Dorsey Health Law
Accountable Care Organizations
CMS Announces Relief for Participants in Quality Reporting Programs in Response to COVID-19
On March 22, 2020, the Centers for Medicare & Medicaid Services (CMS) announced in a press release that it is granting exceptions from reporting requirements and extensions for upcoming data submission and measure reporting deadlines for Medicare quality reporting programs. The exceptions and extensions are intended to reduce data collection and reporting burdens for entities that are responding to COVID-19 so that they can continue to focus on caring for patients. CMS states that this is “unprecedented relief for the clinicians, providers, and facilities participating in Medicare quality reporting programs including the 1.2 million clinicians in the Quality Payment Program and on the front lines of America’s fight against the 2019 Novel Coronavirus (COVID-19).” The CMS programs impacted by this “extreme and uncontrollable circumstances” policy exceptions and extensions include, among others, the Quality Payment Program–Merit-based Incentive Payment System (MIPS), Medicare Shared Savings Program Accountable Care Organizations (ACOs), and various hospital quality reporting programs (e.g., Hospital-Acquired Condition Reduction Program). CMS provided a table in the press release indicating how both 2019 and 2020 data submissions are impacted. For programs that have data submission deadlines in April and May 2020, this submission will be optional. In addition, no data reflecting services provided from January 1 through June 30, 2020 will be used in CMS’s calculations for value-based purchasing programs and Medicare quality reporting. CMS stated as follows: “CMS recognizes that quality measure data collection and reporting for services furnished during this time period may not be reflective of their true level of performance on measures such as cost, readmissions and patient experience during this time of emergency and seeks to hold organizations harmless for not submitting data during this period.” For other Dorsey publications on Medicare’s Quality Payment Program, see here and here.
March 23, 2020
Employee Benefits
Supreme Court holds “actual knowledge” in ERISA statute means “what it says”
On February 26, 2020, the Supreme Court held that the term “actual knowledge” in the ERISA statute of limitations clause found in 29 U.S.C. §1113(2), ERISA §413 applicable to breach of fiduciary duty cases means “what it says”: “to have ‘actual knowledge’ of a piece of information, one must in fact be aware of it.” The ruling came out of the case Intel Corp. Investment Policy Committee v. Sulyma, No. 18–1116, filed in 2015 by an ERISA plan participant on behalf of a putative class alleging that the Intel Corp. Investment Policy Committee (“Intel”) breached its fiduciary duties when it increased investments in “alternative” investments (e.g. hedge funds, private equity, and commodities) that generated sub-par returns in the post-recession market. Sulyma received disclosures from Intel regarding the Committee’s investment decisions in 2011 and 2012, but he testified that he did not remember viewing them. After Sulyma filed suit in 2015, Intel moved for summary judgment, arguing that because he received the disclosures more than three years earlier, his claim was time barred under the three-year statute of limitations set forth in §1113(2). Rejecting Sulyma’s argument that his claim was instead subject to ERISA’s six-year statute of repose, the district court agreed with Intel and granted its motion for summary judgment. The Ninth Circuit reversed on the basis that “actual knowledge” required more than proof of sufficient disclosure, further widening a circuit split created by a 2010 Sixth Circuit opinion holding that actual knowledge required only such disclosure. See Brown v. Owens Corning Investment Review Comm., 622 F.3d 564, 571 (6th Cir. 2010). The Supreme Court affirmed the Ninth Circuit, thereby resolving the circuit split. To arrive at this holding, the Supreme Court relied on dictionary definitions, past precedent, and Congress’s repeated “linguistic distinctions” in the ERISA statutory scheme regarding what a plaintiff should know or actually knows. Specifically, the Court placed great stock in the fact that in some parts of the ERISA statutory scheme, Congress created statutes of limitation based on “the earliest date on which the plaintiff acquired or should have acquired actual knowledge of the existence of such cause of action,” while in others it specified only actual knowledge. Compare 29 U.S.C. §1303(e)(6), (f)(5) (emphasis added) with §1113(2). Because section 1113(2) provides only for “actual knowledge” without explicitly identifying any other forms of knowledge, the Court ruled that constructive knowledge was not enough to trigger the statute. Although Sulyma involved a retirement plan, it has implications for employer-sponsored health plans that are also governed by ERISA. While the Court’s ruling makes it harder for defendants to win summary judgment on ERISA’s three-year “actual knowledge” statute of limitation, the Court did not entirely foreclose such relief. The Court stated defendants can still prove actual knowledge through inferences from circumstantial evidence, such as evidence of disclosure, electronic records showing receipt and reviews of those disclosures, and actions taken in response to the information contained within them. But such evidence may be disputed as a factual matter, making judgment on an early dispositive motion more difficult. Nevertheless, some plan sponsors may wish to consider implementing additional procedures associated with the distribution of plan documents and the disclosure of plan information to create a stronger evidentiary record of when participants become aware of a particular development. In addition, the Court opened a potential window for defeating motions for class certification. Under the Federal Rules of Civil Procedure, a class may be certified only when plaintiffs present “common issues” of law and fact, and when their claims are “typical” of those of others in the class. Fed. R. Civ. P. 23. Whether a participant had “actual knowledge” of a particular communication or disclosure that might trigger the statute is inherently individual in nature, arguably precluding certification of a class. Thus, although Sulyma may provide ERISA plan participants with additional ammunition for defeating statute of limitation defenses in fiduciary misconduct cases, such claims may be more difficult to certify. Finally, although the Sulyma Court did not address the subject, employers should be mindful of potential opportunities to manage ERISA risk by incorporating shorter limitation periods in plan documents. In Heimeshoff v. Hartford Life & Acc. Ins. Co., 571 U.S. 99 (2013), the Supreme Court ruled that plans could impose shorter statutes of limitations on ERISA claims for benefits. Sponsors who choose to include such plan terms should be careful to ensure that these limits are consistent with updated case law and are properly communicated to participants and claimants. Although there is little case law providing that this same rule will apply to breach of fiduciary duty claims, compare Hewitt v. W. & S. Fin. Group Flexible Benefits Plan, 17-5862, 2018 WL 3064564, at *2 (6th Cir. Apr. 18, 2018) (enforcing plan provision for shorter statute of limitations to fiduciary claim) with Chelf v. Prudential Ins. Co. of Am., 3:17-CV-00736-GNS, 2018 WL 4219424, at *7 (W.D. Ky. Sept. 5, 2018) (declining to enforce plan provision for shorter statute of limitations to fiduciary claim), courts may provide greater clarity in future litigation.
March 23, 2020
coronavirus
COVID-19 and Cross-State Clinician Licensure: Federal and State Regulations, Revisited, and What To Do About Them
The COVID-19 pandemic has dramatically increased the number of patients and providers seeking to implement and use telehealth visits and other digital health solutions – and rapidly, at that. The challenge of implementing digital health solutions, particularly telehealth, has historically been the patchwork setup of both federal and various state regulations that made it difficult for providers and telehealth vendors to offer solutions at a large scale, particularly across state lines. In the current state of public emergency, both the federal government and various state governments are recognizing the need to ease prior restrictions and expand telehealth availability in order to help patients receive care at home; this helps limit the spread of COVID-19 by further enabling social distancing and freeing up providers’ brick-and-mortar hospitals and clinics to treat COVID-19 patients. The need is clear, as is the desire by all parties to jump in and offer telehealth visits. The new challenge has become understanding how state requirements fit in daily updates to federal law. In this blog post, we will look first to the current legal environment with respect to the federal waiver and state regulations, and then provide recommendations (in numbered list below) as to what this means for your plans to offer telehealth visits. Specifically, clinical licensure has traditionally been amongst the most challenging regulations to contend with in offering telehealth visits. Federal reimbursement and state clinician licensure rules generally restrict clinicians from offering telehealth services to a patient physically located in a state without the appropriate medical license in that state. Now, however, through CMS 1135 waivers and state-specific executive orders, which we have described more below, clinicians are able to leverage relaxed cross-state reimbursement and licensure rules to offer telehealth services more easily and immediately during this time of public health emergency. Historically, the general rule, with few exceptions, is that a clinician must be licensed to practice in the state in which the patient receiving telehealth services is located. These rules are derived from state professional licensing laws, as well as from payor requirements, including the conditions of payment under the Medicare and Medicaid programs. Therefore, a physician licensed to practice in Minnesota, for example, could not typically provide telehealth services to a patient located in Iowa during the time of the visit without first obtaining an Iowa license to practice medicine. Failure to do so could subject the physician’s medical license to discipline, and could also render the services not billable to various private and governmental payors. Currently, the in-state licensure requirements of payors and professional licensing bodies are beginning to change within the confines of the COVID-19 public health emergency. With respect to Medicare and Medicaid billing requirements, under the emergency proclamation by the President, CMS has the authority to issue “1135 waivers” that will temporarily waive or modify certain Medicare and Medicaid requirements to ensure that sufficient health care items and services are available to meet the needs of individuals enrolled in Federal health care programs. Shortly following the Proclamation on Declaring a National Emergency Concerning the Novel Coronavirus Disease (COVID-19) Outbreak, both HHS and CMS issued statements announcing a number of COVID-19 1135 waivers now either applicable automatically nationwide or available through request by individual providers and the states, depending on the type of waiver. These waivers encompass an array of options and relaxing of rules that apply to services provided to Medicare and Medicaid patients. One of the waivers provides that CMS will “temporarily waive [reimbursement] requirements that out-of-state providers be licensed in the state where they are providing services when they are licensed in another state” (the “Clinician Licensing Waiver”). (Other waivers ease restrictions surrounding provider Medicare and Medicaid enrollment, skilled nursing and other long-term care facility requirements, and bed allocation requirements). This is an enormous and important shift, and one that digital health advocates have been championing for a long time, as it enables clinicians to “see” patients in other states without a protracted cross-state licensure process. The challenge, however, is understanding how the federal waivers and existing state requirements interact. These 1135 waivers apply only to federal requirements, and any providers looking to practice in accordance with these waivers must be careful to also comply with applicable state laws. Largely, the COVID-19 1135 waivers fall in two categories: (1) blanket waivers; and (2) case-by-case waivers. The blanket waivers include those waivers listed by CMS in their statement and are applicable automatically nationwide with respect to Medicare rules (not Medicaid or other CMS programs, except by request, as noted below). The Clinician Licensing Waiver is one such waiver. This waiver applies automatically to Medicare reimbursement, but clinicians must also ensure they are practicing in accordance with a particular state’s licensing rules before issuing professional services in that state. States that would like these Medicare blanket waivers, including the Clinician Licensing Waiver, to apply to their state’s Medicaid program must send a request to CMS for case-by-case approval. Currently, only Florida and Washington have received approval for their requested COVID-19 1135 waivers, including the Clinician Licensing Waiver along with other provider enrollment and prior authorization requirement waivers. However, CMS states that it will continue to expeditiously review and approve 1135 waivers during the COVID-19 public health emergency. This CMS website will provide up-to-date information on all states that receive any COVID-19 1135 waivers. While the Clinician Licensing Waiver is limited in applicability to Medicare and Medicaid reimbursement, states are beginning to follow suit by temporarily waiving their state level professional licensure requirements for telehealth providers. Still, providers should take caution to not provide services without a state license unless and until it is confirmed that the state will allow this practice. One state that we have identified as permitting telehealth practice without a state license during the COVID-19 public health emergency is Iowa. Iowa’s emergency proclamation contains a section that temporarily suspends various telehealth practice standards, including the requirement that Iowa telehealth providers be licensed in Iowa. Note, however, that commercial payor rules may be unaffected by both the federal waivers and the easing of state professional licensing rules. From an operational standpoint, the Clinician Licensing Waiver ostensibly eases offering telehealth visits across state lines, but the state-specific regulations still require ongoing vigilance. For those providers and other types of vendors seeking to offer telehealth, we would encourage the following: Identify exactly which populations you must be able to treat in order for the telehealth visits to be feasible and viable (financially and operationally) for your organization While organizations would like to be able to immediately offer telehealth visits for everyone, the reality at this time, while states sort out whether they will ease state licensure restrictions, is that you may only be able to conduct telehealth visits and receive reimbursement in states in which your clinician is allowed to practice without a license and for certain populations only. It will vary tremendously by state, and the answer may change on a near-daily basis, as states make their decisions. Speak with your attorney about the states in which you want to offer visits (or where your patient populations may currently be) to understand the current status for those states Per above, the situation is changing rapidly, and we strongly recommend asking your attorney to check the state’s status vis-à-vis the federal waivers. We would advise adding that into your tracking document (see next item). Draft your quick state-by-state plan and what your readiness checks will be to start with a new state (and do not worry – this can be rough-and-ready) We often help our clients with state rollout plans and readiness checklists, and they are still important now; however, given the dramatic need for speed, do not let the perfect be the enemy of the good. Based on your answers to the above two items, you should confirm with your team both the plan for which states you will be able to offer visits in and also the criteria for when and how you will assess and identify the next states in which you can offer telehealth services. You can perfect and polish these plans at a later point, but having a plan of action for all involved will prevent confusion or, worse, lack of compliance if you do not pay careful attention to states’ evolving rules. We would recommend that your state readiness checklist include an attorney approval step; this is particularly important now, since the states’ rules are changing so rapidly. The good news is that, for the most part, the changes are leaning toward the more permissive rather than restrictive, so you may find new states in which you are able to operate. Identify exactly which active state licenses your clinicians hold and document, ideally in a spreadsheet or other easy tracking mechanism We recommend (and create for our clients) tracking tools with respect to clinical licensure during regular times, and it is equally important now. While the goal is to be able to offer telehealth visits to patients in states in which your clinicians are not currently licensed, you will need to keep track of who is actually licensed where, so that if and when regulations should revert, or if and when there should be changes to the scope of licensure or reimbursement, you are able to quickly assess your own staff’s licensure status and pivot as needed. These tracking tools need not be fancy, though it is helpful to tie them to calendar reminders or other ticklers to enable consistent monitoring. Keep in mind – and regularly monitor – other relevant requirements as you contemplate the nature and process of the telehealth visits. For example, you will still want to abide by current HIPAA requirements (which are also changing during this public emergency – please see our article here), documentation requirements, and reimbursement-related considerations. Your standard operating procedure and telehealth visit process will likely need to be altered to include verbal caveats or discussion points between your providers and the patients. We would advise reviewing and then either drafting or updating your current visit script, as well as the documentation presented on your website portal for the telehealth visit. Your plan for downtime procedures is going to become all the more important – assess if you’re ready and that your providers are aware of what to do. With so many people using internet and particularly video chat services, our IT infrastructure and that of the telehealth platform vendors themselves is experiencing a surge in usage, which will test capacity levels. This would be the case in “regular” life, but becomes more important now, as you reach out to and conduct telehealth visits with new patients: does your script and posted information include information as to how the patient can reach you if the telehealth visit is interrupted? What should be their plan with respect to reaching out to local (in-state) providers versus your organization, both for downtime and post-visit? This issue is rapidly changing and being updated at both the Federal and state level on a day-to-day basis. For additional information on various COVID-19 responses, guidance and resources, please see our articles on Medicare payment for telehealth services; HIPAA provisions now allowing the use of personal devices and everyday communication technology to deliver telehealth; DEA prescribing laws now allowing controlled substances to be prescribed via telehealth without an in person exam; and numerous other helpful legal analyses and guidance on COVID-19 related matters. If you would like specific information on how your state is currently treating these issues, please reach out to the authors or your usual Dorsey attorney or Dorsey Health Strategies business consultant.
