Dorsey Health Law
coronavirus
Biden Administration Orders Long Term Care Facilities to Require COVID-19 Vaccinations To Receive Federal Funds; OSHA Issues Updated COVID-19 Recommendations For All Workplaces
As we have previously written, the landscape for employers in the time of COVID-19, particularly health care employers and long term care facilities, is ever-changing and quickly moving. In the last year, health care employers have had to navigate state laws, Centers for Disease Control and Prevention (“CDC”) and Centers for Medicare & Medicaid Services (“CMS”) guidance, EEOC guidelines, as well as compliance with a complex Emergency Temporary Standard (“ETS”) issued by the Occupational Safety and Health Administration (“OSHA”). In the midst of all that, health care providers have grappled with whether to implement policies requiring COVID-19 vaccinations for employees absent a religious or medical exemption. In Iowa, Unity Point Health, Sanford Health, MercyOne, Genesis Health System, and Trinity Health will require employees to be vaccinated for COVID-19 in the next few weeks and months. This includes long term care facilities administered by those entities. In a somewhat unexpected twist, the Biden Administration announced today that CMS and the CDC are “developing an emergency regulation requiring staff vaccinations within the nation’s more than 15,000 Medicare and Medicaid-participating nursing homes.” According to the announcement, a rule is expected in the coming weeks. The Administration’s order will surely generate multiple lawsuits challenging the legality of the mandate. We estimate that those lawsuits will likely not be successful, in part based how quickly similar lawsuits against hospital employers have been dismissed by courts across the country. For example, this summer a court swiftly dismissed a lawsuit filed by employees of Houston Methodist hospital challenging the hospital’s COVID-19 vaccine mandate. Last week, in addition to the OSHA ETS for healthcare employers published on June 21, 2021, OHSA issued new recommendations for all employers with a specific focus on protecting unvaccinated workers. To combat the continued spread of COVID-19, OSHA recommends that employers do the following: Assist employees in getting vaccinated for COVID-19, including paid time off to get and recover from vaccines. Some employers can receive tax benefits for voluntarily paying employees under these and other circumstances. Remove employees with known or suspected COVID-19 exposure from the workplace for either 14 days or until the employee receives a negative test result. Make sure that unvaccinated and high risk employees physically distance from others, limit the number of unvaccinated and high risk employees at one place at any given time, allowing remote working for unvaccinated and high risk employees, and installing transparent barriers when physical distancing is not feasible. Require employees to wear masks indoors (unless other PPE is otherwise required for the job), and provide face coverings to employees who do not have their own. Educate employees on workplace COVID-19 policies and procedures, including providing materials in multiple languages as needed. Suggest that unvaccinated customers, vendors, visitors, or other guests wear a mask. Maintain properly working ventilation systems. Follow CDC guidelines regarding cleaning and disinfection. Record and report workplace infections and deaths related to COVID-19. Implement policies and procedures to ensure that employees who raise concerns about COVID-19 in the workplace are not subject to retaliation. Follow any other applicable mandatory OSHA standards. In sum, OSHA recommends that, for the most part, all employers follow the requirements set forth for healthcare providers in the ETS. We want to help all employers keep their employees safe and protected from COVID-19, and we want to help you do your part to prevent the spread of the virus. If you have any questions about what you are required by law to do in your workplace, or what is not required but recommended, please contact a qualified employment and healthcare attorney.
August 18, 2021
Health Insurance
HHS Gives Guidance to Providers on the No Surprises Act in Interim Final Rule
Overview On July 1, 2021, the Department of Health and Human Services (HHS), along with other federal agencies, released an interim final rule implementing certain provisions of the No Surprises Act.[1] The No Surprises Act aims to protect health plan participants and beneficiaries from surprise medical bills when they receive items and services in certain settings from out-of-network providers and health care facilities. The rule will be enforced beginning January 1, 2022. The rule includes requirements applicable to: (1) group health plans and health insurance issuers that offer group or individual health insurance coverage; (2) certain types of health care providers; and (3) health benefit plans offered by carriers under the Federal Employees Health Benefits Act. This article will focus on provider requirements under the new rule. Provider Requirements Under the Interim Final Rule Under the No Surprises Act, nonparticipating providers, facilities, and air ambulance providers are prohibited from balance billing individuals. This means that the nonparticipating provider, facility, or air ambulance provider may not bill an individual for a dollar amount that exceeds the individual’s in-network cost-sharing obligations. A nonparticipating provider is any physician or other health care provider acting within the scope of their licensure under applicable state law and who does not have a contractual relationship with the health plan or health insurance issuer. The balance billing prohibition applies to the following health care services: (1) emergency services provided by a nonparticipating provider or nonparticipating emergency facility; (2) non-emergency services provided by a nonparticipating provider at a participating health care facility; and (3) air ambulance services furnished by a nonparticipating air ambulance service provider. For purposes of the balance billing prohibition for non-emergency services provided by a nonparticipating provider at a participating health facility, a participating health care facility is a hospital, hospital outpatient department, critical access hospital or ambulatory surgical center that has a direct or indirect contractual relationship with the health plan or health insurance issuer with respect to the item or service furnished. Any participants, beneficiaries, or enrollees in a group health plan or group or individual health insurance coverage offered by an issuer, including Federal Employees Health Benefits beneficiaries, are covered by the rule’s protections. Disclosure Requirements The No Surprises Act requires providers, facilities, plans and issuers to disclose the patient protections against balance billing to individuals. Per the interim final rule, the disclosure must: (1) contain clear and understandable language of the protections, including how to contact federal and state agencies for suspected violations; (2) be provided within the required time frame, and (3) comply with federal civil rights laws regarding communication and language barriers. Air ambulance service providers are exempt from the disclosure requirements. For providers and facilities, the deadline for providing disclosure depends on the circumstances. If an appointment is scheduled at least 72 hours before the date of the appointment, then disclosure must be made no later than 72 hours prior to the date of appointment. If an appointment is schedule within 72 hours of the appointment, disclosure must be provided on the same date as, and at least three hours prior to, the appointment. Disclosure must be provided via three channels: Public location. Providers must post the required disclosure in a prominent, central location where services are provided, such as near a scheduling or check-in desk. Public website. The public website disclosure must be searchable and accessible free of charge and without any login or personal information inputting requirements. Providers and facilities that do not have a website are exempt from this requirement. One-page notice. Individuals must be provided with a one-page notice of the disclosure. The notice must have a minimum of 12-point font, and it may be double-sided. Provider Exception To prevent duplicate disclosure notices to individuals, HHS created an exception to the disclosure requirement for providers. If a provider furnishes items or services covered by the plan or coverage at a facility, including hospital emergency departments and independent freestanding emergency departments, it satisfies the disclosure requirements if the facility agrees in writing to provide the required disclosure on behalf of the provider. This is available regardless of whether the provider and facility bill jointly or separately. If the facility fails to provide proper disclosure under the written agreement, the facility, not the provider, is in violation of the rule. Notice and Consent Exception Under the No Surprises Act, the prohibition on balance billing does not apply if notice is given to an individual, and the individual consents to waiving balance billing protections with respect to the providers and/or facilities named in the notice. What to Include Providers and facilities are required to use the standard notice and consent forms that will be issued by HHS for this exception to apply. These forms must be tailored to include certain specific information, including (1) the out-of-network providers and/or facilities to which it applies, and (2) a good-faith cost estimate for the applicable items or services. The notice, and subsequent consent, will only be valid for those providers and/or facilities named in the notice. How to Provide Notice The notice and consent documents must be given to the individual together, and they must be physically separate from, and not attached or incorporated into, any other documents. The documents may be given electronically if the individual so chooses. Additional Details Like the disclosure requirements, the notice and consent forms must meet language access and timing requirements specified by the rule. The individual may revoke their consent at any time prior to the furnishing of the relevant items or services by notifying the provider/facility in writing. Providers and facilities may refuse to treat individuals who do not consent, subject to other state and federal laws. Exceptions to the Exception In the following circumstances, the notice and consent exception is unavailable, and the balance billing prohibition always applies: Where notice is received by the individual, but consent is either not given or is revoked; Emergency services; Post-stabilization services, unless certain conditions are met; Air ambulance services; Items or services furnished as a result of unforeseen, urgent medical needs that arise at a time an item or service is furnished for which notice and consent was received; and Ancillary services, such as anesthesiology, pathology, radiology, and neonatology, whether provided by a physician or a non-physician practitioner. Penalties HHS may impose civil monetary penalties of up to $10,000 per violation on providers and facilities that violate the balance billing prohibition requirements. However, these penalties may be waived if a provider or facility unknowingly violates the statute and should not have reasonably known that it did so, and within 30 days withdraws the bill in violation and reimburses the plan or individual for the difference between the amount billed and the correct billable amount, plus interest. Conclusion The final interim rule makes clear that beginning January 1, 2022, providers and facilities must address the disclosure and balance billing prohibitions in the No Surprises Act. While this article is not meant to encompass all of the details, it offers providers an overview of what these expectations are and what measures must be taken to comply with the rule. If you have questions regarding the No Surprises Act, please contact the authors or any member of Dorsey’s Health Transactions and Regulations practice group. [1] Office of Personnel Mgmt. et al., Requirements Related to Surprise Billing; Part I, at *2 (2021). Summer Associate Hannah McCallum provided substantial assistance researching and drafting this article.
August 2, 2021
Centers for Medicare and Medicaid Services
Living in a Virtual World: The Post-Pandemic Future of Telehealth
The COVID-19 pandemic required health care providers of all sizes to make drastic changes to the mode of patient care delivery. Telehealth quickly emerged as a safe alternative to in-person patient visits, and many providers quickly transitioned to virtual services. The pandemic-initiated expansion of telehealth was rapid and significant, but the pandemic likely accelerated existing trends more than creating new ones. The increased availability of telehealth has offered patients greater access levels and types of care that would otherwise be difficult to obtain due to geography, limited appointment availability, or affordability. Despite the increased access to care and positive experiences with telehealth over the past year and a half, many regulatory actions temporarily enabling the use of telehealth services have expired or will end in the coming months. What does the post-COVID future hold for tele health? Health care industry leaders are tracking the following developments: Licensing State professional licensure laws are major obstacles for telehealth providers wanting to offer telehealth services as an option for patients who reside or are otherwise located in other states. State laws governing the practice of medicine, nursing, social work, and other health professions generally require the provider furnishing care to be licensed in the state where the patient is located. At the beginning of the pandemic, the spike in demand for virtual care led states to quickly take action to loosen or waive professional licensure requirements. Many states allowed out-of-state health care providers of all types to provide telehealth services to their residents, including Hawaii, Idaho, and Vermont. States such as Illinois and Maryland permitted telehealth practice only where a provider had a pre-existing relationship with the patient, and others only relaxed requirements for physicians or mental health providers, such as in Minnesota. Post-pandemic, we expect to see continued efforts to remove licensing barriers faced by telehealth providers. Several states have enacted the Interstate Medical Licensure Compact or have entered into cross-border licensure waiver agreements with neighboring states, but these waiver agreements may only apply to certain practitioners or involve slow, costly application processes. Some states may follow the approach taken in Florida and Georgia, where health care providers can obtain a “telemedicine license” with less burdensome requirements. Action on the federal level is also possible. In response to COVID-19, the Centers for Medicare & Medicaid Services (“CMS”) temporarily waived the Medicare requirement that providers be licensed in the state they are delivering telemedicine services when practicing across state lines, subject to certain conditions. While this waiver does not exempt providers from licensure requirements under state law, subsequent action taken at the federal level may set a trend followed by state governments. Providers should also be aware of existing state laws permitting the practice of telehealth across state lines when an existing patient is on vacation or attending college in another state. For example, in Minnesota, out-of-state physicians are exempt from licensure requirements if only providing telehealth services on an “irregular or infrequent basis” as defined in Minn. Stat. § 147.032. And Colorado allows non-Colorado-licensed health care providers to provide occasional services or consultation via telehealth to patients in Colorado as long as they meet certain requirements, such as maintaining certain levels of insurance, not maintaining an office in the state, and not informally or formally agreeing to provide care on a regular or routine basis. See Colo. Rev. Stat. § 12-240-107. Reimbursement Before the pandemic, reimbursement options for telehealth were limited and low payment rates were a significant financial burden for providers seeking to provide telehealth services. As we described in a previous blog post, CMS implemented sweeping changes to Medicare reimbursement and coverage requirements at the start of the COVID-19 outbreak. Dozens of new services were added to the list of telehealth services covered by Medicare, restrictions on geography and originating sites were removed, and payment rates for telehealth services were raised to match the rates for the same in-person service. On July 13, CMS released its annual proposed rule for payments under the Medicare Physician Fee Schedule, which would make many temporary Medicare flexibilities for mental and behavioral health services permanent. If finalized, the rule would allow beneficiaries to receive such telehealth services from home, reimburse providers for audio-only services, and keep certain recently added services on the Medicare telehealth list through December 31, 2023. The rule would require an in-person visit within six months prior to an initial telehealth service and at least once every six months thereafter, but CMS is seeking input on whether a different interval may be necessary or appropriate. The agency is also soliciting comment on: Whether additional documentation should be required in the patient’s medical record to support the clinical appropriateness of audio-only telehealth; Whether or not audio-only telehealth for particular high-level services should be covered; and What additional guardrails should be put in place in order to minimize concerns about program integrity and patient safety. Several states have passed or proposed payment parity legislation that would permanently require insurance coverage and/or reimbursement for certain telehealth services at a level equal to in-person visits. For example, legislation was recently enacted in Oklahoma requiring payment parity for all telemedicine services. In states like Georgia and California, laws require equal coverage for both virtual and in-person services, but allow payers and providers to negotiate alternate payment rates. A recent Connecticut law requires payment parity for telehealth services under its state Medicaid program, and a Massachusetts law mandates payment parity for behavioral health services. Privacy In response to the pandemic, the Office for Civil Rights (“OCR”) announced several telehealth flexibilities to allow providers to care for patients remotely during the pandemic. OCR announced it would not impose penalties on providers for noncompliance with certain HIPAA obligations in connection with their “good faith provision of telehealth” using any non-public communication platform, such as FaceTime or Zoom. Given increasing concerns about cybersecurity and privacy risks, we expect continued discussions at the federal and state level about how to safeguard patient’s health information while allowing continued access to telehealth services. Providers should conduct a comprehensive risk assessment of its privacy and security protections and vendor agreements to ensure all telehealth technologies and IT systems comply with HIPAA standards. Conclusion The COVID-19 pandemic has profoundly changed the health care delivery landscape. As emergency orders end and regulatory flexibilities expire, policymakers at the state and national level are considering how best to regulate telehealth post-pandemic. Telehealth services ease the burden of obtaining quality healthcare services for medically underserved populations, including communities of color, people with disabilities, and residents of rural areas. Telehealth also gives patients the opportunity to conveniently obtain routine and preventative care, which could positively impact health outcomes and improve health equity. Dorsey attorneys are closely monitoring federal and state actions regarding telehealth. For more information on how to navigate the existing legal landscape and prepare for future developments, contact the authors or your regular Dorsey attorney.
