record each instance identified by the employer in which an employee is COVID–19 positive, regardless of whether the instance is connected to exposure to COVID–19 at work; making records available upon request for examination and copying, including all versions of the employer’s written COVID-19 policy, the individual COVID-19 log entry for a particular employee, a version of the COVID-19 log that removes employee identifying information; and reporting COVID–19 fatalities and hospitalizations to OSHA. With the expiration of OSHA’s ETS, healthcare employers are no longer required—under the ETS—to screen employees for COVID-19. However, that does not necessarily mean that employers should stop screening altogether. It is prudent for healthcare employers to continue some level of a screening process to ensure compliance with OSHA’s general duty clause, which requires all employers to provide a work environment “free from recognized hazards that are causing or are likely to cause death or serious physical harm.” (Recall that when OSHA issued the ETS for healthcare employers, it identified COVID-19 as a recognized hazard). While screening won’t guarantee that employees will avoid catching COVID-19 at work, ongoing screening for the duration of the public health emergency will serve an important role in demonstrating an employers’ mitigation strategies in the event an employer is audited or must respond to an OSHA complaint. This approach of ongoing screening is further underscored by the following from OSHA’s December 27, 2021, statement, in which OSHA encouraged employers “to continue to implement the ETS’s requirements in order to protect employees from a hazard that too often causes death or serious physical harm to employees.” What Should Healthcare Employers Do? Healthcare employers should consider the following practices: Include language in agency or other contractor agreements that addresses CMS’s vaccine mandate, and/or amend existing agreements. Follow CDC masking guidance for healthcare facilities. Continue to screen for COVID-19. Dorsey’s employment and health care attorneys will continue to monitor the developments related to COVID-19 requirements, and will update our health law blog with changes. Feel free to reach out to the authors or to your regular Dorsey attorney if you have any questions about the vaccine mandate, language for agency or other contractor agreements, screenings, OSHA obligations and record keeping.
March 3, 2022
COVID-19
U.S. Supreme Court Lifts Injunction Against CMS’ Health Care Facility Vaccine Mandate: What Does This Mean for Your Health Care Facility?
Health care employers are not alone in feeling overwhelmed by the constantly changing legal status of the various federal vaccine mandates. On Thursday afternoon, the Supreme Court made its rulings on two preliminary challenges to workplace mandates related to the COVID-19 pandemic: the Occupational Safety and Health Administration (OSHA)’s Emergency Temporary Standard (ETS) for large employers (100+ employees), and the Centers for Medicare and Medicaid Services (CMS) vaccine mandate for health care employers. This article focuses on the current status of CMS’s Interim Final Rule (IFR), issued on November 4, 2021. The IFR detailed staff vaccination requirements as a condition of receipt of Medicare or Medicaid funds. CMS estimated that there would be more than 180 million staff, patients, and residents employed or treated at facilities covered by the rule. Legal Challenges to CMS’s Vaccine Mandate On November 29, 2021, a federal court in Missouri stayed the CMS vaccine mandate in Alaska, Arkansas, Iowa, Kansas, Missouri, Nebraska, New Hampshire, North Dakota, South Dakota, and Wyoming. On December 15, 2021, a federal court in Louisiana stayed the CMS rule for fourteen additional states: Louisiana, Montana, Arizona, Alabama, Georgia, Idaho, Indiana, Mississippi, Oklahoma, South Carolina, Utah, West Virginia, Kentucky and Ohio. Therefore, at that time, the CMS rule was on hold in the 25 (referred to in this article as the “injunction states”) and enforceable in the rest of the country (referred to in this article as the “non-injunction states”). A few days later, though, CMS indicated that it would temporarily halt enforcement nationwide. The next day, the federal government filed a Petition asking the Supreme Court to lift the CMS IFR stay in the 25 injunction states. The Supreme Court heard oral arguments on that Petition, as well as whether the OSHA ETS nationwide stay, on January 7, 2022. The Supreme Court’s Ruling On January 13, 2021, the Supreme Court overturned the stay of the CMS vaccine mandate in the injunction states in a 5-4 decision. In the ruling, a majority of Supreme Court justices held that CMS’s IFR “fits neatly within the language of the statute” that authorizes the Secretary of Health and Human Services to impose conditions on the receipt of Medicare and Medicaid funding that are “necessary in the interest of the health and safety of individuals who are furnished services.” This includes other vaccination requirements, such as hepatitis B, influenza, and measles, mumps, and rubella. The court focused on the fact that those seeking health care services at this time are likely more susceptible to contracting the COVID-19 virus, and stated: [E]nsuring that providers take steps to avoid transmitting a dangerous virus to their patients is consistent with the fundamental principle of the medical profession: first, do no harm. It would be the “very opposite of efficient and effective administration for a facility that is supposed to make people well to make them sick with COVID–19.” For their part, the dissenting justices were concerned with a federal agency forcing health care workers to choose between getting a vaccine that they have thus far failed to receive and remaining employed. In addition, the dissent disapproved of CMS’s decision to issue the vaccine mandate prior to receiving and addressing public comments. Finally, the dissent took issue with the federal government getting involved in an issue (vaccine mandates) typically reserved for states. According to the dissent, “[i]f Congress had wanted to grant CMS authority to impose a nationwide vaccine mandate, and consequently alter the state-federal balance, it would have said so clearly. It did not.” Somewhat in response to that argument, the majority cautioned that while federal agencies’ ability to exercise their powers is not limitless, “such unprecedented circumstances provide no grounds for limiting the exercise of authorities that the agency has long been recognized to have.” With the majority of the Supreme Court voting to lift the stay, the CMS IFR is back on. CMS Guidance Regarding its Vaccine Mandate Prior to the ruling (on December 28, 2021), CMS issued QSO-22-07-ALL, Guidance for the Interim Final Rule. That guidance essentially rescinded CMS’s temporary halt on nationwide enforcement of the IFR and established compliance deadlines and additional guidance for covered facilities operating in the non-injunction states. The Guidance included provide-specific instructions for each type of facility covered by the CMS IFR (for example, Long Term Care and Skilled Nursing Facilities, Ambulatory Surgical Centers, Hospitals, Community Mental Health Centers, and Outpatient Physical Therapy. The Supreme Court’s ruling did not change the requirements of the CMS IFR. In essence, covered facilities must: Implement a process or plan to vaccinate all eligible staff by the compliance deadline (which is different for the injunction and non-injunction states). The CMS IFR is not a “vaccinate-or-test” mandate like the OSHA ETS. Rather, under the IFR, vaccination is the only option unless staff qualify for a medical or religious exemption. Implement a process or plan to consider requests medical and religious exemptions. Implement a process or plan to track and document staff vaccines and exemptions so each facility can produce the documentation during a survey. Our prior blog post, available here, provides additional detail on the IFR’s requirements as well as practical recommendations for compliance and next steps. In response to the Supreme Court’s ruling, on January 14, 2022 CMS issued additional guidance, QSO-22-09-ALL for the IFR, applying to all but one of the injunction states (Texas was exempted from the new guidance due to ongoing separate challenges, and CMS instructed state surveyors in the guidance to not undertake any efforts to enforce the IFR at this time). That new CMS guidance contains the same provider-specific instructions as the previous guidance, except that there are new compliance deadlines for the injunction states. Under QSO-22-07-ALL and QSO-22-09-ALL: Penalties for non-compliance in nursing homes, home health agencies, and hospice include civil monetary penalties, denial of payments, and as a final measure, termination of participation in Medicare and Medicaid programs. Penalties for non-compliance for hospitals and other acute and continuing care providers is termination of participation in Medicare and Medicaid programs. However, “CMS’s primary goal is to bring health care facilities into compliance.” Termination from the Medicare and Medicaid programs will generally only occur after CMS gives a facility an opportunity to come into compliance. Absent approved medical or religious exemptions, CMS will consider facilities non-compliant if facility staff (as defined by the IFR) vaccination rates are under 100%. To provide covered facilities an opportunity to reach that 100% vaccination rate, CMS has adopted a phase-in period: Facilities are considered compliant with CMS’s IFR if, 30 days after the applicable QSO: 1) the facility has policies and procedures developed to ensure all facility staff are vaccinated for COVID-19, and 2) 100% of staff have at least dose of a COVID-19 vaccine (unless exempted) or 80% of staff have at least one dose of a COVID-19 vaccine and the facility has a plan to achieve 100% vaccination within 60 days. For the non-injunction states, the 30-day deadline is January 27, 2022. For the injunction states, the 30-day deadline is February 13, 2022. Facilities are considered non-compliant with CMS’s IFR if, 60 days after the applicable QSO, less than 100% of all non-exempted staff have at least one dose of a one-dose COVID-19 vaccine or two doses of a two-dose series. In that case, the facility will receive a notice of non-compliance, except that facilities with a vaccination rate (less exemptions) above 90% with a plan to reach 100% (less exemptions) within 30 days will not be subject to additional enforcement action. For the non-injunction states, the 60-day deadline is February 28, 2022. For the injunction states, the 60-day deadline is March 15, 2022. Facilities are considered non-compliant with CMS’s IFR if, 90 days after the applicable QSO (and anytime thereafter), less than 100% of all non-exempted staff have received at least one dose of a one-dose COVID-19 vaccine or two doses of a two-dose series. These facilities may be subject to enforcement action. For the non-injunction states, the 90-day deadline is March 28, 2022. For the injunction states, the 90-day deadline is April 14, 2022. It is important to note that the Supreme Court did not rule on the merits (legality) of the CMS IFR. Last week’s ruling is limited to whether the CMS IFR should be enjoined prior to a ruling on the merits. The merits question is still yet to be resolved and when federal courts make those decisions, they will almost certainly make their way back to the Supreme Court for a final decision. Given the language and reasoning of the Supreme Court’s injunction decision, it appears there is a high likelihood that a majority of Supreme Court justices would uphold CMS’s vaccine mandate on the merits. The bottom line is that the CMS IFR is now in effect throughout the country, except in Texas, and despite CMS’s message that it will provide entities with some leeway as described above, covered entities should immediately take steps to become compliant. Dorsey’s health care and labor & employment attorneys are available to assist any health care provider with questions about implementation of CMS’ vaccine mandate.
January 17, 2022
Centers for Medicare and Medicaid Services
Limited Preliminary Injunction Issued for CMS Vaccine Mandate
On November 29, 2021, a federal court in Missouri enjoined the Centers for Medicare and Medicaid Services’ (CMS) vaccine mandate in the following states: Alaska, Arkansas, Iowa, Kansas, Missouri, Nebraska, New Hampshire, North Dakota, South Dakota, and Wyoming. Those ten states filed a lawsuit on November 10, 2021, challenging the vaccine mandate and requesting a preliminary injunction. The new CMS vaccine mandate which we wrote about here requires covered staff to receive their first COVID-19 vaccine dose by December 5, 2021 and be fully vaccinated by January 4, 2022. In granting the preliminary injunction, the district court specifically ordered: Defendants are preliminarily enjoined from the implementation and enforcement of 86 Fed. Reg. 61,555 (Nov. 5, 2021), the Interim Final Rule with Comment Period entitled “Medicare and Medicaid Programs; Omnibus COVID-19 Health Care Staff Vaccination,” against any and all Medicare- and Medicaid-certified providers and suppliers within the States of Alaska, Arkansas, Iowa, Kansas, Missouri, Nebraska, New Hampshire, North Dakota, South Dakota, and Wyoming pending a trial on the merits of this action or until further order of this Court. Defendants shall immediately cease all implementation or enforcement of the Interim Final Rule with Comment Period as to any Medicare- and Medicaid certified providers and suppliers within the States of Alaska, Arkansas, Iowa, Kansas, Missouri, Nebraska, New Hampshire, North Dakota, South Dakota, and Wyoming. What this means is that as of November 29, 2021, the December 5, 2021, and January 4, 2022 deadlines are on hold for employers covered by the CMS mandate in Alaska, Arkansas, Iowa, Kansas, Missouri, Nebraska, New Hampshire, North Dakota, South Dakota, and Wyoming. Any vaccine mandates enforced by covered employers in those states will be considered voluntary and subject to any state laws regarding vaccine mandates. Of the ten states, only Arkansas, Iowa, and Kansas have laws regulating COVID-19 vaccine mandates for private employers: Arkansas – On October 13, 2021, Arkansas’ Governor allowed several vaccine-related bills to become law without his signature. The bills require employers to allow employees to obtain a waiver from a COVID-19 vaccine mandate if the employee produces a negative COVID-19 test once a week or provides proof of COVID-19 antibodies once every six months. Iowa – On October 29, 2021, Iowa’s Governor signed a law requiring employers to grant exemptions from vaccine mandates beyond those required by federal law. Specifically, in addition to waivers for sincerely held religious beliefs, Iowa employers that voluntarily implement vaccine mandates must grant a waiver if an employee submits a statement that receiving the vaccine would be injurious to the health and well-being of the employee or an individual residing with the employee. In addition, Iowa employees discharged for not complying with an employer’s vaccine mandate are eligible for unemployment benefits under the new law. Kansas – On November 22, 2021, the Governor of Kansas signed a law with medical waiver requirements similar to Iowa’s law. On religious waivers, Kansas’ law goes beyond what is required by federal law, mandating that employers grant requests for religious exemptions “without inquiring into the sincerity of the request.” The law also outlines a complaint and investigation procedure for alleged violations and provides for monetary penalties that increase depending on the size of the employer. In addition, like the Iowa law, Kansas employees discharged for not complying with an employer’s vaccine mandate are eligible for unemployment benefits. The Biden Administration will almost certainly appeal the preliminary injunction. The Eighth Circuit Court of Appeals would consider the appeal and could overturn the injunction and reinstate the mandate. Given the timeline, we expect that new compliance deadlines would be established in the event the preliminary injunction is overturned. What should employers do? Covered employers in the ten states at issue who do not wish to proceed with a voluntary vaccine mandate may pause their current efforts to comply with the CMS vaccine mandate, but should at a minimum proceed with preparing a policy, religious and medical exemption forms, and an exemption review process so that employers are ready to proceed within any established deadlines if the preliminary injunction is lifted and the mandate is reinstated. This is the same recommendation we have given to large employers covered by the Occupational Safety and Health Administration’s COVID-19 Vaccination and Testing Emergency Temporary Standard (OSHA ETS), which was stayed by the Fifth Circuit Court of Appeals on November 12, 2021.[1] Employers looking for consistency when it comes to COVID-19 vaccine mandates will not find it in today’s ruling and healthcare employers can once again add themselves to the list of employers who operate in multiple states and must undertake the task of wading through the various federal mandates and their legal statuses. It is both possible and probable that multi-state healthcare employers will be required to comply with CMS’s federal vaccine mandate in one state while operating in another state wherein, at least for now, CMS’s federal vaccine mandate no longer exists. Dorsey’s employment and health care attorneys will continue to monitor the developments in this matter and will update our blog with changes. [1] On November 23, 2021, the Biden Administration asked the Sixth Circuit Court of Appeals to reinstate the OSHA ETS vaccine mandate, following a lottery that assigned to that Circuit multiple challenges to the vaccine mandate.