March 20, 2020
coronavirus
Medicare Telehealth Payment Expanded to Help Address the COVID-19 Public Health Emergency
On March 17, 2020, the Centers for Medicare and Medicaid Services (“CMS”) and the Department of Health and Human Services Office of the Inspector General (“OIG”) each issued policy statements which expand access to telehealth services for Medicare beneficiaries and permit physicians and other practitioners to reduce or waive beneficiary cost-sharing obligations for Medicare telehealth services during the COVID-19 public health emergency. Immediately following the enactment of the Coronavirus Preparedness and Response Supplemental Appropriations Act, available here, CMS issued a temporary expansion of the Medicare telehealth benefit beginning as of March 6, 2020 and effective until the public health emergency declared by the Secretary of the Department of Health and Human Services ends. The CMS policy statement can be found here. A key element of this telehealth expansion is that payment will be made for office visits and other covered Medicare telehealth services furnished to beneficiaries located in any part of the U.S. Moreover, the CMS waiver facilitates payment for telehealth services furnished while the beneficiary is located in their home or in any care setting. Without this emergency expansion, current Medicare rules at Social Security Act § 1834(m) generally limit coverage for telehealth services to beneficiaries located in rural areas, and only when the beneficiary is within a hospital, clinic, or other medical facility at the time of the telehealth visit. Clinicians who may offer telehealth services to Medicare beneficiaries include physicians, nurse practitioners, physician assistants, clinical social workers, clinical psychologists, and registered dieticians. CMS also states that to the extent Medicare reimbursement for a telehealth service requires a prior relationship between the clinician and beneficiary, CMS will use its enforcement discretion and not audit claims submitted during the public health emergency to determine if such a prior relationship existed. The CMS waiver explicitly permits clinicians to use telephones with audio and video capabilities to furnish Medicare telehealth services during the COVID-19 public health emergency. Together with the new waiver of certain HIPAA privacy rules (addressed in our prior blog post found here), this now will permit clinicians to conduct visits with Medicare beneficiaries using common communications tools such as personal phones, devices and computers, and common technologies such as FaceTime or Skype. CMS issued a FAQ document on this temporary and emergency telehealth benefit expansion, which can be found here. In tandem with CMS’ expansion of the Medicare telehealth benefit, the OIG issued a policy statement to address the potential anti-kickback and beneficiary inducement issues that providers may face during this emergency. OIG states that it will not sanction physicians or other practitioners for reducing or waiving cost-sharing obligations that a beneficiary may owe for telehealth services furnished during the COVID-19 public health emergency and furnished in accordance with the then-applicable Medicare rules (which would include the CMS telehealth benefit expansion during the emergency). Normally, the routine reduction or waiver of Medicare beneficiary cost-sharing obligations would implicate the federal anti-kickback statute and the civil monetary penalty law prohibiting beneficiary inducement. Clinicians are not obligated to reduce or waive Medicare beneficiary coinsurance and deductible obligations, but may do so in accordance with the OIG policy statement without risk of anti-kickback or beneficiary inducement enforcement. Moreover, the OIG states that it will not view providing future services that may occur as a result of any free telehealth services to, by itself, be evidence of beneficiary inducement. The OIG Policy Statement can be found here. These CMS and OIG issuances are intended to give providers added flexibility to combat the COVID-19 emergency. Hospitals and other providers should consider how the temporary Medicare telehealth expansion and the flexibility in dealing with beneficiary cost-sharing can help them keep clinicians and beneficiaries safer, alleviate some of the burden on provider staff and space, and help reduce the spread of COVID-19. If you have any questions, please contact the author or any member of Dorsey’s healthcare transactions and regulations practice group.
March 18, 2020
coronavirus
Controlled Substance Prescribing Exceptions During Public Health Emergencies
In light of the novel coronavirus pandemic, health care practitioners should be aware of relaxed guidelines for prescribing controlled substance. This blog post describes when practitioners can prescribe controlled substances via telemedicine and exceptions available to opioid treatment programs. Telemedicine Prescribing Typically, an in-person medical evaluation must be conducted before a prescription for a controlled substance is issued through telemedicine or other internet means. However, when the Secretary of Health and Human Services has declared a public health emergency, as he recently did, prescribers may utilize an exception to the in-person evaluation requirement. For as long as the Secretary’s designation of a public health emergency remains in effect, DEA-registered practitioners may issue prescriptions for controlled substances to patients for whom they have not conducted an in-person medical evaluation, provided all of the following conditions are met: The prescription is issued for a legitimate medical purpose by a practitioner acting in the usual course of their professional practice; The telemedicine communication is conducted using an audio-visual, real-time, two-way interactive communication system; and The practitioner is acting in accordance with applicable Federal and State law. As long as the practitioner satisfies all of these requirements, the prescription may be issued using any method of prescribing currently set forth in DEA regulations. Thus, the practitioner may issue a prescription either electronically (for schedules II-V), by calling in an emergency schedule II prescription to a pharmacy, or by calling in a schedule III-V prescription to the pharmacy. Note that regardless of whether there is a public health emergency, a prescribing practitioner that has previously conducted an in-person medical evaluation of a patient may issue a prescription for a controlled substance after communicating with the patient via telemedicine. The prescription must still be issued for a legitimate medical purpose and comply with applicable Federal and State law. More information about the DEA-response to the coronavirus may be found here. Medications for Patients with Opioid Use Disorders Additionally, the Substance Abuse and Mental Health Services Administration (“SAMHSA”) has also issued guidance regarding medications for patients with opioid use disorders in treatment programs. If a state has declared a state of emergency, the state may request blanket exceptions for all stable patients in an Opioid Treatment Program (OTP) to receive 28 days of take-home doses of the patient’s medication for opioid use disorder. The state may request up to 14 days of take-home medication for those patients who are less stable, but who the OTP believes can safely handle this level of take-home medication. In states that have not declared states of emergency, an OTP can provide a blanket exemption request for its clinic per the guidance above (i.e., up to 28 days for stable patients and up to 15 days for less stable patients). These requests do not have to be submitted on a per-patient basis. Programs and states should use appropriate clinical judgment and existing procedures to identify stable patients. SAMHSA notes that as an increased medication supply will likely accompany these requests, OTPs and states must ensure that there is enough medication ordered and on hand to meet patient needs. We are continuing to monitor the federal response to the coronavirus pandemic and will continue to post updates. If you have any further questions, please contact the authors of this post or your regular Dorsey attorney.
March 18, 2020
coronavirus
New HIPAA Waivers for Health Care Providers During the COVID-19 Emergency
This post provides an update on a number of HIPAA waivers that have just been made available to health care providers: (1) Waivers for hospitals in the initial 72 hours of enacting a disaster protocol; and (2) Waivers for all health care providers to allow them to use “everyday communications technologies, such as FaceTime or Skype, during the COVID-19 nationwide public health emergency” for the provision of patient care services. Each waiver is addressed more fully, below: Waivers for Hospitals in the Initial 72 Hours of Enacting a Disaster Protocol First, the Secretary of the Department of Health and Human Services (HHS) has issued limited HIPAA waivers to hospitals. The waivers are retroactive to March 15, 2020. See the HHS HIPAA waiver document here. We addressed the possibility of these waivers in our earlier post, available here, along with a summary of some of the main HIPAA laws already in place which may be helpful to covered entities and business associates during this time of national and public health emergency. The HIPAA waiver document starts by reminding covered entities and their business associates that, in general, the HIPAA rules are not suspended during this time of a national and public health emergency. In particular, addressing a topic of much discussion among providers, the guidance includes a reminder that the HIPAA security safeguards rules (mandating reasonable administrative, technical and physical safeguards) apply to uses and disclosures of electronic protected health information as always. This statement is a reminder to health care providers of their obligations to use appropriate safeguards when using or disclosing protected health information (but, see Part 2 of this blog post, below, which describes a new waiver allowing providers to use everyday communications technologies for patient care.) The HIPAA waiver will only apply to hospitals: (1) in the emergency area identified in the public health emergency declaration (the declaration applies nationwide, see the declaration here); (2) that have instituted a disaster protocol; and (3) for up to 72 hours from the time the hospital implements its disaster protocol. After the 72 hours elapses, the hospital is required to return to full HIPAA compliance, even for patients who are still under care at the time. Also, if the national emergency or the public health emergency is terminated, the hospital is required to return to full HIPAA compliance, even if the 72 hours has not elapsed. The waivers permit U.S. hospitals that have instituted their disaster protocol to have the following HIPAA requirements waived during the initial 72 hours of the disaster protocol: • the requirements to obtain a patient's agreement to speak with family members or friends involved in the patient's care. See 45 CFR 164.510(b). • the requirement to honor a request to opt out of the facility directory. See 45 CFR 164.510(a). • the requirement to distribute a notice of privacy practices. See 45 CFR 164.520. • the patient's right to request privacy restrictions. See 45 CFR 164.522(a). • the patient's right to request confidential communications. See 45 CFR 164.522(b). Waivers for All Health Care Providers to Allow the use of Everyday Communications Technologies for Patient Care Second, the HHS Office for Civil Rights (OCR) announced that it will “exercise enforcement discretion and waive penalties for HIPAA violations against health care providers that serve patients in good faith through everyday communications technologies, such as FaceTime or Skype, during the COVID-19 nationwide public health emergency”. See the announcement from OCR here. A few days later, OCR issued FAQs regarding telehealth and OCRs waiver of penalties for the use of everyday communications technologies, available here. This second announcement is particularly refreshing for health care providers who have been anxiously seeking easier methods, such as the use of personal devices and specific technologies, to interact via audio and/or video technologies with their patients and colleagues. Specifically, OCR states: “A covered health care provider that wants to use audio or video communication technology to provide telehealth to patients during the COVID-19 nationwide public health emergency can use any non-public facing remote communication product that is available to communicate with patients….This exercise of discretion applies to telehealth provided for any reason, regardless of whether the telehealth service is related to the diagnosis and treatment of health conditions related to COVID-19.” OCR provides the following examples of technology that will be allowed: “…a video chat application connecting the provider’s or patient’s phone or desktop computer in order to assess a greater number of patients while limiting the risk of infection of other persons who would be exposed from an in-person consultation.” “…popular applications that allow for video chats, including Apple FaceTime, Facebook Messenger video chat, Google Hangouts video, or Skype…” The OCR makes clear that this technology is also allowed to assess or treat any other medical condition, even if not related to COVID-19. Further, the OCR also states in the notice that it will not impose penalties against health care providers that do not have a business associate agreement in place with such technology vendors. The OCR provides the following examples of technology that will not be allowed because they are public facing: Facebook Live Twitch TikTok similar video communication applications are public facing Finally, the OCR acknowledges that some health care providers may still wish to use technology vendors that are “HIPAA compliant” and with whom the health care provider has entered into a business associate agreement related to the vendor’s video communications products. The OCR provides a list of some technology vendors that represent that they provide HIPAA-compliant video communication products and will enter into a business associate agreement (although the OCR states that it does not endorse any particular technology and it has not reviewed the business associate agreements of these vendors): Skype for Business Updox VSee Zoom for Healthcare Doxy.me Google G Suite Hangouts Meet However, a few words of caution: The OCR encourages providers to notify their patients that these third-party applications potentially introduce privacy risks. Providers should also take as many security precautions as possible to protect patient information such as enabling “all available encryption and privacy modes when using such applications,” and having these conversations in private spaces to avoid others who are not involved in the patient’s care overhearing the communication. Further, even if a provider is using “everyday communications technologies”, providers should take care to record the interactions in the patient’s medical record to ensure that patients’ records are complete and accurate. We are continuing to monitor this ever evolving area of the law and will continue to post updates. Please call the authors of this post or your regular Dorsey attorney if you have any questions.
