Dorsey Health Law
Significant New Healthcare Privacy and Cybersecurity Developments
As the federal government continues to take action in response to events impacting the healthcare landscape, stakeholders must ensure that they are staying up-to-date with health information privacy and security developments in the healthcare industry. This blog post summarizes two recent significant actions: a new HIPAA final rule and proposed federal cybersecurity legislation. New HIPAA Final Rule The U.S. Department of Health and Human Services (“HHS”) has expressed concern about patient trust in the privacy of health care information since the U.S. Supreme Court’s decision in Dobbs v. Jackson Women’s Health Organization in 2022. Most recently, on April 22, 2024, HHS’s Office for Civil Rights (“OCR”) issued a new final regulation under the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) Privacy Rule: HIPAA Privacy Rule to Support Reproductive Health Care Privacy. The final rule strengthens privacy protections for sensitive information about reproductive health care by: Prohibiting covered entities and their business associates from using or disclosing protected health information (“PHI”) for the purpose of an investigation into or proceeding against an individual or entity who seeks, obtains, provides, or facilitates lawful reproductive health care, which includes providing information on or paying for any such services. This prohibition does not apply in situations of suspected abuse, neglect, or endangerment. Prohibiting covered entities and their business associates from identifying any individual or entity for the purpose of any such investigation or proceeding. Requiring covered entities and their business associates to obtain a signed attestation when they receive a request for PHI potentially related to reproductive health care for the purpose of health oversight activities, judicial or administrative proceedings, law enforcement, or coroner or medical examiner disclosures. The attestation must include the individual or class of individuals whose PHI is requested, the covered entity or business associate, the requestor, a statement that the PHI will not be used or disclosed for any prohibited purpose, and a statement acknowledging the criminal penalties for any violation of the Privacy Rule. Prohibiting a provider from refusing to treat a person as the personal representative of a patient merely because they provided or facilitated reproductive health care for a patient. Requiring covered entities to revise their Notice of Privacy Practices. The final rule is scheduled for publication in the Federal Register on April 26, 2024. It will become effective 60 days after publication, with compliance to occur by February 16, 2026 for the Notice of Privacy Practices requirement and within 240 days after publication for all other requirements. As the compliance dates quickly approach, covered entities and business associates must ensure alignment of their policies, practices, and Notices of Privacy Practices with this new final rule. Covered entities and business associates may also need to revise their business associate agreements, to the extent that such agreements would permit a business associate’s use or disclosure of PHI that is prohibited under the new rule. Proposed Federal Cybersecurity Legislation The healthcare industry has seen a recent increase in cybersecurity incidents. According to OCR, over the past few years, the number of large breaches reported and the number of individuals affected by those breaches have doubled. Now, following the Change Healthcare breach, Congress is considering new legislation: Health Care Cybersecurity Improvement Act of 2024 (S.B. 4054). On March 22, 2024, Senator Mark R. Warner (D-VA), introduced the proposed federal legislation, which has been referred to the Senate Committee on Finance. Sen. Warner, who is a member of the Committee on Finance and co-founder and co-chair of the Senate Cybersecurity Caucus, is a well-known advocate of enhanced cybersecurity in the healthcare industry. The proposed legislation charges the Secretary of HHS with setting minimum cybersecurity standards for Medicare’s Accelerated Payment Program and Advance Payments Program. During the COVID-19 public health emergency, the Centers for Medicare and Medicaid Services offered accelerated and advance payments to assist in disruptions to claims payments due to the public health emergency. Under the Health Care Cybersecurity Improvement Act of 2024, if a participating Part A hospital or one of its intermediaries does not meet the set standards, the hospital will not receive accelerated payments under the Accelerated Payment Program where a cybersecurity incident caused the disrupted operations or cash flow problems. Similarly, if a participating Part B provider or one of its intermediaries does not meet the set standards, the provider will not receive advance payments under the Advance Payments Program where a cybersecurity incident caused the delayed claims payments by health insurance companies. Notably, the accelerated and advance payments are only for Medicare Part A and Part B claims payments. Currently, the bill is still in the early stages of the legislative process, and, if the law were enacted, enforcement would not occur until two years after its enactment. However, given the continuing prevalence of cybersecurity incidents in the healthcare industry, additional detailed HIPAA Security Rule cybersecurity guidance, as well as emerging state agency activity (such as New York’s proposed cybersecurity regulations for hospitals), now is the time for healthcare providers and other covered entities and business associates to focus on HIPAA Security Rule compliance to protect against hacking, ransomware and other cybersecurity attacks, and the resulting disruptions to clinical care. If you have any questions about the HIPAA Privacy Rule or Security Rule, proposed cybersecurity legislation, or their potential impact on you or your organization, please contact the authors or your regular Dorsey attorney.
April 29, 2024
Employment
What Employers Need to Know about Iowa’s Religious Freedom Restoration Act
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s William Miller and Joshua Hughes for the following e-newsletter update: On April 2, 2024, Governor Kim Reynolds signed Iowa’s religious freedom restoration act into law, effective immediately. While supporters praised the law’s commitment to strengthening the free exercise of religion, some opponents expressed concerns that the law could lead to discrimination justified on religious grounds. In this alert, Dorsey & Whitney attorneys Bill Miller and Josh Hughes explain what the law says, how it works in practice, and what considerations both public and private sector employers need to take into account going forward. Read more here.
April 11, 2024
Transactions
FinCEN Proposes AML Compliance Obligations for Non-Financed Real Estate Transactions
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Joseph Lynyak, Erin Bryan, and Matthew Dickerson for the following e-newsletter update: FinCEN Proposes AML Compliance Obligations for Non-Financed Real Estate Transactions FinCEN has proposed to expand anti-money laundering requirements on a national basis to include non-financed residential real estate transactions in which a transfer of real property would take place between a transferor and a transferee such as an entity or a trust. The reporting obligation would rest with a person or entity that takes the lead role in the settlement process. The proposal when adopted will impose new and significant disclosure responsibilities on non-financed residential real estate transactions, and will impact, among other things, real estate transfers generally, estate and tax planning and related transactions. Accordingly, advance planning to anticipate the reporting requirements of the proposal would be advisable. Read more here.
March 20, 2024
Employment
Popovich v. Allina Health – Sea Change, Ripple, or Something In-Between?
In July 2020, the Minnesota Supreme Court in Popovich v. Allina Health, 946 N.W.2d 885 (Minn. 2020), departed from 30 years of precedent regarding vicarious liability for hospitals. Before Popovich, a hospital could not be held vicariously liable for the negligence of independent contractors. After Popovich, a hospital can be held liable under a theory of apparent authority for the professional negligence of independent contractors in the hospital’s emergency room if: (1) the hospital held itself out as the provider of the services in question; and (2) the patient looked to the hospital for care and relied on the hospital to select the individuals that provided services. Although Popovich involved emergency care, the decision was expected to have wide-ranging impacts on healthcare providers. Among other things, Popovich was expected to impact professional service agreements between hospitals and independent physician groups. It was expected to impact contract provisions related to liability insurance and indemnification. It was expected to impact the manner in which certain services were marketed to the public. Many of these expectations have come to fruition. And there can be no dispute that Popovich’s application of apparent authority principles to healthcare providers has allowed some claims to proceed that, previously, would have been dismissed early in litigation or not brought at all. But interestingly, in the four years since the Minnesota Supreme Court issued its decision, the handful of Minnesota courts tasked with applying Popovich have dismissed the vicarious liability claims before them because the reliance element had not been satisfied. For example, in Rock v. Abdullah, 2022 Minn. App. Unpub. LEXIS 457 (Minn. Ct. App. July 18, 2022), the Minnesota Court of Appeals determined that a hospital could not be held vicariously liable for the alleged negligence of a non-employee physician with surgical privileges there. The court’s decision was based on the second element of Popovich: reliance. Because plaintiff did not rely on the hospital to select the physician that performed the plastic surgery, but instead made that selection herself and in advance of surgery, the hospital was not liable under a theory of apparent authority. In so holding, the Rock v. Abdullah court recognized that reliance is a context-specific standard. In Popovich, the care at issue took place in the emergency room, a situation in which most people do not select the medical professionals that treat them. By contrast, in Rock v. Abdullah, plaintiff had several visits with the physician before the treatment at issue. The mere fact that the physician may have been “affiliated” in some manner with the hospital did not satisfy the reliance standard. As another example, the Minnesota Court of Appeals, in Lund v. Calhoun Orange, Inc., 2023 Minn. App. Unpub. LEXIS 933 (Minn. Ct. App. Dec. 4, 2023), considered whether Ultimate Fitness could be held vicariously liable for the emergency medical care provided by one of its subsidiary fitness studios. The court framed the sole question before it as “whether knowledge alone satisfies the reliance prong” of Popovich. The court reviewed pre-Popovich case law, including precedent from over a century ago, and concluded that knowledge alone did not satisfy the reliance standard: “Each [pre-Popovich] case defined knowledge as a prerequisite to reliance rather than defining the terms as interchangeable. The district court correctly determined that ‘apparent authority reliance requires more than simply whether or not plaintiff was aware of the representations of authority by the principal.’” Because there was no evidence that plaintiff relied on Ultimate Fitness’s representations of authority when choosing the specific fitness studio at issue, the court affirmed dismissal of the apparent authority claim. As a final example, in Doe v. Meany, 2023 Minn. Dist. LEXIS 5370 (Minn. Dist. Ct. May 31, 2023), the Hennepin County District Court granted summary judgment to defendant on plaintiff’s vicarious liability claim. Plaintiff sued defendant (a psychiatry practice) under a theory of apparent authority for the misconduct of an independent contractor who practiced at defendant’s business. The court dismissed the case on reliance grounds. Plaintiff had identified no facts indicating that she relied on defendant to provide the independent contractor as her psychiatrist. Instead, plaintiff herself conducted a Google search, identified the psychiatrist, and scheduled an appointment directly with him. In those circumstances, plaintiff’s purported knowledge of an affiliation between defendant and the independent contractor was insufficient to satisfy the reliance standard from Popovich. As shown by these examples, Popovich has expanded the types of vicarious liability claims that may survive early dispositive motion practice. However, when these claims reach the summary judgment stage of litigation, and when evidence is required to demonstrate reliance, post-Popovich courts have expressed a willingness to hold plaintiffs to their burden. There must be specific evidence showing that plaintiff relied on the healthcare provider to select the independent contractor that ultimately provided the services in question. Absent such evidence, Minnesota courts have granted summary judgment and affirmed those decisions on appeal. To reduce the risk of apparent authority liability, healthcare providers should carefully consider their professional service agreements with independent contractor physicians, including indemnification obligations, insurance coverage, and scheduling practices. The reliance element from Popovich is more likely to be satisfied if providers are matching patients with physicians—a common occurrence in emergency care situations—as opposed to patients driving that process.