November 29, 2021
CMS Guidance
CMS’ COVID-19 Vaccine Mandate: What Health Care Providers and Suppliers Need to Know
**Note that a federal court has issued a temporary injunction stopping the CMS COVID-19 vaccine mandate in certain states. Please read our blog post here for the latest information on this injunction. Last week, the Centers for Medicare and Medicaid Services (CMS) and the Occupational Safety and Health Administration (OSHA) published their much-anticipated rules mandating COVID-19 vaccinations. This article focuses on the new CMS rules, and you can read about Dorsey’s analysis of the new OHSA Emergency Temporary Standard (ETS) here. Please note that if the CMS COVID-19 vaccine mandate applies to your facility, you must comply with the CMS COVID-19 vaccine mandate instead of with the new OSHA ETS. However, the above link to our article on the new OSHA ETS provides useful guidance on topics which apply generally to employers such as how to handle vaccine exemption requests. On November 4, 2021, the Centers for Medicare & Medicaid Services (CMS) issued its interim final rule (IFR) with comment period regarding staff vaccination requirements as a condition of receipt of Medicare or Medicaid funds. CMS estimates that there will be more than 180 million staff, patients, and residents employed or treated at facilities covered by the rule, making the impact colossal. The IFR is an emergency regulation, meaning that it takes effect on the date it is published in the federal register, November 5, 2021, and prior to the comment period. Stakeholders will have 60 days, until January 4, 2022, to submit formal comments. At that point, CMS will consider the comments in any future rulemaking it undertakes. CMS also issued a press release and published FAQs to assist health care facilities in the understanding of these new regulations. The IFR applies to the following Medicare/Medicaid certified providers and suppliers: Ambulatory Surgical Centers (ASCs) Hospices Psychiatric residential treatment facilities (PRTFs) Programs of All-Inclusive Care for the Elderly (PACE) Hospitals (acute care hospitals, psychiatric hospitals, hospital swing beds, long term Care hospitals, children’s hospitals, transplant centers, cancer hospitals, and rehabilitation hospitals/inpatient rehabilitation facilities) Long Term Care (LTC) Facilities, including Skilled Nursing Facilities (SNFs) and Nursing Facilities (NFs), generally referred to as nursing homes Intermediate Care Facilities for Individuals with Intellectual Disabilities (ICFs-IID) Home Health Agencies (HHAs) Comprehensive Outpatient Rehabilitation Facilities (CORFs) Critical Access Hospitals (CAHs) Clinics, rehabilitation agencies, and public health agencies as providers of outpatient physical therapy and speech-language pathology services Community Mental Health Centers (CMHCs) Home Infusion Therapy (HIT) suppliers Rural Health Clinics (RHCs)/Federally Qualified Health Centers (FQHCs) End-Stage Renal Disease (ESRD) Facilities[1] Indian Health Service (IHS) Facilities A. What Must Covered Facilities Do? Under the IFR, the above-described “covered facilities” must develop, by December 5, 2021, a plan and procedure for requiring the COVID-19 vaccine for covered staff (as defined below),[2] collecting and storing vaccination data, considering medical and religious exemptions for covered staff, and contingency planning for unvaccinated staff. Individuals are on a deadline to be fully vaccinated against COVID-19, with accommodations considered as required by law (discussed below). Unless exempted, staff must have their first dose of a two-dose COVID-19 vaccine or a one-dose COVID-19 vaccine by December 5, 2021. Staff must complete the vaccination series, and be “fully vaccinated”, by January 4, 2022. Fully vaccinated is defined as two or more weeks after the completion of a vaccination series; staff members will be considered compliant even if not fully vaccinated by January 4 as long as they have completed the vaccination series by then.[3] A previous COVID-19 infection will not be considered a substitute for proof of vaccination. Staff hired after December 5, 2021 must receive their first vaccine dose prior to providing any care, treatment, or other services. The IFR defines the term “staff” to include “facility employees; licensed practitioners; students, trainees, and volunteers; and individuals who provide care, treatment, or other services for the facility and/or its patients, under contract or other arrangement.”[4] The fact that care may not be provided in a formal clinical setting does not relieve staff from the mandate. How frequently a person physically enters a covered healthcare setting is also irrelevant. Only those staff who perform 100% of their work remotely (i.e. telehealth or payroll) are fully exempt from the vaccine mandate. This means that even staff who “occasionally encounter fellow staff, such as in an administrative office or at an off-site staff meeting, who will themselves enter a health care facility or site of care for their job responsibilities,” also must be vaccinated under the IFR. The IFR lists the following as acceptable proof of vaccination: CDC COVID-19 vaccination record card (or a legible photo of the card), documentation of vaccination from a health care provider or electronic health record, or a state immunization information system record. Covered facilities must keep the proof of vaccination confidential, i.e. with a facilities immunization record, health information files, or other relevant confidential documents. Facilities may choose how to collect and store this information. B. Exemptions from COVID-19 Vaccination Requirements and Conflicts with State Laws Title VII of the Civil Rights Act of 1964 (Title VII) and the Americans with Disabilities Act (ADA) allow for religious and medical exemptions, respectively, to the COVID-19 vaccine. The IFR specifically directs healthcare entities to provide exemptions from the COVID-19 vaccine consistent with federal law, but medical exemptions appear narrow, including certain allergies and recognized medical conditions that make the COVID-19 vaccine contraindicated. The IFR specifically directs facilities to the CDC’s Summary Document for Interim Clinical Considerations for Use of COVID-19 Vaccines Currently Authorized in the United States. Medical exemption request must be supported by documentation that is: Signed and dated by a licensed practitioner, who is not the individual requesting the exemption, and who is acting within their respective scope of practice as defined by, and in accordance with, all applicable State and local laws. Such documentation must contain all information specifying which of the authorized COVID-19 vaccines are clinically contraindicated for the staff member to receive and the recognized clinical reasons for the contraindications; and a statement by the authenticating practitioner recommending that the staff member be exempted from the facility’s COVID-19 vaccination requirements based on the recognized clinical contraindications. But, what happens when there are conflicts with state laws on exemptions? New state laws signed by the governors of Texas and Iowa, for example, provide employees with exemptions beyond those required by these federal laws. For example, employers in Texas must allow exemptions from the COVID-19 vaccine based on an employee’s “reason of personal conscience.” This Texas law expands the application of religious exemptions beyond a “sincerely held religious belief, practice or observance” which is the standard for a waiver under Federal law. In Iowa, employers must allow exemptions from the COVID-19 vaccine based on an employee’s statement that receiving the vaccine “would be injurious to the health and well-being of the employee or an individual residing with the employee.” The Iowa law not only expands the medical exemption beyond the ADA, but also removes the requirement that a medical exemption be supported by a licensed practitioner. Anticipating such conflicts, the IFR explicitly states: We understand that some states and localities have established laws that would seem to prevent Medicare- and Medicaid-certified providers and suppliers from complying with the requirements of this IFC. We intend, consistent with the Supremacy Clause of the United States Constitution, that this nationwide regulation preempts inconsistent State and local laws as applied to Medicare- and Medicaid-certified providers and suppliers. . . . As is relevant here, this IFC preempts the applicability of any State or local law providing for exemptions to the extent such law provides broader exemptions than provided for by Federal law and are inconsistent with this IFC. (Emphasis added) The FAQs issued by CMS underscore this position, stating that no exemptions should be granted if not legally required under the ADA or Title VII, nor should an exemption be granted to someone “who requests an exemption solely to evade vaccination.”[5] In response to the federal government’s simultaneous release of the equally long-awaited Emergency Temporary Standard (ETS) from OSHA, Iowa Governor Kim Reynolds announced plans to challenge the ETS in court. She made no similar plans regarding the IFR. In addition, Arkansas, Alaska, Missouri, Iowa, Montana, Nebraska, New Hampshire, North Dakota, South Dakota and Wyoming joined in a federal lawsuit filed last week in Missouri challenging the government’s vaccination requirements for federal contractors and subcontractors. The OSHA ETS was promptly stayed in court, and as of the publication of this article, we are awaiting a decision about whether the ETS will be permitted to proceed. Healthcare employers are encouraged by CMS to follow the guidance released by the Equal Employment Opportunity Commission (EEOC) related to medical and religious exemptions for employees. Employers should develop a process for fairly reviewing medical and religious exemptions on an individualized basis that shows thoughtful consideration and analysis of each request. If employers grant exemptions, they must take steps to minimize the risk of COVID-19 transmission. Such steps could include additional or enhanced personal protective gear, separation barriers, elimination or substitution of less critical job duties, temporary modification of work schedules, or moving the location of where one performs work. C. How the Federal Rules Interact: Conflicts Between Federal Laws In addition to potential conflicts between state laws and the federal rules, healthcare facilities may also have questions about which of the federal rules reign supreme. The IFR’s FAQs address this as well: If a Medicare- or Medicaid-certified provider or supplier falls under the requirements of CMS’s IFR, the IFR must be followed. If facilities participate in and are certified under the Medicare and Medicaid programs and are regulated by the CMS health and safety standards known as the Conditions of Participation (CoPs), Conditions for Coverage (CfCs), and Requirements for Participation (RoPs), then they, too, are expected to abide by the requirements established in CMS’s IFR. Importantly, the IFR takes priority over other federal vaccination requirements (i.e. the Executive Order for federal contractors and subcontractors, and the OSHA ETS for employers with 100+ employees). The Executive Order for federal contractors and subcontractors may apply to staff who are not subject to the vaccination requirements outlined in the IFR. If a facility is subject to both the Executive Order and the new OSHA ETS for large employers, the facility should follow the Executive Order for federal contractors and subcontractors. The OSHA ETS for employers with 100+ employees applies to employers that are not subject to the CMS IFR or the Federal Contractor and Subcontractor Executive Order. Additionally, employers subject to the OSHA COVID-19 Healthcare ETS need not also comply with the new OSHA ETS for large employers. The bottom line is that the federal government does not intend for an employer or covered facility to assure compliance with more than one federal rule. If there is some question about with rule applies to a particular entity, entities should comply with the strictest federal rule applicable to the entity. Vaccine mandate laws, interpretations and challenges are rapidly developing across the U.S. If you have any questions about vaccine mandates, please contact your regular Dorsey attorney or any of the authors of this article. [1] The IFR does not apply to other healthcare entities not regulated by CMS (i.e. physician offices, Assisted Living Facilities, Group Homes, home and community-based services, or schools), but those entities could be subject to other federal vaccine requirements. In addition, Religious Nonmedical Health Care Institutions (RNHCIs), Organ Procurement Organizations (OPOs), and Portable X-Ray Suppliers are not covered by the IFR even though those entities are regulated by CMS. However, it is important to note that staff of these entities may be indirectly included in CMS’ vaccine requirements through their service arrangements with hospitals, long term care facilities, and other providers and suppliers who are covered under the IFR. Further, it is possible that staff may be required by other federal or state laws to obtain a COVID-19 vaccination. [2] Covered individuals will be referred to throughout this post as “staff,” because coverage of the rule extends beyond those individuals who are employed by covered facilities, but also includes medical staff, contractors and volunteers, as discussed herein. [3] The IFR references booster vaccines but does not require them. [4] CMS considered limiting vaccine requirements to full-time employees. Ultimately, CMS concluded that including a broader group of those required to be vaccinated would be manageable without creating major issues for compliance, enforcement, and record-keeping. [5] The FAQs also add that the IFR preempts any contrary state laws pursuant to the Supremacy Clause of the United States Constitution.