March 17, 2020
coronavirus
Public Health Emergencies and the HIPAA Privacy Rule
Will HIPAA obligations be relaxed or waived in the wake of the coronavirus outbreak in the United States? They could be. This blog post contains information that is helpful to understand in preparation for such possibility. The Secretary of the Department of Health and Human Services (the “Secretary”) has the authority to declare a Public Health Emergency in situations such as a pandemic. A Public Health Emergency declaration allows the Secretary to take certain actions in response to the emergency, including waiving certain HIPAA Privacy Rule requirements. The Secretary recently made this declaration, and covered entities and their business associates should be aware of their HIPAA Privacy obligations and potential relief from these obligations. When would covered entities and their business associates know of a HIPAA Privacy Rule waiver? First, the President must declare an emergency or disaster pursuant to the National Emergencies Act or the Robert T. Stafford Disaster Relief and Emergency Assistance Act. The President made this declaration on March 13, 2020. Additionally, the Secretary must declare a Public Health Emergency (“PHE”) pursuant to the Public Health Service Act. You can read more about this declaration here. Finally, at least two days before waiving any HIPAA requirements, the Secretary must provide a certification and advance written notice to Congress about the Secretary’s intent to waive HIPAA requirements. 42 U.S.C. § 1220b-5. The DHS website would likely post this notice or the information contained within the notice, or otherwise make it publicly available. What will be the scope of a waiver? The Secretary’s notice to Congress must include a description of: the specific provisions that will be waived or modified; the health care providers to whom the waiver or modification will apply; the geographic area in which the waiver or modification will apply; and the period of time for which the waiver or modification will be in effect. 42 U.S.C. § 1220b-5. If a waiver is issued, Dorsey will provide more guidance about its scope and application. What HIPAA Privacy provisions could be waived? The Secretary may waive sanctions and penalties against covered entities that do not comply with certain provisions of the HIPAA Privacy Rule, including: The requirements to obtain a patient’s agreement to speak with family members or friends involved in the patient’s care; The requirement to honor a request to opt out of the facility directory; The requirement to distribute a notice of privacy practices; The patient’s right to request privacy restrictions; The patient’s right to request confidential communications The Secretary also has authority to modify (but not waive) deadlines and timetables for the performance of required activities, such as reporting requirements. 42 U.S.C. § 1220b-5(b)(5). Are there any existing HIPAA Privacy Rule exceptions that are relevant during a pandemic? Yes. The HIPAA Privacy Rule currently includes exceptions for when protected health information may be shared even if no PHE has been declared. Covered entities may disclose protected health information without individual authorization under certain circumstances: To a public health authority for the purpose of preventing or controlling disease; At the direction of a public health authority, to a foreign government agency; and To persons at risk of spreading a disease if other law, such as state law, authorizes the covered entity to do so. 45 C.F.R. §§ 164.501, 164.512(b)(1). Protected health information may also be shared under certain circumstances: To family friends, and others involved in an individual’s care and for notification; To prevent a serious and imminent threat to the health and safety of a person or to the public; and In limited circumstances, to others not involved in the care of the patient. 45 C.F.R. §§ 164.510, 164.512, 164.508. Please see the February 2020 HIPAA Privacy and Novel Coronavirus bulletin from the DHHS Office for Civil Rights for more details on these current HIPAA provisions and when they apply. What do covered entities and their business associates need to do in preparation for a waiver? Covered entities and their business associates do not have advanced requirements in order to be eligible for a waiver. If a PHE is declared and the Secretary issues a waiver, that announcement will provide details about modifications to or waivers from specific HIPAA rules, as well as information about to whom the waivers or modifications apply. Once those details are released, covered entities will need to evaluate the applicability of the waivers to their operations, and if they are applicable, how they will be implemented. Additionally, the DHHS Emergency Preparedness Decision-Tool may be helpful in determining what protected health information can be released for planning or response activities in emergency situations. The DHHS February 2020 bulletin also offers helpful guidance about the existing HIPAA Privacy Rule requirements and exceptions which may already be useful to help address uses and disclosures in the context of this public health outbreak. Until any waivers are issued, covered entities and business associates should continue to comply with all HIPAA Privacy Rule obligations. We will continue to closely monitor the federal response to the coronavirus pandemic. If you have further questions or need advice on how a Public Health Emergency affects your HIPAA Privacy obligations, please contact the authors or your regular Dorsey attorney.
March 13, 2020
coronavirus
Coronavirus Resource Center
As the 2019 Novel Coronavirus (COVID-19) outbreak continues to unfold governments, economies, businesses, and countries are being adversely affected. Many companies are therefore also facing significant and urgent business and legal challenges so we have created a resource center to provide information that may be helpful in decision making. Click here to access articles, webinars and client alerts Dorsey has posted. This website will be updated often to provide the latest resources for our clients.
March 13, 2020
Anti-Kickback
First EKRA Enforcement Announced
The first publicly disclosed prosecution under the Eliminating Kickbacks in Recovery Act (“EKRA”) occurred last month, a little over a year after EKRA became law. As we described in a previous blog post, EKRA criminalizes certain health care payment arrangements related to referrals, regardless of payor. In the recent EKRA prosecution, an office manager of a Kentucky substance abuse treatment clinic pleaded guilty to soliciting kickbacks from a toxicology laboratory in exchange for urine drug testing referrals. Theresa Merced, the 80-year-old office manager, admitted that the CEO of the toxicology lab gave her a $4,000 check as part of a larger bundle of promised inducements. When law enforcement questioned Merced about the check, she denied knowledge of it and said it was likely a loan from the CEO to her husband. After the questioning, Merced asked the CEO to alter the laboratory’s financial records to reflect her story. Last month, Merced plead guilty to one count of violating EKRA, one count of making false statements, and one count of attempted tampering with records. She is scheduled to be sentenced on May 1, 2020, and faces up to twenty years in prison and a maximum fine of $250,000. EKRA was passed as part of the Substance Use-Disorder Prevention that Promotes Opioid Recovery and Treatment for Patients and Communities Act of 2018 (the “SUPPORT Act”) in response to concerns that the federal Anti-Kickback Statute (“AKS”) was not broad enough to adequately address abusive payment arrangements related to addiction treatment centers. The laws are similar, yet are distinct in several ways. Like the AKS, EKRA makes it a crime to knowingly and willfully solicit, receive, pay or offer any remuneration in order to induce referrals. EKRA, however, only covers arrangements that induce referrals to specific entities: recovery homes, clinical treatment facilities (i.e., certain non-hospital settings that provide substance use treatment), and laboratories. Additionally, EKRA applies to payment arrangements involving all payors, not just those involving federal health care programs like Medicare and Medicaid. Both the AKS and EKRA are criminal statutes with a maximum term of imprisonment of ten years. Both laws provide for several similar safe harbors, but the EKRA safe harbors are narrower in certain respects. For example, although the AKS provides a safe harbor for any payment that is part of any bona fide employment arrangement, EKRA’s employment safe harbor only permits payment that does not vary based on the number of individuals referred, the number of tests or procedures performed, or the amount billed to or received from the health care benefit program from the individuals referred. Thus, EKRA does not protect employment compensation to the same extent that the AKS does. . Although the DOJ has authority to clarify the law and its safe harbors by regulations, none have been proposed. Since EKRA passed in October 2018, many have raised concerns about whether Congress intended for the law to apply so broadly and whether it will be enforced for activity that was previously permissible under the AKS. The Merced prosecution did not involve employment compensation, so does not shed light on whether DOJ or HHS will pursue criminal enforcement for business practices previously permitted under the AKS. The prosecution also dispels hopes that the DOJ would refrain from prosecuting under the statute until clarifying the law through regulations or guidance. The consequences of EKRA are potentially far-reaching and severe. Until clarifying regulations are promulgated, healthcare providers and other entities should evaluate whether their referral and compensation practices comply with the EKRA safe harbors in addition to the safe harbors of the Stark Law and AKS. Because EKRA applies to all payors, this evaluation should take into account practices related to all claims, not just government-reimbursed claims. We will continue to closely monitor the state of EKRA for guidance, revisions to the law, and enforcement. If you have further questions or need advice on how to restructure payment arrangements to comply with EKRA, please contact the authors or your regular Dorsey attorney.
March 2, 2020
False Claims Act
Triggering the Public Disclosure Bar: It’s in the Details
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Lindsey Schmidt for the following post to Dorsey's FCA Now Blog:
February 18, 2020
Justice Department Touts FY2019 False Claims Act Statistics as Evidence of Administration’s “High Priority” Against Fraud, but the Numbers Show Less of a Priority on Qui Tams
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Kirk Schuler and Alex Hontos from Dorsey's FCA Now blog:
January 28, 2020
Employee Benefits
Don’t Get Bitten by Your COBRA Notices
In a growing wave of class action lawsuits, plaintiffs are targeting employers who have allegedly failed to provide proper notice of health care coverage under the Consolidated Omnibus Budget Reconciliation Act of 1985 (“COBRA”). The wave prompted at least six new lawsuits in 2019 alone, and some have already netted seven-figure settlements. To avoid this litigation trend, employers should take a hard look at their COBRA notices to ensure they comply with governing regulations. COBRA requires employers who sponsor group health plans to allow plan participants to continue coverage at their own cost when a “qualifying event” occurs that would otherwise terminate coverage. 29 U.S.C. § 1161(a). The most common “qualifying event” is termination of employment, but there are several others, including the death or divorce of a covered employee. Under COBRA, plan administrators must provide an individual with notice of the right to continued COBRA coverage (a) when the individual first joins the plan and (b) when a qualifying event occurs. 29 U.S.C. § 1166(a). That COBRA notice must explain the right to continue coverage “in a matter calculated to be understood by the average plan participant.” 29 C.F.R. § 2590.606-4(b)(4). Federal regulations specify 14 items that the notice should include—for example, an explanation of how to enroll in COBRA. 29 C.F.R. § 2590.606-4(b)(4)(i)-(xiv). In addition, the Department of Labor (“DOL”) has published a model COBRA notice. Use of the DOL model notice “is not mandatory.” 29 C.F.R. § 2590.606-4(g). But according to DOL official publications, use of the model notice represents “good faith compliance with COBRA’s general notice content requirements.” The recent wave of class action lawsuits challenges whether employers’ COBRA notices were sufficient. While the precise allegations differ, the plaintiffs generally allege that the notice they received did not include all the information set forth in the regulations or in the DOL’s model notice, and that the average plan participant could not understand the notice. Failure to comply with COBRA’s notice requirements can be costly, especially in the context of a class action. COBRA provides a statutory penalty up to $110 per day per person for failure to provide the required notices. 29 U.S.C. § 1132(c)(1). The penalty adds up quickly. Take, for example, a class of 100 employee who lost their coverage one year ago and received a deficient COBRA notice. The penalty for the employer could be several million dollars, before accounting for an award of legal fees and costs (which COBRA allows). Thus far, employers have been unsuccessful in defeating these COBRA notice lawsuits at the pleading stage. Some employers have argued that the plaintiff lacked constitutional standing to sue because the alleged defects in the notice—often seemingly innocuous—did not cause any concrete injury. Other employers have argued they were in substantial compliance with the DOL regulations. To date, however, those arguments have not convinced courts to dismiss complaints at the pleading stage. A few of the lawsuits have already settled for seven- and six-figure numbers. The rest are proceeding forward. There are steps employers can take now to minimize the risk of being swept into this COBRA notice litigation. To begin, employers should check whether their COBRA notices contain the 14 items suggested by the regulations. See 29 C.F.R. § 2590.606-4(b)(4) (i)-(xiv). Employers should also draft their notices in as simple, straightforward language as possible. In addition, employers should seriously consider using the DOL’s model notice to gain the protection of “good faith compliance.” Even when using the model notice, it may be appropriate to supplement with additional, plan-specific information. Regardless of whether your COBRA notices could use minor or major changes, now is the time to make those changes. Doing so could save you from a class action complaint.