July 28, 2021
SCOTUS ACA Ruling Allows Employers to Consider Improvements
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Steve Lucke, Melinda Maher, and Meredith Gingold for the following article: SCOTUS ACA Ruling Allows Employers to Consider Improvements Reproduced with permission. Published Jul. 7, 2021. Copyright 2021 by The Bureau of National Affairs, Inc. (800-372-1033) http://www.bloombergindustry.com
July 26, 2021
Anti-Kickback
SCOTUS Denies Review of Dismissal at DOJ’s Request; Circuit Split Remains
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Christopher DeLong for last week's FCA Now blog post: On June 28, 2021, the United States Supreme Court denied review of a Seventh Circuit decision affirming the Department of Justice (“DOJ”)-requested dismissal of a False Claims Act (“FCA”) suit alleging a drug kickback scheme. Cimznhca LLC v. United States, No. 20-1138, 2021 U.S. LEXIS 3404 (June 28, 2021). As a result, the circuit split regarding the standard that applies to a Government’s motion to dismiss an FCA action remains unresolved. To continue reading, click here.
July 9, 2021
coronavirus
Update Regarding Publication of OSHA Emergency Temporary Standard
On June 10, 2021, Dorsey’s Labor & Employment attorneys outlined an Emergency Temporary Standard (“ETS”) issued by OSHA. At the time, the ETS was not an official regulation because it had not yet been published in the Federal Register. On June 21, 2021, the ETS was published and, for covered healthcare employers, the compliance clock started ticking. As a refresher, the ETS applies to “all settings where any employee provides healthcare services or healthcare support services.” 1910.502(a)(1). Broadly, the following activities are exempted from coverage: the provision of first aid by an employee who is not a licensed health care provider; the dispensing of prescriptions by pharmacists in retail settings; non-hospital ambulatory care settings where all non-employees are screened prior to entry and people with suspected or confirmed COVID–19 are not permitted to enter those settings; well-defined hospital ambulatory care settings where all employees are fully vaccinated and all non-employees are screened prior to entry and people with suspected or confirmed COVID–19 are not permitted to enter those settings; home health care settings where all employees are fully vaccinated and all non-employees are screened prior to entry and people with suspected or confirmed COVID–19 are not present; health care support services not performed in a health care setting (e.g., off-site laundry, off-site medical billing); or telehealth services performed outside of a setting where direct patient care occurs. In addition, for covered employers, ETS requirements regarding masking, physical barriers, and physical distancing do not apply to fully vaccinated employees in well-defined areas where there is no reasonable expectation that any person with suspected or confirmed COVID–19 will be present. 1910.502(a)(2)(i)-1910.502(a)(4). As to employee vaccinations, the ETS specifically contemplates that there may be medical conditions, disabilities, or religious reasons employees cannot be vaccinated. Employers are reminded in the ETS guidance that they should make exceptions where appropriate. We discussed EEOC guidance regarding employee vaccinations in a previous blogpost. Except for requirements regarding physical barriers, ventilation, and training, employers must comply with the ETS mandates by July 6, 2021. Employers must become compliant with the physical barrier, ventilation, and training requirements by July 21, 2021. When OSHA first issued the ETS, little direction was available directly from OSHA in terms of how employers could comply with the ETS’s many mandates. Since publication of the ETS in the Federal Register, OHSA has fortified existing resources and added new ones. Employers should visit OSHA's ETS website for Fact Sheets, FAQs, Notification Removal and Return to Work Flow Charts for both Employers and Employees, Employee Training Presentations, and more. Further, it is important to understand how the new OSHA regulations interact with already existing guidance on similar COVID-19 related topics for health care providers which have been published by other federal and state agencies, such as the Centers for Medicare and Medicaid Services and the Centers for Disease Control and Prevention. In most cases, the various guidance and regulations do not conflict, but a careful review of all related laws and agency guidance is prudent, in order to fully understand the rules that apply in a given situation, especially when there is a conflict. A qualified employment lawyer can assist employers with matters such as developing their COVID-19 Plan, planning the Workplace Hazard assessment, and conducting training; all things which are required by the ETS. Please contact the author of this blog post or your regular Dorsey & Whitney labor and employment attorney with further questions about how to come into compliance with the new OSHA guidance by the July 6 and July 21 deadlines.
June 23, 2021
False Claims Act
Eight Years Later: “Speculative” and “Straightforward” FCA Allegations Against Walmart Dismissed
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Donna Reuter from Dorsey’s FCA Now blog for today’s post: Walmart successfully ended eight years of protracted litigation under the False Claims Act (“FCA”) on June 4, 2021, when the Sixth Circuit affirmed dismissal of Medicare and Medicaid fraud allegations against the major retailer. The case was first filed in February 2013. See United States ex rel. Sheoran v. Wal-Mart Stores E., No. 13-10568, 2019 U.S. Dist. LEXIS 140710, at *2 (E.D. Mich. Aug. 20, 2019). The case was originally filed by Ashwani Sheoran, a former Walmart pharmacist. (Read more here.)
June 21, 2021
COVID-19
OSHA Issues COVID-19 Workplace Safety Rule for Healthcare Employers
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Rebecca Bernhard, Aaron Goldstein and Alyson Dieckman for the following e-newsletter update: OSHA Issues COVID-19 Workplace Safety Rule for Healthcare Employers On June 10, 2021, the Occupational Safety and Health Administration (“OSHA”) released the first nationwide workplace safety rule in response to the COVID-19 pandemic. OSHA’s guidance is only binding on healthcare employers. OSHA reported that it will issue supplemental voluntary guidance for other industries. (Read more here.)
June 11, 2021
coronavirus
Considerations for Health Care Employers under Iowa’s Vaccine Passport Law and Recent CDC, CMS and EEOC Guidelines
One of the last pieces of legislation the Iowa legislature sent to Governor Kim Reynolds’ desk for guaranteed signature was a bill banning vaccine passports in Iowa. House File 889 contains several prohibitions regarding inquiries into a person’s COVID-19 vaccine status. For entities that contract with the state government or otherwise receive state funding, the law contains financial consequences for a violation (but is silent as to penalties for others). While the law contains clear proscriptions, it also has notable explicit and implicit exclusions. Healthcare providers, and nursing home facilities specifically, have additional considerations under recently released CMS, CDC and OSHA guidance. All employers have considerations under state and federal anti-discrimination laws and updated EEOC technical assistance. Iowa Law Iowa’s law prohibits the designation of COVID-19 vaccine status on state or political subdivision-issued identification cards. That means there will be no COVID-19 notations on Iowa drivers’ licenses anytime soon. The law also forbids businesses or governmental entities from requiring customers, patrons, clients, patients, or other persons invited onto the premises (“invitees”) to show proof of a COVID-19 vaccine. However, the law does not list employees in the category of people who are protected from having to show proof of a COVID-19 vaccine. Therefore, under Iowa law, employers can legally require employees to show proof of a COVID-19 vaccine as a condition of employment. Further, the law explicitly excludes healthcare facilities from the definition of a business or a governmental entity. Healthcare facilities include hospitals and other licensed inpatient centers, ambulatory surgical or treatment centers, skilled nursing centers and nursing facilities, residential treatment centers, diagnostic, laboratory and imaging centers, rehabilitation and other therapeutic health settings, and intermediate care facilities for people with mental illness or intellectual disabilities. CDC, CMS and OSHA Guidance On April 27, 2021, the Centers for Disease Control and Prevention (CDC) published updated health care infection prevention and control recommendations following the wide availability of COVID-19 vaccination, available here. The CDC guidance includes updated COVID-19 testing recommendations, updated visitation guidance for health care facilities, and additional guidance for communal activities and dining in healthcare settings. Shortly thereafter, on May 11, 2021, CMS published updated guidance for long term care (LTC) facilities, called an interim final rule. That rule, available here, focuses on COVID-19 vaccination education, consent, and refusal, as well as the procedures LTC facilities must follow in offering vaccinations to employees and residents. It also includes recordkeeping requirements. The guidance is silent regarding whether LTC facilities can require employee or resident vaccinations, instead simply stating, “[f]acilities should follow state law and facility policies with respect to staff refusal of vaccination.” In Iowa, that means long term care facilities could choose to require all staff and residents to be vaccinated. On June 10, 2021, OSHA published the first guidance for employers governing workplace safety rules related to COVID-19, which applies only to employment settings where employees provide healthcare services or healthcare support services in a healthcare setting. The new OSHA rules are entitled, the “COVID-19 Healthcare Emergency Temporary Standard”, and they are available here. FAQs regarding the new regulations were published by OSHA and are available here. The scope of this article does not cover the new OSHA COVID-19 Healthcare Emergency Temporary Standard because Dorsey attorneys published a separate article on this new guidance including practical tips for its implementation, which is available here. EEOC Guidance Health care facilities adopting COVID-19 vaccination requirements should be mindful of state and federal anti-discrimination laws such as the Iowa Civil Rights Act (ICRA) and the Americans with Disabilities Act (ADA). Both the ICRA and the ADA prohibit employers and places of public accommodation from discriminating against people on the basis of their religion or disability, among other things. Public accommodations include, but are not limited to places that offer services, facilities, or goods for a fee or charge. To name a few, a person’s health condition could prohibit them from getting a COVID-19 vaccine, a person’s religion might prohibit vaccinations, a person may be reluctant to get the vaccine while pregnant, and data has shown that minority communities disparately have lower vaccination rates. Health care facilities mandating vaccines could run into legal issues if they are unwilling to make exceptions in certain circumstances. Additionally, on May 28, 2021, the EEOC updated its technical guidance regarding whether employers can provide COVID-19 vaccine incentives for employees in a technical assistance Q&A, available here. The EEOC guidance echoes the considerations above, noting that employers must take care not to run afoul of state and federal employment laws when making decisions about vaccine requirements. The guidance also states the vaccine incentives cannot be coercive, and that employers must keep vaccine information confidential. Practical Tips and Take Aways In light of the ever-changing status of employment and health laws and guidance related to COVID-19, healthcare facilities drafting or updating policies related to COVID-19 mitigation should consult with their employment and health care counsel to make sure the policies are consistent with Iowa’s vaccine passport law, state and federal employment laws and technical assistance, and any recent CDC and CMS publications. That said, the following tips may help to guide health care facilities’ development of employment-related COVID-19 policies and procedures: Healthcare employers, particularly LTC facilities, considering mandating the COVID-19 vaccine for employees should also think about the impact such a mandate might have on the available workforce. With data suggesting that only about half (or less) of Iowa’s LTC facility employees are fully vaccinated, employers might see crippling staff shortages if they start making the COVID-19 vaccination a condition of new or continued employment. Healthcare employers seeking to increase their workforce’s COVID-19 vaccination rates could come up with ways to fairly incentivize employees, consistent with the recent EEOC technical assistance. Regardless of the type of vaccine, if employers choose to require vaccinations as a condition of employment, they should remember to keep all vaccination information confidential pursuant to the ADA. If employers believe that a lack of convenient access is a contributing factor to low employee COVID-19 vaccine rates, employers could consider holding vaccine clinics consistent with the CMS guidance described and linked above. Employers who do choose to hold vaccine clinics or otherwise make the COVID-19 vaccine available to employees at work should be cognizant of their workforce and adjust accordingly. For example, employers should think about whether informational materials should be offered in languages other than English and whether some of the people administering vaccines should be bilingual. Healthcare employers which are covered under the new OSHA COVID-19 Healthcare Emergency Temporary Standard referenced above (generally, those with 10 or more employees) should ensure that the company’s written COVID-19 plan incorporates all of the elements required under the new COVID-19 Healthcare Emergency Temporary Standard, including providing reasonable time off and paid leave for vaccinations and vaccine side effects for employees. For more information on the new OSHA standards, see a separate post by our Dorsey colleagues, available here. Prior to taking any adverse action against an employee related to that person’s COVID-19 vaccination status, or any other conduct pertaining to COVID-19, employers should seek guidance from a knowledgeable employment law attorney. As described in an earlier blog post, COVID-19 related lawsuits against employers are on the rise (including in Iowa), and employers need to be proactive in ensuring their decisions are consistent with the ever-changing legal landscape on these issues.