March 11, 2024
Corporate Transparency Act
Corporate Transparency Act and the Friendly Physician Model
On January 1, 2024, final regulations issued by the U.S. Department of the Treasury’s Financial Crimes Enforcement Network (“FinCEN”) went into effect in order to implement the requirements of the Corporate Transparency Act (“CTA”). For background on the CTA and an outline of the final regulations generally, please see this separate Dorsey publication written by members of Dorsey’s CTA task force. The purpose of this Dorsey Health Law blog post is to dive deeper into the regulations and discuss the CTA’s reporting obligations as they may relate to the friendly physician model used widely across the provider sectors of the health care industry. Note that the CTA and implementing final regulations are both currently in their infancy and new regulatory guidance regarding these rules continues to be released. The analysis presented in this blog post is meant to be general and based on guidance available as of the date of this post only. Applicability of the CTA to any business structure should be assessed on a case-by-case basis. Friendly Physician Model A majority of the United States prohibits corporations owned by non-professional (unlicensed) persons from practicing medicine, e.g., by employing licensed physicians to provide patient care. This doctrine is commonly referred to as the corporate practice of medicine prohibition (“CPOM”). In order to comply with CPOM, many healthcare companies use a structure commonly referred to as the “friendly physician model”. The friendly physician model involves forming a professional entity (most often a professional corporation or professional limited liability company) owned by a licensed professional that contracts with a management services organization (“MSO”) for administrative services. The contracts entered into with the MSO also typically establish control mechanisms that allow the MSO to make certain non-professional business decisions on behalf of the professional entity, including decisions related to changes in ownership and governance of the professional entity by particular licensed professionals. CTA Beneficial Ownership Reporting The CTA requires that all “Reporting Companies” file a report of “Beneficial Owners” to FinCEN. The definition of “Reporting Company” is generally broad and includes all entities formed by filing with a secretary of state. However, this definition is limited by twenty-three (23) exemptions focused on highly regulated industries (e.g., banking; insurance; but not health care providers generally) and large organizations. If an entity qualifies as a Reporting Company but does not meet one of the twenty-three (23) exemptions, it must file a report with FinCEN that includes information on such entity’s Beneficial Owners, defined broadly as any “individual who, directly or indirectly, through any contract, arrangement, understanding, relationship, or otherwise (i) exercises substantial control over the entity; or (ii) owns or controls not less than 25 percent of the ownership interests of the entity.”[1] Exemption from CTA Reporting for Friendly Physician Model Professional Entities The friendly physician model’s unique structure requires a nuanced analysis of the CTA and its implementing regulations in order to determine whether Beneficial Owner reporting is required for a professional entity formed within an organization’s friendly physician model. First, a few assumptions: The MSO contracting with a professional entity may itself be considered exempt from CTA reporting (likely under either the “large company” or “subsidiary” exemptions, discussed further below). The contracts entered into between the MSO and a professional entity include terms that establish control mechanisms that allow the MSO to make certain non-professional business decisions on behalf of the professional entity, including decisions related to changes in all ownership and governance of the professional entity by particular licensed professionals. Of the twenty-three (23) exemptions from CTA reporting available, only two (2) can likely be considered for a professional entity formed within an organization’s friendly physician model: the “large company” exemption or the “subsidiary” exemption. I. Large Company Exemption The large company exemption is available for any entity that “(i) employs more than 20 employees on a full-time basis in the United States; (ii) filed in the previous year Federal income tax returns in the United States demonstrating more than $5,000,000 in gross receipts or sales in the aggregate, including [consolidated receipts]; and (iii) has an operating presence at a physical office within the United States.”[2] While a professional entity formed within an organization’s friendly physician model may be able to demonstrate the gross receipts necessary for this exemption, many such professional entities may not be able to demonstrate direct employment of 20 employees. If a professional entity can meet this exemption, then such professional entity is not required to report Beneficial Owner information to FinCEN. II. Subsidiary Exemption The subsidiary exemption is available to any entity “of which the ownership interests are owned or controlled, directly or indirectly, by 1 or more [already exempt] entities.”[3] While the MSO contracting with a professional entity formed within an organization’s friendly physician model cannot be the direct owner of a professional entity (as such would be a violation of CPOM), it is possible that the MSO’s contracting relationship with the professional entity could be considered to establish at least indirect control over the professional entity sufficient to meet the subsidiary exemption. Neither the CTA nor the implementing regulations expressly detail what “control” means with respect to the subsidiary exemption. However, the implementing regulations do provide additional definitions for “control” in the context of Beneficial Ownership, and preamble language from FinCEN’s final regulations suggests it would be reasonable to review such “control”-related definitions in analyzing the subsidiary exemption. In rejecting rule commenters’ suggestions to include “wholly” controlled within the regulation’s subsidiary exemption language, FinCEN states that the use of the term ”control” already “covers the intended concept of control set out in the CTA.” In so stating, FinCEN indicates that the concept of “control” should be consistent throughout the implementation of the CTA. FinCEN’s CTA implementing final regulations provide the following, in part, related to the concept of “control”: “an individual exercises substantial control over a reporting company if the individual: . . . has authority over the appointment or removal of any senior officer or a majority of the board of directors (or similar body); or . . . directs, determines, or has substantial influence over important decisions made by the reporting company.” FinCEN clarifies that substantial control can be exercised indirectly “through . . . any other contract, arrangement, understanding, relationship or otherwise.” Further, FinCEN’s January 12, 2024 FAQ update provides that “control” is only established for purposes of the subsidiary exemption if control is maintained over all of the ownership interests. Therefore, with reference to the assumptions placed above, it would be a reasonable conclusion that a professional entity formed within an organization’s friendly physician model could be exempt from CTA reporting by way of being indirectly controlled by the MSO and therefore a subsidiary of an already exempt entity. In the event a professional entity formed within an organization’s friendly physician model is found to be a Reporting Company under the CTA, additional case-by-case analysis of who the Beneficial Owners are would be necessary. If you have any questions about the CTA’s potential application to a friendly physician model, reach out to your regular Dorsey attorney or to any member of the Dorsey & Whitney LLP Healthcare Transactions and Regulations practice group. Erin Bryan, a Partner in Dorsey’s Consumer Financial Services Group and a Member of the firm’s CTA Working Group, provided substantial consultation for this blog post. [1] 31 U.S. Code § 5336(a)(3)(A) [2] 31 U.S. Code § 5336(a)(11)(B)(xxi) [3] 31 U.S. Code § 5336(a)(11)(B)(xxii)
February 1, 2024
Employment
Workplace Drug Testing: New Iowa Court of Appeals Ruling Signals Best Practices for Employers
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s William Miller and Joshua Hughes for the following publication: On January 10, 2024, the Iowa Court of Appeals filed its opinion in Hampe v. Charles Gabus Motors, Inc., et al., which involved a former employee who was terminated for refusing to submit to a random workplace drug test. While the court of appeals’ ruling does not impose any new requirements on employers, the ruling provides clarity on an employer’s obligations when complying with Iowa Code 730.5, Iowa’s private sector drug testing law. Read more here.
January 18, 2024
Data Privacy and Security
HIPAA on the Horizon in the New Year: Important Lessons from an Active 2023 and Regulatory Initiatives to Watch for in 2024
2023 marked 20 years since the first compliance deadline under the Health Insurance Portability and Accountability Act’s (“HIPAA”) privacy rule. Despite the two decades of experience with HIPAA, compliance continues to remain a challenge for HIPAA-covered entities as well as for their business associates. 2023 brought a large number of important HIPAA-related developments and lessons-learned that privacy/security officials and health care attorneys should be aware of when planning for HIPAA compliance activities in 2024. This article features lessons learned in some of the most significant HIPAA-related enforcement actions and guidance documents from the U.S. Department of Health and Human Services’ Office for Civil Rights’ (“OCR”) in 2023, and ends with a summary of some of the ongoing OCR regulatory initiatives to monitor in 2024. OCR’s First Enforcement Action Related to a Phishing Attack On December 7, 2023, the OCR announced a $480,000 settlement with Lafourche Medical Group (“LMG”), a Louisiana-based medical group specializing in emergency medicine, occupational medicine, and laboratory testing. The settlement marks the first time that OCR resolved a phishing attack under HIPAA. According to OCR Director Melanie Fontes Rainer, phishing is “the most common way that hackers gain access to health care systems to steal sensitive data and health information.” In March 2021, a staff member of LMG was the victim of a phishing attack that compromised the staff member’s email account containing the electronic protected health information (“PHI” or “ePHI”) of as many as 34,000 patients. LMG reported the incident to OCR in May 2021, and OCR began its investigation in January 2022. After OCR investigated the breach, it determined that LMG had failed to comply with the following basic HIPAA requirements: (i) conducting a risk analysis to determine vulnerabilities to PHI, and (ii) creating and maintaining policies and procedures to regularly review information system activity and to safeguard PHI against cyberattacks. As a result of these findings, LMG entered into a resolution agreement with OCR on November 3, 2023, which requires LMG to pay a $480,000 penalty to OCR and implement a two-year corrective action plan (“CAP”) to address the HIPAA violations identified in OCR’s investigation. As part of the CAP, LMG has agreed to undertake HIPAA compliance activities that are required of health care providers: Establish and implement security measures to reduce security risks and vulnerabilities; Develop, maintain, and revise written policies and procedures as necessary to comply with HIPAA; and Provide training to all staff members who have access to patient PHI on HIPAA policies and procedures. OCR’s report of this first-of-a-kind settlement noted that in 2023 (through November), based on data breaches reported to it, over 89 million individuals had been affected by large data breaches (those involving 500 or more individuals). This was up from 2022, in which over 55 million individuals were affected by these large data breaches. To drive home the significance of OCR’s enforcement action, OCR noted in its press release about the settlement, “Phishing attacks can result in identity theft, financial loss, discrimination, stigma, mental anguish, negative consequences to the reputation, health, or physical safety of the individual or to others identified in the individual’s protected health information.” Lesson learned: Covered entities should regularly update and review the risk analysis and ensure the organization has adopted business grade security measures to protect ePHI. Covered entities should also routinely review and update written HIPAA privacy and security policies and procedures, and, most importantly, deliver frequent staff training to ensure staff remain vigilant and skeptical of any suspicious emails or other contact, and report the emails or other contact immediately to the privacy and security officers. Staff training is a critical line of defense against phishing attacks. Embedded Tracking Technologies- HIPAA Covered Entities and Business Associates Should Carefully Review Their Websites In December 2022, OCR issued a bulletin that warned HIPAA covered entities and business associates against the use of embedded tracking technologies that could track individually-identifiable health information on the covered entities’ or business associates’ websites. OCR defined “tracking technology” as “a script or code on a website or mobile app used to gather information about users as they interact with the website or mobile app.” While some covered entities track online user activity internally, many covered entities contract with third-party analytics companies to track and analyze the data about the individual users’ access to and interaction with the covered entity’s website. Common third-parties used to track website use data include: Meta Pixel, Google Analytics and Adobe Analytics. Tracking technologies allow the covered entity to gain insights about users’ online activities for marketing purposes, and to help improve patient experience on the website and to improve patient care, among other reasons. However, the third-parties who track the data are also able to use the data to target ads and to otherwise profile the users. The guidance points out that individually identifiable health information (such as a person’s appointment date, home or email address, or IP address) is “protected health information” that is governed by HIPAA, even if the individual does not have a pre-existing relationship with the covered entity and even if the information does not include sensitive information like treatment information, diagnosis or billing data. As OCR noted in its guidance, the risk that the data being tracked is