January 21, 2020
Healthcare Fraud and Abuse
OIG’s Latest Congressional Report Sees Continued Emphasis on Fraud and Abuse Enforcement
In the final quarter of calendar year 2019, the Department of Health and Human Services Office of Inspector General ("OIG") released its Semiannual Report to Congress (the "Report"). The Report covers the six-month period from April 2019 through September 2019 and details for Congress the OIG’s activities during that time and how the office uses its resources. For the six-month period detailed throughout the Report, one thing is obvious: the OIG continued its aggressive approach in pursuing providers of all kinds for suspected fraud and abuse in HHS programs. The Report details how the OIG’s investigative work, in conjunction with other federal and state agencies, led to $2.74 billion in expected investigative recoveries, 388 criminal actions, 364 assessments of monetary penalties, and 1,347 exclusions of individuals and entities from Federal health care program. For comparison, for entirety of 2018, OIG reported expected recoveries of $2.91 billion, criminal actions against 764 individuals or entities, and exclusion of 2,712 entities from federal healthcare programs. Thus, 2019 was a much more active year for the OIG. Among other highlights included in the Report, the OIG reports an April 2019 investigation (known as Operation Brace Yourself) that dismantled a healthcare fraud scheme involving over $1.2 billion in losses. In the alleged scheme, medical professionals working with fraudulent telemedicine companies received illegal kickbacks and bribes from medical equipment companies. In exchange, the medical equipment companies obtained prescriptions for medically unnecessary orthotic braces and used them to fraudulently bill Medicare. The operation led to charges against twenty-four defendants across seventeen federal districts. In the six-month period outlined in the Report, the OIG also netted the largest healthcare fraud scheme ever charged by federal authorities. The fraud scheme involved a record $1.3 billion in claims. According to the investigation, the leader of the scheme bribed physicians to admit patients into care facilities he owned, and then cycled the patients through facilities in his network. In addition to billing Medicare and Medicaid for services and prescription drugs that were unnecessary or not provided, witnesses testified that the facilities were in poor condition and provided inadequate care—information that was concealed by bribing a state regulator for advance notice of surprise inspections. The leader of the scheme was sentenced to twenty years in prison, and his accomplice was sentenced to over six years in prison. The Report also recounts the case of an inpatient rehabilitation company that settled allegations of submitting false patient diagnoses and admitting patients unnecessarily to bolster Medicare payments. The company allegedly provided false diagnoses on patient assessments to keep its facilities eligible for a special Medicare status that pays a higher rate. The company also allegedly admitted and billed for Medicare patients that did not need the care they were provided. The company ended up paying $48 million to resolve the allegations. What this means for you: the OIG's aggressive pursuit of providers for fraud and abuse related to federal and state healthcare programs continues to ramp up, with OIG reporting a $5.4 billion in expected recoveries from FY 2019, which is a significant increase over 2018’s $2.91 billion. It's critical that providers ensure their operations, including all of their agreements, are up to date with the most current requirements under the law. Hospitals and health systems need to ensure their providers are educated on the fraud and abuse laws and remain diligent in the upcoming year. To paraphrase, according to Acting Inspector General Joanne M. Chiedi, 2020 will see the OIG continue its bold pursuit of those who attempt to cheat HHS programs or harm HHS beneficiaries and the agency will be resolute in catching and holding accountable perpetrators of fraud and identifying misspent funds.
January 15, 2020
CMS Guidance
2020 CPI-U and DHS Code List Updates Posted on CMS Website
The Centers for Medicare & Medicaid Services (“CMS”) recently posted two annual updates related to the physician self-referral law (“Stark Law” or “Stark”) on its Stark website: (1) CPI-U updates related to the nonmonetary compensation exception and medical staff incidental benefits exception; and (2) CPT/HCPCS codes used to identify certain categories of Stark designated health services (or “DHS”). These updates are important for stakeholders to be aware of as they seek to ensure continued compliance with Stark Law requirements. CPI-U Updates As per usual, the CPI-U Updates page of the CMS Stark website, found here, was updated before the end of the year to reflect the new compensation limits (based on inflation) for the nonmonetary compensation exception (at 42 C.F.R. § 411.357(k)) and medical staff incidental benefits exception (at 42 C.F.R. § 411.357(m)). For calendar year 2020, the non-monetary compensation limit is $423 (up from $416 for calendar year 2019) and medical staff incidental benefits must be less than $36 per occurrence (up from $35 in calendar year 2019). DHS Code List Updates As we explained in our blog post here, in the calendar year 2020 Medicare physician fee schedule final rule (“PFS”), CMS finalized changes to the advisory opinion process under the Stark Law, and also included the annual update to the list of CPT/HCPCS codes used to identify certain categories of DHS (the “Code List”). As we also explained, the Stark Law regulations at 42 C.F.R. § 411.351 specify that the following four categories of DHS are defined by reference to the Code List: (1) clinical laboratory services; (2) physical therapy, occupational therapy, and outpatient speech-language pathology services; (3) radiology and certain other imaging services; and (4) radiation therapy services and supplies. The Code List is updated annually to reflect changes in the most recent CPT and HCPCS Level II publications. Further, items and services that may qualify for either of two Stark Law exceptions—the exception for preventive screening tests, immunizations and vaccines at 42 C.F.R. § 411.355(h) and the exception for EPO and other dialysis-related drugs at 42 C.F.R. § 411.355(g)—are identified by reference to the Code List. The Code List included the annual updates to the codes eligible for the preventive screening tests, immunizations and vaccines exception. However, as in previous years, the Code List does not include any codes eligible for the EPO and other dialysis-related drugs exception (for reasons explained by CMS in the rule). The PFS rule includes tables showing the additions and deletions to the Code List. As per usual, the complete Code List was posted before the end of the year to the CMS Stark website dedicated to the Code List, found here. The new list is effective January 1, 2020.
January 7, 2020
Hospitals
New Proposal to Remove Disincentives to Living Organ Donation
On December 20, 2019, the Department of Health and Human Services (“DHHS”) issued a notice of proposed rulemaking (the “Proposal”) that removes financial barriers to organ donation by expanding the scope of reimbursable expenses paid through the Health Resources and Services Administration’s Reimbursement of Travel and Subsistence Expenses Incurred toward Living Organ Donation program (the “Program”). Specifically, the Proposal would allow living organ donors to be reimbursed for donation-related lost wages, child-care expenses, and elder-care expenses through the Program. With the Proposal, DHHS is hoping to increase the number of living organ transplants and improve the overall quality and outcome of organ donations. Generally, federal law prohibits any person from knowingly acquiring, receiving, or otherwise transferring any human organ for valuable consideration for use in human transplantation. 42 U.S.C. § 274e. However, valuable consideration does not include “the reasonable payments associated with the removal, transportation, implantation, processing, preservation, quality control, and storage of a human organ or the expenses of travel, housing, and lost wages incurred by the donor of a human organ in connection with the donation of the organ.” Id. (emphasis added). Therefore, organ donors can be reimbursed for their donation-related expenses under certain circumstances. Primarily to aid low-income organ donors in such reimbursement, 42 U.S.C. § 274f describes the Program, which funds the National Living Donor Assistance Center (the “NLDAC”), to reimburse an eligible organ donor’s qualified expenses. Nevertheless, the Program’s current guidelines specifically limit NLDAC qualifying expenses to only those incurred by the donor and/or his/her accompanying person(s) as part of: (1) donor evaluation and/or (2) hospitalization for the living donor surgical procedure, and/or (3) medical or surgical follow-up, clinic visits, or hospitalization within two calendar years following the living donation procedure. As such, the Program (through the NLDAC), does not currently reimburse organ donation-related expenses such as lost wages, child-care, or elder-care. Rather, reimbursement for such expenses can only be received from sources such as state compensation programs, insurance policies, or the recipient of the organ. This reduces the reimbursement options available, which may be especially significant to the low-income organ donors utilizing the Program. To address this, the Proposal sets out to amend the Organ Procurement and Transplantation Network Final Rule by adding Section 121.14(a), stating: The following incidental nonmedical expenses incurred by donating individuals toward making living donations of their organs may be reimbursed: (1) Lost wages; (2) Child-care expenses; and (3) Elder-care expenses. The Proposal fulfills the President’s mandate under Executive Order 13879: Advancing American Kidney Health that DHHS propose a regulation to allow living organ donors to be reimbursed for donation-related lost wages, child-care expenses, and elder-care expenses through the Program. Therefore, some form of the Proposal is likely to become final, and DHHS is accepting comments on the Proposal until February 18, 2020. If you would like to submit comments or have any questions, one of the authors or your regular Dorsey attorney would be happy to assist you.
January 6, 2020
Naughty or Nice: Feds Hand Out More Than Lumps of Coal When it Comes to Healthcare Fraud
The United States government has an arsenal of agencies and civil and criminal statutes at its disposal to choose from in investigating and combating healthcare fraud. A recent federal indictment discussed below exemplifies just how multifaceted government investigations and prosecutions can be. And organizations need to be prepared to respond to such investigations. Last week, the Department of Justice (DOJ) charged fifteen residents of southern Florida in a kickback and bribery scheme involving two VA Medical Centers (West Palm Beach and Miami). According to DOJ, ten of the defendants worked in the VA medical centers’ logistics departments and had distinct roles in the scheme to defraud. DOJ also alleged some of the VA-employee defendants would place fake or inflated orders with supply vendors. Other VA-employee defendants would then allegedly approve the fake orders and still other VA-employee defendants would allegedly falsely enter the supplies as having been received into the VA computer system. Once paid by the government, the defendant supply vendors allegedly would send a portion of the ill-gotten proceeds to the VA-employee defendants as kickbacks. Four individual supply vendors were charged in the scheme. And although not directly related to the kickback scheme, another individual supply vendor defendant was charged for making false statements in connection with VA application for companies seeking designation as a “Service Disabled Veteran Owned Small Business” (SDVOSB). The charges against the fifteen individuals and supply vendors illustrate not only how seriously DOJ takes allegations of fraud in the healthcare and government-contracting arena, but also some of the statutory tools Congress has given DOJ to fight such fraud in the healthcare system. Federal statutes specifically criminalize healthcare fraud and conspiracy to commit healthcare fraud, which generally consists of knowingly and willfully executing (or conspiring to execute) a scheme to “defraud any health care benefit program” or to obtain “any of the money or property owned by, or under the custody or control of, any health care benefit program” by false or fraudulent pretenses. 18 U.S.C. §§ 1347, 1349. The VA is a “health care benefit program,” 18 U.S.C. § 24(b), and the Anti-Kickback Statute provides stiff penalties, including fines and prison time, for fraud involving “federal health care programs” like the VA, see 42 U.S.C. § 1320a-7b. Civil fines under the Anti-Kickback Statute also can be imposed per violation, potentially exposing organizations to millions of dollars in liability. Also the government could have invoked—and may well still invoke—the False Claims Act, 31 U.S.C. § 3729, and its remedy provisions, including treble damages and statutory penalties for each claim submitted by the vendors. Those working in or with the VA system (or healthcare or the U.S. government in general) should take particular care to deter and detect fraud and bribery in their organizations. In this case, for example, ten employees within the Florida VA medical centers alone are alleged to have participated in the scheme. Such widespread misconduct may have been prevented—or detected sooner—with adequate policies and reporting procedures, better employee training, or regular and systematic audits. Regular audits, for example, comparing supply inventory as recorded in VA systems with the actual supply inventory received might have deterred or detected the false purchase orders. Organizations should regularly review their policies and procedures, as well as internal compliance with those policies and procedures, with legal counsel. Likewise, annual employee training and certification also would serve to educate employees about the applicable laws, rules and regulations and changes to them, how to spot red flags, the obligation to report and the mechanism for reporting suspected activity and the serious consequences for failure to comply. Organizations should also review with counsel whether their current practices do or can be adapted to meet one of the many “safe harbors” provided for under the Anti-Kickback Statute regulations. Additionally, the charges for making false statements related to the SDVOSB application are yet another example of the breadth of DOJ investigations and enforcement tools. Federal law broadly criminalizes making certain misrepresentations or omissions “in any matter within the jurisdiction of the executive, legislative, or judicial branch,” see 18 U.S.C. § 1001, which includes government-contracting applications submitted to executive branch agencies like the VA. So even where a government contractor may not have participated in the criminal conduct being directly investigated (which, here, was the alleged kickback scheme), the scope of DOJ’s investigation can creep into other areas (such as representations on government-contracting applications) which place that government contractor in serious legal jeopardy. Government contractors should therefore seek legal counsel before and while participating in any DOJ investigations. Government contractors should also, as a preventative measure, seek legal counsel related to the representations they make on government applications so that they do not make misrepresentations in the first place. Staying compliant with the laws, rules and regulations governing healthcare providers, vendors, and suppliers requires diligence and vigilance. In this ever changing and complex landscape companies and their employees must be pro-active in their efforts to combat fraud and to respond to governmental inquiries and investigations.