November 9, 2021
COVID-19
Updates on Legal Challenges to Health Care Employers’ Voluntary COVID-19 Vaccine Mandates
On May 28, 2021, a group of Houston Methodist Hospital employees filed a lawsuit challenging the hospital’s COVID-19 vaccine mandate for employees. The lawsuit, filed by 117 employees, was the first to challenge a health care employer’s COVID-19 vaccine mandate. The employees’ grievances included that the vaccine is unsafe and that employers may not treat an employee like “a human guinea pig.” At that time, all three COVID-19 vaccines were still being administered under the Food and Drug Administration “FDA”)’s Emergency Use Authorization (“EUA”). On June 12, 2021, a federal district judge dismissed the lawsuit. The judge cited several reasons in dismissing the suit, including the Equal Employment Opportunity Commission (“EEOC”)’s guidance that, with medical and religious exemptions, employers can require employees to get the COVID-19 vaccine. In response to the claim that the hospital was violating employees’ human rights by requiring the COVID-19 vaccine, the judge stated: The hospital’s employees are not participants in a human trial. They are licensed doctors, nurses, medical technicians, and staff members. The hospital has not applied to test the COVID-19 vaccines on its employees, it has not been approved by an institutional review board, and it has not been certified to proceed with clinical trials. As to the employees’ argument that they were being coerced into getting the vaccine or risk termination, the judge held: If a worker refuses an assignment, changed office, earlier start time, or other directive, he may be properly fired. Every employment includes limits on the worker’s behavior in exchange for his remuneration. That is all part of the bargain. The idea that employers routinely set workplace rules by which employees can either choose to abide or find other employment was central to a recent decision by a court in the Eastern District of Kentucky on September 24, 2021. That case, Beckerich, et. al. v. St. Elizabeth Medical Center, et. al., was filed on September 3, 2021, by 40 hospital employees challenging the hospital system’s COVID-19 vaccine mandate. The employees argued several violations, including that the mandate constituted fraud on behalf of the hospital, the United States Government, the Biden Administration, and the media. One difference between the Houston Methodist and the St. Elizabeth case is that on August 23, 2021, the FDA gave full approval to the Pfizer-BioNTech COVID-19 Vaccine. That full approval likely ended the likelihood that any employees going forward will be able to seriously argue that requiring the vaccine was tantamount to human experimentation. In denying the employees’ request for a temporary injunction (which would have halted the hospital’s mandate from going forward until the case could be fully decided on the merits), the court rejected the employees’ attempt to make constitutional claims on the basis that the hospital, by receiving federal funds, is essentially a governmental actor. To that argument the court stated, “[p]rivate hospitals, no matter how much federal funding they may receive, are generally not state actors for purposes of constitutional questions.” The court also examined how the “greater good” should be analyzed in the context of legal challenges to COVID-19 vaccine mandates, asking, “[i]s the ‘greater good’ made up of many different individual liberties, is it a singular collective liberty, or is it both?” The court then looked to a United States Supreme Court case from 1905 upholding Massachusetts’ small pox vaccine mandate. We previously discussed that case in an update outlining President Biden’s COVID-19 Action Plan. Like the court in Houston Methodist, the judge in St. Elizabeth noted that employers make rules all the time, and employees have a choice whether to follow those rules or find work elsewhere: “To work at St. Elizabeth, Plaintiffs agree to wear a certain uniform, to arrive at work at a certain time, to leave work at a certain time, to park their vehicle in a certain spot, to sit at a certain desk and to work on certain tasks. They also agree to receive an influenza vaccine, which Defendants have required of their employees for the past five years. These are all conditions of employment, and ‘“every employment includes limits on the worker’s behavior in exchange for his remuneration.’ . . . If an employee believes his or her individual liberties are more important than legally permissible conditions on his or her employment, that employee can and should choose to exercise another individual liberty, no less significant – the right to seek other employment.” While these cases involve challenges to voluntary COVID-19 vaccine mandates, the legal reasoning utilized by the courts might prove to be a roadmap for challenges to the vaccine mandates that are part of President Biden’s COVID-19 Action Plan. That includes an expansion of a previously announced but not yet released requirement that health care employers (previously just long term care providers) require the COVID-19 vaccination as a condition of receipt of Medicare and Medicaid funds.
September 28, 2021
coronavirus
Biden Administration Orders Long Term Care Facilities to Require COVID-19 Vaccinations To Receive Federal Funds; OSHA Issues Updated COVID-19 Recommendations For All Workplaces
As we have previously written, the landscape for employers in the time of COVID-19, particularly health care employers and long term care facilities, is ever-changing and quickly moving. In the last year, health care employers have had to navigate state laws, Centers for Disease Control and Prevention (“CDC”) and Centers for Medicare & Medicaid Services (“CMS”) guidance, EEOC guidelines, as well as compliance with a complex Emergency Temporary Standard (“ETS”) issued by the Occupational Safety and Health Administration (“OSHA”). In the midst of all that, health care providers have grappled with whether to implement policies requiring COVID-19 vaccinations for employees absent a religious or medical exemption. In Iowa, Unity Point Health, Sanford Health, MercyOne, Genesis Health System, and Trinity Health will require employees to be vaccinated for COVID-19 in the next few weeks and months. This includes long term care facilities administered by those entities. In a somewhat unexpected twist, the Biden Administration announced today that CMS and the CDC are “developing an emergency regulation requiring staff vaccinations within the nation’s more than 15,000 Medicare and Medicaid-participating nursing homes.” According to the announcement, a rule is expected in the coming weeks. The Administration’s order will surely generate multiple lawsuits challenging the legality of the mandate. We estimate that those lawsuits will likely not be successful, in part based how quickly similar lawsuits against hospital employers have been dismissed by courts across the country. For example, this summer a court swiftly dismissed a lawsuit filed by employees of Houston Methodist hospital challenging the hospital’s COVID-19 vaccine mandate. Last week, in addition to the OSHA ETS for healthcare employers published on June 21, 2021, OHSA issued new recommendations for all employers with a specific focus on protecting unvaccinated workers. To combat the continued spread of COVID-19, OSHA recommends that employers do the following: Assist employees in getting vaccinated for COVID-19, including paid time off to get and recover from vaccines. Some employers can receive tax benefits for voluntarily paying employees under these and other circumstances. Remove employees with known or suspected COVID-19 exposure from the workplace for either 14 days or until the employee receives a negative test result. Make sure that unvaccinated and high risk employees physically distance from others, limit the number of unvaccinated and high risk employees at one place at any given time, allowing remote working for unvaccinated and high risk employees, and installing transparent barriers when physical distancing is not feasible. Require employees to wear masks indoors (unless other PPE is otherwise required for the job), and provide face coverings to employees who do not have their own. Educate employees on workplace COVID-19 policies and procedures, including providing materials in multiple languages as needed. Suggest that unvaccinated customers, vendors, visitors, or other guests wear a mask. Maintain properly working ventilation systems. Follow CDC guidelines regarding cleaning and disinfection. Record and report workplace infections and deaths related to COVID-19. Implement policies and procedures to ensure that employees who raise concerns about COVID-19 in the workplace are not subject to retaliation. Follow any other applicable mandatory OSHA standards. In sum, OSHA recommends that, for the most part, all employers follow the requirements set forth for healthcare providers in the ETS. We want to help all employers keep their employees safe and protected from COVID-19, and we want to help you do your part to prevent the spread of the virus. If you have any questions about what you are required by law to do in your workplace, or what is not required but recommended, please contact a qualified employment and healthcare attorney.
August 18, 2021
coronavirus
Update Regarding Publication of OSHA Emergency Temporary Standard
On June 10, 2021, Dorsey’s Labor & Employment attorneys outlined an Emergency Temporary Standard (“ETS”) issued by OSHA. At the time, the ETS was not an official regulation because it had not yet been published in the Federal Register. On June 21, 2021, the ETS was published and, for covered healthcare employers, the compliance clock started ticking. As a refresher, the ETS applies to “all settings where any employee provides healthcare services or healthcare support services.” 1910.502(a)(1). Broadly, the following activities are exempted from coverage: the provision of first aid by an employee who is not a licensed health care provider; the dispensing of prescriptions by pharmacists in retail settings; non-hospital ambulatory care settings where all non-employees are screened prior to entry and people with suspected or confirmed COVID–19 are not permitted to enter those settings; well-defined hospital ambulatory care settings where all employees are fully vaccinated and all non-employees are screened prior to entry and people with suspected or confirmed COVID–19 are not permitted to enter those settings; home health care settings where all employees are fully vaccinated and all non-employees are screened prior to entry and people with suspected or confirmed COVID–19 are not present; health care support services not performed in a health care setting (e.g., off-site laundry, off-site medical billing); or telehealth services performed outside of a setting where direct patient care occurs. In addition, for covered employers, ETS requirements regarding masking, physical barriers, and physical distancing do not apply to fully vaccinated employees in well-defined areas where there is no reasonable expectation that any person with suspected or confirmed COVID–19 will be present. 1910.502(a)(2)(i)-1910.502(a)(4). As to employee vaccinations, the ETS specifically contemplates that there may be medical conditions, disabilities, or religious reasons employees cannot be vaccinated. Employers are reminded in the ETS guidance that they should make exceptions where appropriate. We discussed EEOC guidance regarding employee vaccinations in a previous blogpost. Except for requirements regarding physical barriers, ventilation, and training, employers must comply with the ETS mandates by July 6, 2021. Employers must become compliant with the physical barrier, ventilation, and training requirements by July 21, 2021. When OSHA first issued the ETS, little direction was available directly from OSHA in terms of how employers could comply with the ETS’s many mandates. Since publication of the ETS in the Federal Register, OHSA has fortified existing resources and added new ones. Employers should visit OSHA's ETS website for Fact Sheets, FAQs, Notification Removal and Return to Work Flow Charts for both Employers and Employees, Employee Training Presentations, and more. Further, it is important to understand how the new OSHA regulations interact with already existing guidance on similar COVID-19 related topics for health care providers which have been published by other federal and state agencies, such as the Centers for Medicare and Medicaid Services and the Centers for Disease Control and Prevention. In most cases, the various guidance and regulations do not conflict, but a careful review of all related laws and agency guidance is prudent, in order to fully understand the rules that apply in a given situation, especially when there is a conflict. A qualified employment lawyer can assist employers with matters such as developing their COVID-19 Plan, planning the Workplace Hazard assessment, and conducting training; all things which are required by the ETS. Please contact the author of this blog post or your regular Dorsey & Whitney labor and employment attorney with further questions about how to come into compliance with the new OSHA guidance by the July 6 and July 21 deadlines.
June 23, 2021
coronavirus
Considerations for Health Care Employers under Iowa’s Vaccine Passport Law and Recent CDC, CMS and EEOC Guidelines
One of the last pieces of legislation the Iowa legislature sent to Governor Kim Reynolds’ desk for guaranteed signature was a bill banning vaccine passports in Iowa. House File 889 contains several prohibitions regarding inquiries into a person’s COVID-19 vaccine status. For entities that contract with the state government or otherwise receive state funding, the law contains financial consequences for a violation (but is silent as to penalties for others). While the law contains clear proscriptions, it also has notable explicit and implicit exclusions. Healthcare providers, and nursing home facilities specifically, have additional considerations under recently released CMS, CDC and OSHA guidance. All employers have considerations under state and federal anti-discrimination laws and updated EEOC technical assistance. Iowa Law Iowa’s law prohibits the designation of COVID-19 vaccine status on state or political subdivision-issued identification cards. That means there will be no COVID-19 notations on Iowa drivers’ licenses anytime soon. The law also forbids businesses or governmental entities from requiring customers, patrons, clients, patients, or other persons invited onto the premises (“invitees”) to show proof of a COVID-19 vaccine. However, the law does not list employees in the category of people who are protected from having to show proof of a COVID-19 vaccine. Therefore, under Iowa law, employers can legally require employees to show proof of a COVID-19 vaccine as a condition of employment. Further, the law explicitly excludes healthcare facilities from the definition of a business or a governmental entity. Healthcare facilities include hospitals and other licensed inpatient centers, ambulatory surgical or treatment centers, skilled nursing centers and nursing facilities, residential treatment centers, diagnostic, laboratory and imaging centers, rehabilitation and other therapeutic health settings, and intermediate care facilities for people with mental illness or intellectual disabilities. CDC, CMS and OSHA Guidance On April 27, 2021, the Centers for Disease Control and Prevention (CDC) published updated health care infection prevention and control recommendations following the wide availability of COVID-19 vaccination, available here. The CDC guidance includes updated COVID-19 testing recommendations, updated visitation guidance for health care facilities, and additional guidance for communal activities and dining in healthcare settings. Shortly thereafter, on May 11, 2021, CMS published updated guidance for long term care (LTC) facilities, called an interim final rule. That rule, available here, focuses on COVID-19 vaccination education, consent, and refusal, as well as the procedures LTC facilities must follow in offering vaccinations to employees and residents. It also includes recordkeeping requirements. The guidance is silent regarding whether LTC facilities can require employee or resident vaccinations, instead simply stating, “[f]acilities should follow state law and facility policies with respect to staff refusal of vaccination.” In Iowa, that means long term care facilities could choose to require all staff and residents to be vaccinated. On June 10, 2021, OSHA published the first guidance for employers governing workplace safety rules related to COVID-19, which applies only to employment settings where employees provide healthcare services or healthcare support services in a healthcare setting. The new OSHA rules are entitled, the “COVID-19 Healthcare Emergency Temporary Standard”, and they are available here. FAQs regarding the new regulations were published by OSHA and are available here. The scope of this article does not cover the new OSHA COVID-19 Healthcare Emergency Temporary Standard because Dorsey attorneys published a separate article on this new guidance including practical tips for its implementation, which is available here. EEOC Guidance Health care facilities adopting COVID-19 vaccination requirements should be mindful of state and federal anti-discrimination laws such as the Iowa Civil Rights Act (ICRA) and the Americans with Disabilities Act (ADA). Both the ICRA and the ADA prohibit employers and places of public accommodation from discriminating against people on the basis of their religion or disability, among other things. Public accommodations include, but are not limited to places that offer services, facilities, or goods for a fee or charge. To name a few, a person’s health condition could prohibit them from getting a COVID-19 vaccine, a person’s religion might prohibit vaccinations, a person may be reluctant to get the vaccine while pregnant, and data has shown that minority communities disparately have lower vaccination rates. Health care facilities mandating vaccines could run into legal issues if they are unwilling to make exceptions in certain circumstances. Additionally, on May 28, 2021, the EEOC updated its technical guidance regarding whether employers can provide COVID-19 vaccine incentives for employees in a technical assistance Q&A, available here. The EEOC guidance echoes the considerations above, noting that employers must take care not to run afoul of state and federal employment laws when making decisions about vaccine requirements. The guidance also states the vaccine incentives cannot be coercive, and that employers must keep vaccine information confidential. Practical Tips and Take Aways In light of the ever-changing status of employment and health laws and guidance related to COVID-19, healthcare facilities drafting or updating policies related to COVID-19 mitigation should consult with their employment and health care counsel to make sure the policies are consistent with Iowa’s vaccine passport law, state and federal employment laws and technical assistance, and any recent CDC and CMS publications. That said, the following tips may help to guide health care facilities’ development of employment-related COVID-19 policies and procedures: Healthcare employers, particularly LTC facilities, considering mandating the COVID-19 vaccine for employees should also think about the impact such a mandate might have on the available workforce. With data suggesting that only about half (or less) of Iowa’s LTC facility employees are fully vaccinated, employers might see crippling staff shortages if they start making the COVID-19 vaccination a condition of new or continued employment. Healthcare employers seeking to increase their workforce’s COVID-19 vaccination rates could come up with ways to fairly incentivize employees, consistent with the recent EEOC technical assistance. Regardless of the type of vaccine, if employers choose to require vaccinations as a condition of employment, they should remember to keep all vaccination information confidential pursuant to the ADA. If employers believe that a lack of convenient access is a contributing factor to low employee COVID-19 vaccine rates, employers could consider holding vaccine clinics consistent with the CMS guidance described and linked above. Employers who do choose to hold vaccine clinics or otherwise make the COVID-19 vaccine available to employees at work should be cognizant of their workforce and adjust accordingly. For example, employers should think about whether informational materials should be offered in languages other than English and whether some of the people administering vaccines should be bilingual. Healthcare employers which are covered under the new OSHA COVID-19 Healthcare Emergency Temporary Standard referenced above (generally, those with 10 or more employees) should ensure that the company’s written COVID-19 plan incorporates all of the elements required under the new COVID-19 Healthcare Emergency Temporary Standard, including providing reasonable time off and paid leave for vaccinations and vaccine side effects for employees. For more information on the new OSHA standards, see a separate post by our Dorsey colleagues, available here. Prior to taking any adverse action against an employee related to that person’s COVID-19 vaccination status, or any other conduct pertaining to COVID-19, employers should seek guidance from a knowledgeable employment law attorney. As described in an earlier blog post, COVID-19 related lawsuits against employers are on the rise (including in Iowa), and employers need to be proactive in ensuring their decisions are consistent with the ever-changing legal landscape on these issues.