HIPAA-protected PHI is highest on those portions of a covered entity’s website that have user-authenticated pages (where the individual logs in) because the information on those pages are more likely to include sensitive health information like diagnosis, prescription and other treatment information. OCR’s bulletin warned that the use of individually identifiable health information that is tracked on a covered entity’s website must be in compliance with HIPAA’s privacy and security rules. This means, for example, that any third-party data tracker/analyst who the covered entity engages must have a written business associate agreement in place with the covered entity. Prior to, and after OCR’s bulletin, twenty or more class action lawsuits were filed against hospitals and health systems across the U.S. based on allegations that the hospitals were inappropriately sharing patient data with companies like Google, Facebook, Adobe and others for marketing purposes. Some of the cases have settled and others are ongoing. In response to the OCR bulletin, hospitals and health systems expressed alarm due to the proliferation of the use of website data trackers in use at nearly every hospital in the nation. Some have joined a legal challenge against the OCR bulletin. In November 2023, the American Hospital Association, the Texas Hospital Association and others filed suit against OCR claiming that the OCR bulletin improperly imposes HIPAA restrictions on information that is not “protected health information” as that term is defined under HIPAA. In February 2023, the Federal Trade Commission (“FTC”) began enforcing a lesser-known law called the FTC Health Breach Notification Rule (the “HBN Rule”) against companies that use website-embedded tracking technologies and disclose the data being tracked through these technologies to third-party tracking companies. The HBN Rule applies to non-HIPAA covered entities that are vendors of personal health records (or who are a related entity or service provider of a vendor of personal health records). The HBN Rule requires that a breach notification be filed with the FTC if there is an unauthorized disclosure of personal health information, such as to a third party that has embedded tracking technologies on the company’s website. Under this law, the FTC took enforcement action against well-known companies such as BetterHelp, GoodRx and Premom, requiring the payment of large civil money penalties and requiring that the companies adopt and enforce internal prohibitions on sharing user health data with third parties for advertising purposes. Additionally, the FTC issued industry guidance as a warning to others who use embedded tracking technologies on their websites. In July 2023, the OCR and FTC teamed up and issued a joint letter to 130 hospitals and telehealth providers about the risks and concerns regarding the use of the website tracking technologies, and issued a press release with a general warning to the hospital system and telehealth industry against the use of embedded tracking technologies. Lesson learned: HIPAA covered entities should carefully review their websites to ensure that any third party with embedded tracking technologies has signed a HIPAA-compliant business associate agreement, and to ensure that the use or disclosure of any data gleaned from tracking access to the company website is compliant with the HIPAA privacy rule. See our prior articles on this topic here and here. Rights of Access Initiative- Still a Top Priority for OCR In 2023, the OCR reached several new resolution agreements with entities alleged to have violated patients’ rights to timely access of their medical records. Under HIPAA, covered entities, like health care providers and payors, have a maximum of 30 days (which OCR describes as an “outer limit”) to provide patients with a copy of their medical record upon request. The “Right of Access Initiative” became an enforcement priority for OCR at the end of 2019, in an attempt to address patient complaints about difficulties they encountered in obtaining timely copies of their medical records. In fact, OCR’s final resolution agreement of 2023 in the amount of $80,000 marked OCR’s 46th such settlement in a little over three years. In response to what OCR views as a widespread issue of non-compliance, OCR has published guidance for covered entities’ implementation of this individual HIPPA right to access. Lesson learned: Review and audit the administrative processes your organization has in place for responding to requests for patient records to ensure they meet HIPAA’s requirements. Major Source of Risk: Covered Entity and Business Associate Failure to Conduct Enterprise-Wide Security Risk Analysis In May and June 2023, OCR entered into resolution agreements with two separate business associates who, in similar fact patterns, were found to have lacked a sufficient enterprise-wide risk analysis of their security function, leading to the breach of hundreds of thousands of patient records. In one situation, the business associate provided billing, coding and IT services to health care providers and, through a compromise in the business associate’s systems, the PHI of hundreds of individuals was exfiltrated from an unsecured server by an unauthorized person. In the other situation, a business associate that provides practice management, practice analytics and revenue cycle management services to health care providers inadvertently allowed a file transfer protocol (“FTP”) server containing hundreds of thousands of individuals’ data to be openly accessible on the internet. OCR also cited a covered entity for non-compliance with the risk analysis standard. In February 2023, OCR entered into a resolution agreement with a large health system in order to resolve a data breach impacting 2.81M individuals following a hacking incident. When OCR investigated the incident, it found that the health system lacked a risk analysis to determine the risks and vulnerabilities to its patients’ ePHI. OCR also found a number of important security rule violations that stemmed from the initial failure to conduct risk analyses, including failing to implement an authentication process, failing to monitor the activity of users on the system, and failure to have security measures in place for ePHI that was being transmitted electronically. In September 2023, OCR and the Office of the National Coordinator for Health Information Technology (“ONC”) published an updated version of a do-it-yourself security risk assessment tool, intended for small and medium-sized covered entities. The updated tool is intended to make it easier for covered entities and business associates to assess the security risk to ePHI and to mitigate that risk. Lesson learned: In resolution agreements, OCR routinely cites companies for failing to complete an enterprise-side security rule risk analysis. In fact, this is one of the most common sources of HIPAA violations that lead to subsequent settlement agreements with OCR. The bottom line is that there is no substitute for an enterprise-wide security rule risk analysis. This type of risk analysis should be conducted routinely by covered entities and by their business associates in order to identify and mitigate the security risks to all repositories of electronic PHI. Another lesson that comes out of this pair or resolution agreements in 2023 is that covered entities should carefully vet and audit the HIPAA compliance program and practices of their potential and current business associates. In the end, although business associates have their own liability under HIPAA, the patient data and patient relationships at risk are those of the covered entity served by the business associate. Even Small Breaches Can Result in Liability In 2023, OCR settled two cases that contained fact patterns OCR has addressed in guidance and settlement agreements repeatedly: snooping and social media breaches. Notably, these cases each also involved a small number of patients, and the enforcement actions signal to covered entities and business associates that even small breaches can result in liability. One resolution agreement was with a hospital related to its security staff snooping in patient records. The other resolution agreement was with a physician practice that responded to a negative review on Google in a way that acknowledged the patient relationship and disclosed patient information. Lessons learned: Ongoing staff training regarding impermissible uses and disclosures of patient information is a critical element of a provider’s HIPAA compliance activities. Include basic reminders in HIPAA workforce training through, for example, use of the resolution agreements in the way that OCR intends them to used- as an example for others to help prevent similar conduct in the future. COVID-19 HIPAA Enforcement Discretion Ends and OCR Emphasized its Enforcement Priority and Strategy for Cybersecurity In August 2023, years of HIPAA-related enforcement discretion by OCR related to the COVID-19 pandemic came to an end. The enforcement discretion that OCR exercised throughout the early days of the COVID-19 pandemic related to matters such as the use of non-HIPAA compliant telehealth technologies, and non-HIPAA compliance related to COVID-19 vaccine patient scheduling, public health and health oversight disclosures, and community based testing sites. OCR published notifications and guidance to the public to prepare HIPAA covered entities and business associates for an end to the waiver of enforcement discretion. OCR also announced the development of a new enforcement division at OCR, called the Health Information Privacy, Data and Cybersecurity Division, which will focus on OCR’s work and role in cybersecurity. Additionally, citing a 93% increase in large data breaches due to cybersecurity events between 2018-2022 (with a 278% increase in large breaches involving ransomware), the Department of Health and Human Services published a concept paper outlining the Department’s cybersecurity strategy for health care providers. The strategy calls for new voluntary health care-specific cybersecurity goals; developing incentives and supports with Congress that will be used to help hospitals improve cybersecurity; and strategies for increasing accountability and coordination within the health care sector. Ongoing OCR Regulatory Initiatives- Changes are Coming OCR has introduced several HIPAA regulatory initiatives that are still under consideration by the agency, and many of which may become finalized in 2024. It is important for privacy/security officials and health care counsel to be familiar with the proposed regulations in order to understand OCR’s perspective because that helps in steering internal compliance protocols, training and accountability at the organization: Reproductive Health Care OCR issued a Notice of Proposed Rulemaking (“NPRM”) on April 12, 2023 to prohibit the use or disclosure of PHI to identify, investigate, prosecute, or sue patients, providers, and others involved in the provision of legal reproductive health care, including abortion. The public comment period closed on June 16, 2023 and OCR received over 25,000 comments. A final rule has not yet been published. Substance Use Disorder (“SUD”) Treatment Records In coordination with the Substance Abuse and Mental Health Services Administration (SAMHSA), OCR issued a NPRM on November 28, 2022 to align certain aspects of 42 CFR part 2 (Part 2) with HIPAA. Part 2 protects patient records maintained in connection with substance abuse education prevention, training, treatment, rehabilitation or research in order to ensure privacy for SUD patients. The public comment period closed on January 31, 2023 and OCR received over 200 comments. A final rule has not yet been published. HITECH Request for Information (“RFI”) Regarding Mitigating Security Practices and the Sharing of Monetary Settlements with Individuals Harmed OCR published a RFI on April 6, 2022, seeking public input on portions of the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH Act). The RFI specifically requests input on: (i) recognized security practices that OCR will consider when determining potential fines, audit results, or other remedies for resolving potential violations of HIPAA; and (ii) the methodology under which an individual harmed by a potential HIPAA violation may receive a percentage of a monetary penalty/settlement collected with respect to such violation. The public comment period closed on June 6, 2022. OCR has yet to announce further action on this RFI. HIPAA Privacy Rule Updates OCR issued a NPRM on January 1, 2021 to modify the HIPAA Privacy Rule to encourage patient engagement in health care, remove barriers to coordinated care, and decrease regulatory burden. The public comment period closed on May 6, 2021 and OCR received over 1,300 comments. A final rule has not yet been published. The proposed new rules, if finalized, would require some significant changes at HIPAA covered entities and business associates, such as: allowing patients to inspect their PHI in person and take notes or photographs of their PHI; changing the maximum time to provide access to PHI from 30 days to 15 days; new rules about costs for records including certain circumstances when ePHI must be provided at no cost, requirements to provide estimates of fees for copies, and requirements to post fee schedules for records access on the website; individuals will be permitted to request that their PHI be transferred to a personal health application or direct ePHI to be send to another covered entity; covered entities will be required to inform individuals that they have the right to obtain or direct copies of their PHI to a third-party when a summary of PHI is offered instead of a copy; the requirement for HIPAA-covered entities to obtain written confirmation that a Notice of Privacy Practices has been provided will be removed; covered entities will be allowed to disclose PHI to avert a threat to health or safety when harm is “seriously and reasonably foreseeable” (as opposed to the current, more stringent standard that only allows such disclosure when harm is “serious and imminent," and expansion of permissible uses and disclosures by covered entities based on care coordination, case management and based on a good faith belief that the disclosure it is in the best interest of the individual. While the pending HIPAA updates are intended to ease the administration burden on HIPAA-covered entities in the long run, there will be a significant short term burden associated with changes to policies and procedures, changes related to notices of privacy practices, changes to medical record access processes and others. The authors will continue to monitor these initiatives for updates and changes in 2024. If you have any questions about HIPAA, cyber-attacks, OCR investigations, or regulatory changes, reach out to your regular Dorsey attorney or to any member of the Dorsey & Whitney LLP Healthcare Transactions and Regulations practice group.