December 23, 2019
Affordable Care Act
Escobar in Action: Physician-owners’ fraud claims against hospital defeated in Fifth Circuit appeal for lack of materiality
Following the passage of the Affordable Care Act (“ACA”), which placed new limits on physician-owned hospitals, St. Luke’s Health System (“System”) took action to change one of its hospital’s ownership structures through a buy-out of the physicians’ partnership interests pursuant to the Texas Securities Act (“TSA”). The TSA allows rescission for the original price paid for a security, plus interest, in exchange for a release of potential liability under TSA. Three of the physician-owners, who resisted the System’s attempt to rescind their ownership interests, sued the System and other defendants in connection with the buy-out alleging state-law violations and violations of the Anti-Kickback Statute, and by extension, the False Claims Act. To read the full article, view our FCA Now blog, linked here:
December 11, 2019
Healthcare Fraud and Abuse
New Disclosure Requirements to be Phased-In to CMS Enrollment and Revalidation Process
On September 5, 2019, the Centers for Medicare & Medicaid Services (“CMS”) issued a final rule (“Final Rule”) effective November 4, 2019, which increases disclosure requirements for the provider and supplier enrollment and revalidation process. The Final Rule is aimed at increasing the information provided to CMS in enrollment and revalidation to identify fraud, waste, and abuse, and expanding CMS’s authority to deny, revoke, or delay a provider’s or supplier’s ability to participate in Medicare, Medicaid and CHIP based on a provider’s or supplier’s relationship with previously sanctioned entities. The Final Rule revises several existing regulations and adds an onerous regulation titled “disclosure of affiliations,” at 42 C.F.R. § 424.519. This new disclosure requirement mandates that, at the time of reenrollment or revalidation, each provider and supplier must list all “disclosable events” for each “affiliation” within the past five (5) years, even if the provider/supplier is not affiliated with such person/entity at the time of enrollment or revalidation. This new requirement is greatly expanded from the previous disclosure requirement, where providers/suppliers were only required to disclose their own adverse actions. A provider or supplier must disclose its affiliations that have one of the following “disclosable events”: Currently has an uncollected debt to Medicare, Medicaid or CHIP; Has been or is subject to a payment suspension under a federal health care program; Has been or is excluded by the Office of the Inspector General from participation in Medicare, Medicaid, or CHIP; or Has had its Medicare, Medicaid, or CHIP enrollment denied, revoked, or terminated. 42 C.F.R. § 424.502. Note that on the last disclosable event, the Final Rule could be interpreted to require disclosure of any enrollment denial, including billing privileges and arguably denials of Change of Ownership or Change of Location requests. Moreover, CMS articulated a broad definition of “affiliations” which means, in relation to the provider/supplier, any individual or entity that holds: A five (5) percent or greater direct or indirect ownership interest; A general or limited partnership interest (regardless of the percentage); An interest in which an individual or entity exercises operational or managerial control over, or directly or indirectly conducts, the day-to-day operations of another organization regardless of an employment relationship; An officer or director position; or Any reassignment relationship (e.g., reassignment of billing rights). 42 C.F.R. § 424.502. CMS may revoke privileges if a provider or supplier knew or reasonably should have known about an affiliate’s disclosable events. CMS declined to provide an objective standard to such a knowledge requirement, but provided that a provider/supplier must make a “sufficient effort” when evaluating whether an affiliate has a disclosable event that such provider/supplier must report. Such an effort could include the provider/supplier directly contacting the affiliate, and potentially mining historical data, not just publically available data. In the context of complex legal structures including publicly owned companies or private equity-backed providers, CMS’s definition of affiliation can quickly result in a time-consuming process of review. The disclosure requirements in the Final Rule apply to all providers and suppliers, but only at time of initial enrollment and revalidation, which is a significant improvement from the proposed rule (which, if adopted, would have required disclosures for change of ownership and change of information filings). Once an affiliation is disclosed to CMS, CMS will require additional information about the affiliate, the relationship, and the disclosed adverse information, and will conduct an analysis of whether such affiliation presents an “undue risk” of fraud, waste, and abuse to the Medicare Program, such that the disclosing provider/supplier’s billing privileges should be denied or revoked. Recognizing that compliance with this Final Rule will be an arduous task for a large number of providers and suppliers, CMS adopted a “phased in” approach. First, CMS will require disclosure of affiliations only when specifically requested by CMS. CMS will then implement new CMS-855 forms (which will also go through a separate notice and comment period), and will issue subregulatory guidance on the new forms and disclosure requirements. Only then will providers and suppliers be required to comply with the disclosure requirements during initial enrollment and revalidation. It is expected that the “phased-in” approach could extend over the course of the next few years, and in the second phase, may initially only require compliance by certain providers/suppliers. Even though the immediate impact of the disclosure requirements is limited, providers and suppliers should understand the extensive scope of the new requirement and understand what steps will need to be taken to review in detail their affiliations, both past and present, once the complete scope of the disclosure requirements are officially implemented. If you have further questions about this Final Rule, please contact the authors or your regular Dorsey attorney. The Final Rule on the new disclosure requirements can be found on the website of the Federal Register here.
November 25, 2019
Anti-Kickback
CMS Finalizes Changes to the Stark Advisory Opinion Regulations; 2020 DHS Code List and CPI-U Updates
In the calendar year 2020 Medicare physician fee schedule final rule (“PFS”), which was published in the Federal Register on November 15, 2019 (available here), CMS finalized changes to the advisory opinion process under the federal physician self-referral law (“Stark Law” or “Stark”). CMS also published its annual update to CPT/HCPCS codes used to identify certain categories of Stark designated health services (or “DHS”). These regulatory changes and annual code update both go into effect on January 1, 2020. Finalized Changes to Stark Advisory Opinion Regulations Under the CMS advisory opinion process, the regulations for which are found at 42 C.F.R. §§ 411.370–389, parties can seek an advisory opinion from CMS as to whether a referral for DHS (other than clinical laboratory services) is prohibited under the Stark Law. CMS determines in the opinion whether an arrangement constitutes a “financial relationship” that would implicate the Stark Law’s referral prohibition and whether the arrangement or the referred service qualifies for a Stark Law exception. CMS issued a Request for Information (“RFI”) in June 2018 as part of the “Regulatory Sprint to Coordinated Care” about ways CMS could modify the Stark Law regulations in order to reduce barriers to patient care coordination and value-based arrangements and to reduce the regulatory burden of complying with the Stark Law generally, which we wrote about here. CMS did not specifically solicit comments regarding the Stark advisory opinion process in the RFI, but CMS received a number of comments about ways that the Stark advisory opinion process could be improved. CMS explains in preamble to the PFS that it “undertook a fresh review” of the advisory opinion process in light of the comments it received to “identify limitations and restrictions that may be unnecessarily serving as an obstacle to a more robust advisory opinion process.” CMS also recently issued sweeping proposed Stark Law regulatory changes as part of the Regulatory Sprint to Coordinated Care on topics related to the RFI, which we wrote about in a white paper available here. While the changes to the advisory opinion regulations do not directly relate to the shift to a value-based health care delivery system, CMS acknowledges in preamble to the PFS that “a faster and more robust advisory opinion process facilitates the shift to value-based care arrangements by providing more guidance for parties trying to understand how the physician self-referral law applies in an evolving and innovative marketplace. This will help to reduce provider burden by providing insight into what does and does not comply with the law, which encourages innovation.” Since the initial advisory opinion regulations were issued in 1998, CMS has only issued 16 advisory opinions, which are available here. (CMS also issued 15 advisory opinions from 2004-2005 during the 18-month moratorium on physician ownership and investment interests in specialty hospitals that was in effect at that time, which are available here.) In contrast, the Department of Health and Human Services (“HHS”) Office of Inspector General (“OIG”), which has a separate advisory opinion process for the federal anti-kickback statute (“AKS”) and certain other laws, issued 14 advisory opinions in calendar year 2018 alone (available here). In preamble to the PFS, CMS recognizes the importance of an accessible advisory opinion process and acknowledges that the current advisory opinion process has not been widely used. An accessible advisory opinion process is particularly important in the context of the Stark Law, since it is a strict liability statute, and there is a great need for certainty because, as CMS acknowledges, “parties that act in good faith may nonetheless face significant financial exposure if they misunderstand or misapply the law’s exceptions.” We anticipate that the changes to the advisory opinion process may indeed help to make the process more meaningful and accessible to entities that are seeking to understand if their arrangement complies with the Stark Law, particularly due to CMS’s broadening of how advisory opinions can be relied upon (as described below). If you are interested in submitting an advisory opinion request, or for advice on whether and how you can rely on a published advisory opinion in assessing an arrangement for compliance with the Stark Law, please contact the authors or your regular Dorsey attorney. The most notable changes to the advisory opinion regulations in the PFS are the following: Reliance on an Advisory Opinion: Under existing Stark regulations, only the individual or entity that requested the advisory opinion may rely on the opinion. In the PFS, CMS finalizes revisions to regulations to specify the following: An advisory opinion is binding on the Secretary of HHS, and a favorable advisory opinion means that sanctions will not be imposed under the Stark Law with respect to individuals/entities that are parties to the arrangement upon which the opinion was issued (as well as the individuals/entities that requested the opinion). The Secretary of HHS will not pursue sanctions under the Stark Law “against any party to an arrangement that CMS determines is indistinguishable in all its material aspects from an arrangement with respect to which CMS issued a favorable advisory opinion.” Parties can submit an advisory opinion request to determine whether CMS would view their arrangement as “indistinguishable in all material aspects” from another arrangement that has received a favorable opinion, which will be issued by CMS on an expedited basis (as explained below). Individuals/entities can rely on advisory opinions “as non-binding guidance that illustrates the application of the physician self-referral law and regulations to the specific facts and circumstances described in the advisory opinion.” CMS acknowledges that stakeholders already use advisory opinions to inform their decision-making, and this change is intended to make clear that “such reliance is permissible and reasonable.” Timeline for Issuing an Advisory Opinion: Under existing regulations, CMS currently has a 90-day timeframe to issue an advisory opinion. CMS finalizes its proposed changes to the regulatory text to shorten this to 60 “working days” (where “working day” excludes weekends and holidays) after the request has been formally accepted. CMS maintains the discretion it has in existing regulations to extend this time period when a request involves “complex legal issues of first impression or highly complicated fact patterns” and to suspend the time period in certain circumstances. CMS finalizes revisions to regulations to provide for expedited review of advisory opinion requests that relate to whether an arrangement is “indistinguishable in all material aspects” from an arrangement that was the subject of a favorable advisory opinion. The expedited review period will be 30 working days. Fees for the Cost of Advisory Opinions: CMS finalizes revisions to regulations to revise the fee structure for advisory opinions. Specifically, the $250 initial fee is removed and a $220 hourly rate is implemented. In the PFS, CMS also finalizes its proposed changes to the advisory opinion regulations in the following areas (among others): Matters Subject to Advisory Opinions: CMS finalizes revisions to regulations to allow CMS to consider advisory opinion requests that “relate to” existing or planned arrangements, rather than requests that “involve” them, which is intended to capture the scope of appropriate advisory opinion requests. CMS explains that it remains its position that advisory opinion requests cannot be regarding only “hypothetical facts or general questions of interpretation,” but must be about a specific referral, physician, financial relationship and facts/circumstances. CMS does acknowledge, however, that there is some confusion over what is a planned arrangement versus a hypothetical arrangement, so is removing this language from the advisory opinion regulations. It also revised the regulatory text to reflect its view that a request for an advisory opinion would not be accepted if the claim could not be billed to Medicare for some reason unrelated to the Stark Law. CMS finalizes revisions to regulations to allow CMS more flexibility related to advisory opinion requests that involve conduct that is “substantially similar to conduct that is under investigation or is the subject of a law enforcement proceeding.” Certification Requirement: CMS finalizes revisions to regulations to allow for any authorized officer of the corporation to sign the certification statement, in addition to the Chief Executive Officer. Rescission: CMS finalizes revisions to regulations related to when CMS may rescind an advisory opinion, which is when CMS determines that there is good cause to do so. “Good cause” exists when “(i) there is a material change in the law that affects the conclusions reached in an opinion; or (ii) a party that has received a negative advisory opinion seeks reconsideration based on new facts or law.” CMS declines to adopt a minimum wind-down period in regulatory text for arrangements that are the subject of a rescinded advisory opinion, and states that it will work with parties affected by a rescinded opinion to determine a reasonable wind down period. CMS also finalizes regulatory changes to provide for an advance notice to the requestor and the public of a rescinded opinion. 2020 DHS Code List and CPI-U Updates The PFS also includes the annual update to the list of CPT/HCPCS codes used to identify certain categories of DHS (the “Code List”). As we explained in prior posts (such as this one), the Stark Law regulations at 42 C.F.R. § 411.351 specify that the following four categories of DHS are defined by reference to the Code List: (1) clinical laboratory services; (2) physical therapy, occupational therapy, and outpatient speech-language pathology services; (3) radiology and certain other imaging services; and (4) radiation therapy services and supplies. The Code List is updated annually to reflect changes in the most recent CPT and HCPCS Level II publications. Further, items and services that may qualify for either of two Stark Law exceptions—the exception for preventive screening tests, immunizations and vaccines at 42 C.F.R. § 411.355(h) and the exception for EPO and other dialysis-related drugs at 42 C.F.R. § 411.355(g)—are identified by reference to the Code List. The Code List included the annual updates to the codes eligible for the preventive screening tests, immunizations and vaccines exception. However, as in previous years, the Code List does not include any codes eligible for the EPO and other dialysis-related drugs exception (for reasons explained by CMS in the rule). The PFS rule includes tables showing the additions and deletions to the Code List. We expect that, as per usual, the complete list will be posted before the end of the year to the CMS Stark website dedicated to the Code List, found here. We also expect that the CPI-U Updates page of the CMS Stark website, found here, will be updated before the end of the year to reflect the new compensation limits for the nonmonetary compensation exception (at 42 C.F.R. § 411.357(k)) and medical staff incidental benefits exception (at 42 C.F.R. § 411.357(m)), which are both updated annually for inflation.