June 10, 2021
Accountable Care Organizations
The “Regulatory Sprint to Coordinated Care” – Overview and Links to Further Resources from Dorsey & Whitney
In 2018, the U.S. Department of Health and Human Services (“HHS”) launched the “Regulatory Sprint to Coordinated Care” to accelerate a transformation of the healthcare system, with a focus on removing “unnecessary obstacles” to coordinated care (the “Regulatory Sprint”). Several HHS agencies requested comments and information from the public and have published new or proposed regulations as part of the Regulatory Sprint on areas that have historically been viewed as barriers to innovative care coordination arrangements—namely, healthcare fraud and abuse and health information privacy. On November 20, 2020, the HHS Office of Inspector General (“OIG”) and Centers for Medicare & Medicaid Services (“CMS”) each issued a sweeping set of final regulations that introduced significant new value-based terminology, safe harbors and exceptions, as well as clarifications of existing requirements, under the federal anti-kickback statute (“AKS”) and federal physician self-referral law (“Stark Law”), respectively. Additionally, the OIG issued final regulations related to modernizing the civil monetary penalty law governing inducements provided to Medicare and Medicaid beneficiaries (the “CMPL”). The final OIG and CMS rules are effective on January 19, 2021, with the exception of changes to the Stark “group practice” definition, which do not go into effect until January 1, 2022. There are hundreds of pages of preamble guidance and revised regulation text setting forth these sweeping changes to the Stark Law, AKS and CMPL regulations from CMS and OIG. To help you digest these materials, a team of attorneys from Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group has published two white papers, which are available at the links below. In addition, we have posted at a link below the playback of a webinar we hosted about the final rules on January 6, 2021. The white papers and webinar playback provide an in-depth summary of the changes to these regulations, including key provisions from CMS and OIG preamble guidance. Finally, we have posted below redlines comparing the existing Stark Law, AKS and CMPL regulations to the revised version of each of these regulations in the final rules. With respect to health information privacy, the HHS Office for Civil Rights (“OCR”) issued a Notice of Proposed Rulemaking (“NPRM”) on December 10, 2020 which proposes changes to the Health Insurance Portability and Accountability Act (“HIPAA”) and to the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Privacy Rule. Additionally, the HHS Substance Abuse and Mental Health Services Administration (“SAMHSA”) published final rules to revise regulations related to the privacy of substance use disorder treatment records in July 2020. These changes in federal regulations are anticipated to make a significant impact on healthcare providers and other stakeholders that may have been reticent to initiate certain care coordination arrangements because of perceived regulatory barriers and lack of regulatory clarity. In addition, clarifications to existing regulations impact stakeholders beyond their involvement in care coordination arrangements. The team of attorneys in Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group will continue to closely monitor these changes, and post updates and analysis below as new information becomes available. Stark Regulatory Changes Effective January 1, 2022 Require Modifying Certain Group Practice Compensation Methodologies | News & Resources Webinar Playback: Final Stark and Anti-Kickback Statute Rules: What You Need to Know White Paper: Understanding the Final Rules to Revise the Stark Law Regulations White Paper: Understanding the Final Rules to Revise the Anti-Kickback Statute and Beneficiary Inducement Civil Monetary Penalty Regulations The Regulatory Sprint Catches up to HIPAA: New Proposed HIPAA Rules Redline of Final AKS Regulatory Text Redline of Final CMP Regulatory Text Redline of Final Stark Regulatory Text effective 1.1.2022 - 411.352(i) only Redline of Final Stark Regulatory Text effective 1.19.2021 Much-Anticipated Final Rules to Revise Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP Regulations Released under “Regulatory Sprint to Coordinated Care” CMS Finalizes Changes to the Stark Advisory Opinion Regulations; 2020 DHS Code List and CPI-U Updates Sweeping Proposals Issued by CMS to Revise Stark Law Regulations Sweeping Proposals Issued By OIG To Make Changes To The Anti-Kickback Statute Safe Harbors And Add An Exception To The Civil Monetary Penalty Law Governing Beneficiary Inducements A Massive Number of New Health Law Regulatory Proposals as Part of the “Regulatory Sprint to Coordinated Care”: Proposed Changes to the Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP, Privacy Laws Governing Substance Use Disorder Records, and the Stark Law Advisory Opinion Process CMS "Actively Working" on Stark Law Reforms to be Issued Later this Year; "Regulatory Sprint to Coordinated Care" Continues OIG Seeks Public Input on Anti-Kickback Statute and Beneficiary Inducements CMP as part of the “Regulatory Sprint to Coordinated Care” Calls for Modernizing the Stark Law Continue; CMS Seeks Public Input on Stark Law Reforms
April 30, 2021
Anti-Kickback
White Papers: Understanding the Final Rules to Revise the Stark Law, Anti-Kickback Statute and Beneficiary Inducement Civil Monetary Penalty Regulations
In just two weeks, on January 19, 2021, a sweeping set of changes to the federal physician self-referral law (or “Stark Law”) and anti-kickback statute (“AKS”) regulations go into effect. These changes, which are part of the U.S. Department of Health and Human Services (“HHS”) “Regulatory Sprint to Coordinated Care,” are the most significant changes to the Stark Law and AKS in a decade. There are hundreds of pages of preamble guidance and revised regulation text setting forth these sweeping changes from the Centers for Medicare & Medicaid Services (“CMS”) and HHS Office of Inspector General (“OIG”). To help you digest these materials, a team of attorneys from Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group has published two white papers, which are available at the following links: White Paper: Understanding the Final Rules to Revise the Stark Law Regulations White Paper: Understanding the Final Rules to Revise the Anti-Kickback Statute and Beneficiary Inducement Civil Monetary Penalty Regulations These white papers provide an in-depth summary of the changes to these regulations, including key provisions from CMS and OIG preamble guidance. Please contact the authors or your regular Dorsey attorney if you would like assistance with understanding how the final rules impact your organization.
January 5, 2021
HHS Office for Civil Rights
The Regulatory Sprint Catches up to HIPAA: New Proposed HIPAA Rules
Today, the Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) issued a Notice of Proposed Rulemaking (“NPRM”) which proposes significant changes to the Health Insurance Portability and Accountability Act (“HIPAA”) and to the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Privacy Rule (the “Privacy Rule”). The NPRM includes numerous changes to the Privacy Rule that are part of HHS’ Regulatory Sprint to Coordinated Care which is intended to eliminate administrative barriers to a health care delivery system that fosters care coordination and value-based care for patients. OCR also issued a fact sheet about this NPRM, which is available here. This NPRM comes nearly two years after OCR issued a Request for Information (“RFI”) in December 2018 calling for information from the public regarding ways that HIPAA regulations could be modernized to support coordinated, value-based care. These changes in federal regulations are anticipated to make a significant impact on healthcare providers and other stakeholders that may have been reticent to initiate certain care coordination arrangements because of perceived HIPAA violations or a lack of regulatory certainty. Clarifications to existing regulations will impact stakeholders beyond their involvement in care coordination arrangements. The changes will also impact data sharing arrangements and reduce unnecessary administrative burdens on health care providers and health plans, such as eliminating the requirement to obtain an individual’s signature for the Notice of Privacy Practices (“NPP”) or the requirement to retain copies of the NPP for six years. Further, the proposed changes to the Privacy Rule provide clarification to the laws governing patient rights of access to their health records, and help to better facilitate disclosures of health information in order to improve care for patients in emergencies or who are experiencing a health crisis, including mental health crises and opioid overdose situations. Comments to the NPRM are invited from stakeholders, and will be due some time in February 2021, at a date that is 60 days after the NPRM is published in the Federal Register. Please contact the author of this post or your regular Dorsey attorney if you have questions about how these changes to the Privacy Rule could impact you, and for assistance in submitting comments to the OCR. The team of attorneys in Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group will continue to closely monitor these changes, and post updates and analysis on Dorsey’s Health Law Blog and on Dorsey’s Regulatory Sprint Webpage as new information becomes available.
December 10, 2020
Anti-Kickback
Much-Anticipated Final Rules to Revise Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP Regulations Released under “Regulatory Sprint to Coordinated Care”
On November 20, 2020, the Centers for Medicare & Medicaid Services (CMS) and the Department of Health and Human Services (HHS) Office of Inspector General (OIG) each released their much-anticipated final rules to revise the federal self-referral law (or “Stark Law”) regulations, the safe harbors under the federal anti-kickback statute (AKS), and regulations under the beneficiary inducements civil monetary penalty law (CMP). The final rules are part of HHS’s “Regulatory Sprint to Coordinated Care,” which seeks to remove regulatory obstacles to care coordination and a value-based healthcare delivery system. The public inspection copy of the final CMS rules is available here, and the CMS fact sheet on the final rules is available here. The public inspection copy of the final OIG rules is available here, and the OIG fact sheet on the final rules is available here. Both rules will be published in the Federal Register on December 2, 2020. For our prior posts on the Regulatory Sprint to Coordinated Care, see here. We are reviewing the final rules and will post an in-depth analysis in the coming weeks.
November 20, 2020
HHS Office for Civil Rights
2020’s a Bust, but HIPAA Enforcement Is on a Roll!