January 3, 2024
Artificial Intelligence
AI and Healthcare: More Guidance and Regulations are Coming to Town
There is no doubt that artificial intelligence (“AI”) and more specifically, generative AI, is one of the hottest topics in healthcare for 2023. There is also no doubt that it will continue to be a hot topic into 2024 and beyond as healthcare providers and patients have greater access to generative AI and learn how to use it within the world of healthcare. On October 30, 2023, the Biden Administration took another step toward addressing AI by issuing an Executive Order on the Safe, Secure, and Trustworthy Development and Use of Artificial Intelligence (available here). The Executive Order follows an October 2022 blueprint for an AI Bill of Rights, which was intended to outline principles “that should guide the design, use, and deployment of automated systems to protect the American public in the age of artificial intelligence.” The AI Bill of Rights Blueprint is available here. The Executive Order confirms that the Biden Administration recognizes the potential of AI to “solve urgent challenges while making our world more prosperous, productive, innovative, and secure”. However, the Administration also recognizes that “irresponsible use could exacerbate societal harms such as fraud, discrimination, bias, and disinformation; displace and disempower workers, stifle competition; and pose risks to national security.” With these issues in mind, the Executive Order sets forth eight principles: AI must be safe and secure. Promoting responsible innovation, competition and collaboration will allow the United States to lead in AI and unlock its potential to solve some of society’s most difficult challenges. Responsible development and use of AI requires a commitment to supporting American workers. AI policies must be consistent with the advancement of equity and civil rights. The Executive Order specifically mentions that healthcare, in particular, is an area where AI can deepen discrimination and bias. The interests of Americans who increasingly use, interact with, or purchase AI and AI-enabled products in daily life must be protected. The Executive Order notes that this is critical in fields such as healthcare. Americans’ privacy and civil liberties must be protected. The federal government must manage risks in its own use of AI and increase internal capacity to regulate, govern and support responsible use of AI. The United States federal government should lead the way globally with respect to AI. Importantly, the Executive Order provides a comprehensive list of AI-related definitions, some of which already exist in federal statutes or regulations, but perhaps have not previously been applied across the various industries such as healthcare. The Executive Order then provides specific directives and deadlines to various federal agencies to implement the eight principles. With respect to the healthcare sector, the Executive Order directs the Secretary of the Department of Health and Human Services (“HHS”) to take the following actions: Within 90 days, establish an HHS AI Task Force. Within 365 days of being created, the HHS AI Task Force will develop a strategic plan that includes policies and frameworks and possible regulatory actions on responsible deployment and use of AI and AI-enabled technologies in the following areas: Healthcare delivery and financing, and specifically, quality measurements, performance improvement, program integrity, benefits administration and patient experience Safety and performance monitoring of AI-enabled technologies, including clinically relevant or significant modifications and performance across population groups Incorporation of equity principles for AI-enabled technology using disaggregated data and helping to identify and mitigate discrimination and bias in current systems Safety, privacy and security standards for protecting personally identifiable information Development, maintenance and availability of documentation to help users determine safe and appropriate uses of AI in local settings Determine work to be done with state, local, Tribal and territorial health and human service agencies to advance positive uses cases and best practices Identify uses of AI to promote workplace efficiency, including reduction of administrative burdens Within 180 days, develop a strategy with relevant agencies to determine whether AI-enabled technologies maintain appropriate levels of quality, including the development of an “AI assurance policy” that will evaluate important aspects of performance. This includes an infrastructure to enable pre-market assessment and post-market oversight. Within 180 days, consider appropriate actions needed to advance understanding and compliance with federal non-discrimination laws by healthcare providers that receive federal financial assistance and how those laws relate to AI. Within 365 days, in consultation with other federal agencies, establish an AI safety program in partnership with voluntary, federally listed Patient Safety Organizations. This directive calls for establishing a common framework for identifying and capturing clinical error resulting from AI and developing best practices or other guidelines to avoid harms. Within 365 days, develop a strategy for regulating use of AI or AI-enabled tools in drug-development processes. Given this more specific framework and the guidance and regulations expected to result from this Executive Order, it is also likely that states and Congress will continue to review and develop legislation around the use of AI generally, and in healthcare in particular. This will likely result in a varying assortment of regulations that providers, AI developers and others in the healthcare sector will need to understand and address. AI is here to stay, and healthcare providers will need to be alert to forthcoming laws, regulations and guidance from varying levels of government, as well as from professional organizations. See https://www.ama-assn.org/press-center/press-releases/ama-develop-recommendations-augmented-intelligence (providing that the American Medical Association will be developing principles and recommendations on the benefits and unforeseen consequences of relying upon AI-generated medical advice or content). If you have any questions regarding the current AI regulatory framework or how your organization may be impacted, please contact the author or your Dorsey healthcare attorney.
November 28, 2023
Minnesota Supreme Court Holds That The Minnesota Health Records Act Allows Release of Health Records For Permitted Purposes Under HIPAA
On October 11, 2023 the Minnesota Supreme Court issued an opinion in Schneider v. Children's Health Care holding that the Minnesota Health Records Act (“MHRA”) provision allowing health care providers to release health records when there is "specific authorization in law" encompasses all operative law in Minnesota, including permitted disclosures under the federal HIPAA privacy rule. This case appears to resolve longstanding questions about the interaction between the MHRA and the HIPAA privacy rule, and concludes that the MHRA’s health records release prohibitions are no stricter than the HIPAA privacy rule. In 2020, Children's Health Care alerted the Schneider family that a third-party vendor for its foundation had suffered a data breach, and that their child's protected health information may have been compromised. The Schneiders were not aware that Children’s had disclosed their child’s protected health information to its related foundation. The family sued Children's, alleging a violation of the MHRA and claiming that Children’s had obtained no written consent to disclose health records to the foundation for fundraising purposes. However, Children’s was permitted to disclose the health information to its foundation under the federal HIPAA privacy rule. Children's moved for summary judgment, arguing that the MHRA provision allowing release of health records when there is a "specific authorization in law" permits Children’s to release records when permitted under the HIPAA privacy rule. The district court and court of appeals granted summary judgment to Children's, and the Schneiders then petitioned the Minnesota Supreme Court to review. Statutory Background The HIPAA privacy rule prohibits covered entities, such as health care providers, from using or disclosing protected health information (“PHI”) unless permitted under the rule. The HIPAA privacy rule permits the use and disclosure of PHI under various circumstances, including for fundraising purposes. Covered entities under HIPAA may use a limited set of data elements for fundraising (or disclose that same information to a related foundation for fundraising), without any written consent or authorization from the patient. The HIPAA privacy rule also contains a general preemption rule, which provides that any state law that is contrary to the federal privacy rule is preempted. However if a state law affords greater privacy protection for identifiable health information, then the federal rule will not preempt that state law. The MHRA limits when certain Minnesota-licensed health care providers (including hospitals) are permitted to release health records without a patient’s written consent. The MHRA has a fewer number of permitted disclosures without patient consent than the HIPAA privacy rule does. But the MHRA exception at issue in Schneider allows for release of health records if there is a "specific authorization in law." Brief Analysis The Schneiders first argued that the scope of the phrase "specific authorization in law" refers only to Minnesota laws, and thus would not extend to the federal HIPAA fundraising exception. The Court rejected this argument, finding that in this context the plain and ordinary meaning of "law" refers to law that is binding and enforceable in Minnesota, which includes both Minnesota and federal law. Second, the Schneiders argued that the Court has required the Minnesota legislature to explicitly reference a federal law that is to be incorporated into a state statute. They claimed that because the MHRA does not explicitly reference federal law or HIPAA, the HIPAA fundraising exception is not a “specific authorization in law.” The Court rejected that argument, instead finding that the plain language of “law” makes it clear that the legislature explicitly intended to incorporate federal law into the MHRA. The final argument was that the MHRA is more stringent than the HIPAA privacy rule, and as such, is not preempted by the federal rule. This argument rested on the premise that because the MHRA does not have a separate fundraising exception, the MHRA must be more stringent than the HIPAA privacy rule. The Court disagreed, noting that the argument assumes its conclusion that the MHRA does not incorporate the HIPAA privacy rule as a “specific authorization in law.” Because the Court determined that the MHRA does incorporate the HIPAA privacy rule it was unpersuaded by this argument, effectively ruling that the MHRA’s records release provisions are no more stringent than the HIPAA privacy rule. The Schneider v. Children's Health Care case has practical, operational impact on health care providers in Minnesota. The case essentially reconciles permitted health records release under the MHRA with permitted disclosures of PHI under HIPAA. This should relieve Minnesota health care providers of the need to obtain a written patient consent under the MHRA in order to release health records for purposes for which disclosure is permitted under the HIPAA privacy rule, such as coordinating care with unaffiliated providers or billing health insurance. Contact the authors or any member of the Dorsey & Whitney Health Care Regulations & Transactions practice group with questions about HIPAA, the Minnesota Health Records Act, or other health information privacy matters.