November 21, 2019
CMS Guidance
Hospital Price Transparency Rule Finalized; Health Plan Transparency Rule Proposed
The Centers for Medicare and Medicaid Services (CMS) has issued a final rule to require every hospital licensed in the United State to make public a robust set of standard charges for every item or service that the hospital bills. In addition, CMS and other agencies have issued a proposed rule to require group health plans and health insurance issuers to: (1) disclose in-network negotiated rates and out-of-network allowed amounts for every health care item or service; and (2) offer a real-time tool to provide a plan enrollee with an estimate of cost-sharing and out-of-pocket expenses associated with plan covered items and services. The hospital price disclosure rule is effective January 1, 2021. Hospitals and hospital trade associations have stated that they will bring a legal challenge against the final rule as exceeding CMS’ legal authority. The rule will require every licensed hospital to provide two separate sets of standard charge lists: (1) a list of standard charges for at least 300 “shoppable” hospitals services that a consumer can schedule in advance; and (2) a comprehensive list of standard charges for all items and services for which the hospital establishes a charge. Both lists must be updated at least annually and placed on a publicly-accessible website. Only hospitals are regulated under the final rule; ambulatory surgery centers or other clinics or facilities that may provide items and services that are also performed in hospitals are not required to report pricing. For the comprehensive charge list the hospital must report seven data elements for each item or service: (1) description; (2) code used to bill the item or service; (3) hospital’s gross charge; (4) negotiated rate with every third party payer (linked by name to the third party payer and plan); (5) highest charge the hospital has negotiated with any third party payer; (6) lowest charge the hospital has negotiated with any third party payer; and (7) charge applicable to an individual who pays cash. The “shoppable” charge list must include similar data elements, with the addition of the hospital location(s) at which the “shoppable” service is provided. The resulting report will be an exceedingly dense data set of hundreds of thousands of line items for a typical hospital. The biggest change the final rule would effect is that payment rates that a hospital negotiates with third party payers would no longer be confidential or proprietary, and would in fact be public information under the final rule. CMS made clear that a hospital must report data on all items or services the hospital provides and charges, including the professional services of its employed physicians or other clinicians. This appears to apply only to the hospital itself (presumably identified by NPIs associated with the hospital) and not to separate corporate entities, formed for the purpose of operating physician group, that do not operate the hospital but may be owned by the same entity (or corporate affiliate) that operates the hospital. The health plan proposed rule would require every group health plan or health insurance issuers to make available on a website a negotiated rate file that lists: (1) the name and Employer Identification Number (EIN) or Health Insurance Oversight System (HIOS) identifier for each plan option or coverage offered; (2) codes and plan language description for each item or service; and (3) negotiated rate for each item or service furnished by every in-network provider (linked by National Provider Identifier (NPI) to each in-network provider) along with the last date of contract term for that rate. A separate file that lists out-of-network allowed amounts for each items or service furnished by out-of-network providers must also be posted. These lists must be updated monthly under the proposed rule. In addition, health plans must offer a tool to allow plan enrollees to obtain real-time information about cost-sharing information with regard to specific items or services. Unless halted by courts, hospitals will need to begin the considerable work of compiling and formatting the data files required under the final rule. And, although it is unclear how the hospital pricing data will be analyzed and used (and by whom), hospitals should analyze their own pricing data and begin anticipating and preparing for the questions and critiques that will arise.
November 20, 2019
Opioids
Settlement Reached in the First Federal Opioids Trial
This post is an update from our earlier blog post, available here, on the bellwether federal opioids trial in the Northern District of Ohio. Just hours prior to the start of the trial in a consolidated case involving two plaintiff counties in Ohio, all of the remaining defendants in the case, except Walgreens, reached a settlement. In the settlement, distributors, McKesson, Cardinal Health and AmerisourceBergen (distributors of approximately 90% of all prescription medications) will pay $215M to Cuyahoga and Summit Counties in Ohio. A manufacturer, Teva, will pay $20M in cash over three years and will donate $25M worth of Suboxone, an addiction treatment medication. Several manufacturers who were originally named defendants in these two consolidated cases previously settled out of the cases. Judge Polster, the federal judge who has overseen the multi-district litigation (“MDL”), announced that Walgreens would face a separate trial focusing on its role as a dispenser. There are more than 2,000 cases filed in the MDL by states, counties, cities and tribes which Judge Polster has been overseeing for more than two years. The remaining cases involve manufacturers, distributors and large pharmacy chains. Lawyers involved in the cases have expressed hope that the recent settlement could encourage other cases in the MDL to settle as well, although one of the most significant hurdles has been a dispute about how any settlement money would be distributed among the plaintiffs, as well as who would control the use of the settlement funds going forward.
October 24, 2019
Opioids
Drug Companies Preview Trial Defenses for Bellwether Opioid Trial
In the last several years, thousands of cities and counties, as well as most states, have sued various combinations of pharmaceutical manufacturers, retailers, and distributors for damages allegedly caused by the opioid epidemic. Nearly 2,000 of those cases have been consolidated into a multi-district litigation (“MDL”) in the Northern District of Ohio. Until very recently, defendants in the MDL had not revealed how they intended to argue against the charge that they caused or contributed to the opioid crisis. But with the first trial set to begin on October 21, 2019, the defendants recently submitted their trial briefs, which provide a sneak peek at the factual and legal arguments they intend to raise at trial. Among other alleged causes, defendants have pointed to corrupt doctors, criminal cartels, and even local governments. For example, one drugmaker stated that it “fully recognizes the opioid crisis that exists in this country” but suggested that alternative causes such as public policy failures and illicit drug use drove the opioid crisis. More specifically, the defendant stated: [P]ervasive diversion and abuse of oxycodone and hydrocodone pills, unscrupulous doctors and internet pharmacies operating as drug-trafficking organizations, foreign criminal cartels that flooded the country with heroin and fentanyl illegally made in clandestine labs, and state and federal governments that struggled to ensure patients had access to necessary medications while addressing long-known problems of abuse, misuse, diversion, and overdose. (Doc. No. 2633 at 8.) Another drugmaker alleged that rather than blaming defendants, the plaintiffs—i.e., two counties in Ohio—“should be examining their own actions and inaction—which directly contributed to the opioid abuse problem in the United States.” (Doc. No. 2669 at 9.) As an example, the defendant argued that “the Counties continue to reimburse for opioid prescriptions for chronic pain today, thereby influencing what gets prescribed and dispensed to patients—and confirming (against their very own foundational theory in this case) that opioid prescriptions may be appropriate for chronic pain.” (Id.) Similarly, an opioid distributor believes the opioid crisis was caused by “innumerable actors not before the Court, ranging all the way from well-intentioned prescribing doctors to criminal drug dealers and heroin traffickers.” (Doc. No. 2643 at 4-5.) Another distributor suggested that plaintiffs in the MDL overlook the “role of criminal drug cartels and other actors in the illegal opioid market.” (Doc. No. 2659 at 4.) Finally, yet another distributor argued that alternative causes of the opioid crisis preclude recovery in the MDL. This defendant argued that under City of Cleveland v. Ameriquest Mortg. Secs., Inc., 615 F.3d 496 (6th Cir. 2010), the presence of “independent actors between the alleged misconduct and the alleged injury” compel the conclusion that plaintiffs’ claims here are “too indirect to warrant recovery.” Ameriquest, 615 F.3d at 506. The defendant attempted to distance itself from defendants occupying other roles in the chain of distribution by stating that it “does not make opioids available to patients,” and instead, a “patient can obtain opioids only after a doctor makes an independent decision to write a prescription and a pharmacist makes the independent decision to fill the prescription.” (Doc. No. 2667 at 8.) All the finger-pointing between and among plaintiffs and defendants emphasizes what has been increasingly clear as the first MDL cases approach trial; it will take a Herculean effort by the courts (and juries) to sort through the medical, social, political, and economic issues that are intertwined with the opioid crisis. The breadth of the problem even raises the question of whether jury trials are the right tools to address social crises of this magnitude and complexity. Indeed, some studies place the national economic burden of the opioid crisis at $78.5 billion, with over 35,000 people dying annually for drug overdoses related to opioids. U.S. District Judge Dan Polster, who presides over the MDL cases, bluntly emphasized these complex challenges in recent comments: [E]veryone shares some of the responsibility, and no one has done enough to abate it. That includes the manufacturers, the distributors, the pharmacies, the doctors, the federal government and state government, local governments, hospitals, third-party payers and individuals. Just about everyone we’ve got on both sides of the equation in this case. The federal court is probably the least likely branch of government to try and tackle this, but candidly, the other branches of government, federal and state, have punted. So it’s here.