The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) has been actively enforcing HIPAA regulations this year, including a series of seven settlements under OCR’s Right of Access Initiative to enforce patients’ rights to timely access their medical records at a reasonable cost. This year, OCR has recorded more than $12.2 million in resolution agreements. This post summarizes OCR’s settlements in 2020 to date. The OCR settlements have impacted a wide range of sectors in the health industry from health insurers, to hospital systems, physician clinics, FQHCs, mental health and substance abuse providers, business associates, and nonprofits serving those with AIDS/HIV. Enforcement has been taken against all sizes of entities, including against solo practitioners and very small non-profits. As with nearly all settlements with OCR, it was the initial breach notification that triggered the investigation. However, the settlement ultimately resulted after OCR’s investigation discovered widespread non-compliance with HIPAA’s privacy and security requirements. The following post provides a summary of these enforcement actions, and begins with an update about Anthem’s recent $39.5M settlement with 43 states and D.C. stemming from its massive data breach in 2014-2015, which resulted in a record $16 million settlement with OCR in 2018. Health Insurer Enforcement Anthem and 43-State Coalition Reach $39.5 Million Settlement Over Data Breach On September 30, 2020, state attorneys general in 43 states and Washington D.C. announced that they had reached a $39.5 million settlement with Anthem Inc., an Indianapolis, IN-based health insurer. This settlement stemmed from an investigation by the state attorneys general into the largest health data breach in history, a series of state-sponsored cyberattacks in December 2014 and January 2015 that exposed the ePHI of nearly 79 million individuals. In 2018, Anthem agreed to pay $16 million to OCR and to take substantial corrective action to settle potential violations of the HIPAA privacy and security rules related to the 2014 data breach. See the HHS press release about the OCR settlement here. Anthem has also paid $115 million to settle a class action related to the breach, the largest-ever class action settlement related to a data breach. Premera Blue Cross Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People In March, in the second-largest HIPAA settlement ever, Premera Blue Cross (PBC), the largest health plan in the Pacific Northwest, agreed to pay $6.85 to OCR and to implement a corrective action plan to settle potential HIPAA privacy and security rules violations related to a data breach. Using malware installed through a phishing email, cyber-attackers gained access to PBC’s system in August 2014 and went undetected until January 2015, resulting in the exposure of over 10.4 million individuals’ electronic protected health information (ePHI). OCR’s investigation determined that PBC had “systemic noncompliance with the HIPAA Rules including failure to conduct an enterprise-wide risk analysis, and failures to implement risk management, and audit controls.” See the HHS press release here. Hospital and Health System Enforcement Lifespan Pays $1.04 Million to Settle Unencrypted Stolen Laptop Breach Affecting Over 20,000 People In June, Lifespan Health System Affiliated Covered Entity (“Lifespan ACE”), a Rhode Island-based non-profit health system, agreed to pay a $1.04 million settlement to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA privacy and security rules related to the theft of a hospital employee’s unencrypted laptop. The laptop contained the ePHI of more than 20,000 individuals. OCR’s investigation determined that there had been systematic noncompliance with the HIPAA Rules, including a failure to encrypt ePHI on laptops, a lack of device and media controls, and a failure to have a business associate agreement in place with the Lifespan Corporation, the parent company and business associate of Lifespan ACE. See the HHS press release here. Physician and Clinic Enforcement Solo Practice Pays $100,000 for Failing to Implement HIPAA Security Rule Requirements In February, Steven A. Porter, M.D., a Utah gastroenterologist and solo practitioner, agreed to pay $100,000 to OCR and to adopt a corrective action plan to settle a potential violation of the HIPAA security rule. OCR determined that Dr. Porter’s practice had demonstrated significant noncompliance with the HIPAA rules, specifically, failing to conduct any risk analysis and failing “to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.” See the HHS press release here. Orthopedic Clinic Pays $1.5 Million to Settle Systemic Noncompliance with HIPAA Privacy and Security Rules In July, Georgia-based Athens Orthopedic Clinic PA (“Athens Orthopedic”) agreed to pay $1.5 million to OCR and to implement a corrective action plan to settle potential violations of the HIPAA privacy and security rules. A hacker used a vendor’s credentials to access Athens Orthopedic’s electronic medical record system and exfiltrated patient health data, then demanded money from Athens Orthopedic in return for the return of the stolen records. Nearly 210,000 individuals were affected by the breach. OCR’s investigation found noncompliance with the HIPAA privacy and security rules, including “failures to conduct a risk analysis, implement risk management and audit controls, maintain HIPAA policies and procedures, secure business associate agreements with multiple business associates, and provide HIPAA Privacy Rule training to workforce members.” See the HHS press release here. FQHC Pays $25,000 for Failing to Implement HIPAA Security Rule Requirements In March, Metropolitan Community Health Services (“Metro”), doing business as Agape Health Services, agreed to pay $25,000 to OCR and to implement a corrective plan to settle potential violations of the HIPAA security rule. In 2011, Metro reported impermissible disclosure of PHI to an unknown email account, which affected over 1,200 patients. OCR’s investigation found that Metro had failed to conduct any risk analysis, failed to implement any HIPAA security rule policies and procedures, and not provided workforce members with security awareness training until 2016. Metro is a Federally Qualified Health Center that provides medical services in underserved areas in rural North Carolina on a sliding fee scale, which was taken into account in reaching this agreement. See the HHS press release here. Business Associate Enforcement CHSPSC Agrees to Pay $2.3 Million to Settle Data Breach Affecting Over 6 Million People In March, CHSPSC LLC (“CHSPSC”) agreed to pay $2.3 million and to adopt a corrective action plan to settle potential violation of the HIPAA privacy and security rules related to a breach affecting more than 6 million people. CHSPSC is based in Tennessee and provides a variety of business associate services, including IT and health information management. In 2014, the Federal Bureau of Investigation (FBI) notified CHSPSC that it had traced a cyber-attack to CHSPSC’s information system. OCR’s subsequent investigation found “longstanding, systematic noncompliance” with the HIPAA security rule, including “failure to conduct a risk analysis, and failures to implement information system activity review, security incident procedures, or access controls.” See the HHS press release here. Right of Access Initiative Enforcement In 2019, OCR announced the Right of Access Initiative as an enforcement priority to support individuals’ right to timely access to their health records at a reasonable cost and in the readily producible format of their choice under the HIPAA privacy rule’s right of access provision, 45 CFR § 164.524. The HIPAA Rules generally require covered health care providers to provide medical records within 30 days of the request and providers can only charge a reasonable cost-based fee. This right to patient records extends to parents seeking access to their minor children’s medical records. To date this year, OCR has completed seven enforcement actions totaling $396,500 in settlement payments under the Right of Access Initiative, bringing the total number of enforcement settlements under this initiative to nine. In June, Housing Works Inc. (Housing Works), a New York City-based non-profit organization providing a range of services to individuals living with and affected by HIV/AIDS, including health care, agreed to pay $38,000 to OCR and to take corrective actions to settle a potential right of access violation. In complaints filed with OCR in July and August 2019, a patient alleged that he had not received his records in response to a June 2019 request. OCR opened an investigation, found a possible violation, and the patient received his medical records in November 2019. In July, All Inclusive Medical Services (AIMS), a California-based multi-specialty family medicine clinic, has agreed to pay $15,000 to OCR and to adopt a corrective action plan to settle a potential right of access violation. A patient alleged that in January 2018, AIMS had denied her requests to inspect and receive a copy of her records, in an April 2018 complaint filed with OCR. The patient ultimately received her medical records in August 2020. In August, Beth Israel Lahey Health Behavioral Services (BILHBS), the largest network of mental health and substance use disorder services in eastern Massachusetts, agreed to pay $70,000 to OCR and to take corrective actions following a potential right of access violation. A personal representative filed a complaint with OCR in April 2019 alleging that she had requested her father’s medical records in February 2019 and BILHBS had failed to provide them. BILHBS provided the requested medical records in October 2019. In August, Patricia King, M.D. (King MD), a small provider of psychiatric services in Virginia, agreed to pay $3,500 to OCR and to adopt a corrective action plan to settle a potential right of access violation. OCR received a complaint from a patient in October 2018, alleging that King MD failed to respond to her August 2018 request for her medical records. After OCR provided King MD with technical assistance on right of access requirements, a second complaint, and an OCR investigation that found that the failure to provide the requested medical records was a potential violation, the patient received her medical records in July 2020. In August, Wise Psychiatry, PC (Wise Psychiatry) a small provider of psychiatric services in Colorado, agreed to pay $10,000 to OCR and to take corrective actions to settle a potential right of access violation. A father requested his minor son’s medical records in November 2017, and following two complaints to OCR, OCR providing technical assistance to Wise Psychiatry on the HIPAA right of access requirements, and OCR opening an investigation, Wise Psychiatry sent the requested medical records in May 2019. See HHS’s press release about OCR’s first five right to access settlements of 2020 here. In September, Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), agreed to pay $160,000 and to adopt a corrective action plan to settle a potential right of access violation. SJHMC is based in Arizona and is a large, acute-care hospital with several hospital-based clinics. A mother made several requests for her son’s medical records, as his personal representative, beginning in January 2018, but did not receive all of the requested records until December 2019. See the HHS press release here. In September, NY Spine Medicine (NY Spine), a private medical practice specializing in neurology and pain management with offices in New York and Florida, agreed to pay $100,000 and to take corrective actions to settle a potential right of access violation. A patient requested a copy of her medical records in June 2019, and NY Spine provided some records in response, but did not provide the diagnostic films that the patient had specifically requested until October 2020, after OCR had initiated an investigation. See the HHS press release here. OCR’s enforcement of the HIPAA security and privacy rules this year is increasingly aggressive. Per HHS, OCR’s enforcement actions are “designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.” If you have questions about HIPAA compliance, please contact the authors, your regular Dorsey attorney or any attorney in the Dorsey & Whitney health transactions and regulations practice group.
October 15, 2020
Compliance Programs
Is Your Compliance Program More than a Paper Program? DOJ Issues Revised Guidance for Evaluating Corporate Compliance Programs
On June 1, 2020, the Department of Justice (“DOJ”) issued an updated version of its “Evaluation of Corporate Compliance Programs” (the “DOJ Guidance”), available here. The DOJ Guidance is an update to guidance first issued by the DOJ in February 2017 (which we described in our prior blog post), and was last updated by the DOJ in April 2019. Although the DOJ Guidance is directed to prosecutors, it is a useful roadmap for corporations in seeking to ensure their compliance program is effectively preventing, detecting and responding to improper conduct, and is not a program on paper only. The DOJ Guidance is intended to be used by prosecutors to assist them “in making informed decisions as to whether, and to what extent, [a] corporation’s compliance program was effective at the time of [an] offense, and is effective at the time of a charging decision or resolution, for purposes of determining the appropriate (1) form of any resolution or prosecution; (2) monetary penalty, if any; and (3) compliance obligations contained in any corporate criminal resolution (e.g., monitorship or reporting obligations).” Thus, in the event that there is an investigation into alleged improper conduct, having a compliance program that operates in line with the DOJ Guidance may lead to a more favorable resolution than there otherwise would be. The DOJ Guidance notes that there are three “fundamental questions” a prosecutor should ask when evaluating compliance programs: Is the corporation’s compliance program well designed? Is the program being applied earnestly and in good faith? In other words, is the program adequately resourced and empowered to function effectively? Does the corporation’s compliance program work in practice? The DOJ Guidance sets forth a number of sample topics under the heading of each of the three questions listed above, which it says are not a checklist or formula, but are the topics “that the Criminal Division has frequently found relevant in evaluating a corporate compliance program both at the time of the offense and at the time of the charging decision and resolution.” The DOJ Guidance emphasizes the importance of a compliance program being not merely a “paper program,” but rather one that is “implemented, reviewed, and revised, as appropriate, in an effective manner.” The most recent updates to the DOJ Guidance reflect the DOJ’s increased focus of taking a functional and dynamic approach to evaluating the effectiveness of a company’s compliance program. The revisions explain new factors prosecutors may consider in the areas of risk assessment, policies and procedures, training and communications, mergers and acquisitions, and more in their assessment of corporate compliance programs. Organizations should use the DOJ Guidance, including a consideration of these new factors, when evaluating the effectiveness of their compliance program. Key revisions to the DOJ Guidance are summarized below. Risk Assessments. The DOJ Guidance directs prosecutors to consider whether a company has “a process for tracking and incorporating into its periodic risk assessment lessons learned either from the company’s own prior issues or from those of other companies operating in the same industry and/or geographical region.” Prosecutors are also instructed to evaluate whether a company takes a continuous assessment approach to compliance review and updates, as opposed to a “snapshot-in-time” approach. Thus, it is imperative that compliance teams at an organization perform regular assessments, stay up-to-date on compliance problems, and incorporate lessons learned into the risk assessment process. Policies and Procedures. The DOJ Guidance continues to emphasize the importance of adequately communicating compliance policies and procedures throughout the company. The update includes two new questions related to the accessibility of policies and procedures: “Have the policies and procedures been published in a searchable format for easy reference?” and “Does the company track access to various policies and procedures to understand what policies are attracting more attention from relevant employees?” Training and Communications. New questions in the DOJ Guidance instruct prosecutors to evaluate whether a company is evaluating the effect of its training program on employee behavior or operations. Additionally, the DOJ will be assessing whether employees have opportunities to ask questions and whether the company overall has “relayed information in a manner tailored to the audience’s size, sophistication, or subject-matter expertise.” Confidential Reporting. The revisions also address confidential employee hotlines and other reporting mechanisms. Prosecutors will assess whether confidential reporting mechanisms are publicized both to employees and third parties, and whether a company is periodically testing the mechanism’s effectiveness. Third-Party Management. The DOJ Guidance adds a new question about a company’s management of third-party relationships: is risk assessment conducted only during the onboarding process or throughout the lifespan of the engagement? Mergers and Acquisitions. The DOJ has always considered comprehensive due diligence of acquisition targets to be an important part of a compliance program. The recent revisions to the DOJ Guidance, however, recognize that pre-acquisition due diligence may not always be possible. Where such pre-acquisition diligence is not conducted, the DOJ Guidance indicates that a company should have a legitimate reason for not conducting it, and that the company should conduct post-acquisition diligence and audits. In addition, an acquired entity should always be timely integrated into a company’s existing compliance program structure. Compliance Resources. Adequate resources are essential for effective implementation of a compliance program. The DOJ Guidance instructs prosecutors to ask whether a company’s compliance program is “adequately resourced and empowered to function effectively.” Companies should continue to invest in the training and development of personnel and in the compliance program more broadly, throughout all levels of the organization. * * * Overall, the revised DOJ Guidance affirms previous guidance and stresses that compliance programs should be well-resourced, dynamic, and tailored to a company’s unique size, structure, and needs. The DOJ Guidance also serves as a reminder that even in the midst of a global pandemic, the compliance function of an organization must remain robust and ever-adapting. Healthcare organizations should use the DOJ Guidance and other existing resources to thoughtfully design, assess, and revise their compliance programs. Dorsey attorneys have substantial experience with assisting health industry clients in implementing compliance programs following the elements of an effective compliance program from the Department of Health and Human Services Office of Inspector General, in updating compliance programs, and in evaluating the effectiveness of existing compliance programs in line with the DOJ Guidance and other guidance. For assistance with your organization’s compliance program, please contact the authors or your regular Dorsey attorney.