June 10, 2021
Anti-Kickback
OIG Advisory Opinion No. 21-02 Provides Helpful Insights into Risk Mitigation Factors Regarding Health System-, Physician-, and Management Company-Owned Ambulatory Surgery Centers
On April 26, 2021, the Department of Health and Human Services Office of Inspector General (“OIG”) issued favorable Advisory Opinion No. 21-02 regarding a proposed investment in an ambulatory surgery center (“ASC”) by a health system, orthopedic surgeon and neurosurgeon employees of the health system, and a management company. This latest Advisory Opinion is notable because it is the first time that the OIG has considered a venture that included a health system and its employees. As employment of physicians has grown, so have the number of potential ventures between employees and their health systems, making this latest Advisory Opinion particularly relevant. OIG guidance on ASCs is also uncommon, and in fact, this is the first ASC Advisory Opinion in over a decade. So, investors should review the OIG’s analysis carefully to understand the numerous elements that the OIG emphasized for mitigating risk. While the OIG concluded that the proposed investment would lead to sanctionable remuneration under the federal Anti-Kickback Statute (“AKS”) if the requisite intent were present, it determined that it would not impose sanctions on the requesting parties because of several integrated safeguards. A main takeaway from the OIG’s analysis was its conclusion that, with respect to the investments to be made by the health system and physician investors, the proposed investment presents a sufficiently low risk of fraud and abuse under the AKS for the combination of the following reasons. Physician Investors Who Can’t Meet the 1/3rd Income Test Still Integrate the ASC Into Their Regular Practice; Physician Investors Are Not Significant Source of Cross-Referrals Since neurosurgeons primarily perform inpatient procedures, one or more of the neurosurgeon investors may not comply with the safe harbor requirement that at least one-third of each physician investor’s annual income come from the performance of procedures that would be payable by Medicare when performed in an ASC. However, the OIG found it significant that the neurosurgeon investors would integrate use of the proposed ASC into their regular practice. In addition, the physician investors would personally perform almost all of their own referrals to the proposed ASC, rather than referring these procedure to other physicians. The health system estimated that only about 1% of the total number of ASC-qualified procedures done at the ASC would come from a different physician investor’s referral. Risk of Health System’s Influence on Referrals Mitigated The OIG also found that the proposed ASC had sufficient safeguards to mitigate the health system’s potential role in making or influencing referrals to the ASC. The health system certified that its affiliated physicians (i.e., employees, independent contractors, and members of the medical staff) would be paid consistent with fair market value and that such compensation would not be related, directly or indirectly, to the volume or value of their respective referrals to the ASC or its physician investors. The health system also certified that it would neither require nor encourage its affiliated physicians to refer patients to the ASC or its physician investors, and it would not track its affiliated physicians’ actual referrals. Reduce Risk of Rewarding Referrals through Structure of Investment Returns and Offers of Ownership Under the proposed ASC, potential investors’ opportunities to invest, and their investment returns, would not be based on anticipated or actual referrals to the ASC. . Capital contributions and profit distributions would be based on an individual investor’s investment interest in the ASC. Additionally, the ASC and its investors would not be permitted to promise or provide loans for the purpose of another investor gaining an investment interest in the ASC, and investors would be required to invest directly in the ASC (as opposed to through a pass-through entity). Safeguards on Investors’ Other Financial Relationships The ASC committed that its space or equipment leases would comply with the AKS space and equipment rental safe harbors. Similarly, any services rendered by the health system or the real estate company jointly owned by the investors would comply with the applicable AKS safe harbor for personal services and management contracts and outcomes-based payments. In addition, all ASC patients referred by an ASC investor would be given full written notice of the investor’s financial interest in the ASC. Other Safeguards The OIG listed several other significant safeguards against fraud and abuse presented by the proposed ASC. First, the ASC and its investors would provide non-discriminatory treatment to patients covered under any federal health care program. Second, the health system certified that all ancillary services for ASC patients covered under a federal health care program would directly and integrally relate to the ASC’s primary procedures. Further, the health system certified that the ASC would not bill any federal health care program separately for ancillary services. Third, the health system certified that it would not include ASC costs on cost reports or claims for payment by a federal health care program (unless such reporting is otherwise required by the program). With respect to the investments to be made by the management company, the OIG determined that even while the management company may be in a position to directly or indirectly influence referrals and thereby increase its investment returns, the proposed ASC had sufficient safeguards to mitigate that risk. Similar to the health system and physician investors, the management company certified that it would not make or influence referrals to the ASC or its physician investors. Additionally, no physician would have any investment interest in the management company. For all of these reasons, the OIG concluded that the proposed ASC arrangement presents a sufficiently low risk under the AKS and that the OIG would not impose administrative sanctions against the requesting parties in connection with the ASC. While Advisory Opinion No. 21-02 may only be relied upon by the requesting parties, it does provide helpful insight into risk mitigation factors when considering other ASC structures. If you have any questions about ASCs, please contact the author or your regular Dorsey attorney. Summer Associate Laura C.S. Newberry provided substantial assistance researching and drafting this blog post.
June 8, 2021
coronavirus
Coronavirus Lawsuits More Than Double In 2021; Those Against Healthcare Providers Steadily Increase
Despite widespread vaccine availability and the corresponding optimism about returning to “normal,” the coronavirus pandemic continues to spawn hundreds of employment and health-related lawsuits. Many of these lawsuits have been aimed at employers in the healthcare sector and relate to workplace safety, retaliation, and wrongful termination or wrongful denial of leave. In fact, since our last update on this topic (available here), the healthcare sector has increased its relative share of coronavirus lawsuits compared to other industries. In December 2020, approximately 20 percent of lawsuits alleging labor and employment violations related to coronavirus arose from the healthcare industry; today, that number is approximately 25 percent. The total number of coronavirus lawsuits has also increased dramatically. At the end of 2020, 1,235 total lawsuits had been filed against employers related to the coronavirus. Today, that number has more than doubled; there have been 2,560 lawsuits, including 200 class actions. States with the most filings include California (666), New Jersey (293), Florida (198), New York (184) and Ohio (156). Whether brought in California, Iowa, or elsewhere, coronavirus lawsuits most commonly assert that employers violated federal and state mandates, guidelines, and regulations regarding employee safety. One such federal mandate was the Families First Coronavirus Response Act (FFCRA), passed by Congress in March 2020 (and, with certain exceptions, expired in December 2020). While operative, the FFCRA required employers with fewer than 500 workers to provide employees with a certain amount of compensated time off for various reasons linked to COVID-19, including if employees become ill. Importantly, however, the FFCRA provided that certain employees—i.e., “health care providers and emergency responders”—may be excluded from entitlement to both emergency family leave and emergency paid sick leave. In addition to FFCRA cases, employees have also filed lawsuits alleging that their employers violated the federal WARN Act (or similar state laws), which in certain circumstances requires that employers with 100 or more employees provide at least 60 days’ notice before conducting a mass layoff. Even though there are fewer lawsuits involving COVID-19 related issues in states like Iowa, the recently filed Iowa cases are representative of the types of cases occurring across the country. In one case, an employee of a hospital asserts that she was terminated after she raised concerns about the lack of available personal protective equipment and about staff failing to wear masks correctly. She also claims that she raised concerns about an social event where staff were attending without masks and without adhering to social distancing guidelines. Another case involves claims by a food manufacturer’s nurse supervisor asserting her employer’s lack of preparedness for COVID-19 and her resulting firing after she raised safety concerns. Although other employment-related cases in Iowa have been filed against employers outside the health care industry, similar cases could be filed against those in the health care industry in the future. These cases include allegations that employers denied leaves of absence for an individual with high risk conditions and failure to implement proper screening, social distancing and other protective measures, which in one case resulted in deaths from COVID-19. On the flip side, Iowa has also seen recent litigation filed with an individual asserting a civil rights violation for requiring students to wear a mask to school. A recent development that may impact future coronavirus litigation is the updated federal guidance on mask mandates. On May 13, 2021, the U.S. Centers for Disease Control and Prevention (“CDC”) revised its guidance to reflect that “fully vaccinated” individuals no longer need to wear masks, whether indoors or outdoors, except in limited circumstances. And while there is a caveat for “local business and workplace guidance,” OSHA is advising employers to follow CDC guidelines for fully-vaccinated employees. Accordingly, employers across the nation now face the practical challenge of maintaining a safe and compliant workplace in an increasingly open environment, while at the same time minimizing their risk for legal liability. While many states have enacted legislation that limits the liability of healthcare providers for actions or omissions during the pandemic, most of the legislation leaves openings for plaintiff’s lawyers to argue that their clients’ claims are not prohibited, especially with respect to employment-related claims. For example, Iowa enacted the “COVID-19 Response and Back-to-Business Limited Liability Act”. Under the Iowa Act, providers cannot be held civilly liable for various actions, which include, but are not limited to screening, assessing, diagnosing, caring for or treating individuals with COVID-19. The Act also provides protection for acts or omissions relating to non-COVID-19 patients, if those acts or omissions result from supporting the state’s response to COVID-19. This may include acts such as providing treatment outside the premises of a health care facility or using equipment and supplies outside their normal use. As seen by the lawsuits described above, the Iowa Act does not prevent the filing of employment-related claims and notably, liability can still be established even in non-employment related contexts if the provider acted recklessly or engaged in willful misconduct. Navigating the highly dynamic landscape of federal, state, and local coronavirus rules and policies presents numerous challenges for employers. But healthcare providers can still employ a number of proactive steps to reduce their potential exposure. Providers should understand their obligations under relevant federal and state law and provide employees protected leave as appropriate. When in doubt, we recommend that employers err on the side of granting the requested leave. Providers should revise company policies as necessary to incorporate the new regulations that apply to COVID-19 exposure and sick leave. To the extent feasible, providers should consider offering teleworking opportunities for eligible employees. Providers should implement a system for recording employees’ requests for leave and the reasons supporting those requests, i.e., an employee’s symptoms and the date for a test or doctor’s appointment. However, providers should not require employees to provide further documentation, such as certification that the employee sought a diagnosis or treatment from a healthcare provider. Providers should be mindful of the risks of taking personnel actions that could lead to discrimination or retaliation lawsuits by workers who requested or took applicable leave. As always, providers should properly document their termination decisions. Providers should carefully consider whether and how they will ask employees to provide proof of vaccination, and they must be aware of relevant legal considerations if making those inquires. Several jurisdictions have implemented laws banning employers from requiring so-called “vaccine passports” or other methods of requiring individuals to provide proof of vaccination to gain access, entry, or service. Providers may initially want to strongly encourage employees to get vaccinated—with the caveat that it may be mandatory in the future—and only require vaccination in the future if absolutely necessary.