October 16, 2019
California Attorney General Issues Draft Regulations for CCPA
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Joseph Lynyak, Robert Cattanach, Jamie Nafziger and Erin Bryan for the following e-newsletter update: 1. Introduction On October 11, 2019, the California Attorney General (the “California AG”) issued draft regulations (the “Draft Regulations”) pursuant to his authority under the California Consumer Privacy Act of 2018 (“CCPA”).1 The publication of the Draft Regulations commences the public comment period during which numerous interpretative issues relating to the implementation of the CCPA hopefully will be addressed and resolved. Unfortunately, the California AG chose to limit the Draft Regulations to basic process issues relating to the overall structure of the CCPA, and elected not to address many of the more difficult compliance problems identified by industry participants. More troubling is the inclusion of additional procedural steps that a covered “business”2 must follow when complying with “requests” for “personal information”3 (“PI”). (If ultimately adopted, several of these additional compliance obligations could likely create technical and unintended violations of the CCPA.)4 This Alert provides an initial analysis of the approach taken by the Draft Regulations, as well as suggestions for participating in the rule-making process.5 2. Discussion Analysis of the Draft Regulations The Draft Regulations were issued by the California AG pursuant to authority delegated to him by Section 1798.185 of the CCPA. Notwithstanding the fact that the Draft Regulations are proposals and not yet final, the Draft Regulations establish a “backbone” based upon which covered businesses may begin to evaluate whether their implementation and compliance programs appear reasonable. The Draft Regulations are comprised of seven “Articles”; Articles 1 and 7 contain definitions and a severability clause, whereas Articles 2 through 6 are the implementing provisions of the CCPA, and address: The notification process by covered business to California “consumers” of their rights under the CCPA6 The processing of “verifiable consumer requests”7 The verification of identify for consumer requests8 Special rules for minors’ PI,9 and Determining value to comply with the anti-discrimination provisions of the CCPA Articles 2 through 6 of the Draft Regulations will be addressed separately below. A. General In numerous provisions scattered across Articles 2 through 6, the Draft Regulations establish varying degrees of care that must be exercised by a business when dealing with a consumer, including identifying the consumer, evaluating the sensitivity of a consumer’s request, and responding in a manner that protects a request for data or to delete PI.10 In addition, borrowing from federal consumer law that consumer disclosures be “clear and conspicuous,” among other things required notices must be easily understood, formatted, and accessible to consumers, and provided in the languages in which a business interacts with consumers.11 From a drafting perspective, the Draft Regulations intentionally conflate non-internet-based business operations with partial or sole internet contact between businesses and consumers by interrelating and cross-referencing CCPA obligations. This approach (which may be necessary for brevity’s sake yet nevertheless complicated) will require businesses to carefully parse through the Draft Regulations’ compliance mandates in order to identify various subcategories of business models that might apply and may require differing compliance obligations. B. The Notification Process of a Consumer’s Rights Article 2 sets forth several disclosures that have to be prepared and provided by a business to a consumer. It is by far the most instructive of the five Articles, and indicates the content that must be included in disclosures provided to consumers. Article 2 of the Draft Regulations sets forth general principles when providing a disclosures of how a business collects PI, and indicates that a notice must contain the following information: A list of the categories of PI about consumers to be collected, For each category of PI, the business or commercial purpose(s) for which it will be used, If the business sells PI, the link titled “Do Not Sell My Personal Information” or “Do Not Sell My Info,” and A link to the business’s privacy policy.12 Article 2 imposes an expanded disclosure requirement when describing categories of PI, including a requirement that a business explain the business or commercial purpose for which PI will be collected. Further, a specific prohibition states that if a business intends to expand the scope of PI being collected, it must first provide a new disclosure to the consumer (which confirms that a new disclosure process must be undertaken by a business).13 Article 2 addresses several subcategories of notices that must be provided. For example, Article 2 addresses the notice that has to be provided regarding the right of a consumer to “opt-out” of the sale of PI (assuming an exception does not apply).14 Depending upon the nature of the contact between the business and the consumer, a notice of a consumer’s opt-out right must include the following: A description of the consumer’s right to opt-out of the sale of their PI, The web-based form by which the consumer can submit their request to opt-out online (or, if the business does not operate a website, the offline method by which the consumer can submit their request to opt-out), Instructions for any other method by which the consumer may submit their request to opt-out, Any proof required when a consumer uses an authorized agent to exercise their right to opt-out, and A link or the URL to the business’s privacy policy (or, in the case of a printed form containing the notice, the URL of the webpage where consumers can access the privacy policy).15 Another subcategory of notice and disclosure is a notice of financial incentives that describes the incentive being offered, the material terms of the financial incentives and the right of the consumer to withdraw at any time. Finally, Section 999.308(b) the Draft Regulations requires a detailed and expanded description of a businesses’ privacy policy. The privacy policy must be posted on a business’s website (or posted in a conspicuous place if the business dose not operate a website), and must include: The right to know about the collection, disclosure and sale of PI, The right to request deletion of PI, The right to opt-out of the sale of PI, The right to non-discrimination for the exercise of a consumer’s CCPA rights, The use of an authorized agent, A contact for additional information, The date the business’ privacy policy was last updated, and If Section 999.317(g) of the Draft Regulations applies, the metrics required or a link to it.16 C. The Processing of Verified Consumer Requests by Covered Business Article 3 of the Draft Regulations contains a somewhat complicated set of requirements that vary depending upon the mode of conducting business between a business and a consumer. As an initial matter, the Draft Regulations indicate that a business must provide two or more methods for submitting requests to know about PI, which must include a toll-free telephone number, along with several other acceptable methods that may be employed. However, while a request to delete PI must include two permissible methods of making the request, a toll-free number (while permissible) is not mandatory.17 Importantly, any method for making a request must “reflect the manner in which the business primarily interacts with a consumer.”18 If a consumer makes a request that is not a designated methodology selected by the business, the business may choose to treat the request as having been made through a proper channel, or else must contact the consumer and provide specific directions to submit a request properly.19 Following the receipt of a request to know or a request to delete, the Draft Regulations add a new procedural step that is not included in the statutory language of the CCPA—which is a requirement within 10 days of the receipt of a request the business must notify the consumer that the request has been received and how the request will be processed. (It appears that this new 10-day notice falls within the CCPA statutory deadline of 45 days to respond and up to a maximum of 90 days20.)21 The Draft Regulations contain detailed instructions for responding to requests to know and request to delete—the emphasis is placed on verification of the identification of the consumer. If verification is not possible, a business may decline to respond to the request, but must notify the consumer that the denial was based upon the failure to properly identify the consumer. In the instance in which the consumer has a password-protected account with a business, the business may provide a secure portal for retrieving the requested data. In regard to a request to opt-out, a business must provide two alternative methods to submit a request to opt-out, including a mandatory interactive web-based form using a link entitled “Do Not Sell My Personal Information,” or “Do Not Sell My Info” on the business’s website or mobile application.22 (Other alternative methods include a toll-free number, a designated email address, a form submitted in person, or an electronic mechanism to indicated the consumer’s choice to opt-out.) A business may offer a consumer the option to opt-out of sale of certain categories of PI, provided that the opt-out of the sale of all information is more prominently displayed. A request to opt-out must be acted upon within 15 days of the business’s receipt of the request.23 Record retention for compliance is set at 24 months (although retention of requests may by necessity be longer if an exemption is asserted, such as the retention of PI based upon the length of an applicable statute of limitations or threat of litigation being brought against a business for non-compliance). D. Verification Alternatives for Properly identifying a Consumer Article 4 of the Draft Regulations create a sliding scale of consumer verification standards based upon the sensitivity of PI being requested. Factors include: The type, sensitivity, and value of the PI collected and maintained about the consumer (i.e., sensitive or valuable PI requires more stringent verification processes), The risk of harm to the consumer posed by any unauthorized access or deletion, The likelihood that fraudulent or non-authorized individuals are seeking the PI, Whether the PI is sufficiently robust to protect against fraudulent requests or being spoofed or fabricated, The manner in which the business interacts with the consumer, and The availability of technology for verification. In the case of a customer that holds a password-protected account with a business, the business may require the customer to verify the customer’s identity through the account. However, if a request is made, the business must also require that the customer reverify the customer’s identification before disclosing or deleting PI.24 The Draft Regulations establish a sliding scale of verification steps depending upon whether a request is made for categories of PI or specific items of PI. In the case in which a consumer has a password-protected account with a business, the business may employ its existing verification procedures when responding to a consumer’s request. In the case of a request to identify categories of PI when a consumer either does not have a password-protected account or no account with a business, the a business must identify a consumer with a “reasonable degree of certainty”—which is defined to mean matching a consumer with at least two data points of identification. In the case a consumer either does not have a password-protected account or no account with a business and specific items of PI are requested, the standard for verification is a “reasonably high degree of certainty”—which is defined to mean at least three pieces of PI provided by the consumer plus a verification signed by the consumer under penalty of perjury.25 Article 4 also identifies several steps that a business should undertake to verify a consumer’s identity, based upon the factual matter whether the consumer has an account with the business. This combination of qualitative and quantitative factors may require individual attention to a consumer’s request, and in any event may present challenges for developing automated response applications.26 In the case of a request to delete PI, the Draft Regulations would require that the standard and verification methodology would vary depending upon the sensitivity of the PI and the risk of harm to the consumer. Finally, when a consumer employs an agent to make a request, the business may require that the authorization be made in writing and that the consumer verify his/her identity directly with the business. E. Protection of Minors and Their PI Article 4 of the Draft Regulations is relatively straightforward in regard to a business obtaining the consent of a parent of a child for the child’s PI below the age of 13, but requires that the parent (or guardian) adequately verify the status of the parent or guardian. Verification alternatives include: Providing a consent form to be signed by the parent or guardian under penalty of perjury and returned to the business by postal mail, facsimile, or electronic scan, Requiring a parent or guardian, in connection with a monetary transaction, to use a credit card, debit card, or other online payment system that provides notification of each discrete transaction to the primary account holder, Having a parent or guardian call a toll-free telephone number staffed by trained personnel, Having a parent or guardian connect to trained personnel via video-conference, Having a parent or guardian communicate in person with trained personnel, and Verifying a parent or guardian’s identity by checking a form of government-issued identification against databases of such information.27 Unfortunately, Article 5 is silent in regard to any process by which a business might reasonably identify that a minor is communicating with the business. Whether the business can rely upon parental oversight of a minor’s use of the internet is not addressed.28 F. Complying with the anti-discrimination provisions of the CCPA Section 1798.125 of the CCPA prohibits a business from discriminating against a consumer because the consumer exercised a privacy right conferred by the CCPA, such as by opting-out from the sale of PI. However, a business may offer a price or service differential for not exercising CCPA rights if it is reasonably related to the value of the consumer’s PI. Article 6 of the Draft Regulations requires that, when setting a price differential, a business must use one of the following valuation methodologies: The marginal value to the business of the sale, collection, or deletion of a consumer’s data or a typical consumer’s data, The average value to the business of the sale, collection, or deletion of a consumer’s data or a typical consumer’s data, Revenue or profit generated by the business from separate tiers, categories, or classes of consumers or typical consumers whose data provides differing value, Revenue generated by the business from sale, collection, or retention of consumers’ PI, Expenses related to the sale, collection, or retention of consumers’ PI, Expenses related to the offer, provision, or imposition of any financial incentive or price or service difference, Profit generated by the business from sale, collection, or retention of consumers’ PI, or Any other practical and reliable method of calculation used in good-faith.29 The quantification and justification of a value may prove to be problematic to businesses when used to support differing pricing between consumers exercising or not exercising CCPA rights. For example, in the case of a business that employs voluminous data sets, revenue generated by individual consumers may be difficult to correlate a pricing differential that is more than nominal. Further, whether supportive economic evidence is necessary may present a cost factor that smaller businesses may find unrealistic. Providing Input During the Public Comment Period When issuing the Draft Regulations for public comment, the California AG announced that his office would be holding hearings December 2nd in Sacramento, December 3 in LA, December 4th in San Francisco and on December 5th in Fresno. Comments on the Draft Regulations can be provided at those hearings, via mail or via e-mail. Observations The Draft Regulations add new obligations and varying qualitative standards for compliance that may present practical compliance difficulties to covered businesses. Although the process and disclosure clarifications provide a clearer roadmap when preparing a project plan for compliance, efforts will have to be undertaken to ensure that a business’s policies and procedures include the numerous compliance obligations set forth in the Draft Regulations analyzed herein. While as noted above the Draft Regulations attempt to provide a compliance structure for CCPA notices and processing of requests from consumers, the primarily failure of the Draft Regulations is the failure to address reliable interpretations of unresolved issues set forth in the CCPA, such as the various exemptions contained in the CCPA. This may mean that businesses seeking to make use of exemptions or partial exemptions will be forced to submit focused interpretative requests to the California AG. (Whether the California AG will be responsive to requests for interpretations remains to be seen.) The proposed inclusion of non-statutory response times and qualitative standards discussed herein are particularly problematic and could be the subject of a challenge by industry stakeholders that may determine that compliance with these additional requirements is unrealistic and beyond the delegated authority of the California AG. Additionally, industry stakeholders are likely to raise concerns about the proposed requirement that businesses treat user-enabled anti-tracking privacy controls as equivalent to a verifiable opt-out request. Finally, as is frequently the case, completely new regulatory schemes that are initially finalized and issued are rarely modified until their effectiveness is evaluated—which in the case of the Draft Regulations may mean extended period of time. We strongly recommend that businesses consider submitting comment letters to the California AG—either directly or through intermediaries. (Of course, attorneys at Dorsey are available to assist in this task.) * * * Please note that this Alert is an initial analysis of the issues and concerns raised by the Draft Regulations, but is not intended to constitute a comprehensive identification of concerns that businesses will face in their compliance efforts. It is likely that covered businesses will identify other significant compliance issues, and those concerns should be addressed wither through the comment or interpretative administrative processes. We are available to discuss any questions or comments. 1 Section 1798.100 et seq. of the California Civil Code. 2 Section 1798.140(c) of the CCPA. 3 Section 1798(o) of the CCPA. 4 As stated in the Draft Regulations, a violation of the Draft Regulations will be deemed a violation of the statutory requirements of the CCPA. See, Section 999.300(b) of the Draft Regulations (available at: https://oag.ca.gov/privacy/ccpa). 5 https://oag.ca.gov/privacy/ccpa. 6 Section 1798.140(g) defines a “consumer” as a California resident. (Note, however, that AB 25, which was signed by the California Governor, for a 1-year period temporarily exempts most employee-related data from coverage under the CCPA. 7 Section 1798.140(y) of the CCPA. 8 Section 1798.185(a)(7) of the CCPA. 9 Section 1798.120(c) of the CCPA. 10 The Draft Regulations generally use the defined terms a “request to know” and a “request to delete” to mean a communication from a consumer relating to PI and the exercise of the consumer’s privacy rights. See, Sections 999.301(n) and (o) of the Draft Regulations. 11 Disclosures must be readily available with individuals with disabilities, which in the internet world has created significant litigation risk for non-compliance. See, Section 999.305(d) of the Draft Regulations. 12 Section 999.305(b) of the Draft Regulations. 13 Section 999.305(a)(4) of the Draft Regulations. 14 Unfortunately, the Draft Regulations completely ignore how the exercise and disclosure of the various exceptions contain in the CCPA should be handled. 15 Section 999.306(c) of the Draft Regulations. 16 It should be noted that these categories contain numerous items of required disclosure; a business preparing its privacy policy should ensure that it has included all required items. 17 A request to delete must entail a two-step process: first, a request to delete PI, and second, a separate confirmation that deletion of PI has been requested. 18 Section 999.312(c) of the Draft Regulations. 19 Section 999.312(f) of the Draft Regulations. (For large businesses, this latter requirement could present considerable training challenges.) 20 Section 999.313(a) of the Draft Regulations. Compare with, Section 1798.130(a)(2) of the CCPA. 21 This shortening of the response time may be particularly burdensome to large businesses that elect to centralize their CCPA responses. 22 The Draft Regulations are notably silent when differentiating between internet websites and mobile applications; compliance with both alternative communication modes could present technology challenges to businesses if more than a link to a website is required in the case of a mobile application. 23 Section 999.315(e) of the Draft Regulations. In a clear change from the statutory requirements of the CCPA, Section 999.315(h) indicates that a request to opt-out need not meet the standard of a verified consumer request, which may complicate compliance and training policies and procedures. 24 Section 999.324(a) of the Draft Regulations. 25 Sections 999.324 and 999.325 of the Draft Regulations. 26 Sections 999.323, 999.324 and 999.325 of the Draft Regulations. 27 "(b) When a business receives an affirmative authorization pursuant to subsection (a) of this section, the business shall inform the parent or guardian of the right to opt-out at a later date and of the process for doing so on behalf of their child pursuant to section 999.315.” Section 999.330 of the Draft Regulations. 28 Article V of the Draft Regulations. This likely means that the default language is that contained in the CCPA, which imposes special opt-in requirements for minors when a business has “actual knowledge that a consumer is less than 16 years of age.” 29 Section 999.337(b) of the Draft Regulations.