July 10, 2020
CMS Guidance
CMS Issues Explanatory Guidance on Stark Law Blanket Waivers
As we explained in our prior blog post, on March 30, 2020, the Centers for Medicare & Medicaid Services (“CMS”) issued certain blanket waivers of sanctions under the federal physician self-referral law (or “Stark Law”) for “COVID-19 Purposes” (the “Stark Blanket Waivers”), which are available here. On April 21, 2020, CMS issued explanatory guidance, available here, on the scope and application of the Stark Blanket Waivers to certain financial relationships (the “Explanatory Guidance”). In addition to answering a variety of questions raised by the initial announcement of the Stark Blanket Waivers, the Explanatory Guidance provides an important reassurance to stakeholders. CMS states: “The Secretary will work with the Department of Justice to address False Claims Act relator suits where parties using the blanket waivers have a good faith belief that their remuneration or referrals are covered by a blanket waiver.” Despite this reassurance, however, it is crucial that parties seeking to rely on a Stark Blanket Waiver ensure that their arrangement, in fact, relates to “COVID-19 Purposes” (as defined in the Stark Blanket Waivers document), falls within the parameters of a specifically enumerated waiver within the Stark Blanket Waivers document, and that all non-waived requirements of an applicable Stark Law exception are met. We also note that, as CMS reminds parties in the Explanatory Guidance, relying on a Stark Blanket Waiver may not be necessary for certain arrangements related to COVID-19 Purposes, if these arrangements satisfy the requirements of an existing Stark Law exception. The following information summarizes the Explanatory Guidance. A. Compliance with Non-Waived Requirements of an Applicable Exception Many of the Stark Blanket Waivers eliminate or alter some, but not all, of the existing requirements of particular Stark Law exceptions. CMS warns that financial relationships or referrals must satisfy all non-waived requirements of an applicable exception in order to avoid implicating the Stark Law’s referral and billing prohibitions. We note that this includes, for example, meeting the “set in advance” requirement of applicable compensation exceptions, as this requirement is not waived by any of the Stark Blanket Waivers. B. Amendment of Compensation Arrangements The Explanatory Guidance clarifies when parties may modify the remuneration terms of an existing arrangement during the COVID-19 emergency period, and whether such terms can be amended during the emergency period and again at the conclusion of the emergency period to return to the original terms. This guidance applies when parties are relying on a compensation exception that has both a one-year term requirement and a “set in advance” requirement (such as the personal services arrangements exception). CMS points to the preamble guidance in the Fiscal Year 2009 Inpatient Prospective Payment System final rule (“FY 2009 IPPS Rule”), which CMS interprets as allowing for a second or subsequent amendment of the compensation terms of an arrangement, even within the first year of an initial amendment of those terms, as long as each time those terms are amended, “all requirements of an applicable exception are satisfied, the amended remuneration is determined before the amendment is implemented, the formula for the amended remuneration does not take into account the volume or value [of] referrals or other business generated by the referring physician, and the overall arrangement remains in place for at least 1 year following the amendment.” CMS reiterates that if parties amend a compensation arrangement during the emergency period, all non-waived requirements of an applicable exception must be met. The compensation terms of the arrangement may again be amended after the public health emergency is over. This further amendment may restore the original terms of the arrangement or make additional changes, as long as each of the criteria from the FY 2009 IPPS Rule (described above) are met. Finally, CMS points out that a modification of an existing arrangement could instead be analyzed as an additional compensation arrangement, for which the parties could use the Stark Blanket Waivers (if all applicable requirements are met). C. Applicability of Blanket Waivers to Indirect Compensation Arrangements The Explanatory Guidance states that the Stark Blanket Waivers do not apply to indirect compensation arrangements, and only apply to direct compensation arrangements. Parties can, however, seek an individual waiver of sanctions related to indirect compensation arrangements. The Explanatory Guidance goes on to note that many compensation arrangements that may appear to be indirect may be analyzed as direct compensation arrangements under the “stand in the shoes” provisions of the Stark Law. D. Repayment Options for Loans between a DHS Entity and a Physician (or the Immediate Family Member of a Physician) Two Stark Blanket Waivers (waivers #10 and #11) involve remuneration in the form of a loan with an interest rate below fair market value or on terms that are unavailable from a lender that is not in a position to make referrals to or generate business for the party making the loan. CMS states that these waivers do not require cash payments to the lender to satisfy a borrower’s debt. Loans may be repaid through in-kind payments, as long as the aggregate value of the in-kind payments is consistent with the amount of the loan and the arrangement is commercially reasonable. CMS provides that an example in-kind payment could be the maintenance of a medical practice and continuing to serve patients in the community where the entity is located. E. Repayment of Loans, Rent Abatement, or Other Amounts Due Following the End of the Emergency Period CMS clarified that, if parties use the Stark Blanket Waivers such as the loan arrangements described above, repayment obligations do not need to be completed prior to the termination of the Stark Blanket Waivers (which will be at the end of the public health emergency that was declared related to the COVID-19 outbreak). Many parties expressed concern that, after the termination of the Stark Blanket Waivers, the compensation arrangements entered into would no longer satisfy the requirements of an applicable exception because the interest charges or other charged amounts would not be consistent with the fair market value of the remuneration provided. The Explanatory Guidance provides that appropriate repayment terms agreed to before the termination of the Stark Blanket Waivers may continue beyond the termination of the waivers. However, disbursement of loan proceeds or additional remuneration after the termination of the Stark Blanket Waivers must satisfy all requirements of the applicable Stark exception. F. Restructuring of Existing Recruitment Arrangements with Income Guarantees CMS also responded to inquiries about the extension or restructuring of existing physician recruitment arrangements, such as whether a hospital could extend an income guarantee to address a recruited physician’s medical practice interruption due to the COVID-19 pandemic. The Explanatory Guidance states that CMS maintains its position that, under the Stark Law exception for physician recruitment, the terms of a recruitment arrangement cannot be altered once the physician has relocated their practice. Some Stark Blanket Waivers, however, may be available for remuneration from a hospital (or other entity) to assist a relocated physician whose medical practice is disrupted due to the pandemic in order to maintain the availability of medical care and related services for patients and the community. * * * For help determining whether an existing or proposed arrangement complies with a Stark Blanket Waiver and/or for inquiries regarding individual waiver requests, please contact the authors of this post or your regular Dorsey attorney. We continue to closely monitor the legal landscape related to the COVID-19 pandemic. You can access Dorsey’s health law blog providing health law updates, available here. You can also access Dorsey’s coronavirus resource center, containing a wide variety of legal resources related to the coronavirus outbreak, available here.
April 29, 2020
coronavirus
The Paycheck Protection Program and Health Care Enhancement Act: Summary of “Phase 3.5” COVID-19 Stimulus Package
On Friday, April 24, 2020, President Trump signed into law the “Paycheck Protection Program and Health Care Enhancement Act,” colloquially referred to as “Phase 3.5.” Phase 3.5 comes on the heels of three much larger bills passed into law intended to address the effects of the ongoing coronavirus pandemic. The first three phases, the Coronavirus Preparedness and Response Supplemental Appropriations Act, the Families First Coronavirus Response Act, and the CARES Act, provided much-needed funding to hospitals and health care providers affected by COVID-19. Phase 3.5 continues this funding by providing additional emergency appropriations totaling $484 billion, the majority of which ($384 billion) goes to replenishing the Paycheck Protection Program, Economic Injury Disaster Loans, and Emergency Grants funds as established in the CARES Act. Phase 3.5 allocates an additional $75 billion to the Public Health and Social Services Emergency Fund for providers to prevent, prepare for, and respond to coronavirus. The Phase 3.5 package also includes $25 billion for COVID-19 testing, $11 billion of which is earmarked for states to aid in their efforts to ramp up testing. A breakdown of the major funding provisions included in the Phase 3.5 bill is below. Paycheck Protection Program Phase 3.5 appropriates an additional $321 billion to replenish the funds for the Paycheck Protection Program (“PPP”). The PPP was originally funded by the CARES Act with $349 billion to protect small businesses and help them avoid layoffs and rehire employees. The loan amounts distributed under the PPP will be forgiven so long as the loan proceeds are used to cover payroll costs, and most mortgage interest, rent, and utility costs, and employee and compensation levels are maintained. Phase 3.5 specifically sets aside $60 billion of these funds for small, midsize, and community lenders in an effort to avoid forcing smaller companies to compete with larger companies for the same funds. Economic Injury Disaster Loans Program Phase 3.5 appropriates $50 billion for Economic Injury Disaster Loans and an additional $10 billion for Emergency Injury Disaster Loan Grants. Public Health and Social Services Emergency Fund Phase 3.5 provides an additional $75 billion to the Public Health and Social Services Emergency Fund for hospitals and other health care providers to prevent, prepare for, and respond to coronavirus. This fund is managed by the Department of Health and Human Services. The CARES Act originally appropriated $100 billion to this fund, $30 billion of which was distributed beginning on April 10, 2020 with payments arriving in eligible health care providers’ bank accounts via direct deposit. On April 22, 2020, HHS unveiled the next phase of these distributions through a series of general and targeted distributions aimed in part at providing relief to those providers in areas highly impacted by COVID-19. Funds Allocated for Testing Phase 3.5 also provides $25 billion to the Public Health and Social Services Emergency Fund specifically for expenses surrounding the research, development, validation, manufacture, purchase, administration, and expanding of capacities for COVID-19 testing. A breakdown of the allocations for testing in Phase 3.5 is below: • $11 billion of these funds have been allocated to states to develop, purchase, administer, process, and analyze COVID-19 tests, including support for workforce, epidemiology, use by employers, scale up testing by public health and hospital laboratories, and community-based testing sites, health care facilities, and other entities engaged in testing. • $2 billion is to be provided to the states based on the Public Health Emergency Preparedness cooperative agreement in FY 2019; • $4.25 billion is to be allocated based on the number of COVID-19 cases; and • $750 million is to be provided to the Indian Health Service to aid tribes, tribal organizations, and Indian Health Service facilities. • $1 billion to the CDC for surveillance, epidemiology, laboratory capacity expansion, contact tracing, public health data surveillance and analytics infrastructure modernization, disseminating information about testing, and workforce support. • $1 billion to the NIH to develop, validate, improve, and implement testing and associated technologies and to accelerate research, development, and implementation of point of care and other rapid testing. • $1 billion to the Biomedical Advanced Research and Development Authority to cover research expenses. • $22 million to the FDA to support activities associated with diagnostic, serological, antigen, and other testing. • $600 million to HRSA for grants under the Health Centers program. • $225 million to rural health clinics to provide COVID-19 testing, with such funds also available to RHCs for building or construction of temporary structures, leasing of properties, and retrofitting facilities as necessary to support COVID-19 testing. • $1 billion for covering the costs of testing the uninsured. We are keeping a close eye on the rapid developments surrounding COVID-19. If you have any questions about this latest guidance issued by HHS, the CARES Act, or any questions related to COVID-19, please contact the author of this blog or contact your Dorsey and Whitney LLP attorney. You can access Dorsey’s coronavirus resource center, which contains a wide variety of legal resources related to the coronavirus outbreak, available here. You can also access Dorsey’s health law blog related to health law updates, including those applicable to tax exempt entities in the health care space, available here.