June 7, 2021
Accountable Care Organizations
The “Regulatory Sprint to Coordinated Care” – Overview and Links to Further Resources from Dorsey & Whitney
In 2018, the U.S. Department of Health and Human Services (“HHS”) launched the “Regulatory Sprint to Coordinated Care” to accelerate a transformation of the healthcare system, with a focus on removing “unnecessary obstacles” to coordinated care (the “Regulatory Sprint”). Several HHS agencies requested comments and information from the public and have published new or proposed regulations as part of the Regulatory Sprint on areas that have historically been viewed as barriers to innovative care coordination arrangements—namely, healthcare fraud and abuse and health information privacy. On November 20, 2020, the HHS Office of Inspector General (“OIG”) and Centers for Medicare & Medicaid Services (“CMS”) each issued a sweeping set of final regulations that introduced significant new value-based terminology, safe harbors and exceptions, as well as clarifications of existing requirements, under the federal anti-kickback statute (“AKS”) and federal physician self-referral law (“Stark Law”), respectively. Additionally, the OIG issued final regulations related to modernizing the civil monetary penalty law governing inducements provided to Medicare and Medicaid beneficiaries (the “CMPL”). The final OIG and CMS rules are effective on January 19, 2021, with the exception of changes to the Stark “group practice” definition, which do not go into effect until January 1, 2022. There are hundreds of pages of preamble guidance and revised regulation text setting forth these sweeping changes to the Stark Law, AKS and CMPL regulations from CMS and OIG. To help you digest these materials, a team of attorneys from Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group has published two white papers, which are available at the links below. In addition, we have posted at a link below the playback of a webinar we hosted about the final rules on January 6, 2021. The white papers and webinar playback provide an in-depth summary of the changes to these regulations, including key provisions from CMS and OIG preamble guidance. Finally, we have posted below redlines comparing the existing Stark Law, AKS and CMPL regulations to the revised version of each of these regulations in the final rules. With respect to health information privacy, the HHS Office for Civil Rights (“OCR”) issued a Notice of Proposed Rulemaking (“NPRM”) on December 10, 2020 which proposes changes to the Health Insurance Portability and Accountability Act (“HIPAA”) and to the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Privacy Rule. Additionally, the HHS Substance Abuse and Mental Health Services Administration (“SAMHSA”) published final rules to revise regulations related to the privacy of substance use disorder treatment records in July 2020. These changes in federal regulations are anticipated to make a significant impact on healthcare providers and other stakeholders that may have been reticent to initiate certain care coordination arrangements because of perceived regulatory barriers and lack of regulatory clarity. In addition, clarifications to existing regulations impact stakeholders beyond their involvement in care coordination arrangements. The team of attorneys in Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group will continue to closely monitor these changes, and post updates and analysis below as new information becomes available. Stark Regulatory Changes Effective January 1, 2022 Require Modifying Certain Group Practice Compensation Methodologies | News & Resources Webinar Playback: Final Stark and Anti-Kickback Statute Rules: What You Need to Know White Paper: Understanding the Final Rules to Revise the Stark Law Regulations White Paper: Understanding the Final Rules to Revise the Anti-Kickback Statute and Beneficiary Inducement Civil Monetary Penalty Regulations The Regulatory Sprint Catches up to HIPAA: New Proposed HIPAA Rules Redline of Final AKS Regulatory Text Redline of Final CMP Regulatory Text Redline of Final Stark Regulatory Text effective 1.1.2022 - 411.352(i) only Redline of Final Stark Regulatory Text effective 1.19.2021 Much-Anticipated Final Rules to Revise Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP Regulations Released under “Regulatory Sprint to Coordinated Care” CMS Finalizes Changes to the Stark Advisory Opinion Regulations; 2020 DHS Code List and CPI-U Updates Sweeping Proposals Issued by CMS to Revise Stark Law Regulations Sweeping Proposals Issued By OIG To Make Changes To The Anti-Kickback Statute Safe Harbors And Add An Exception To The Civil Monetary Penalty Law Governing Beneficiary Inducements A Massive Number of New Health Law Regulatory Proposals as Part of the “Regulatory Sprint to Coordinated Care”: Proposed Changes to the Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP, Privacy Laws Governing Substance Use Disorder Records, and the Stark Law Advisory Opinion Process CMS "Actively Working" on Stark Law Reforms to be Issued Later this Year; "Regulatory Sprint to Coordinated Care" Continues OIG Seeks Public Input on Anti-Kickback Statute and Beneficiary Inducements CMP as part of the “Regulatory Sprint to Coordinated Care” Calls for Modernizing the Stark Law Continue; CMS Seeks Public Input on Stark Law Reforms
April 30, 2021
Stark
Stark Regulatory Changes Effective January 1, 2022 Require Modifying Certain Group Practice Compensation Methodologies
On January 1, 2022, changes to the federal physician self-referral law (“Stark Law” or “Stark”) group practice definition special compensation rule go into effect. Among other things, these changes revise the rule related to overall profits to prohibit pooling and distributing profits from designated health services (“DHS”) on a service-by-service basis, which is sometimes referred to as “split pooling.” As of that date, profits from all the DHS of the practice, or a component of the practice that consists of at least five physicians (a “5+ physician pod”), must be aggregated before distribution. Group practices that use split pooling need to modify their compensation methodologies to account for this change by January 1. Because of the time and effort involved in modifying physician compensation methodologies, now is the time for physician practices to evaluate whether any modifications to their compensation methodologies are needed in order to comply with this change. Physician practices also need to be aware of important commentary from the Centers for Medicare & Medicaid Services (“CMS”) on the special rule that clarifies CMS’s intentions regarding permissible DHS profit sharing and additional revisions to the regulation text that impact profit sharing, which may also necessitate (or, in some cases, permit) changes to certain group practice compensation methodologies. These changes and commentary, which are described in detail below, are part of a sweeping set of final rules issued last fall by CMS to revise the Stark regulations, which were part of the “Regulatory Sprint to Coordinated Care” (the “Final Rules”). This white paper summarizes the Final Rules, and more information about the Regulatory Sprint can be found here. Most of the Final Rules went into effect on January 19, 2021, but changes to the group practice definition will not become effective until January 1, 2022. The revised version of the group practice definition that will be in effect as of January 1 is available here, and a redline comparing the version that is currently in effect to the revised version is available here. Read more here.
April 30, 2021
Long Term Care
Granny Cams Are Likely Here to Stay: Taking Steps to Address the Inevitable
“Granny cams” or family-placed electronic monitoring in a nursing facility have become more commonplace. Cameras are easier to obtain and set up and can easily be linked to one or more family member’s cell phones. With COVID visiting restrictions making it more difficult for families to visit their loved ones in person, more and more people will be considering their options for keeping an eye on their family member living in a long term care facility. Some states have passed legislation to establish certain regulations or parameters around the use of granny cams in the long term care setting. Others, including Iowa, are considering such legislation. Most states, however, do not have any statutory or regulatory requirements and thus, long term care facilities must determine how to deal with use of such cameras. The first question a long term care facility must ask is whether it is advisable to have a written policy. If you are in a state with a statute or regulation on granny cams, you likely should have – and may be required to have – a written policy to comply with those requirements. If you are in a state without any statutory or regulatory provisions on electronic monitoring in long term care, your initial reaction may be that having a policy provided to residents and family members will only encourage them to obtain cameras. However, a resident or family member who wants a camera will likely place one anyway, and you may be better off to at least have a set of ground rules for everyone to follow with respect to such cameras. There are numerous considerations for handling the use of family-placed electronic monitoring in your facility: Is the resident competent to decide if he or she wants a camera in the room? If not, who can make the decision for the resident as to whether a camera can be placed in the room? Financial and medical power of attorneys do not expressly cover the ability to consent to being videotaped, but such consent arguably falls under some of the broad powers generally given to a medical power of attorney. The decision-maker question gets messier if there is no designated medical power of attorney or if there are joint medical power of attorneys who do not agree. Does the resident have a roommate? If so, the roommate has privacy rights that must be considered and protected. A policy can provide restrictions on the direction the camera is pointing and also require that a roommate must give consent. The policy can also address the resident’s options when a roommate does not consent to having the camera in the shared room. Should you require that the family disclose the existence of the camera to you? Any policy should require such disclosure so that proper signage could be placed on the doors to the room alerting people that they may be videotaped while in the room. This disclosure and signage will help reduce or eliminate liability to you (and the family) for possible illegal, covert recordings that may violate state or federal wiretapping and/or communication interception laws. Will the recording be video only or will it include audio? The inclusion of audio increases the complications and issues involved, because it may “pick up” discussions that are confidential or private in nature regarding the resident’s roommate or other discussions that may occur in the hallway or near the room. This issue should be assessed in light of federal and state-specific laws regarding the recording of verbal conversations. Who is responsible for the camera set up and operation and the resulting video? A policy should clarify that the family is responsible for the camera, its operation and the videos that are created by it. If the facility were to take possession of the recordings, it unleashes a whole host of regulatory issues including HIPAA protections and possible self-reporting or disclosure requirements. The policy should place certain restrictions upon the camera, such as requiring a proper electrical connection (i.e., not using an extension cord or draping a cord across a room), where and how it can be mounted or placed and/or generally requiring that the camera be placed in a safe manner that will not cause safety or fire hazards. A facility may also consider whether the use of its private Wi-Fi (and any associated cost) versus public Wi-Fi would be allowed for cameras requiring an internet connection. The policy should also address what happens when the camera malfunctions. For example, if it goes off (like a fire alarm) due to low battery or other complications, can it simply be turned off? Does the family need to be notified when such issues occur? The best bet is to have the facility take little to no responsibility for the actual operation of the camera or its resulting video and rather simply provide parameters around its placement and safe use. What are the evidentiary rules and issues with the camera footage? While this question is not likely something that you can fully address or avoid with a policy, you should consider the possible uses of the video and inform your staff to be aware of these possibilities. Videos could be submitted to the state survey agency and used to confirm or dispute that certain cares were provided, they could be used in criminal actions, and they could be used in civil actions for malpractice. While every state’s evidentiary rules and case law may differ and the facts of how the video was captured and maintained will impact its admissibility, everyone should be aware that their actions may be recorded. Hopefully, this awareness will encourage everyone to do better and at the end of the day, improve the cares that are provided to your residents. If you are operating an assisted living facility, the considerations are slightly different in that the space in which the camera is situated is usually considered more like a personal home and is typically subject to landlord tenant laws. However, some of the same considerations – especially those involving whether the camera is capturing video and audio, ensuring that use of the camera is compliant with federal and state wiretapping and communication interception laws and avoiding fire and other safety hazards with the camera – will need to be addressed. While these are difficult issues that can vary from state to state, facilities should not avoid this discussion. Granny cameras will likely only increase in use, especially as technology improves and as families tend to live further away from their parents or grandparents who are now living in your facility. A clear policy and transparent communications with families on this issue can actually result in a positive relationship. Families will realize that a facility who is willing to allow them to place a camera must feel confident about the good care that will be provided to their loved ones, and everyone will understand the “rules of the game” when using such cameras.