October 27, 2023
Leaning Toward Commonality: States Enact New Comprehensive Consumer Data Privacy Laws
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Dustin Berger for the following post on the TheTMCA blog: The year 2023 will likely go down in history as a major inflection point in the enactment of comprehensive consumer data privacy laws in the United States. At the beginning of the year, only five states (California, Virginia, Colorado, Utah, and Connecticut) had enacted comprehensive consumer data privacy laws. And, of these, only the California and Virginia laws are currently in effect. The privacy laws in Connecticut and Colorado go into effect on July 1, 2023, and Utah’s law becomes enforceable on December 31, 2023. Read more here.
June 15, 2023
U.S. Supreme Court Expands Options for Residents & Families Suing Nursing Homes
In a ruling issued today, the United States Supreme Court held that the family of a nursing home resident could bring a claim against the nursing home under the Federal Nursing Home Reform Act via section 1983. In Health & Hospital Corporation of Marion County v. Talevski, Talevski’s family claimed that the nursing home where Talevski resided violated his right to be free from unnecessary physical or chemical restraints and his right to only be discharged or transferred upon the satisfaction of certain conditions. The family asserted that these rights arose out of the Federal Nursing Home Reform Act (“FNHRA”), which provides the regulatory provisions to which nursing homes are held and surveyed upon by the Centers for Medicare & Medicaid and state survey agencies. In other words, these regulatory violations can now serve as a basis for a private right of action. As noted above, the case expressly focused on two regulations: the requirement that nursing homes must protect and promote a resident’s right to be free from physical or chemical restraints imposed for purposes of discipline or convenience and not required for the treatment of medical conditions; and the requirement that nursing homes cannot discharge a resident without meeting certain conditions (i.e.., the involuntary discharge requirements). The Court’s majority opinion noted that both of these regulations are within the “resident’s rights” statutory provisions of FNHRA, which has an ‘individual ‘rights-creating’ focus.” The Court also made clear that it is Medicaid-participant nursing homes who are required to respect and honor these rights and thus, who may be sued under FNHRA. In other words, these private rights of action under FNHRA would apply to any facility subject to the regulations in the FNHRA. While the Court recognized that there is already a scheme in place to address the FNHRA violations (i.e., the survey process), it held that allowing a private right of action did not thwart the operation of that administrative process in any way. While nursing home residents and their families always had the ability to sue nursing homes for negligence or malpractice, this decision holds that nursing homes can now also be sued – under section 1983 – by private parties for violating the FNHRA regulations. The impact on nursing facilities is primarily two fold. First, it provides a federal cause of action that would allow a plaintiff to sue a nursing facility in federal – rather than state – court. Second, it provides the plaintiffs in these cases another potential area of financial recovery, because successful claims under section 1983 give the court the ability to award attorney fees. While the full impact of this decision remains to be seen, a few likely impacts should be noted. Plaintiffs’ attorneys will be looking more closely at a facility’s regulatory violations and determining whether they can serve as an additional basis for what would have traditionally been a simple negligence claim. From a practical perspective, nursing homes should take this into consideration when they decide whether they want to challenge a regulatory violation. The potential litigation exposure has increased and thus, it may make sense to spend time and effort challenging a regulatory violation where in the past the nursing home may have just agreed to pay the fine. As noted above, now that a federal private right of action exists, plaintiffs will have more ready access to the federal courts. This will mean new judges and juries that have not traditionally addressed nursing home cases. Additionally, the 1983 action not only gives plaintiffs’ attorneys the ability to potentially recover attorney fees, but the existence of a separate federal claim likely also allows a plaintiff to escape caps on damages that some state legislatures have enacted. In short, the Talevski decision increases the overall financial exposure of nursing facilities.
June 8, 2023
Transactions
New Minnesota Health Care Transaction Oversight Law Imposes Additional Requirements on Nonprofit Health Care Entities
On May 26, 2023, the Governor of Minnesota signed into law Minnesota bill HF 402 to increase government oversight of health care transactions that occur in Minnesota or involve Minnesota-based health care entities. A general overview of the new law’s oversight provisions can be found in a previous Dorsey Health Law blog post. The new law also contains provisions specific to nonprofit health care organizations, including additional transaction requirements and extension of the moratorium on certain conversion transactions. Given the prevalence of nonprofit health care organizations in Minnesota, we expect this new legislation to materially impact both payors and providers in the State. This blog post summarizes those provisions, all of which have already gone into effect. Additional Transaction Requirements for Nonprofit Health Care Entities In addition to the general notice requirements now effective under this new law and summarized in our previous post, HF 402 imposes further requirements on (1) nonprofit health care entities that are either incorporated under the Minnesota Nonprofit Corporation Act or organized as a Minnesota nonprofit limited liability company, and (2) the subsidiaries of such nonprofit entities, regardless of their incorporation or organizational status. These entities are now required to ensure the following before proceeding with a transaction: The transaction complies with the Minnesota Nonprofit Corporation Act, the charitable trusts statutes, and other applicable laws; The transaction does not involve or constitute a breach of charitable trust; The transferring nonprofit entity will receive the full and fair value for its public benefit assets, unless the discount between the full and fair value of the assets and the value received for the assets will further the nonprofit purposes of the entity or is in the public interest; The value of the public benefit assets to be transferred has not been manipulated in a manner that causes or has caused the value of the assets to decrease; The proceeds of the transaction will be used in a manner consistent with the public benefit for which the assets are held by the nonprofit health care entity; The transaction will not result in a breach of fiduciary duty; and There are procedures and policies in place to prohibit any officer, director, trustee, or other executive of the nonprofit health care entity from directly or indirectly benefiting from the transaction. Currently, it is not entirely clear how or to what extent these additional transaction requirements for nonprofit health care entities will be reviewed in conjunction with the general notice requirements for health care entities. Moratorium on Conversion Transactions A moratorium on conversion transactions involving nonprofit health plan entities operating under the Minnesota Nonprofit Health Service Plan Corporations Act or Health Maintenance Act that was set to expire July 2023 has been extended through July 2026. The moratorium was initially enacted in response to concerns of some lawmakers that nonprofit assets could be transferred to for-profit carriers in a merger or acquisition. These nonprofit health plan entities “may only merge or consolidate with; convert; or transfer, as part of a single transaction or a series of transactions within a 24-month period, all or a material amount of its assets to” an entity that is incorporated under the Minnesota Nonprofit Corporation Act; “or to a Minnesota nonprofit hospital within the same integrated health system as the health maintenance organization.” A “material amount” is defined as the “lesser of ten percent of an entity’s total admitted net assets as of December 31 of the previous year, or $50,000,000.” The moratorium does not apply if the nonprofit health plan entity files an intent to dissolve due to insolvency of the corporation or if insolvency proceedings are commenced. Related Study and Recommendations HF 402 requires that the Minnesota commissioner of health study and develop recommendations on the regulation of conversions, mergers, transfers of assets, and other transactions primarily affecting Minnesota-domiciled nonprofit health maintenance organizations (HMOs). These recommendations must address the following: Monitoring and regulation of Minnesota-domiciled for-profit HMOs; Issues related to public benefit assets held by a nonprofit HMO, including identifying the portion of the organization’s assets that are considered public benefit assets to be protected, establishing a fair and independent process to value the assets, and determining how public benefit assets should be stewarded for the public good; Providing a state agency or executive branch office with authority to review and approve or disapprove a nonprofit HMO’s plan to convert to a for-profit organization; Establishing a process for the public to learn about and provide input on a nonprofit HMO’s proposed conversion to a for-profit organization; and Issues, including statutory language and regulatory implementation, related to a potential statutory requirement that nonprofit HMOs licensed under Minnesota Statutes chapter 62D, and health systems organized as a charitable organization, upon the sale or transfer of control to an out-of-state or for-profit entity, return to the state’s general fund an amount equal to the value of any charitable assets the HMO or health system received from the state. The commissioner is required to seek public comment on the regulation of conversion transactions involving nonprofit HMOs no later than October 1, 2023. A final recommendations report must be submitted to the appropriate legislative committees by June 30, 2024. If you have any questions regarding HF 402 and how your organization or transaction may be impacted, please contact the authors or your regular Dorsey attorney. Summer Associate Lindsey VerMurlen provided substantial assistance researching and drafting this blog post.
June 7, 2023
Iowa Governor Signs Legislation Impacting Iowa’s Long-Term-Care Industry
On June 1, 2023, Iowa Governor Kim Reynolds signed into law Iowa bill HF 685, which will significantly impact the future of Iowa’s long-term-care industry. Among other provisions, HF 685 increases scrutiny imposed on parties who seek to acquire an Iowa nursing facility, imposes a temporary moratorium on adding new nursing facility beds in the state, and mandates a publicly available dashboard regarding the availability of nursing facility services. Enhanced Scrutiny of Nursing Facility CHOWs. In recent years, a number of states and the Federal Government have increased the level of scrutiny applied to nursing facility changes of ownership (“CHOWs”). HF 685 continues that trend by requiring nursing facility license applicants to provide additional information to the Department of Inspections, Appeals, and Licensing (“DIAL”) before the agency will issue a nursing facility license. The information required is not limited to the applicant’s proposed nursing facility operations, but also includes information related to any assisted living programs, hospice services, home health agencies, or other long-term care related health services provided by the applicant or by a related party of the applicant. Applicants must now provide information about the applicant’s organizational and ownership structure (including related parties), any related party transactions and associated reimbursement structures, the applicant’s financial suitability to operate a nursing facility, and the applicant’s regulatory history with any other state or licensing jurisdiction. The legislation also permits DIAL to require an applicant to create an escrow account with sufficient funds to operate the nursing facility for at least two months. The escrow account would need to be fully funded before DIAL issues a nursing facility license to the applicant, and the applicant may be required to maintain the escrow account for up to five years from the date the applicant commences operation of the nursing facility. DIAL would be permitted to reduce the amount in the escrow account after the applicant has operated the facility for two years. If DIAL files an application for the appointment of a receiver for a facility, and the court appoints a receiver, DIAL would then be permitted to draw on the funds in the escrow account to operate the facility. Administrative rules drafted by DIAL to implement these new requirements are forthcoming. Moratorium on Additional Nursing Facility Beds. Commencing on July 1, 2023, HF 685 imposes a temporary moratorium on the addition of new nursing facility beds in the state. The initial term of the moratorium is twelve months. DIAL is permitted to extend the term of the moratorium in additional six-month increments, but for no longer than a total of 36 months. The legislation permits DIAL, in consultation with the Department of Health and Human Services (“DHHS”), to waive the moratorium with respect to a specific proposal if the two departments jointly determine there is a specialized need for the nursing facility beds requested, or if the average occupancy of nursing facility beds in the county and contiguous counties have exceeded 85 percent during the three most recent calendar quarters. Nursing Facility Dashboard. HF 685 also requires DHHS to develop a publicly available dashboard to provide information regarding the availability of nursing facility services across the state. The dashboard will provide the number of nursing facility beds available in the state, the overall quality rating of each nursing facility (as reported by the CMS Star Ratings), changes in the number of nursing facility beds available in each county, and an explanation of such changes. The legislation requires the dashboard to be available no later than January 1, 2024. If you have any questions regarding HF 685 and how your organization may be impacted, please contact the authors or your regular Dorsey attorney.