April 27, 2020
Anti-Kickback
OIG Initiatives to Ease Provider Burdens Related to COVID-19
The U.S. Department of Health and Human Services Office of Inspector General (“OIG”) has taken numerous steps to minimize regulatory burdens for providers who need to make their primary focus delivering patient care during the COVID-19 national emergency. These steps, along with recent steps taken by other agencies to provide temporary regulatory flexibility, provide further welcomed relief to providers who are facing a tremendous burden during this time. 1. AKS Administrative Sanctions Not Imposed for Remuneration Covered by Stark Blanket Waivers related to “COVID-19 Purposes” As we wrote about in our prior blog post, on March 30, 2020, the Centers for Medicare & Medicaid Services (“CMS”) issued 18 blanket waivers of sanctions under the federal physician self-referral law (or “Stark Law”) for remuneration and referrals related to “COVID-19 Purposes” (the “Stark Blanket Waivers”). Then, on April 3, 2020, the OIG issued a Policy Statement notifying interested parties that it “will exercise its enforcement discretion not to impose administrative sanctions under the Federal anti-kickback statute [(“AKS”)] for certain remuneration related to COVID-19” that is covered by certain of the Stark Blanket Waivers. As the OIG explained in this Policy Statement, ordinarily, some financial relationships that implicate the Stark Law may also implicate, and may potentially violate, the AKS. In the Policy Statement, the OIG stated that it will not impose sanctions with respect to remuneration covered by the first 11 of the Stark Blanket Waivers, provided that all of the conditions and definitions within the Stark Blanket Waivers are met. This includes certain remuneration to or from a physician that is above or below fair market value and remuneration to a physician in the form of medical staff incidental benefits or non-monetary compensation that exceeds the limits set forth in applicable Stark exceptions (when specified requirements are met). Note that the remainder of the 18 Stark Blanket Waivers relates to referrals rather than remuneration. In the Policy Statement, the OIG specified that parties can submit questions via email to OIGComplianceSuggestions@oig.hhs.gov related to the application of the OIG’s administrative sanctions for remuneration associated with referrals described in items 12-17 of the Stark Blanket Waivers. (The OIG did not mention the 18th Stark Blanket Waiver, which relates to compensation arrangements that do not satisfy the writing or signature requirements of an applicable Stark exception, even though various AKS safe harbors also have writing and signature requirements. Presumably, parties can also submit questions to OIG about such arrangements, although many such arrangements may not implicate the AKS based on a facts and circumstances analysis outside of safe harbor protection.) The OIG stated that its purpose in issuing the Policy Statement was to avoid the need for parties to undertake a separate legal review under the AKS for arrangements that are covered by the Stark Blanket Waivers. The OIG cautioned, however, that the Policy Statement does not have any bearing on arrangements that are not covered by the Stark Blanket Waivers. This would include, for example, arrangements between a manufacturer and a physician, and arrangements that do not involve a physician (or immediate family member of a physician). The Policy Statement applies to conduct occurring on or after April 3, 2020, whereas the Stark Blanket Waivers were retroactive to March 1, 2020. The Policy Statement terminates the same day that the Stark Blanket Waivers terminate (i.e., the end of the Public Health Emergency (“PHE”) that was declared related to COVID-19). 2. Other Recent OIG Initiatives In addition to the Policy Statement described above, the OIG has undertaken other notable initiatives lately related to COVID-19. Specifically: The OIG issued a “Message from leadership on minimizing burdens on providers” on March 30, 2020, in which it stated: “For any conduct during this emergency that may be subject to OIG administrative enforcement, OIG will carefully consider the context and intent of the parties when assessing whether to proceed with any enforcement action.” On April 3, 2020, the OIG posted a FAQ website about the application of OIG’s administrative enforcement authorities (specifically, the AKS and beneficiary inducements civil monetary penalty) to arrangements connected to the COVID-19 PHE. This website sets forth instructions for submitting questions and limitations on the FAQs, including how this informal feedback during the unique circumstances of the PHE differs from the legally binding OIG advisory opinion process (which remains available to interested parties). Thus far, the FAQ website has one FAQ posted, in which the OIG responded to a question about whether health care providers/practitioners can furnish services for free or at a reduced rate to assist long-term care providers facing staffing shortages. The OIG stated: “In the unique circumstances resulting from the COVID-19 outbreak, we believe that these scenarios likely would present a low risk of fraud and abuse under the Federal anti-kickback statute and the Beneficiary Inducements CMP provided the services being offered are (i) necessary to meet patient care needs as a result of staffing shortages directly connected to the COVID-19 outbreak; (ii) provided for free or at a reduced cost only when necessary as a result of the COVID-19 outbreak; (iii) limited to the period subject to the COVID-19 Declaration; and (iv) not contingent on referrals for any items or services that may be reimbursable in whole or in part by a Federal health care program, either during or after the COVID-19 Declaration period.” The OIG has a “COVID-19 Portal” website, which includes a link for submitting questions regarding OIG’s authorities during the COVID-19 PHE, as well as links for information about other news and resources regarding OIG’s COVID-19 initiatives. On April 3, 2020, the OIG published a report based on brief phone interviews (or “pulse surveys”) that it conducted from March 23 to March 27, 2020 from a random sample of 323 hospitals across the country on challenges the hospitals are facing in responding to COVID-19, strategies used to address those challenges, and how the government can provide support. A summary of the report can be found here, and the complete report can be found here. Finally, while not related to easing provider burdens during the COVID-19 PHE, we note that on March 23, 2020, the OIG alerted the public about new fraud schemes related to COVID-19. In addition, a number of recently added OIG work plan items relate to COVID-19 response matters. * * * For assistance in determining whether an existing or proposed arrangement meets the criteria for waiving AKS administrative sanctions under the OIG Policy Statement described herein, or for any other questions regarding recent OIG initiatives related to COVID-19, please contact the authors or your regular Dorsey & Whitney LLP attorney. Dorsey is closely monitoring the rapidly evolving legal landscape related to the COVID-19 pandemic. You can access Dorsey’s health law blog related to health law updates, available here. You can also access Dorsey’s coronavirus resource center, which contains a wide variety of legal resources related to the coronavirus outbreak, available here.
April 7, 2020
CMS Guidance
New CMS COVID-19 Blanket Waivers for Health Care Providers
On March 30, 2020, the Centers for Medicare & Medicaid Services (“CMS”) published a compilation of COVID-19 Emergency Declaration Blanket Waivers for Health Care Providers (each, a “Blanket Waiver”). Section 1135 of the Social Security Act gives CMS the authority to issue waivers that ease requirements for providers affected by an emergency if: (1) the President makes an emergency declaration under the Robert T. Stafford Disaster Relief and Emergency Assistance Act, 42 U.S.C. 5121-5207 (the “Stafford Act”); and (2) the Secretary of the Department of Health and Human Services declares a Public Health Emergency (“PHE”), both of which have now occurred in light of COVID-19. CMS is permitted to issue both blanket waivers and provider/supplier requested waivers on a case-by-case basis. Blanket waivers apply to all applicable providers and suppliers, while individual waivers apply only to the requesting provider or supplier. A provider or supplier need not request a provider/supplier-specific waiver of a requirement if CMS has issued a blanket waiver addressing the same requirement. It is important to note that 1135 waivers apply solely to federal requirements and do not apply to state licensure or other requirements. Any applicable state requirements (e.g., licensure) must also be addressed with the relevant state agency. Another important note of caution is that these 1135 waivers often include specific details and requirements. It is critical for health care providers to review the waivers carefully before taking action under them. To that end, providers should visit the CMS Coronavirus Waivers & Flexibilities website, here, to locate the specific guidance and requirements from CMS about the type of program waiver(s) being sought. CMS has provided numerous Frequently Asked Questions (“FAQ”) documents and provider-specific fact sheets that detail the details about and limits of the available waivers and flexibilities for each type of provider (hospital, skilled nursing facility, physicians, laboratories, home health providers, etc.). Additionally, this website contains links to all of the waivers provided in each state. The following is a summary of the Blanket Waivers CMS has made available to providers and suppliers on March 30, 2020. These Blanket Waivers are retroactively effective back to March 1, 2020 and will continue through the end of the emergency declaration. I. Hospital Waivers The Blanket Waivers include significant regulatory relief for hospitals. The following is a summary of the hospital-specific Blanket Waivers, and here is a CMS Fact Sheet that was published for hospitals to further explain these specific Blanket Waivers: a. Temporary Expansion Sites (a.k.a. Hospitals Without Walls) Under this Blanket Waiver, hospitals are permitted to offer health care services in locations that are not currently part of the hospital. Previously, hospitals would have been required to meet Life Safety Code and other regulatory provisions and obtain approvals to provide services in a new location. This waiver will help hospitals set up temporary expansion sites to offer inpatient services (e.g., nursing, room and board) in locations such as shell space in a hospital, parking structures, dormitories and the like – as long as the hospital exercises control and oversees the services provided at the location, and as long as the location is approved by the state (to ensure safety and comfort for patients and staff). CMS is also allowing currently enrolled ambulatory surgery centers (“ASCs”) to temporarily enroll as hospitals by calling the COVID-19 Provider Enrollment Hotline to complete and sign an attestation form in order to enroll and provide services during the PHE as a hospital. CMS also encourages other entities (e.g., freestanding emergency departments which are not currently allowed to enroll in Medicare) to call the COVID-19 Provider Enrollment Hotline to complete and sign an attestation form in order to enroll and provide services during the PHE. Further, CMS is allowing hospitals to change their provider-based locations to address patient needs, as well as allowing additional flexibilities related to inpatient services furnished under arrangements. Moreover, hospitals are permitted to screen patients at locations off of a provider’s campus, in order to avoid the spread of COVID-19. Further, for surge facilities in off campus departments, CMS is waiving the requirements to have policies and procedures for evaluating emergencies so these facilities do not need to focus time on drafting policies and procedures but rather can focus on patient care needs. b. Relaxed Paperwork, Policies, Cost Reporting, Filing Deadlines and Enrollment Requirements For hospitals that are impacted by a widespread outbreak of COVID-19, the timeframes for providing patients a copy of their medical records are waived, as are the requirements related to visitation and seclusion. Additionally, CMS is granting a 30-day post-discharge requirement to complete medical records, CMS is waiving medical records department staffing requirements, and also waiving specific requirements for the form and content of the medical record and the medical record completion requirements. Further, verbal orders can be authenticated more than 48 hours after the fact (although read-back verification is still required). CMS is also waiving requirements to provide information about advanced directives to patients. Further, To ensure that hospitals and critical access hospitals focus on patient care and ensuring patients are discharged in an appropriate setting, as opposed to focusing on the paperwork and other regulatory obligations, CMS is waiving the detailed regulatory paperwork and other requirements related to discharge planning. For example, CMS recognizes that during the PHE, hospitals may not be able to use specific quality metrics and other data, or a comprehensive list of nursing homes in the area, to select a nursing home or home health agency. However, hospitals are still required to work with families to ensure that the discharge meets patients’ care needs. Further, CMS is waiving the entire condition of participation related to utilization review plans and committees, nursing care plans, having available a current therapeutic diet manual, developing and implementing emergency preparedness policies and procedures and communication plans, as well as waiving the detailed provisions governing a hospital’s quality assessment and performance improvement program (although hospitals must still have such a program in place). CMS has established a toll-free hotline for all providers as well as significant flexibilities in provider enrollment. See here for additional information from CMS on provider enrollment relief, as well as our previous blog post on this topic, available here. Further, CMS is waiving the signature and proof of delivery requirements for Part B drugs and durable medical equipment (although the delivery and the fact that a signature could not be obtained due to COVID-19 should be documented in the record). Additionally, CMS is delaying the cost-report filing deadlines until June and July, and CMS is extending the data submission deadlines for hospitals on the reporting of occupational mix of employees until August 3, 2020. Further, Medicare Administrative Contractors (“MACs”), Qualified Independent Contractors (“QICs”), and Independent Review Entities (“IREs”) are allowed to grant extensions to providers on appeals and are permitted to offer other flexibilities on filings and deadlines. c. Critical Access Hospitals (“CAHs”) Without Walls CAHs are now permitted to exceed their 25 bed limit and the 96 hour length of stay limit. CMS is also permitting CAHs to treat patients in urban areas (they typically must be located in a rural area) as needed in order to establish surge locations. Further, CMS is waiving the restrictions on CAHs’ ability to establish off campus provider based locations, and to establish the normally restricted co-location arrangements with other providers. CMS is waiving the minimum personnel qualification requirements at CAHs for clinical nurse specialists, nurse practitioners and physician assistants, and CMS is deferring to the state for the requirements of staff licensure, certification or registration, which will allow more flexibility to CAHs in states where federal requirements are more stringent. d. Distinct Part Units CMS is also now allowing hospitals to house acute care patients in excluded distinct part units (as long as the unit’s beds are appropriate for acute inpatients). Hospitals are permitted to bill for the care provided in the distinct part unit under the Inpatient Prospective Payment System. Providers should annotate in the medical record to explain that the care was provided in the distinct part unit due to capacity issues related to the PHE. Hospitals are also now permitted to provide care in acute care beds and units for patients who would normally be treated in distinct part psychiatric units or distinct part rehabilitation units, as long as the acute beds and units are appropriate for such patients. Hospitals should continue to bill under the Inpatient Psychiatric or Inpatient Rehabilitation Prospective Payment System for those patients, and annotate in the medical record to explain that the care was provided in the acute care unit due to capacity issues or other exigent circumstances related to the PHE. e. Telemedicine CMS is waiving telemedicine restrictions on hospitals and CAHs to make it easier for these providers to provide telemedicine for their patients through agreements with off-site hospitals, in order to improve access to specialty care. f. Workforce CMS is waiving the sterile compounding requirements to allow the re-use of face masks. CMS is also waiving the 2-year reappointment period for medical staff re-credentialing, the requirement that patients in a hospital be under the care of a physician (to allow other practitioners like physician assistants and APRNs to be used to the fullest extent possible), and CMS is waiving the requirement for CRNAs to work under the supervision of a physician. Further, CMS has stated that Hospitals do not have to designate in writing the personnel qualified to perform specific respiratory care procedures or the amount of supervision required for personnel to carry out those procedures. II. Long-Term Care, Skilled Nursing Facilities, and Nursing Facility Waivers The Blanket Waivers provide a number of flexibilities related to nursing services. See here for the CMS fact sheet published specifically for long term care facilities. CMS is waiving the 3-day prior hospitalization requirement for coverage of a skilled nursing facility (“SNF”) stay, waiving the timeframe requirements for certain data submission for SNFs and long-term care (“LTC”) facilities, and allowing nursing homes to suspend pre-admission screening and annual resident review