February 25, 2021
Centers for Medicare and Medicaid Services
Nursing Facilities and CMPs: The Latest Fight
On January 18, 2021, a lawsuit was filed against the U.S. Department of Health and Human Services (“HHS”) and the Centers for Medicare and Medicaid Services (“CMS”) challenging a CMS policy change dating back to 2017. The plaintiffs, the National Consumer Voice for Quality Long-Term Care and the California Advocates for Nursing Home Reform, are non-profit consumer advocacy groups for long-term care. The policy at the heart of the lawsuit concerns a change CMS made as to how civil monetary penalties (“CMP”) are imposed against nursing facilities. As a bit of background, under the Nursing Home Reform Act of 1987 (NHRA), Congress created a scheme whereby CMS and the states shared responsibility for ensuring states meet federal quality and safety standards of resident care for residents in nursing facilities. Under this scheme, state agencies regularly evaluate a nursing facility’s compliance with the requirements by conducting periodic surveys, often unannounced. The survey findings would then be reported to the CMS regional offices (“RO”) with recommended enforcement actions. Acting on the survey results and the recommendation from the state agency, the ROs would then impose per-day CMPs on facilities for past noncompliance with federal standards. The 2017 change, however, made clear that ROs, regardless of findings and recommendations from state survey agencies, are to impose a CMP for past noncompliance based only on each instance of noncompliance that occurred but was corrected before the state survey is conducted. “Past noncompliance” is a statutorily defined term which means those situations in which a state finds that a nursing facility meets all of the federal requirements “but, as of a previous period, did not meet such requirements.” With this 2017 policy change, if a facility has corrected that noncompliance just before the survey team shows up at the facility, even if the noncompliance had lasted months, then the facility would not be penalized for each day of noncompliance but rather, would receive a “per instance” CMP. The plaintiffs in the recently filed litigation argue that, by announcing to the state survey agencies that its ROs will assess CMPs only for each instance of past noncompliance and not for each day of past noncompliance, CMS’ policy change effectively contravenes Congress’ express intent to give the states the direction to recommend (and CMS the discretion to impose) a per-day CMP for past noncompliance. The complaint alleges that the plaintiffs have been adversely impacted by this change. Per instance CMPs currently range in amount, as adjusted for inflation, from a minimum of $2,233 to a maximum of $22,320 for each instance of noncompliance. 42 C.F.R. § 488.438(a)(2); 45 C.F.R. § 102.3. Taking the example of a non-immediate jeopardy deficiency, the maximum per-instance CMP that a nursing facility faces for this type of deficiency is $22,320, regardless of whether the facility has allowed the deficiency to remain uncorrected for one day, one week, or one month. By contrast, the maximum per day CMP for this type of deficiency begins to exceed, and quickly dwarfs, the maximum per instance CMP whenever the facility has allowed the deficiency to remain uncorrected for four or more days (4 x $6,695 = $26,780). The plaintiffs argue that the imposition of only per instance CMPs for past noncompliance will thus encourage nursing facilities to knowingly allow deficiencies to linger for days, weeks, or even months, until the next state survey, because the penalty will be the same regardless of whether the deficiency persisted for a day or a month. As long the facility remedies the deficiency before the next survey (usually 12-15 months apart), the facility can only be fined the per instance maximum of $22,320. The human impact of this, as argued in the lawsuit, is that for each day a facility permits a deficiency to persist, whether it be for one week or a number of months, the residents at that facility may be endangered by the deficiency. As a result, the plaintiffs assert that if facilities do not fear the monetary penalties, they will be less inclined to make their facilities safe for residents. Certainly, nursing facilities across the country will see it very differently from the plaintiffs in the litigation. Because surveys are unannounced, facilities do not “let down their guard” and intentionally allow the facilities to become less safe simply because they know they will be assessed a per instance penalty instead of a per day penalty. Rather, the possibility of getting a per instance CMP (as opposed to a per day penalty) would be an incentive for nursing facilities to identify and correct issues immediately so that such issues will be identified as past noncompliance when the state survey agency does come knocking. While there may be some bad actors out there, most nursing facilities are doing all that they can to avoid noncompliance. In other words, facilities’ actions and decisions are not based upon whether they would rather have a per day versus a per instance penalty. It is also notable that, while the litigation mentions the COVID-19 pandemic, it does not mention the enhanced CMPs that are now available for infection control violations. CMS has been aggressively using these enhanced CMPs to impose large per instance and large per day CMPs for relatively low-level transgressions. For example, having one employee make an error on his/her mask wearing or daily documentation regarding COVID-19 symptoms (even if it does not lead to any adverse consequences) can result in a $15,000 CMP if the facility had any infection control deficiency in the last two years. A surveyor may see a staff member not following the requirements every time (e.g. not wiping down the face shield after they sit it down for a few seconds, letting their mask fall below their nose, etc.) and may assess severe penalties as a result. While most facilities would agree that infection control is important, these penalties are excessive, especially taking into account they are assessed for some of the more minor and isolated events that may occur. Facilities should be cognizant of this litigation and the views expressed by the organizations seeking to change the CMP landscape to be harsher than it is now. CMS has already shown its willingness to increase the CMP levels for infection control purposes, and they may seek to expand such penalties on a more permanent basis. If you have any questions about any of the topics addressed in this post, please contact the authors or any member of the Dorsey & Whitney Health Transactions & Regulations Practice Group.
February 10, 2021
False Claims Act
Borrowers and Banks Beware: The New Year Brings the Nation’s First False Claims Act Settlement for Paycheck Protection Program Fraud
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s FCA Now blog for today's post.
January 15, 2021
Anti-Kickback
White Papers: Understanding the Final Rules to Revise the Stark Law, Anti-Kickback Statute and Beneficiary Inducement Civil Monetary Penalty Regulations
In just two weeks, on January 19, 2021, a sweeping set of changes to the federal physician self-referral law (or “Stark Law”) and anti-kickback statute (“AKS”) regulations go into effect. These changes, which are part of the U.S. Department of Health and Human Services (“HHS”) “Regulatory Sprint to Coordinated Care,” are the most significant changes to the Stark Law and AKS in a decade. There are hundreds of pages of preamble guidance and revised regulation text setting forth these sweeping changes from the Centers for Medicare & Medicaid Services (“CMS”) and HHS Office of Inspector General (“OIG”). To help you digest these materials, a team of attorneys from Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group has published two white papers, which are available at the following links: White Paper: Understanding the Final Rules to Revise the Stark Law Regulations White Paper: Understanding the Final Rules to Revise the Anti-Kickback Statute and Beneficiary Inducement Civil Monetary Penalty Regulations These white papers provide an in-depth summary of the changes to these regulations, including key provisions from CMS and OIG preamble guidance. Please contact the authors or your regular Dorsey attorney if you would like assistance with understanding how the final rules impact your organization.
January 5, 2021
ERISA
Is Data the Next Frontier in ERISA Litigation?
Health and retirement benefit plans subject to the Employee Retirement Income Security Act (“ERISA”) have troves of personal information regarding plan participants and their beneficiaries—e.g., participants’ age, marital status, personal assets, medical and prescription drug claim data, and medical history. Although the Health Insurance Portability & Accountability Act (“HIPAA”) regulates treatment of protected health information, ERISA does not expressly address how plan fiduciaries may have a responsibility with respect to participants’ personal data or personally identifiable information (“PII”). Nevertheless, one emerging trend in ERISA litigation is lawsuits arguing that ERISA’s duties of loyalty and prudence, among other ERISA duties, impose a duty to protect participants’ privacy. These lawsuits often argue that participants’ data is a “plan asset” that, when used or disclosed improperly, gives rise to claims for breach of fiduciary duties and other claims under ERISA. Plan sponsors and fiduciaries should pay attention to this developing area of law and be proactive to ensure that their actions do not put participants’ personal information at risk, and be able to demonstrate that reasonable steps have been taken to protect such data. I. ERISA Duties Regarding Plan Assets ERISA imposes several duties on plan fiduciaries with respect to their use of plan assets. ERISA requires that plan fiduciaries act for the “exclusive purpose” of providing benefits to participants and beneficiaries. 28 U.S.C. § 1104(a)(1)(A). ERISA requires that fiduciaries act “with the care, skill, prudence, and diligence under the circumstances then prevailing that a prudent man acting in a like capacity and familiar with such matters would use . . .” Id. § 1104(a)(1)(B). ERISA also prohibits plan fiduciaries from engaging in certain prohibited transactions, including transactions between the plan and certain related parties, also known as parties in interest, which the fiduciary knows constitute a direct or indirect transfer to, or use by or for the benefit of, a party in interest, of any assets of the plan. 29 U.S.C. § 1106(a)(1). II. ERISA Liability for Fraudulent Distributions of Plan Assets When participants’ money is fraudulently withdrawn from their’ benefit accounts, they have sued plan fiduciaries for breach of fiduciary duty. For example, in Leventhal v. MandMarblestone Grp., LLC, a law firm partner brought an ERISA fiduciary breach claim against a plan administrator for approving fraudulent distributions from his 401(k) account. 2019 U.S. Dist. LEXIS 74123, at *7-17 (E.D. Pa. May 1, 2019). The court ruled that the claim survived dismissal because the plaintiff sufficiently alleged that the defendant failed “to act with the requisite prudence and diligence” when it did not alert plaintiff or institute other safeguards to protect against the fraudulent withdrawal requests. Id. at *15-17. A similar claim against the operator of a plan’s benefit center and website survived dismissal in Bartnett v. Abbott Labs., 2020 U.S. Dist. LEXIS 182645, at *18-19 (N.D. Ill. Oct. 2, 2020). These cases follow a familiar trend—lawsuits seeking to recover money that was stolen as a result of a data or cybersecurity lapse. Recent case law, however, suggests that fiduciaries may face ERISA claims for the improper use or disclosure of participant data itself, regardless of whether that data is used to make a subsequent fraudulent distribution. III. Is Participant Data Itself a “Plan Asset”? ERISA does not specifically define “plan assets,” but states that “’plan assets’ means plan assets as defined by such regulations as the Secretary [of Labor] may prescribe.” Those regulations define certain categories of “plan assets”—for example, “plan investments” (See 29 C.F.R. §§ 2510.3-101(a)(2)—but the Department of Labor has stated that “in situations outside the scope of the plan assets-plan investments regulation (29 C.F.R. § 2510.3-101), the assets of a plan generally are to be identified on the basis of ordinary notions of property rights under non-ERISA law.” See, e.g., Advisory Opinion 1993-14A. The question, therefore, is whether participant data is a plan asset under those “ordinary notions of proper rights.” Whether participant data is a plan asset is currently the subject of debate. On one hand, two recent court-approved settlements suggest that participant data may be viewed as plan asset. In Cassell v. Vanderbilt Univ., the university paid $14.5 million to settle breach of fiduciary duty and prohibited transactions claims premised on the plan’s recordkeeper’s use of participant data to market and sell additional services to the plaintiffs. See Second Amend. Compl., ¶¶ 279-82, No. 16-cv-02086 (M.D. Tenn. June 6, 2018), ECF No. 102. The settlement required the plan’s current recordkeeper to refrain from using participant data to market or sell products or services to plan participants. See Class Action Settlement Agreement § 10.6, No. 16-cv-02086 (M.D. Tenn. April 23, 2019), ECF No. 147-1. Another lawsuit alleging similar claims settled for $14 million and the settlement agreement contained a similar prohibition on the use of participant data to cross sell other products. See Class Action Settlement Agreement § 10.8, Kelly v. Johns Hopkins Univ., No. 16-cv-02835 (D. Md. Aug. 6, 2019), ECF No. 84-2. On the other hand, at least one court has ruled that participant data is not a “plan asset.” In Divane v. Northwestern Univ., plan participants alleged that the university breached its fiduciary duties and engaged in prohibited transactions when it allowed the plans’ recordkeeper to access participant data and use it to sell products to them. 2018 U.S. Dist. LEXIS 87645, at *36-37 (N.D. Ill. May 25, 2018), aff’d on other grounds, 953 F.3d 980 (7th Cir. 2020). The court rejected those claims, ruling that although “a compilation of the information [the recordkeeper] has on participants has some value . . . the Court cannot conclude that it is a plan asset under ordinary notions of property rights.” Id. at *38-39. The court emphasized that no court has yet recognized such a right, and that participant data was not “property the plan could sell or lease in order to fund retirement benefits.” Id. While Divine may have been the first court to rule on the issue, it will not be the last. The issue of whether participant data constitutes a plan asset is also pending in Harmon v. Shell Oil, Co., a case before the United States District Court for the Southern District of Texas. There, plaintiffs allege that the plan recordkeeper used (or could use) participant data to convince them to move their funds into higher cost, lower performing investments rather lower cost, better performing investments. See generally Am. Compl., 20-cv-00021 (S.D. Tex. May 21, 2020), ECF No. 84. According to the plaintiffs, that conduct amounts to a breach of fiduciary duties and prohibited transactions. In opposing dismissal, plaintiffs argue that participant data is an “asset” because it amounts to “intimate knowledge of financial and personal information combined with insider knowledge of exploitable triggering events,” such as retirement and marital status. Opp’n to Defs.’ Mot. to Dismiss at 14-15, 20-cv-00021 (S.D. Tex. June 6, 2020), ECF No. 93. Further, Plaintiffs argue that since this information “is collected by the Plan for the exclusive purpose of administering the Plan and providing benefits to participants,” it is a plan asset. Id. Plaintiffs also argue that the definition of “plan asset” includes participant data. Id. at 15-17. These cases are likely only the opening salvo of litigation regarding ERISA fiduciaries’ duties with respect to participant data. While the cases have primarily involved retirement benefit plans, they have implications for fiduciaries of health benefit plans regulated by ERISA as well. In addition to potential ERISA claims arising from data breaches or cybersecurity lapses, health plans may face ERISA claims regarding their use of participant data. Although the law in this area is still emerging, to minimize exposure ERISA fiduciaries should ensure that they are taking appropriate steps to protect participant data. There are many steps ERISA fiduciaries can take to safeguard participant data, including: Develop cybersecurity policies, including both procedures to prevent improper use or disclosure of participant data as well as an Incident Response Plan to execute in the event of a breach; Review agreements with third-party service providers to ensure they appropriately limit the use of participant data and mandate proper cybersecurity practices; Improve data security protocols to minimize the likelihood of unauthorized access to or use of participants’ data; and Consider obtaining cybersecurity insurance that will provide coverage in the event of a breach or other improper use of participant data. It may be too much to expect that participant data can be perfectly protected under all circumstances, especially given the almost ubiquitous attacks by cyber criminals, but ERISA fiduciaries would be well served to be able to demonstrate that reasonable steps were taken to provide data security, and that procedures were in place to respond to any unauthorized disclosure.