June 2, 2023
Transactions
Minnesota Attorney General Notification of Health Care Transactions
On May 26, 2023, the Governor of Minnesota signed into law Minnesota bill HF 402 to increase government oversight of health care transactions that occur in Minnesota or involve Minnesota-based health care entities. Minnesota joins a growing number of states considering or enacting similar measures, including New York, Connecticut, Delaware, Massachusetts, Nevada, New Jersey, Oregon, Rhode Island, Washington, and California. The following is a general overview of this new law, many portions of which have gone into effect already. General Prohibition and Key Definitions HF 402’s purpose is to prohibit transactions by any health care entity that would “substantially lessen competition or tend to create a monopoly or monopsony.” In order to enforce this prohibition, HF 402 institutes a number of transaction notification requirements and grants the Minnesota attorney general with the power to review, enjoin, or unwind any applicable transaction in violation of HF 402. Here are key definitions from HF 402 that outline the law’s scope: “Health care entity” is defined as hospitals, hospital systems, captive professional entities, medical foundations, health care provider group practices, entities organized or controlled by one of the above entity types, and entities that own or exercise control over one of the above entity types. “Transaction” is defined as a single action or a series of actions that occur within a five-year period in Minnesota or involving a health care entity formed or licensed in Minnesota, that constitutes: A merger or exchange of a health care entity with another entity; The sale, lease, or transfer of 40 percent or more of the assets of a health care entity to another entity; The granting of a security interest of 40 percent or more of the assets of a health care entity to another entity; the transfer of 40 percent or more of the shares or other ownership of a health care entity to another entity; An addition, removal, withdrawal, substitution, or other modification of one or more members of a health care entity’s governing body that transfers control, responsibility for, or governance of the health care entity to another entity; The creation of a new health care entity; An agreement or series of agreements that results in the sharing of 40 percent or more of a health care entity’s revenues with another entity, including affiliates of such other entity; An addition, removal, withdrawal, substitution, or other modification of the members of a health care entity formed under the Minnesota Nonprofit Corporation Act that results in a change of 40 percent or more of the membership of the health care entity; or Any other transfer of control of a health care entity to, or acquisition of control of a health care entity by, another entity. “Control,” along with “controlling,” “controlled by,” and “under common control with” is defined as the possession, direct or indirect, of the power to direct or cause the direction of the management and policies of a health care entity, whether through the ownership of voting securities, membership in an entity formed under the Minnesota Nonprofit Corporation Act, by contract other than a commercial contract for goods or nonmanagement services, or otherwise, unless the power is the result of an official position with, corporate office held by, or court appointment of, the person. Control is presumed to exist if any person, directly or indirectly, owns, controls, holds with the power to vote, or holds proxies representing 40 percent or more of the voting securities of any other person, or if any person, directly or indirectly, constitutes 40 percent or more of the membership of an entity formed under the Minnesota Nonprofit Corporation Act. Furthermore, the attorney general may determine that control exists in fact, notwithstanding the absence of a presumption to that effect. If a transaction meets the definition above (noting that certain transactions are excluded from the definition, including, for example, those involving only nursing homes and home care providers), such transaction may be subject to certain reporting requirements as outlined further below. Reporting Requirements Now effective, HF 402 requires notice to the attorney general and the Minnesota commissioner of health at least 60 days before the proposed closing date of any transaction where either “(i) the health care entity involved in the transaction has average revenue of at least $80,000,000 per year; or (ii) the transaction will result in an entity projected to have average revenue of at least $80,000,000 per year once the entity is operating at full capacity.” The notice to the attorney general and the commissioner of health must include a number of disclosures, including the following non-exhaustive list of items: The entities involved in the transaction; The leadership of the entities involved in the transaction, including all board members, managing partners, member managers, and officers; The services provided by each entity and the attributed revenue for each entity by location; The primary service area for each location; The proposed service area for each location; The current relationships between the entities and the affected health care providers and practices, the locations of affected health care providers and practices, the services provided by affected health care providers and practices, and the proposed relationships between the entities and the affected health care providers and practices; The terms of the transaction agreement or agreements; All consideration related to the transactions; Markets in which the entities expect post-merger synergies to produce a competitive advantage; Potential areas of expansion, whether in existing markets or new markets; Plans to close facilities, reduce workforce, or reduce or eliminate services; The brokers, experts, and consultants used to facilitate and evaluate the transaction; The number of full-time equivalent positions at each location before and after the transaction by job category, including administrative and contract positions; The current governing documents for all entities involved in the transaction and any amendments to these documents; The transaction agreement or agreements and all related agreements; Any collateral agreements related to the principal transaction, including leases, management contracts, and service contracts; All expert or consultant reports or valuations conducted in evaluating the transaction, including any valuation of the assets that are subject to the transaction prepared within three years preceding the anticipated transaction closing date and any reports of financial or economic analysis conducted in anticipation of the transaction; Copies of all filings submitted to federal regulators, including any filing the entities submitted to the Federal Trade Commission under the Hart-Scott-Rodino Act in connection with the transaction; A certification sworn under oath by each board member and chief executive officer for any nonprofit entity involved in the transaction; Audited and unaudited financial statements from all entities involved in the transaction and tax filings for all entities involved in the transaction covering the preceding five fiscal years; and Any other information or documents relevant to evaluating the transaction that are requested by the attorney general or the commissioner of health. Effective January 1, 2024, HF 402 requires data reporting of certain smaller transactions to the commissioner of health at least 30 days before the proposed closing date of the transaction or within 10 business days of the date the parties first reasonably anticipate entering into the transaction if the expected completion is within less than 30 days, where either “(i) the health care entity involved in the transaction has average revenue between $10,000,000 and $80,000,000 per year; or (ii) the transaction will result in an entity projected to have average revenue between $10,000,000 and $80,000,000 per year once the entity is operating at full capacity.” This data reporting includes disclosure of much of the same type of information as outlined above. Please note that HF 402 imposes additional requirements on nonprofit health care entities not identified above. Attorney General Enforcement Powers HF 402 grants the attorney general broad enforcement powers. It permits the attorney general to extend the notice and waiting period for the $80,000,000+ transactions for an additional 90 days by notifying the health care entity in writing of the extension or to waive all or any part of the waiting period or disclosure requirements, including requirements for disclosures to the commissioner of health. Additionally, the attorney general is permitted to bring an action in district court to compel compliance with the notice, waiting period, disclosure and submission requirements, or to enjoin or unwind a transaction or seek other equitable relief necessary to protect the public interest if a health care entity or transaction violates HF 402 or is contrary to the public interest. Failure of the entities involved in a transaction to provide timely information to the attorney general or the commissioner of health is an independent and sufficient ground for a court to enjoin or unwind the transaction or provide other equitable relief, however the attorney general must notify the entities of the deficiency and provide a reasonable opportunity to remedy it. If you have any questions regarding HF 402 and how your organization or transaction may be impacted, please contact the authors or your regular Dorsey attorney.
May 30, 2023
Privacy
Broad New Washington Privacy Law Requires Immediate Compliance Action
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Ross D'Emanuele, Jamie Nafziger and Bianca Tillman for the following publication: Companies may face class action lawsuits as early as July 2023 based on Washington’s new privacy law. Governor Jay Inslee recently signed House Bill 1155, the WA My Health, My Data Act (“MHMDA” or “the Act”), giving companies and non-profits a very short compliance window. MHMDA is part of “Washington State’s nation-leading effort to stem the attack on choice”1 in response to the Supreme Court’s 2022 decision in Dobbs that overturned Roe v. Wade. Lawmakers state that the new law was designed to “protect the independence and dignity of individuals when they make healthcare decisions”2 in the state of Washington by safeguarding the privacy of Consumer Health Data not previously covered by the Health Insurance Portability and Accountability Act (“HIPAA”). However, the MHMDA is much more comprehensive than it seems and covers more than health data. All companies, even those not traditionally associated with health or wellness, should assess whether they fall in scope of the MHMDA’s broad reach and if so, take immediate compliance steps. Read more here.