assessments. Certain physical environment requirements are now waived, allowing for expanded use of non-SNF buildings or non-resident rooms in a LTC facility for patients in certain emergency circumstances. To promote social distancing: requirements that residents participate in-person in resident groups are waived; requirements related to room-sharing and moving a resident’s room are waived for the purpose of grouping or separating residents with respiratory illness symptoms and/or residents with a confirmed COVID-19 diagnosis from residents without these symptoms or diagnosis; and physicians and non-physician practitioners may conduct visits through telehealth options when previously the visits were required to be in-person. CMS is also partially waiving training and certification requirements required for nurse aids employed for longer than four months at a facility in order to assist with potential staffing shortages. CMS has waived certain resident transfer and discharge requirements in particular circumstances, though advance notification and receiving facility agreements are generally still required, and related care planning requirements are also waived in certain circumstances. Additionally, CMS is delaying the cost-report filing deadlines until June and July, and CMS is extending the data submission deadlines for hospitals on the reporting of occupational mix of employees until August 3, 2020. Further, Medicare Administrative Contractors (“MACs”), Qualified Independent Contractors (“QICs”), and Independent Review Entities (“IREs”) are allowed to grant extensions to providers on appeals and are permitted to offer other flexibilities on filings and deadlines. III. Home Health, Hospice, ESRD, and DMEPOS Waivers CMS has provided FAQ documents on these waivers for home health, here; for hospice, here; for ESRD Facilities, here; and for DME Suppliers, here. Under the Blanket Waivers, CMS provided extensions for home health, hospice, and ESRD providers to complete certain assessment required for Medicare reimbursement. CMS also waived certain home health, hospice and ESRD in-person assessment, visit, and supervision requirements to reduce the need for ordinary course check-ins and to allow for greater use of telehealth. In addition, hospices are relieved of the requirement to provide non-core hospice services, such as physical therapy, occupational therapy, and speech-language pathology. In providing additional flexibility in timing and in-person visits, CMS’s goal is to support containment efforts for at-risk populations and to free up professional resources to focus on treatment of those infected with coronavirus and to focus on operations related to the pandemic. In addition, CMS is waiving certain routine audits, maintenance, and certification requirements for ESRD Facilities and ESRD Facility staff. Again, CMS is attempting to free up resources and provide flexibility to support providers’ focus on pandemic-related efforts. CMS authorized the establishment of Special Purpose Renal Dialysis Facilities (“SPRDF”) to mitigate transmission among the at-risk population. Such facilities do not require a federal survey to be completed before providing services. CMS is allowing physicians that are appropriately credentialed at a certified dialysis facility to provide care at a “designated isolation location” such as a SPRDF without separate credentialing. Dialysis services may now also be provided in nursing homes and SNFs, so long as the services and necessary equipment and supplies are provided by personnel of the resident’s usual Medicare-certified dialysis facility. In an effort to expedite supply of and reimbursement for DMEPOS, CMS is waiving the replacement requirements (such as the face-to-face requirement, a new physician’s order, and new medical necessity documentation) for DMEPOS that are lost, destroyed, irreparably damaged, or otherwise rendered unusable. DMEPOS suppliers must still provide a narrative description about why the equipment must be replaced. IV. Practitioner Licensure, Provider Enrollment, Appeals, and Medicaid/CHIP Waivers CMS has provided a specific fact sheet describing the waivers and flexibilities available for physicians and other clinicians, available here. The Blanket Waivers are intended to ease the burden on the health system in order to allow providers to focus on patient care. To that end, CMS is temporarily waiving the Medicare reimbursement requirements that out-of-state practitioners be licensed in the state in which they are providing services when they are licensed in another state when the following four conditions are met: The practitioner must be enrolled in Medicare; The practitioner must have a valid license to practice in the state which relates to his or her Medicare enrollment; The services must be furnished, whether in-person or remote via telehealth, in a state in which the emergency is occurring in order to contribute to relief efforts in his or her professional capacity; and The practitioner must not be excluded in any state that is part of the PHE. Please note that the foregoing Medicare reimbursement waiver for licensure does not waive state or local licensure requirements. As a result, providers must review the state licensure requirements in each jurisdiction prior to delivering telehealth to patients in that location. Please see the blog post we published on this topic of telehealth opportunities here. Additionally, CMS has taken a number of steps to ease the provider enrollment requirements. See here for additional information from CMS on provider enrollment relief, as well as our previous blog post on this topic, available here. CMS has set up a hotline for physicians and non-physician practitioners to enroll and receive temporary Medicare billing privileges. Additionally, CMS has taken the following steps to facilitate the enrollment of providers in the wake of the COVID-19 outbreak, including: Waiver of certain screening requirements, including application fees, background checks, and site visits; Postponement of revalidation actions; Allowing licensed providers to render services outside their state of enrollment; Expediting pending or new applications; Easing telehealth restrictions; and Allowing physicians and non-physician practitioners to terminate opt-out status early and enroll in Medicare. Regarding appeals, the new waivers grant broad powers to MACs, QICs, and IREs to relax the requirements of federal regulations regarding the appeals process in FFS, and Parts C and D. MACs, QIEs, and IREs are instructed to allow extensions to file an appeal and to permit the waiver of requests for timeliness requirements for additional information to adjudicate appeals. MACs, QICs, and IREs are now allowed to process an appeal even with incomplete Appointment of Representation forms as outlined in federal regulations. Additionally, MACs, QICs, and IREs can now process appeals that do not meet the required elements of those same federal regulations. MACs, QICs, and IREs are given broad flexibility with respect to other parts of the appeals process so long as good cause requirements are satisfied. Finally, regarding Medicaid and CHIP, the new waivers permit states to request approval that certain statutes and implementing regulations be waived under section 1135. To request such an approval, states may submit an 1135 waiver request directly to their Center for Medicaid and CHIP Services (CMCS) state lead or Jackie Glaze, Acting Director, Medicaid and CHIP Operations Group, Center for Medicaid and CHIP Services at CMS by e-mail (Jackie.Glaze@cms.hhs.gov) or by letter. CMS sets forth a number of examples of the kinds of requests that states can make under this waiver, including: Waiver of prior authorization requirements for FFS programs; Waiver of out-of-state requirements for providers to provide care to another state’s Medicaid enrollees impacted by COVID-19; Temporary suspension of provider enrollment and revalidation requirements to increase access to care; Temporary waiver of state licensure requirements; Temporary suspension of requirements for pre-admission and annual screening requirements for nursing home residents. CMS encourages states to assess their needs and take advantage of these waivers. To assist states with the waiver request process and provide additional guidance, CMS released the Medicaid and CHIP Disaster Response Toolkit, which can be found here. Further, the CMS Coronavirus Waivers & Flexibilities website, here, contains a link to each state’s request for waivers and the responses from CMS. V. Stark Waivers On the same date, CMS also issued much-anticipated Blanket Waivers of sanctions under the federal physician self-referral law, or “Stark Law,” for “COVID-19 Purposes.” These Blanket Waivers are set forth here. Please see our separate post, available here, with detailed information about these Stark Law Blanket Waivers. * * * If you have questions about the new CMS waivers, please contact the authors or your regular Dorsey & Whitney LLP attorney. Dorsey is closely monitoring the rapidly evolving legal landscape related to the COVID-19 pandemic. You can access Dorsey’s health law blog related to health law updates, available here. You can also access Dorsey’s coronavirus resource center, which contains a wide variety of legal resources related to the coronavirus outbreak, available here.
April 2, 2020
CMS Guidance
Stark Law Blanket Waivers Related to “COVID-19 Purposes” Announced
The COVID-19 pandemic has led to rapid and drastic changes to health care delivery in the United States, including as it relates to arrangements between health care providers and physicians that may implicate the federal physician self-referral law, or “Stark Law.” On March 30, 2020, the Centers for Medicare & Medicaid Services (“CMS”) issued much-anticipated nationwide blanket waivers of sanctions under the Stark Law for “COVID-19 Purposes” (the “Stark Blanket Waivers”), which are available here. The Stark Blanket Waivers have a retroactive effective date of March 1, 2020 and will continue through the end of the Public Health Emergency (“PHE”) that was declared related to the COVID-19 outbreak. The Stark Blanket Waivers, which were issued under Section 1135 of the Social Security Act, permit numerous flexibilities to ensure that: “(1) sufficient health care items and services are available to meet the needs of individuals enrolled in the Medicare, Medicaid, and CHIP programs; and (2) health care providers . . . that furnish such items and services in good faith, but are unable to comply with one or more of the specified requirements of [Stark] as a result of the consequences of the COVID-19 pandemic, may be reimbursed for such items and services and exempted from sanctions for such noncompliance, absent the government’s determination of fraud or abuse.” These flexibilities provide welcome relief for health care providers that are facing much uncertainty and overwhelm in this time of rapid and drastic change. Stark is a strict liability law with very significant civil penalties and prohibitions on billing the Medicare program associated with its violation. However, during the PHE, CMS will reimburse for services provided pursuant to referrals that would otherwise violate Stark, and will not impose penalties, as long as the Stark Blanket Waivers are followed. It is important to keep in mind that each Stark Blanket Waiver is limited to the specific circumstances described in the waiver. Health care providers are required to satisfy every condition of the Stark Blanket Waiver in order to take advantage of it, so special attention should be paid to the requirements. CMS cautioned that any remuneration described in the Stark Blanket Waivers must be directly between the entity and: (1) the physician or the physician organization in whose shoes the physician stands under 42 C.F.R. § 411.354(c); or (2) the immediate family member of the physician. Further, CMS cautioned that the remuneration and referrals described in the Stark Blanket Waivers must be solely related to “COVID-19 Purposes.” CMS specifies that “COVID-19 Purposes” means, for purposes of the Stark Blanket Waivers: Diagnosis or medically necessary treatment of COVID-19 for any patient or individual, whether or not the patient or individual is diagnosed with a confirmed case of COVID-19; Securing the services of physicians and other health care practitioners and professionals to furnish medically necessary patient care services, including services not related to the diagnosis and treatment of COVID-19, in response to the COVID-19 outbreak in the United States; Ensuring the ability of health care providers to address patient and community needs due to the COVID-19 outbreak in the United States; Expanding the capacity of health care providers to address patient and community needs due to the COVID-19 outbreak in the United States; Shifting the diagnosis and care of patients to appropriate alternative settings due to the COVID-19 outbreak in the United States; or Addressing medical practice or business interruption due to the COVID-19 outbreak in the United States in order to maintain the availability of medical care and related services for patients and the community. There are eighteen Stark Blanket Waivers. It is critical to know that each waiver is specific in its requirements and application, so health care providers should not rely on this summary in order to use a Stark Blanket Waiver. Instead, providers should carefully review the details of each waiver prior to making a decision to proceed with an arrangement in reliance on a waiver. A few of the Stark Blanket Waivers are briefly summarized as follows: Remuneration to a physician that is above or below fair market value for services personally performed by the physician. Rental charges paid to a physician that are below fair market value. Remuneration to a physician in the form of medical staff incidental benefits or non-monetary compensation that exceeds the limits set forth in applicable Stark regulations. Loans to a physician with below fair market value interest rates or on terms that are not available from a traditional lender. Referrals by a physician owner of a hospital that temporarily expands its facility capacity above its baseline number without prior application and approval of the facility expansion as required under Stark. Referrals by physicians in a group practice in a location that does not qualify as the “same building” or “centralized building” as typically required under Stark. Referrals by a physician to an entity with which the physician has a compensation arrangement that does not satisfy the writing or signature requirements of the applicable Stark exception, as long as all of the other requirements of the exception are met (unless the other requirements have been waived under one or more of the Stark Blanket Waivers). While no data or notification is required to be submitted to CMS in order to use the Stark Blanket Waivers, parties seeking to utilize the Stark Blanket Waivers should develop and retain records related to the use of the waivers in order to support the fact that the decision to use the waivers was for COVID-19 Purposes, and to document that each requirement of the waiver was satisfied. These records must be made available to the Secretary of the Department of Health and Human Services upon request. At the end of the document setting forth the Stark Blanket Waivers, CMS provided two pages of examples of the application of the Stark Blanket Waivers. CMS clarified that unless a Stark Blanket Waiver expressly applies only to a specific type of entity (e.g., a home health provider), then the examples that CMS provided which reference a hospital would apply to any entity that furnishes designated health services. Finally, CMS provided the email address for individuals to use to submit inquiries about the blanket waivers, available here: 1877CallCenter@cms.hhs.gov. We note that individual waivers of sanctions under the Stark Law are still available and may be granted upon request submitted to the email address noted above. Such individual waiver requests are a good option for a party to consider if an existing or proposed arrangement does not appear to qualify for a Stark Blanket Waiver (or an existing Stark exception). * * * For assistance in determining whether an existing or proposed arrangement complies with a Stark Blanket Waiver and/or for inquiries regarding individual waiver requests, please contact the authors or your regular Dorsey & Whitney LLP attorney. Dorsey is closely monitoring the rapidly evolving legal landscape related to the COVID-19 pandemic. You can access Dorsey’s health law blog related to health law updates, available here. You can also access Dorsey’s coronavirus resource center, which contains a wide variety of legal resources related to the coronavirus outbreak, available here.
April 2, 2020
coronavirus
CARES Act Summary of Provisions that Support America’s Health Care System
On March 27, 2020, the President signed into law the “Coronavirus Aid, Relief, and Economic Security Act’’ (“CARES Act”). The CARES Act is the third phase of the federal government’s response to the coronavirus following two other laws to support American families and address health sector needs that were approved on March 6, 2020 (Phase I here) and March 18, 2020 (Phase II here). The CARES Act includes provisions which provide cash payments and other resources to help individuals, small businesses, state and local governments and hospitals/healthcare providers. The CARES Act includes four sections (called “Titles”) and each title addresses a different topic. This e-update summarizes Title III of the CARES Act titled “Supporting America’s Health Care System in the Fight Against the Coronavirus”. Title III provides much needed financial assistance to the health care industry, as well as additional guidance and other provisions which provide information on waivers and other benefits to help hospitals and others who are on the front lines of fighting the COVID-19 pandemic. The following is a summary of the major provisions of Title III, organized in order by section numbers under the CARES Act but does not address subtitle B – Education Provisions and subtitle C – Labor Provisions. We will provide links to summaries of other provisions in the CARES Act prepared by our colleagues throughout the firm as they become available. Click here to read the summary.
March 27, 2020