January 4, 2021
coronavirus
Coronavirus Lawsuits Against Healthcare Providers are on the Rise
Among its many impacts, the coronavirus pandemic has already spawned hundreds of employment and health-related lawsuits, with even more litigation likely as businesses continue to bring back workers and increase operations. Many of these lawsuits have been aimed at employers in the healthcare sector and relate to workplace safety, retaliation, and wrongful termination or wrongful denial of leave. In fact, over 20 percent of the lawsuits alleging labor and employment violations related to the coronavirus arise from the healthcare industry. A recent lawsuit filed by a fired nursing assistant serves as a good example of the types of claims health care providers may soon face. On April 1, 2020, Za’Taya Ballard was hired as a nursing assistant by Highland Park Care Center, a nursing home located in Pittsburgh. On May 16, Ballard learned she had “prolonged close contact” with a person who had the virus. Ballard was not wearing personal protective equipment at the time of the exposure. Thereafter, Ballard notified the nursing home of her exposure and was removed from the upcoming work schedule so she could self-isolate for 14 days. However, Ballard alleges that two days later, she was fired for missing work. On October 20, Ballard filed suit against the nursing home in Pennsylvania state court. The case is Ballard v. Highland Park Care Center LLC, Case No. GD-20-011291, in the Court of Common Pleas of Allegheny County, Pennsylvania. In her Complaint, Ballard brings a single count for “wrongful discharge in violation of public policy.” According to Ballard, guidelines promulgated by the Centers for Disease Control, the Pennsylvania Department of Health, and the Governor of Pennsylvania evidence a “clearly-defined public policy” “for individuals who had prolonged exposure to confirmed cases of COVID-19 without protective gear to isolate themselves in an effort to prevent the virus’s spread.” By purportedly firing her due to her request to quarantine, Ballard alleges the nursing home violated “a clear mandate of Pennsylvania and United States public policy.” Ballard seeks back pay, compensatory damages, and punitive damages. Claims like those brought by Ballard are on the rise. During the first five months of the pandemic, 459 lawsuits were filed against employers due to alleged labor violations related to the coronavirus. During the next four months, 776 lawsuits were filed. In the first half of November alone, 158 complaints were filed. Of the 1,235 total lawsuits, 116 are class actions. For example, in September, workers in California, Michigan, and Georgia filed unrelated lawsuits in which they claimed they were fired for quarantining after contracting COVID-19. Whether brought by an individual plaintiff or on behalf of a purported class, these lawsuits most commonly assert that employers violated federal and state mandates, guidelines, and regulations regarding employee safety. One such federal mandate is the Families First Coronavirus Response Act (FFCRA), passed by Congress in March. The FFCRA requires employers with fewer than 500 workers to provide employees with a certain amount of compensated time off for various reasons linked to COVID-19, including if employees become ill. Importantly, however, the FFCRA provides that certain employees—i.e., “health care providers and emergency responders”—may be excluded from entitlement to both emergency family leave and emergency paid sick leave. Please see our e-alert on this topic, available here. In addition to FFCRA cases, employees have also filed lawsuits alleging that their employers violated the federal WARN Act (or similar state laws), which in certain circumstances requires that employers with 100 or more employees provide at least 60 days’ notice before conducting a mass layoff. Although lawsuits focused on COVID-19 largely remain at the early stages of litigation, health care providers can employ a number of proactive steps to reduce their potential exposure. Providers should understand their obligations under relevant federal and state law and provide employees protected leave as appropriate. When in doubt, we recommend that employers err on the side of granting the requested leave; Providers should revise company policies as necessary to incorporate the new regulations that apply to COVID-19 exposure and sick leave; To the extent feasible, providers should consider offering teleworking opportunities for eligible employees; Providers should implement a system for recording employees’ requests for leave and the reasons supporting those requests, i.e., an employee’s symptoms and the date for a test or doctor’s appointment. However, providers should not require employees to provide further documentation, such as certification that the employee sought a diagnosis or treatment from a healthcare provider; and Providers should be mindful of the risks of taking personnel actions that could lead to discrimination or retaliation lawsuits by workers who requested or took applicable leave. As always, providers should properly document their termination decisions.
December 11, 2020
HHS Office for Civil Rights
The Regulatory Sprint Catches up to HIPAA: New Proposed HIPAA Rules
Today, the Department of Health and Human Services’ (“HHS”) Office for Civil Rights (“OCR”) issued a Notice of Proposed Rulemaking (“NPRM”) which proposes significant changes to the Health Insurance Portability and Accountability Act (“HIPAA”) and to the Health Information Technology for Economic and Clinical Health Act (“HITECH”) Privacy Rule (the “Privacy Rule”). The NPRM includes numerous changes to the Privacy Rule that are part of HHS’ Regulatory Sprint to Coordinated Care which is intended to eliminate administrative barriers to a health care delivery system that fosters care coordination and value-based care for patients. OCR also issued a fact sheet about this NPRM, which is available here. This NPRM comes nearly two years after OCR issued a Request for Information (“RFI”) in December 2018 calling for information from the public regarding ways that HIPAA regulations could be modernized to support coordinated, value-based care. These changes in federal regulations are anticipated to make a significant impact on healthcare providers and other stakeholders that may have been reticent to initiate certain care coordination arrangements because of perceived HIPAA violations or a lack of regulatory certainty. Clarifications to existing regulations will impact stakeholders beyond their involvement in care coordination arrangements. The changes will also impact data sharing arrangements and reduce unnecessary administrative burdens on health care providers and health plans, such as eliminating the requirement to obtain an individual’s signature for the Notice of Privacy Practices (“NPP”) or the requirement to retain copies of the NPP for six years. Further, the proposed changes to the Privacy Rule provide clarification to the laws governing patient rights of access to their health records, and help to better facilitate disclosures of health information in order to improve care for patients in emergencies or who are experiencing a health crisis, including mental health crises and opioid overdose situations. Comments to the NPRM are invited from stakeholders, and will be due some time in February 2021, at a date that is 60 days after the NPRM is published in the Federal Register. Please contact the author of this post or your regular Dorsey attorney if you have questions about how these changes to the Privacy Rule could impact you, and for assistance in submitting comments to the OCR. The team of attorneys in Dorsey & Whitney’s Healthcare Transactions and Regulations Practice Group will continue to closely monitor these changes, and post updates and analysis on Dorsey’s Health Law Blog and on Dorsey’s Regulatory Sprint Webpage as new information becomes available.
December 10, 2020
Anti-Kickback
OIG Skeptical of Medical Device and Pharmaceutical Speaker Programs
The Department of Health and Human Services Office of Inspector General (“OIG”) has issued a Special Fraud Alert to highlight what it views as inherent risks associated with speaker programs that pharmaceutical and medical device companies organize and fund. These programs are typically company-sponsored events at which one or more physicians or other health care professionals make presentations about a device or drug product or disease state. The company will usually pay the speaker an honorarium and expenses, and may pay travel or other costs of attendees. Using unusually strong language, the OIG states that it is “skeptical about the educational value of such programs.” Numerous investigations have revealed to the OIG that, often, health care professionals receive generous compensation to speak at these programs, and that the programs are offered under circumstances unconducive to learning, or involve audience members who have no legitimate reason to attend. These cases cause the OIG to conclude that in many circumstances at least one purpose of the compensation paid to the speaker (and to the attendees), is to induce or reward referrals of the company’s products. Any payment made purposefully to induce or reward referrals of items payable by a federal health care program is a violation of the federal anti-kickback statute, which is a felony punishable by a fine of up to $100,000, imprisonment for 10 years, or both. Violation of the anti-kickback statute can also lead to liability under the federal civil false claims act, civil monetary penalties, and exclusion from federal health care programs. Health care professionals who solicit or accept such payments are also at risk of violating the anti-kickback statute. Some of the characteristics of suspect speaker programs include: Sales or marketing personnel influence speaker selection; Health care professionals attend multiple programs on the same topic; The company sponsors numerous programs on the same or similar topics, particularly without a recent substantive change in the information; Significant time elapses with no new medical or scientific information nor new FDA-approved or cleared indication for a product; The company pays more than fair market value for the speaking services or pays compensation that takes into account the volume or value of past or potential future business generated by the health care professionals; Attendees include those without a legitimate business reason to attend; The location of the program is not conducive to the exchange of education information; or Alcohol (particularly fee alcohol), or a meal exceeding modest value is provided to attendees. The OIG points out that many other ways exist for health care professionals to obtain information about drug or device products, such as online resources, third-party educational conferences, medical journals, and others. The existence of these other resources that do not involve payment to health care professionals suggests to the OIG that at least one purpose of payment associated with speaker programs is often to induce or reward referrals. The current pandemic emergency has put many in-person speaking programs on hold. When in-person speaking programs resume, it will be important for medical device and pharmaceutical companies to review their speaker program practices, and take into account the OIG’s strong skepticism. Both the OIG fraud alert and the alternative ways that health care professionals have learned about drug and device products during the pandemic have altered the landscape for speaker programs: speaker program sponsors should take notice. If you have questions about the topic addressed here, please contact the author of any member of the Dorsey &Whitney Health Care Transactions & Regulations Practice Group.
November 25, 2020
Anti-Kickback
Much-Anticipated Final Rules to Revise Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP Regulations Released under “Regulatory Sprint to Coordinated Care”
On November 20, 2020, the Centers for Medicare & Medicaid Services (CMS) and the Department of Health and Human Services (HHS) Office of Inspector General (OIG) each released their much-anticipated final rules to revise the federal self-referral law (or “Stark Law”) regulations, the safe harbors under the federal anti-kickback statute (AKS), and regulations under the beneficiary inducements civil monetary penalty law (CMP). The final rules are part of HHS’s “Regulatory Sprint to Coordinated Care,” which seeks to remove regulatory obstacles to care coordination and a value-based healthcare delivery system. The public inspection copy of the final CMS rules is available here, and the CMS fact sheet on the final rules is available here. The public inspection copy of the final OIG rules is available here, and the OIG fact sheet on the final rules is available here. Both rules will be published in the Federal Register on December 2, 2020. For our prior posts on the Regulatory Sprint to Coordinated Care, see here. We are reviewing the final rules and will post an in-depth analysis in the coming weeks.
November 20, 2020
HHS Office for Civil Rights
2020’s a Bust, but HIPAA Enforcement Is on a Roll!