May 24, 2023
HHS OCR Settles HIPAA Investigation with Business Associate for $350,000
Over the past decade, the number of health care data breaches reported to the U.S. Department of Health and Human Services’ Office for Civil Rights (“OCR”) has increased dramatically. From 2009 to 2022, over 5,000 data breaches affecting 500 or more records were reported to OCR, accounting for the exposure of over 380 million health care records. More and more often, these breaches have involved business associates performing third-party services for covered entities. This year, some of the largest business associate breaches have involved Cerebral, Inc. (> 3 million individuals affected), NationsBenefits Holdings, LLC (> 3 million individuals affected), and NextGen Healthcare (> 1 million individuals affected). The latest business associate settlement with OCR, involving MedEvolve, Inc., provides important lessons for both business associates and covered entities. The HIPAA Fundamentals The Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) creates rules for the privacy and security of individually identifiable health information held by covered entities and business associates (the “HIPAA Rules”). A “covered entity” is a health plan, a health care provider that electronically transmits health information in connection with certain financial and administrative transactions, or a health care clearinghouse. A “business associate” is a person or entity that provides services to a covered entity that involve creating, receiving, maintaining, or transmitting protected health information (“PHI”). Any subcontractor of a business associate that creates, maintains, or transmits PHI on behalf of that business associate is also a business associate. All arrangements between covered entities and business associates, including between business associates and subcontractors, must involve a business associate agreement (BAA) which outlines each party’s obligations to protect PHI and report any data breaches. OCR is the office tasked with enforcement of the HIPAA Rules. Under the HIPAA Rules, covered entities are required to notify affected individuals, OCR, and in some cases, the media, following the discovery of a breach of unsecured PHI. Business associates are also required to notify covered entities following the discovery of a breach. OCR investigates written complaints and conducts compliance reviews and audits to enforce the HIPAA Rules. If violations of HIPAA are discovered, OCR can enter into a resolution agreement with the violating entity. Resolution agreements often require the entity to complete a corrective action plan (CAP) and pay a settlement amount. OCR’s Settlement with MedEvolve, Inc. On May 16, OCR announced a settlement of potential violations of the HIPAA Rules with MedEvolve, Inc. (MedEvolve), a business associate that provides practice management, revenue cycle management, and practice analytics software services to covered health care entities. The alleged HIPAA violations occurred in 2018, when MedEvolve suffered a data breach exposing the PHI of more than 200,000 individuals. Specifically, one of MedEvolve’s servers containing PHI such as patient names, billing addresses, and phone numbers was reported as openly accessible to the internet. As OCR investigated the breach, it determined that MedEvolve had failed to: (i) conduct a risk assessment to determine vulnerabilities to PHI, and (ii) enter into a BAA with a subcontractor. Pursuant to the resolution agreement, MedEvolve has paid a $350,000 penalty to OCR and agreed to implement a corrective action plan (CAP) to address potential violations of the HIPAA Rules. As part of the CAP, MedEvolve has agreed to: Conduct a risk analysis to determine vulnerabilities; Implement a risk management plan; Revise its written HIPAA policies and procedures; and Provide HIPAA training for employees with access to PHI. Additionally, OCR will monitor MedEvolve for a period of two years to ensure compliance with the HIPAA Rules. Lessons for Covered Entities and Business Associates While covered entities have historically reported the largest number of data breaches, the number of business associate data breaches continues to increase. Hacking/IT incidents accounted for 79% of the large data breaches reported to OCR in 2022, and network servers were the most common targets in these incidents. Thankfully, both covered entities and business associates can take precautions to strengthen their cybersecurity practices and lower the risk of a breach. Steps that should be taken include: Covered entities should conduct due diligence on any vendor that will handle PHI. This should include investigating the vendor’s: (i) IT security measures employed to protect data, (ii) employee training used to ensure staff understands how to protect PHI; and (iii) processes in place for responding to incidents. Covered entities and business associates should have a BAA in place and understand their reporting obligations under the BAA. The BAA should govern a business associate’s reporting obligations to the covered entity. When a breach is reported to the government, OCR will have questions about the BAA and the parties’ reporting obligations. Employees pose the biggest risk to an employer’s security. Employees should be trained to recognize and avoid phishing attempts and to report concerns immediately when they suspect a breach has occurred. When it comes to cybersecurity, an ounce of prevention is worth a pound of cure. Dorsey’s health care attorneys strongly recommend regularly reviewing your HIPAA compliance and updating your policies and procedures to reflect current best practices.
May 19, 2023
HHS and FDA Take Additional Measures to Aid Post-PHE Transition for Pharmacy Providers
For the last three years, the federal government has taken considerable steps to aid providers in the fight against COVID-19. Although many of the waivers and flexibilities initiated in response to the pandemic have since expired or are in the process of being phased out, other federal agencies, including the Department of Health and Human Services (“HHS”) and the Food & Drug Administration (“FDA”) have taken new steps to aid the post-public health emergency (“PHE”) transition. PREP Act Liability Immunity Extended Through 2024 for Pharmacists and Pharmacy Personnel On May 9, 2023 the Secretary of HHS (“Secretary”) issued the Eleventh Amendment to the Declaration Under the Public Readiness and Emergency Preparedness (PREP) Act for Medical Countermeasures Against COVID-19 (the “Amendment”). Crucially, the Amendment extends PREP Act liability immunity for pharmacists, pharmacy technicians and pharmacy interns through December 31, 2024, clearing up confusion among stakeholders as to the continued applicability of the PREP Act declarations in the waning hours of the federally-declared PHE which officially expired at 11:59 pm on May 11, 2023. At the beginning of the COVID-19 pandemic in March of 2020, then-Secretary Alex Azar issued the initial declaration under the PREP Act approving certain medical countermeasures against COVID-19 (“Declaration”). As the battle against COVID-19 evolved, that initial Declaration was amended several times, adding new categories of qualified providers, new COVID-19 countermeasures and revising the scope of prior amendments. Many of those amendments to the Declaration expanded the scope of practice of pharmacists, pharmacy technicians, and pharmacy interns, permitting them to administer COVID-19 and influenza vaccines and other COVID-19 countermeasures irrespective of state laws to the contrary. When the official end of the public health emergency was announced, there was confusion as to whether the amendments under the PREP Act would also end. In the latest Amendment, the Secretary makes clear that certain authorizations under the PREP Act will continue through December 31, 2024, acknowledging the end of the PHE while simultaneously noting that COVID-19 continues to present a risk for future public health emergencies. The provisions of the Amendment are intended to mitigate that risk. Specifically, the Amendment, in relevant part, provides the following: Extends liability coverage for licensed pharmacists, pharmacy interns, and pharmacy technicians authorized to order and/or administer the “Covered Countermeasures” while they are authorized under an Emergency Use Authorization (EUA), when consistent with the terms of the EUA. This is intended to allay any concerns about liability risks arising from continued manufacturing, distribution, administration or use of Covered Countermeasures while they are authorized under an EUA. Recognizing the burden on healthcare providers caused by coterminous seasonal influenza infections and COVID-19 infections, the Amendment extends the time period of PREP Act coverage through December 31, 2024 to Qualified Persons who are licensed pharmacists to order and administer, and pharmacy interns and qualified pharmacy technicians to administer, Covered Countermeasures that are COVID-19 vaccines, seasonal influenza vaccines, and COVID-19 tests, in accordance with other requirements (e.g. CDC/ACIP and FDA authorizations). To the extent that any state law would otherwise prohibit these healthcare professionals from prescribing, dispensing, or administering covered countermeasures that are COVID-19 vaccines, seasonal influenza vaccines or COVID-19 tests, such law is preempted. Importantly, the Amendment made no changes to PREP Act immunity as it relates to pharmacists, pharmacy technicians, and pharmacy interns dispensing COVID-19 oral anti-viral treatments such as Paxlovid and Lagevrio, which is authorized under FDA authority. Additionally, the Amendment made no change to the “Test to Treat” program, which will continue to receive liability protection under the PREP Act. The practical result of the Amendment is that patients will continue to have access to COVID-19 care. As noted in the Amendment, pharmacies are the most accessible health care providers, particularly in medically underserved areas. Despite liability immunity, it remains crucial for pharmacists and pharmacy personnel to maintain accurate documentation of their activities during emergency response efforts. Documentation should include patient information, administration records, adverse events, and any deviations from standard procedures. Compliance with state and federal regulations, such as reporting requirements for adverse events or medication errors, remains essential to ensure accountability and quality of care. The extension of PREP Act liability immunity through 2024 brings clarity and extends legal protections for pharmacists and pharmacy personnel involved in the public health emergency response. By shielding them from liability, this extension enables pharmacists and pharmacy personnel to fulfill their roles with confidence and make informed decisions in the face of evolving challenges. However, it is important for pharmacists and pharmacy personnel to remember that adherence to standards of care should always guide their actions, even as they operate under the umbrella of liability immunity. FDA Provides Exemptions from Certain DSCSA Requirements for Covered COVID-19 Products On May 11, 2023, the FDA, using its authority under the Food, Drug, and Cosmetic Act (the “Act”), granted exemptions for covered COVID-19 products from certain requirements under the Drug Supply Chain Security Act (DSCSA). For purposes of the FDA’s new exemptions, Covered COVID-19 products are “prescription drug products approved or authorized by the FDA to diagnose, cure, mitigate, treat, or prevent COVID-19.” This includes vaccines and antivirals, among others. The FDA issued these exemptions in response to the expiration of the PHE under Section 319 of the Public Health Service Act and its related COVID-19 DSCSA guidance that was implemented in the wake of the PHE. In an effort to avoid potential supply chain disruptions and aid manufacturers, wholesale distributors, repackagers, dispensers and their trading partners, the FDA determined that these new exemptions, many of which align with the FDA exemptions during the PHE, were needed. Manufacturers The section 582(b)(1) product tracing requirements. The section 582(b)(2) product identifier requirements. The section 582(b)(4)(A)(i)(II) requirements to verify product at the package level using the product identifier and validate any applicable transaction history and transaction information in the manufacturer’s possession for the purposes of a suspect product investigation, responding to an illegitimate product notification under section 582(b)(4)(B)(iii). However, manufacturers must still promptly conduct an investigation in coordination with trading partners as applicable and otherwise investigate the product to determine if it is illegitimate in accordance with section 582(b)(4)(A)(i)(II), and, upon determining such product is illegitimate, follow the requirements in section 582(b)(4)(B)(i) and (ii); these exemptions do not extend to these requirements. The section 582(b)(4)(C) requirement that upon request from an authorized trading partner in possession or control of a product that it believes to be made by the manufacturer, such manufacturer verify the product using the product identifier. However, if the manufacturer has reason to believe the product is an illegitimate product, the manufacturer must still advise the person making the request of such belief at the time such manufacturer responds to the request for verification; the exemptions do not extend to this requirement. The section 582(b)(4)(E) requirement to verify the product identifier of a saleable returned product that is intended for further distribution. Wholesale Distributors The 582(c)(1) product tracing requirements. The section 582(c)(2) product identifier requirements. The section 582(c)(4)(A)(i)(II) requirements to verify product at the package level using the product identifier and validate any applicable transaction history and transaction information in its possession for the purposes of a suspect product investigation or when responding to an illegitimate product notification under section 582(c)(4)(B)(iii). However, such wholesale distributors must still promptly conduct an investigation in coordination with trading partners as applicable and otherwise investigate the product to determine if it is illegitimate in accordance with section 582(c)(4)(A)(i)(II) and, upon determining such product is illegitimate, follow the requirements in section 582(c)(4)(B)(i) and (ii); these exemptions do not extend to these requirements. The section 582(c)(4)(D) requirement to verify the product identifier of saleable returned product packaged without product identifiers that is intended for further distribution. Dispensers The section 582(d)(1) product tracing requirements. The section 582(d)(2) product identifier requirements. The section 582(d)(4)(A)(ii)(II) requirement to verify a portion of suspect products at the package level using the product identifier], and section 582(d)(4)(A)(ii)(III) requirement to validate any applicable transaction history and transaction information in a dispenser’s possession for the purpose of an investigation of suspect product under 582(d)(4)(A) or when responding to an illegitimate product notification under section 582(d)(4)(B)(iii). However, dispensers must still verify lot number in accordance with section 582(d)(4)(A)(ii)(I) and otherwise conduct an investigation the product to determine if it is illegitimate as required by section 582(d)(4)(A)(ii)(IV), and, upon determining such product is illegitimate, follow the requirements in section 582(d)(4)(B)(i) and (ii); these exemptions do not extend to these requirements. Repackagers The section 582(e)(1) product tracing requirements. The section 582(e)(2) product identifier requirements. The section 582(e)(4)(A)(i)(II) requirements to verify product at the package level using the product identifier] and validate any applicable transaction history and transaction information in its possession for the purposes of a suspect product investigation, responding to an illegitimate product notification under section 582(e)(4)(B)(iii) or when prompted by a request for verification under 582(e)(4)(C). However, repackagers must still promptly conduct an investigation in coordination with trading partners as applicable and otherwise investigate the product to determine if it is illegitimate in accordance with section 582(e)(4)(A)(i)(II) and, upon determining such product is illegitimate, follow the requirements in section 582(e)(4)(B)(i) and (ii); these exemptions do not extend to these requirements. The section 582(e)(4)(C) requirement that upon request from an authorized trading partner in possession or control of a product that it believes to be repackaged by the repackager, such repackager verify the product using the product identifier. However, if the repackager has reason to believe the product is an illegitimate product, the repackager must still advise the person making the request of such belief at the time such repackager responds to the request for verification; these exemptions do not extend to this requirement. The section 582(e)(4)(E) requirement to verify the product identifier of a saleable returned product that is intended for further distribution In each case, the exemptions above apply only to covered COVID-19 products introduced by a manufacturer or repackager in a transaction into interstate commerce before November 27, 2024, and are effective until expiration of such product. Trading partners must continue to comply with all other applicable requirements of the DSCSA not identified in the new guidance. Note, too, that the FDA encourages trading partners to communicate any such reliance on the new exemptions to its trading partners so as to not delay distribution. To the extent that compliance with the DSCSA does not present a barrier to distribution of covered COVID-19 products, the FDA encourages trading partners to continue complying with those exempted requirements. The significant steps taken by HHS and the FDA will likely be welcomed by pharmacy providers who are emerging from a legal landscape that has been dramatically altered by the pandemic. Although we all are officially now living in the post-PHE world as of May 11, 2023, it is clear that the federal government is keeping a close eye as to how that transition unfolds. The healthcare attorneys at Dorsey & Whitney LLP will be doing the same.