October 16, 2019
Anti-Kickback
A Massive Number of New Health Law Regulatory Proposals as Part of the “Regulatory Sprint to Coordinated Care”: Proposed Changes to the Stark Law, Anti-Kickback Statute, Beneficiary Inducement CMP, Privacy Laws Governing Substance Use Disorder Records, and the Stark Law Advisory Opinion Process
Today, the Centers for Medicare & Medicaid Services (CMS) and the Department of Health and Human Services (HHS) Office of Inspector General (OIG) each released their long-anticipated proposed rules to revise the federal self-referral law (or “Stark Law”) regulations, the safe harbors under the federal anti-kickback statute (AKS), and the civil monetary penalty law (CMP) for beneficiary inducements. The proposed rules are part of HHS’s “Regulatory Sprint to Coordinated Care,” which seeks to remove regulatory obstacles to care coordination and a value-based healthcare delivery system. The HHS press release regarding the proposed rules is available here, and includes links to each of the CMS and OIG proposed rules. For our prior posts on the Regulatory Sprint to Coordinated Care, see here and here. Relatedly, the Substance Abuse and Mental Health Services Administration (SAMHSA) published proposed rules to revise privacy rules for substance use disorder records on August 26, and CMS published proposed rules to revise the Stark Law advisory opinion regulations on August 14 (as part of the Medicare Physician Fee Schedule proposed rule). We are reviewing the proposed rules and will post an in-depth analysis shortly.
October 9, 2019
Medicare / Medicaid
Reimbursement for Remote Patient Monitoring Services in 2019
Medicare reimbursement for remote patient monitoring has taken a number of steps forward throughout this year. New and proposed rules from the Centers for Medicare and Medicaid Services both expand the billing options available to health care providers and also build in additional flexibility in the provision of remote patient monitoring in order to further the health industry’s push to value-based care. Remote patient monitoring (“RPM”) is a form of digital health in which medical data from individual patients is collected in one location and electronically transmitted to health care providers in a different location for assessment and recommendations. RPM differs from other digital health services in that there is not necessarily a live, or “real-time”, interaction between the patient and their health care provider. Instead, RPM is used by health care providers to monitor various aspects of their patient’s vital signs, including: weight, blood pressure, blood sugar, heart rate, and oxygen levels. RPM is not only a useful tool for health care providers to use during a patient’s hospitalization, but it is also useful in reducing the number of hospitalizations altogether. For example, RPM can be used to allow older or disabled individuals to live at home longer and avoid having to move into skilled nursing facilities, since their vitals can be monitored without having to see a health care provider in person. Until this year, Medicare reimbursement for RPM services was difficult to come by. While Medicare previously offered reimbursement for RPM services billed under CPT code 99091, the code did not take current technology and staffing models into account (likely because the language from the code dates back roughly 16 years). In order to address this issue and further incentivize health care providers to use RPM, the Centers for Medicare and Medicaid Services (“CMS”) finalized three new RPM billing codes that were effective January 1, 2019 (“Final Rule”). The new codes are titled, “Chronic Care Remote Physiologic Monitoring” and included the following descriptions: CPT code 99453: “Remote monitoring of physiologic parameter(s) (e.g., weight, blood pressure, pulse oximetry, respiratory flow rate), initial; set-up and patient education on use of equipment.” CPT code 99454: “Remote monitoring of physiologic parameter(s) (e.g., weight, blood pressure, pulse oximetry, respiratory flow rate), initial; device(s) supply with daily recording(s) or programmed alert(s) transmission, each 30 days.” CPT code 99457: “Remote physiologic monitoring treatment management services, 20 minutes or more of clinical staff/physician/other qualified healthcare professional time in a calendar month requiring interactive communication with the patient/caregiver during the month.” Finalization of these new codes did not come without fair criticism and disparate interpretations of the level of required supervision. In creating the codes, CMS stated that RPM could not be delivered “incident to” a practitioner’s professional services. Therefore, RPM services could not be reimbursed if the services were furnished by auxiliary personnel (individuals acting under the supervision of a physician). Following backlash of this conclusion, CMS issued a technical correction to the Final Rule on March 14, 2019, that allows “incident to” billing of RPM services by auxiliary personnel if they are under direct supervision. This was overall a win for RPM reimbursement; however, through separate codes (CPT 99487, 99489, and 99490), CMS allows reimbursement for Chronic Care Management under general supervision. The difference being that general supervision does not require a physician to be in the same building at the same time as the auxiliary personnel delivering the services. This contradictory treatment resulted in commentators arguing that CMS’s approach hinders, rather than increases, a patient’s access to digital health services by limiting where a physician may be located during the supervision of such services. CMS seems to be addressing this concern in the proposed 2020 Physician Fee Schedule that was published August 14, 2019 (“Proposed Rule”). The Proposed Rule would allow “incident to” RPM services to be reimbursed under general supervision rather than limiting reimbursement to direct supervision. By way of example, this means RPM could be reimbursed when the auxiliary personnel use RPM with patients who are in a hospital while the auxiliary personnel are supervised via other telemedicine modalities by a physician at their home. This change would greatly improve a patient’s access to RPM by enabling physicians to bill for such services delivered in a more flexible manner. In addition to this change, the Proposed Rule revises CPT code 99457 and adds yet another code to allow for additional reimbursement for each 20-minute interval that RPM services are provided. This is in contrast to the Final Rule’s version of CPT code 99457, which allowed only one reimbursement for RPM services delivered for 20 minutes or more. CMS is accepting comments on the Proposed Rule until September 27, 2019. If you would like to submit comments or have any questions, one of the authors or your regular Dorsey attorney would be happy to assist you.
September 20, 2019
CCPA Compliance Screening and Assessment Tools–Now Available
From Robert Cattachach, a Dorsey Partner with our Regulatory Affairs Group: I am pleased to announce that Dorsey has launched web-based CCPA Screening and Assessment Tools to help organizations in preparing for the California Consumer Privacy Act (CCPA), which goes into effect on January 1, 2020. Companies can determine whether the CCPA will apply to their operations by using the screening tool available on Dorsey’s website. This free tool is available to all organizations and typically takes less than five minutes to complete. It parses the CCPA into four threshold questions, and upon completion of the questionnaire, the tool provides a free report on whether the act applies to the organization based on the answers provided. The online tool can be found here. If the CCPA applies, Dorsey also offers a more comprehensive online Assessment Tool to help companies evaluate their current CCPA compliance status. Existing Dorsey clients will have immediate access to our online Assessment Tool. Please email us if you would like to receive the link to send to a client. For companies that are not current clients of the firm, but you think might like access to the Assessment Tool, please email one of our CCPA assessment professionals. Dorsey can offer clients legal services ranging from individualized advice on discrete issues to fixed-fee suites of services for CCPA-related compliance projects. This new law marks a dramatic sea change in American privacy law, as it imposes significant new burdens on organizations that collect, use or share data on California residents. In addition to imposing significant statutory penalties for non-compliance, the CCPA creates an unprecedented right for consumers to bring class actions if their data is compromised in a breach, even if there are no actual damages. By imposing automatic statutory penalties for each affected consumer if a company fails to implement reasonable security practices and procedures, the CCPA is expected to create potentially enormous class action liability for companies suffering a breach. Dorsey continues to publish timely CCPA updates on its website. Updates can be accessed here.
September 17, 2019
CCPA Requires “Reasonable Security”: but You Can’t have Reasonable Security Without Proper Vulnerability Management
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Divya Gupta and Cody Wamsley for the following e-news letter update: With the California Consumer Privacy Act (“CCPA”) set to take effect on January 1, 2020, and the resulting looming specter of statutory damages and data breach class action litigation for failure to implement “reasonable security” on the near horizon, reducing or mitigating the harms that result from such cyber-attacks is more important than ever. Since 2015, more than three in five Californians have been a victim of a data breach, making implementation of reasonable security controls now a critical and necessary component of CCPA compliance.1 While the retail industry has had record breaking breaches from malware and hacking, especially with card data, no industry is risk free when it comes to adequate data security. Managing or mitigating risk, however, requires implementing “reasonable security,” which derives from the Center for Internet Security's Top 20 Critical Security Controls (CSC 20) per then California Attorney General in 2016, Kamala Harris. In California’s 2016 Data Breach Report, Harris stated that “[The CSC 20] are the priority actions that should be taken as the starting point of a comprehensive program to provide reasonable security.”2 Recommendation 1 of the same report is more explicit: The 20 controls in the Center for Internet Security's Critical Security Controls identify a minimum level of information security that all organizations that collect or maintain personal information should meet. The failure to implement all the Controls that apply to an organization's environment constitutes a lack of reasonable security. (emphasis added). Based on these statements, the CSC 20 likely comprise a defensive list to detect, prevent, respond to, and mitigate security incidents, and are designed to address various domains of information security to provide organizations with a roadmap to achieve resiliency. Whether the CSC 20 will become the explicit standard for “reasonable security” is still an open question, but given the California AG’s previous statements, these controls should be top-of-mind for any organization that seeks to avoid significant liability under the CCPA. The CSC 20 is broken down into three main categories of controls: Basic, Foundational, and Organizational. The total scope of the CSC 20 is beyond the scope of this article, but suffice it to say that an organization may be hard-pressed to assert that it has “reasonable security” in place if it does not at least adhere to the Basic controls. The Basic controls consist of the following 6 items: Inventory and Control of Hardware Assets Inventory and Control of Software Assets Continuous Vulnerability Management Controlled Use of Administrative Privileges Secure Configuration for Hardware and Software on Mobile Devices, Laptops, Workstations and Servers Maintenance, Monitoring and Analysis of Audit Logs Of these 6 Basic controls, #3, Continuous Vulnerability Management, stands out as one of the most important for an organization to focus on to prevent data breaches. According to a recent study, nearly 60% of recent data breaches were the result of unpatched vulnerabilities.3 Indeed, the California AG stated that “patching newly discovered security vulnerabilities is critical” while citing the related CSC 20 control. In the last few years, the importance of vulnerability management has become more apparent and this control has risen to become the #3 control in the CSC 20. Vulnerability management's main purpose is to identify and remedy software vulnerabilities as quickly as possible. It often doesn't take any significant skill on an attacker's part to exploit published vulnerabilities and so once a software vendor releases a patch, knowledge of its associated vulnerability quickly becomes widespread and the race is on between organizations deploying patches and attackers attempting to exploit the vulnerability. Organizations that do not scan for and proactively address vulnerabilities are at great risk for a breach. Patching software security is a no-brainer, or so you’d think. Well, the challenge lies in the scale of the organization, the effect a patch could have on other organization systems, and the attacker’s ability to quickly weaponize ahead of scheduled patch rollouts, among other things. To properly implement vulnerability management may not be as easy as we'd like, but it is critical and low-hanging fruit on the CSC 20 tree. The European Union deems privacy a fundamental human right, and is taking enforcement seriously -- think Marriott and British Airways GDPR fines. We expect to see similar, if not greater, liability for organizations that violate the upcoming CCPA. Organizations that haven’t yet automated the process to monitor for and remediate vulnerabilities on networks and systems should do so now and should institute vulnerability and patch management policies. While all of the CSC 20 controls are important, perhaps the most effective solution to prevent a major data breach for any organization lies in assessing and managing known vulnerabilities. Modernizing vulnerability management programs should be a focus in the short term run up to January 1, 2020 effective date. Dorsey’s Cybersecurity and Privacy Team has developed a catalog of security practices and procedures to help achieve operational resilience and defend companies from the forthcoming wave of data breach litigation. Notably, Dorsey has partnered with leading technical security industry organizations to offer full service advice.4 Additional references: https://www.us-cert.gov/sites/default/files/c3vp/crr_resources_guides/CRR_Resource_Guide-VM.pdf https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r3.pdf https://www.sans.org/reading-room/whitepapers/threats/implementing-vulnerability-management-process-34180 1 See California’s 2016 Data Breach Report, available at https://oag.ca.gov/sites/all/files/agweb/pdfs/dbr/2016-data-breach-report.pdf. 2 https://oag.ca.gov/sites/all/files/agweb/pdfs/dbr/2016-data-breach-report.pdf. 3 https://www.darkreading.com/vulnerabilities---threats/unpatched-vulnerabilities-the-source-of-most-data-breaches/d/d-id/1331465. 4 https://www.dorsey.com/services/cybersecurity-privacy-social-media.
September 16, 2019