The Office for Civil Rights (OCR) at the U.S. Department of Health and Human Services (HHS) has been actively enforcing HIPAA regulations this year, including a series of seven settlements under OCR’s Right of Access Initiative to enforce patients’ rights to timely access their medical records at a reasonable cost. This year, OCR has recorded more than $12.2 million in resolution agreements. This post summarizes OCR’s settlements in 2020 to date. The OCR settlements have impacted a wide range of sectors in the health industry from health insurers, to hospital systems, physician clinics, FQHCs, mental health and substance abuse providers, business associates, and nonprofits serving those with AIDS/HIV. Enforcement has been taken against all sizes of entities, including against solo practitioners and very small non-profits. As with nearly all settlements with OCR, it was the initial breach notification that triggered the investigation. However, the settlement ultimately resulted after OCR’s investigation discovered widespread non-compliance with HIPAA’s privacy and security requirements. The following post provides a summary of these enforcement actions, and begins with an update about Anthem’s recent $39.5M settlement with 43 states and D.C. stemming from its massive data breach in 2014-2015, which resulted in a record $16 million settlement with OCR in 2018. Health Insurer Enforcement Anthem and 43-State Coalition Reach $39.5 Million Settlement Over Data Breach On September 30, 2020, state attorneys general in 43 states and Washington D.C. announced that they had reached a $39.5 million settlement with Anthem Inc., an Indianapolis, IN-based health insurer. This settlement stemmed from an investigation by the state attorneys general into the largest health data breach in history, a series of state-sponsored cyberattacks in December 2014 and January 2015 that exposed the ePHI of nearly 79 million individuals. In 2018, Anthem agreed to pay $16 million to OCR and to take substantial corrective action to settle potential violations of the HIPAA privacy and security rules related to the 2014 data breach. See the HHS press release about the OCR settlement here. Anthem has also paid $115 million to settle a class action related to the breach, the largest-ever class action settlement related to a data breach. Premera Blue Cross Pays $6.85 Million to Settle Data Breach Affecting Over 10.4 Million People In March, in the second-largest HIPAA settlement ever, Premera Blue Cross (PBC), the largest health plan in the Pacific Northwest, agreed to pay $6.85 to OCR and to implement a corrective action plan to settle potential HIPAA privacy and security rules violations related to a data breach. Using malware installed through a phishing email, cyber-attackers gained access to PBC’s system in August 2014 and went undetected until January 2015, resulting in the exposure of over 10.4 million individuals’ electronic protected health information (ePHI). OCR’s investigation determined that PBC had “systemic noncompliance with the HIPAA Rules including failure to conduct an enterprise-wide risk analysis, and failures to implement risk management, and audit controls.” See the HHS press release here. Hospital and Health System Enforcement Lifespan Pays $1.04 Million to Settle Unencrypted Stolen Laptop Breach Affecting Over 20,000 People In June, Lifespan Health System Affiliated Covered Entity (“Lifespan ACE”), a Rhode Island-based non-profit health system, agreed to pay a $1.04 million settlement to OCR and to adopt a corrective action plan to settle potential violations of the HIPAA privacy and security rules related to the theft of a hospital employee’s unencrypted laptop. The laptop contained the ePHI of more than 20,000 individuals. OCR’s investigation determined that there had been systematic noncompliance with the HIPAA Rules, including a failure to encrypt ePHI on laptops, a lack of device and media controls, and a failure to have a business associate agreement in place with the Lifespan Corporation, the parent company and business associate of Lifespan ACE. See the HHS press release here. Physician and Clinic Enforcement Solo Practice Pays $100,000 for Failing to Implement HIPAA Security Rule Requirements In February, Steven A. Porter, M.D., a Utah gastroenterologist and solo practitioner, agreed to pay $100,000 to OCR and to adopt a corrective action plan to settle a potential violation of the HIPAA security rule. OCR determined that Dr. Porter’s practice had demonstrated significant noncompliance with the HIPAA rules, specifically, failing to conduct any risk analysis and failing “to implement security measures sufficient to reduce risks and vulnerabilities to a reasonable and appropriate level.” See the HHS press release here. Orthopedic Clinic Pays $1.5 Million to Settle Systemic Noncompliance with HIPAA Privacy and Security Rules In July, Georgia-based Athens Orthopedic Clinic PA (“Athens Orthopedic”) agreed to pay $1.5 million to OCR and to implement a corrective action plan to settle potential violations of the HIPAA privacy and security rules. A hacker used a vendor’s credentials to access Athens Orthopedic’s electronic medical record system and exfiltrated patient health data, then demanded money from Athens Orthopedic in return for the return of the stolen records. Nearly 210,000 individuals were affected by the breach. OCR’s investigation found noncompliance with the HIPAA privacy and security rules, including “failures to conduct a risk analysis, implement risk management and audit controls, maintain HIPAA policies and procedures, secure business associate agreements with multiple business associates, and provide HIPAA Privacy Rule training to workforce members.” See the HHS press release here. FQHC Pays $25,000 for Failing to Implement HIPAA Security Rule Requirements In March, Metropolitan Community Health Services (“Metro”), doing business as Agape Health Services, agreed to pay $25,000 to OCR and to implement a corrective plan to settle potential violations of the HIPAA security rule. In 2011, Metro reported impermissible disclosure of PHI to an unknown email account, which affected over 1,200 patients. OCR’s investigation found that Metro had failed to conduct any risk analysis, failed to implement any HIPAA security rule policies and procedures, and not provided workforce members with security awareness training until 2016. Metro is a Federally Qualified Health Center that provides medical services in underserved areas in rural North Carolina on a sliding fee scale, which was taken into account in reaching this agreement. See the HHS press release here. Business Associate Enforcement CHSPSC Agrees to Pay $2.3 Million to Settle Data Breach Affecting Over 6 Million People In March, CHSPSC LLC (“CHSPSC”) agreed to pay $2.3 million and to adopt a corrective action plan to settle potential violation of the HIPAA privacy and security rules related to a breach affecting more than 6 million people. CHSPSC is based in Tennessee and provides a variety of business associate services, including IT and health information management. In 2014, the Federal Bureau of Investigation (FBI) notified CHSPSC that it had traced a cyber-attack to CHSPSC’s information system. OCR’s subsequent investigation found “longstanding, systematic noncompliance” with the HIPAA security rule, including “failure to conduct a risk analysis, and failures to implement information system activity review, security incident procedures, or access controls.” See the HHS press release here. Right of Access Initiative Enforcement In 2019, OCR announced the Right of Access Initiative as an enforcement priority to support individuals’ right to timely access to their health records at a reasonable cost and in the readily producible format of their choice under the HIPAA privacy rule’s right of access provision, 45 CFR § 164.524. The HIPAA Rules generally require covered health care providers to provide medical records within 30 days of the request and providers can only charge a reasonable cost-based fee. This right to patient records extends to parents seeking access to their minor children’s medical records. To date this year, OCR has completed seven enforcement actions totaling $396,500 in settlement payments under the Right of Access Initiative, bringing the total number of enforcement settlements under this initiative to nine. In June, Housing Works Inc. (Housing Works), a New York City-based non-profit organization providing a range of services to individuals living with and affected by HIV/AIDS, including health care, agreed to pay $38,000 to OCR and to take corrective actions to settle a potential right of access violation. In complaints filed with OCR in July and August 2019, a patient alleged that he had not received his records in response to a June 2019 request. OCR opened an investigation, found a possible violation, and the patient received his medical records in November 2019. In July, All Inclusive Medical Services (AIMS), a California-based multi-specialty family medicine clinic, has agreed to pay $15,000 to OCR and to adopt a corrective action plan to settle a potential right of access violation. A patient alleged that in January 2018, AIMS had denied her requests to inspect and receive a copy of her records, in an April 2018 complaint filed with OCR. The patient ultimately received her medical records in August 2020. In August, Beth Israel Lahey Health Behavioral Services (BILHBS), the largest network of mental health and substance use disorder services in eastern Massachusetts, agreed to pay $70,000 to OCR and to take corrective actions following a potential right of access violation. A personal representative filed a complaint with OCR in April 2019 alleging that she had requested her father’s medical records in February 2019 and BILHBS had failed to provide them. BILHBS provided the requested medical records in October 2019. In August, Patricia King, M.D. (King MD), a small provider of psychiatric services in Virginia, agreed to pay $3,500 to OCR and to adopt a corrective action plan to settle a potential right of access violation. OCR received a complaint from a patient in October 2018, alleging that King MD failed to respond to her August 2018 request for her medical records. After OCR provided King MD with technical assistance on right of access requirements, a second complaint, and an OCR investigation that found that the failure to provide the requested medical records was a potential violation, the patient received her medical records in July 2020. In August, Wise Psychiatry, PC (Wise Psychiatry) a small provider of psychiatric services in Colorado, agreed to pay $10,000 to OCR and to take corrective actions to settle a potential right of access violation. A father requested his minor son’s medical records in November 2017, and following two complaints to OCR, OCR providing technical assistance to Wise Psychiatry on the HIPAA right of access requirements, and OCR opening an investigation, Wise Psychiatry sent the requested medical records in May 2019. See HHS’s press release about OCR’s first five right to access settlements of 2020 here. In September, Dignity Health, doing business as St. Joseph’s Hospital and Medical Center (SJHMC), agreed to pay $160,000 and to adopt a corrective action plan to settle a potential right of access violation. SJHMC is based in Arizona and is a large, acute-care hospital with several hospital-based clinics. A mother made several requests for her son’s medical records, as his personal representative, beginning in January 2018, but did not receive all of the requested records until December 2019. See the HHS press release here. In September, NY Spine Medicine (NY Spine), a private medical practice specializing in neurology and pain management with offices in New York and Florida, agreed to pay $100,000 and to take corrective actions to settle a potential right of access violation. A patient requested a copy of her medical records in June 2019, and NY Spine provided some records in response, but did not provide the diagnostic films that the patient had specifically requested until October 2020, after OCR had initiated an investigation. See the HHS press release here. OCR’s enforcement of the HIPAA security and privacy rules this year is increasingly aggressive. Per HHS, OCR’s enforcement actions are “designed to send a message to the health care industry about the importance and necessity of compliance with the HIPAA Rules.” If you have questions about HIPAA compliance, please contact the authors, your regular Dorsey attorney or any attorney in the Dorsey & Whitney health transactions and regulations practice group.
October 15, 2020
Organ Donation
Finalized Rule to Remove Disincentives to Living Organ Donation
On September 22, 2020, the Department of Health and Human Services (“DHHS”) finalized a new rule to expand the scope of qualified reimbursable expenses incurred by living organ donors to include lost wages, child-care expenses, and elder-care expenses. The new rule goes into effect on October 22, 2020, and is a win for living organ donation. This final rule aligns with the initial proposed rule, and you can read our post on the proposed rule here for additional background. The final rule is associated with Section 8 of Executive Order 13879 titled “Advancing American Kidney Health,” issued on July 10, 2019. The Executive Order directed DHHS to propose a regulation allowing living organ donors to be reimbursed for related lost wages, child-care expenses, and elder-care expenses through the Reimbursement of Travel and Subsistence Expenses Incurred toward Living Organ Donation program (the “Program”) authorized under section 377 of the Public Health Service Act. Every 10 minutes, another person is added to the national organ transplant waiting list, and approximately 20 people die every day while waiting for a transplant. This final rule should expand the pool of willing organ donors and also improve donation outcomes by: (i) providing for the receipt of more high quality organs; (ii) reducing the waiting period for an organ; and (iii) resulting in better clinical outcomes than continuing dialysis or receiving a deceased donor kidney transplant. A new regulatory section will be added at 42 C.F.R. § 121.14 to list the categories of “incidental non-medical expenses” to include lost wages, child-care expenses, and elder-care expenses. The other criteria of the Program remain applicable and will still need to be met for reimbursement to be provided to living organ donors and other individuals evaluated for living organ donation. Of note, concurrently with the publication of this final rule DHHS published a final notice that changes the Program’s eligibility guidelines to increase the household income eligibility threshold to 350 percent of the DHHS Poverty Guidelines (from the current threshold of 300 percent) for living organ donors and organ recipients. If you have any questions on this new rule, one of the authors or your regular Dorsey attorney would be happy to assist you.
October 1, 2020
CMS Guidance
CMS Issues Interim Final Rule to Enforce COVID-19 Reporting Requirements
The Centers for Medicare and Medicaid Services (“CMS”) published an Interim Final Rule in the Federal Register on September 2, 2020 to supplement and strengthen the agency’s enforcement of COVID-19 reporting requirements. The final rule also modifies various aspects of Medicare reimbursement methodologies for health plans, physicians, and other providers. This post summarizes each of these regulatory changes, which are effective as of September 2, 2020. New Enforcement Requirements for COVID-19 Related Data Reporting To assist public health officials in detecting and tracking COVID-19 outbreaks and save lives, CMS is adding new reporting requirements for healthcare facilities along with expanded CMS enforcement authority to ensure compliance with such reporting requirements. The Interim Final Rule addresses reporting and related enforcement for three general categories of healthcare entities: long term care (LTC) facilities, hospitals and critical access hospitals (CAHs), and laboratories. A. LTC Facilities Under CMS regulations issued in May, LTC facilities are required to electronically report COVID-related data to the Centers for Disease Control and Prevention (CDC) on a weekly basis. Facilities must report a variety of information, including suspected and confirmed COVID-19 infections among residents and staff, the number of COVID-19 resident and staff deaths, the personal protective equipment and hand hygiene supplies in the facility, and more. The Interim Final Rule allows CMS to impose civil money penalties (“CMPs”) if a LTC facility fails to submit its weekly report. CMS may impose a minimum of $1,000 for an initial violation. For every subsequent time the facility fails to report the required data, the CMP imposed will increase by $500, up to a maximum of $6,500. For example, a facility that fails to report for two consecutive weeks will be subject to a minimum CMP of $2,500: $1,000 for the first week and $1,500 for the second week. CMS waived the normal notice-and-comment process due to the urgent need to track and contain COVID-19 infection outbreaks. LTCs are subject to these new penalties for reporting failures effective September 2, 2020, and the penalties will continue to be in effect for up to one year beyond the end of the COVID-19 public health emergency (“PHE”). B. Hospitals and CAHs The Interim Final Rule also makes daily reporting of COVID-related data a Condition of Participation in the Medicare and Medicaid programs for hospitals and CAHs. To support broader surveillance of the spread of COVID-19, CMS will require hospitals and CAHs to report certain COVID-related information to the Department of Health and Human Services (“HHS”) daily, through a standardized format specified by HHS, set forth here. CMS does not have authority to impose CMPs on hospitals or CAHs who fail to provide this reporting. However, should a hospital or CAH fail to consistently report test results throughout the duration of the PHE, it will be non-compliant with the hospital and the CAH Conditions of Participation set forth at 42 CFR §§ 482.42(e) and 485.640(d), respectively, and consequently subject to CMS termination of its Medicare provider agreement. C. Laboratories Additionally, the Interim Final Rule modifies the Clinical Laboratory Improvement Amendments of 1988 (“CLIA”) to require all laboratories to report SARS-CoV-2 test results within 24 hours of a positive test result. Reports must be made throughout the PHE, as specified here. If a laboratory fails to submit SARS-CoV-2 test results as required under the CLIA modifications, the Department of Health and Human Services may impose CMPs or other penalties on the laboratory. CMS states that CMPs for reporting violations will be $1000 for the first day of noncompliance, and $500 for each subsequent day the laboratory fails to report SARS-CoV-2 test results. The applicable statute allows for the imposition of CMPs of up to $10,000 for each violation. LTCs Must Test Residents and Staff for COVID-19 In addition to reporting COVID-related data, LTCs are required under the new rule to test their facility residents and staff for COVID-19. Testing includes not only staff employees, but volunteers and those providing services under arrangements at the facility. Testing must be conducted in a manner consistent with current professional standards of practice for COVID testing. Documentation of testing and resulting must be provided in staff personnel records, and in resident medical records. CMS has published additional guidance here that addresses testing frequency, types of testing that should be conducted, and guidance on handling staff who refuse testing, among other topics. Limitation on Medicare Coverage of COVID-19 Testing Without an Order In a prior Interim Final Rule with Comment Period, CMS expanded coverage for COVID-19 testing for Medicare beneficiaries by eliminating the need for an order from a treating physician or other practitioner. CMS has now revised this policy, citing fraud and abuse concerns and clinical concerns that beneficiaries are receiving too many COVID-19 tests without medical attention and oversight. Consequently, beginning September 2 and continuing for the duration of the PHE, Medicare will cover only one (1) COVID-19 diagnostic test without the order of a physician or other practitioner. A single otherwise covered laboratory test each for influenza or a similar respiratory condition needed to obtain a final COVID-19 diagnosis, when performed in conjunction with a COVID-19 test, will also be covered. Medicare will cover additional COVID-19 tests only with the order of a physician or other practitioner. Any COVID-19 test(s) that a beneficiary received prior to September 2, 2020 is disregarded for purposes of this new single COVID-19 test coverage rule. CMS points out that this coverage rule applies to the Medicare program only; COVID-19 testing coverage policies for group health plans, health insurance issuers, and other public programs must comply with applicable law. CMS is also allowing pharmacists and other practitioners allowed to order laboratory tests in accordance with state scope of practice and other laws to fulfill the requirements related to orders for covered COVID-19 tests for Medicare patients. Quality Reporting: Updates to the Extraordinary Circumstances Exceptions (ECE) Granted for Four Value-Based Purchasing Programs in Response to the PHE for COVID-19, and Update to the Performance Period for the FY 2022 SNF VBP Program Early in the PHE, CMS granted several “Extraordinary Circumstances Exceptions” (“ECEs”) which relieved facilities of certain data collection and reporting obligations so that more time and resources could be directed to patient care. CMS used such data reporting to score certain program performance, resulting in adjustments of Medicare payments pursuant to certain value-based and quality-related features of Medicare reimbursement methodologies. CMS states that, although it was gathering data on these programs, it has concerns about the national comparability of data due to the geographic differences of COVID-19 incidence rates and hospitalizations and the impacts of varying state and local laws and policy changes implemented in response to COVID-19. Therefore, the Department proposes updating the ECEs it granted for the following value-based purchasing programs: The End-Stage Renal Disease Quality Incentive Program (ESRD QIP); The Hospital-Acquired Condition (HAC) Reduction Program; The Hospital Readmissions Reduction Program (HRRP); and The Hospital Value-Based Purchasing (HVBP) Program. Under the updated ECEs, CMS will only score data that was voluntarily reported for the fourth quarter of calendar year 2019. Further, CMS will exclude all data reported for the first or second quarter of calendar year 2020, due to the significant and variable impacts COVID-19 had on facilities during this period. In addition, the Interim Final Rule updates the performance period for the fiscal year 2022 SNF VBP Program, because CMS believes that the current measurement periods would not produce reliable results for measuring SNF quality of care as determined by hospital readmission rates. The measurement periods are changing from October 1, 2019 through December 31, 2019 and July 1, 2020 through September 30, 2020 to April 1, 2019 through December 31, 2019 and July 1, 2020 through September 30, 2020. NCD Procedural Volumes for Facilities and Practitioners to Maintain Medicare Coverage The Interim Final Rule acknowledges that, because of the PHE, far fewer non-essential procedures have been performed over the past several months. As a result, hospitals and practitioners may not be able to meet certain procedural volume requirements that are set forth in certain national coverage determinations (“NCDs”), including: NCD 20.34 Percutaneous Left Atrial Appendage Closure (LAAC). NCD 20.32 Transcatheter Aortic Valve Replacement (TAVR). NCD 20.33 Transcatheter Mitral Valve Repair (TMVR). NCD 20.9.1 Ventricular Assist Devices (VADs). Typically, failure to meet the procedural volume requirements would prevent Medicare payment for those categories of procedures. However, CMS will not enforce the procedural volume requirements contained in the four above-noted NCDs because of disruptions caused by the PHE. This waiver of enforcement only applies to facilities and practitioners that had met the volume requirements prior to the PHE for COVID-19. All other non-volume based coverage requirements under these NCDs remain in effect. Merit-Based Incentive Payment System (MIPS) Updates CMS is making changes to the Merit-Based Incentive Payment System (“MIPS”) for physicians and other clinicians, to reflect the manner in which Medicare beneficiaries are receiving primary care services during the PHE. For the 2020 MIPS performance year and any subsequent performance year that starts during the PHE, CPT and HCPCS codes for communications technology-based services and telephone evaluation and management services are to be included in the definition of primary care services under MIPS. This will allow those remote services to be included in CMS determinations of where Medicare beneficiaries receive a plurality of their primary care services for purposes of MIPS beneficiary assignment to physicians and other clinicians. CMS is also modifying one of the Improvement Activities in MIPS relating to COVID-19 clinical trial participation, so that clinicians can receive credit under this Improvement Activity not only for participating in a COVID-19 clinical trial, but also for participating in the care of patients diagnosed with COVID-19 and simultaneously submitting relevant clinical data to a clinical data registry for ongoing or future COVID-19 research. Recognizing Temporary Premium Credits as Premium Reductions CMS previously adopted policies allowing health insurance issuers offering health insurance coverage in the individual and small group markets on the American Health Benefit Exchanges established under The Patient Protection and Affordable Care Act (Pub. L. 111-148) to grant temporary premium credits for individuals and small businesses that may be struggling to pay premium during the PHE. In this Interim Final Rule, CMS makes a number of technical changes and clarifications to ensure that health plan premium reporting takes into account any premium credits granted, including for purposes of medical loss ratio (MLR) reporting and rebates. Part C and Part D Health Plan Star Ratings Finally, CMS made changes to the Star Rating system for Medicare Part C and Part D health plans. The Star Rating system allows CMS to publish comparative information to beneficiaries about Medicare Advantage and Medicare Part D health plans, and is the basis for determining quality bonus payments to Medicare Advantage plan, as well as beneficiary rebates. CMS currently excludes certain scores within the Stark Rating system if a plan has 60 percent or more of its enrollees living in a Federal Emergency Management Agency (FEMA)-designated Individual Assistance area. Because of the PHE, the maintenance of this rule would remove almost all plans from those scoring metrics. Consequently, CMS is removing that 60 percent rules for the 2022 Star Ratings (for which 2020 is the measurement year) to avoid having to exclude the vast majority of plans from the methodology. This recent Interim Final Rule clearly indicates that CMS wants to ensure consistent reporting of COVID-19 related data from laboratories, hospitals and long term care facilities. It also illustrates the profound and widespread degree to which the PHE continues to impact Medicare reimbursement methodologies and systems. If you have any questions about the Interim Final Rule or any of the topics addressed in this post, please contact the authors or any member of the Dorsey & Whitney Health Transactions & Regulations Practice Group.
September 11, 2020
DOJ
DOJ Demonstrates Continued Focus on Opioid Crisis with $600 Million Criminal and Civil Settlement Against Indivior Solutions, Indivior Inc., and Indivior plc
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. We would like to thank Vanessa J. Szalapski for the following post from Dorsey’s FCA Now blog: The Department of Justice’s (“DOJ”) most recent settlement with Indivior Solutions, Inc., Indivior Inc., and Indivior plc (together, “Indivior”) demonstrates not only that the DOJ is continuing its pursuit of claims and settlements related to the opioid crisis, but also that the DOJ is searching for creative penalties beyond large monetary payouts. [Continue Reading]
August 25, 2020
Compliance Programs
Is Your Compliance Program More than a Paper Program? DOJ Issues Revised Guidance for Evaluating Corporate Compliance Programs
On June 1, 2020, the Department of Justice (“DOJ”) issued an updated version of its “Evaluation of Corporate Compliance Programs” (the “DOJ Guidance”), available here. The DOJ Guidance is an update to guidance first issued by the DOJ in February 2017 (which we described in our prior blog post), and was last updated by the DOJ in April 2019. Although the DOJ Guidance is directed to prosecutors, it is a useful roadmap for corporations in seeking to ensure their compliance program is effectively preventing, detecting and responding to improper conduct, and is not a program on paper only. The DOJ Guidance is intended to be used by prosecutors to assist them “in making informed decisions as to whether, and to what extent, [a] corporation’s compliance program was effective at the time of [an] offense, and is effective at the time of a charging decision or resolution, for purposes of determining the appropriate (1) form of any resolution or prosecution; (2) monetary penalty, if any; and (3) compliance obligations contained in any corporate criminal resolution (e.g., monitorship or reporting obligations).” Thus, in the event that there is an investigation into alleged improper conduct, having a compliance program that operates in line with the DOJ Guidance may lead to a more favorable resolution than there otherwise would be. The DOJ Guidance notes that there are three “fundamental questions” a prosecutor should ask when evaluating compliance programs: Is the corporation’s compliance program well designed? Is the program being applied earnestly and in good faith? In other words, is the program adequately resourced and empowered to function effectively? Does the corporation’s compliance program work in practice? The DOJ Guidance sets forth a number of sample topics under the heading of each of the three questions listed above, which it says are not a checklist or formula, but are the topics “that the Criminal Division has frequently found relevant in evaluating a corporate compliance program both at the time of the offense and at the time of the charging decision and resolution.” The DOJ Guidance emphasizes the importance of a compliance program being not merely a “paper program,” but rather one that is “implemented, reviewed, and revised, as appropriate, in an effective manner.” The most recent updates to the DOJ Guidance reflect the DOJ’s increased focus of taking a functional and dynamic approach to evaluating the effectiveness of a company’s compliance program. The revisions explain new factors prosecutors may consider in the areas of risk assessment, policies and procedures, training and communications, mergers and acquisitions, and more in their assessment of corporate compliance programs. Organizations should use the DOJ Guidance, including a consideration of these new factors, when evaluating the effectiveness of their compliance program. Key revisions to the DOJ Guidance are summarized below. Risk Assessments. The DOJ Guidance directs prosecutors to consider whether a company has “a process for tracking and incorporating into its periodic risk assessment lessons learned either from the company’s own prior issues or from those of other companies operating in the same industry and/or geographical region.” Prosecutors are also instructed to evaluate whether a company takes a continuous assessment approach to compliance review and updates, as opposed to a “snapshot-in-time” approach. Thus, it is imperative that compliance teams at an organization perform regular assessments, stay up-to-date on compliance problems, and incorporate lessons learned into the risk assessment process. Policies and Procedures. The DOJ Guidance continues to emphasize the importance of adequately communicating compliance policies and procedures throughout the company. The update includes two new questions related to the accessibility of policies and procedures: “Have the policies and procedures been published in a searchable format for easy reference?” and “Does the company track access to various policies and procedures to understand what policies are attracting more attention from relevant employees?” Training and Communications. New questions in the DOJ Guidance instruct prosecutors to evaluate whether a company is evaluating the effect of its training program on employee behavior or operations. Additionally, the DOJ will be assessing whether employees have opportunities to ask questions and whether the company overall has “relayed information in a manner tailored to the audience’s size, sophistication, or subject-matter expertise.” Confidential Reporting. The revisions also address confidential employee hotlines and other reporting mechanisms. Prosecutors will assess whether confidential reporting mechanisms are publicized both to employees and third parties, and whether a company is periodically testing the mechanism’s effectiveness. Third-Party Management. The DOJ Guidance adds a new question about a company’s management of third-party relationships: is risk assessment conducted only during the onboarding process or throughout the lifespan of the engagement? Mergers and Acquisitions. The DOJ has always considered comprehensive due diligence of acquisition targets to be an important part of a compliance program. The recent revisions to the DOJ Guidance, however, recognize that pre-acquisition due diligence may not always be possible. Where such pre-acquisition diligence is not conducted, the DOJ Guidance indicates that a company should have a legitimate reason for not conducting it, and that the company should conduct post-acquisition diligence and audits. In addition, an acquired entity should always be timely integrated into a company’s existing compliance program structure. Compliance Resources. Adequate resources are essential for effective implementation of a compliance program. The DOJ Guidance instructs prosecutors to ask whether a company’s compliance program is “adequately resourced and empowered to function effectively.” Companies should continue to invest in the training and development of personnel and in the compliance program more broadly, throughout all levels of the organization. * * * Overall, the revised DOJ Guidance affirms previous guidance and stresses that compliance programs should be well-resourced, dynamic, and tailored to a company’s unique size, structure, and needs. The DOJ Guidance also serves as a reminder that even in the midst of a global pandemic, the compliance function of an organization must remain robust and ever-adapting. Healthcare organizations should use the DOJ Guidance and other existing resources to thoughtfully design, assess, and revise their compliance programs. Dorsey attorneys have substantial experience with assisting health industry clients in implementing compliance programs following the elements of an effective compliance program from the Department of Health and Human Services Office of Inspector General, in updating compliance programs, and in evaluating the effectiveness of existing compliance programs in line with the DOJ Guidance and other guidance. For assistance with your organization’s compliance program, please contact the authors or your regular Dorsey attorney.
July 10, 2020