May 16, 2023
Tracking Online User Activity: HIPAA and Other Legal Risks
The use of tracking technologies on websites and mobile applications (e.g., cookies) has become largely ubiquitous in our technology-driven world. Health care providers and organizations, for example, may use tracking technologies to identify their patients’ care needs and improve patient experience. As the use of tracking technologies burgeons, so do concerns from individuals about how to protect their personal information. Understandably so, as this technology comes with significant risks if collected information ends up in the wrong hands. Further, because of the sensitivity of the information involved, entities that handle Protected Health Information (“PHI”) and are regulated by the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”) must be particularly cautious when using tracking technologies. On December 1, 2022, the Office of Civil Rights (“OCR”) at the U.S. Department of Health and Human Services (“HHS”), which is responsible for enforcing HIPAA, issued a Bulletin addressing the use of tracking technologies by regulated entities, including Covered Entities and Business Associates, as defined by HIPAA.[1] The Bulletin does not create new obligations for HIPAA-regulated entities, and seeks only to clarify current HIPAA obligations as it relates to the use of tracking technologies, specifically, when a third-party vendor is utilized. What is a Tracking Technology? A tracking technology is a “script or code” on a website or mobile application (“app”) that collects information about users as they interact with the website or application.[2] The information gathered is analyzed and used to “create insights about users’ online activities”, and even their personal characteristics, wants or needs.[3] Tracking technologies include mechanisms such as cookies, pixels, web beacons, and embedded tracking codes in apps and devices. One such example is the Facebook pixel by Meta, which website owners can embed into their website to track site visits and user activity on the website.[4] How is HIPAA Implicated? HIPAA-regulated entities are required to safeguard PHI, which includes protecting it from impermissible disclosures. When regulated entities utilize third-party vendors to track the activity of website or app users, information is collected through tracking technologies placed on the website or app, which is then sent to that vendor to perform data analytics. If the collected information includes PHI, it is protected by HIPAA, and the HIPAA Privacy, Security, and Breach Notification Rules (“HIPAA Rules”) apply.[5] The rule for what qualifies as PHI in this context is much broader than one might think. Sometimes it is apparent: a patient portal that a patient must log in to almost certainly has access to PHI, such as the person’s medical or billing information. However, even an unauthenticated webpage that does not require a login, such as a health care provider’s public website, may provide a tracking technology vendor access to PHI. For example, tracking technologies might collect identifying information, such as an individual’s email address or IP address. If that person then begins searching for a provider or information on a particular medical condition, which is also tracked and sent to the vendor, the regulated entity is now disclosing PHI to the vendor.[6] Likewise, mobile apps may collect information such as health and billing information, as well as information about the user’s device (fingerprints, network location, etc.). This, too, is PHI, and any disclosure to the vendor must comply with HIPAA. Purported Class Action Lawsuits In recent months, several health plans and hospital systems have been the target of purported class action lawsuits from private plaintiffs alleging that the defendants utilized tracking technology vendors and unlawfully disclosed PHI without individual consent. Because there is no private right of action under the HIPAA Rules, these lawsuits do not bring HIPAA claims. But they appear to use alleged HIPAA Rule violations as a basis for claims under the Electronic Communication Privacy Act of 1986, the Computer Fraud and Abuse Act, and state law common law privacy claims. Accordingly, this is not merely a technical HIPAA matter, and can result in real consequences. What Should Regulated Entities Do to Comply with HIPAA When Using Tracking Technology Vendors? Make sure a Business Associate Agreement (“BAA”) is in place. A tracking technology vendor is a Business Associate when it creates, receives, maintains, or transmits PHI on behalf of a Covered Entity.[7] Further, disclosures to the vendor must be permitted by the HIPAA privacy rule, and only the minimum necessary PHI for the applicable purpose may be disclosed. If a BAA is not practicable or sufficient (e.g., there is no applicable permitted disclosure under the HIPAA privacy rule), the regulated entity must obtain individuals’ HIPAA-compliant authorization before any disclosure to the vendor occurs.[8] It is worth noting here certain mechanisms that do not qualify as HIPAA-compliant authorization: Privacy policy or terms of use. While a regulated entity may disclose the use of tracking technology here, that is insufficient to permit a disclosure of PHI that requires an individual’s authorization under the HIPAA privacy rule. Website banners asking individuals to accept or reject tracking technologies, such as cookies. A tracking technology vendor that promises to de-identify PHI before using information it receives or promises not to save PHI, because disclosure has already occurred at that point. Apply administrative, physical and technical safeguards to electronic PHI, as required under the Security Rule (e.g., encrypt PHI sent to the vendor), and consider and address tracking technologies when performing risk assessments. Notify individuals, the Secretary, and the media as required if a breach occurs. Final Thoughts HIPAA-regulated entities that utilize tracking technologies, and in particular, tracking technology vendors, must remain vigilant as to how PHI may be collected on various platforms. In particular, be aware that even a public, unauthenticated webpage could result in disclosure of PHI due to identity- or device-tracking pixels. When using a tracking technology vendor, a BAA must be in place, and the purpose of the disclosure must be permitted under the HIPAA Rules. Failure to do could result in impermissible disclosure of PHI, constituting a violation of the HIPAA Rules. The practice could also attract claims from private plaintiffs under various statutory and common law theories. Be proactive in addressing this potential gap in your privacy program; do not wait until the problem finds you. [1] 45 CFR § 160.103. [2] Use of Online Tracking Technologies by HIPAA Covered Entities and Business Associates, Dep’t of Health & Human Services (Dec. 1, 2022), https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html - ftn8. [3] Id. [4] See https://www.facebook.com/gpa/blog/the-facebook-pixel. [5] See 45 CFR parts 160 and 164. [6] https://www.hhs.gov/hipaa/for-professionals/privacy/guidance/hipaa-online-tracking/index.html - ftn8. [7] Id. [8] 45 CFR § 164.508(b).
March 15, 2023
FTC Takes First Enforcement Action for Violation of the Health Breach Notification Rule – A Federal Health Privacy Rule Beyond HIPAA
On February 1, 2023, the Federal Trade Commission (FTC) filed a complaint in the U.S. District Court for the Northern District of California alleging that digital health platform GoodRx violated the FTC Act by repeatedly sharing personal health information with advertising companies and platforms, such as Facebook and Google, and failed to report the unauthorized disclosures pursuant to its Health Breach Notification Rule (16 C.F.R. § 318). Though GoodRx maintains that it shared all health information appropriately, according to the proposed stipulated order, the digital health platform has agreed to pay a $1.5 million civil penalty. Once the proposed order is approved by a federal court judge, the monetary penalty, as well as several non-monetary sanctions, will go into effect. This settlement may signal the beginning of a new era of health privacy enforcement, where the Health Insurance Portability and Accountability Act of 1996 (HIPAA) is not the only federal health privacy law for which organizations must ensure compliance. The FTC’s Health Breach Notification Rule is not new—even though the GoodRx complaint marks its first enforcement action. The rule went into effect in September 2009 and was the subject of a 2021 FTC policy statement. Substantively, the Health Breach Notification Rule is very similar to HIPAA’s Breach Notification Rule (45 C.F.R. §§ 164.400-414). Pursuant to both rules, a data holder must notify the subject of any unsecured “individually identifiable health information” and the agency responsible for enforcing the applicable rule in response to a breach of such information. Also pursuant to both rules, if a breach of unsecured personal health information involves more than 500 individuals (and, in the case of the Health Breach Notification Rule, if a breach involves exactly 500 individuals), the data holder must notify the media. The primary differentiating factor between the rules are the types of entities to which they apply. The HIPAA Breach Notification Rule is specific in scope and only applies to Covered Entities and their Business Associates. A Covered Entity is limited to a: (1) health plan, (2) health care clearinghouse, or (3) health care provider, who also electronically transmits health information in connection with transactions for which HHS has adopted standards. A Business Associate is a person or entity who, on behalf of a Covered Entity, performs or assists in performance of a function or activity involving the use or disclosure of individually identifiable health information. The FTC’s Health Breach Notification Rule is broader in scope and applies to all vendors that “offer or maintain a personal health record (PHR).” A PHR is an electronic record of “individually identifiable health information,” as defined in section 1171(6) of the Social Security Act (42 U.S.C. 1320d(6)), that can be drawn from multiple sources and that is managed, shared, and controlled by or primarily for the individual. The FTC has stated that an example PHR Vendor might be a health app that collects information from consumers and can sync with a consumer’s fitness tracker. The Health Breach Notification Rule also applies to “PHR related entities” and “third-party service providers.” A PHR Related Entity interacts with a PHR Vendor by either offering products or services through the Vendor’s website, offering products or services through a Covered Entity’s website that offers individual’s health records, or by accessing information in a PHR or sending information to a PHR. The FTC states that an example of a PHR Related Entity might be a company that offers a fitness tracker and sends information to health apps. A Third Party Service Provider is an entity that provides services to a PHR Vendor in connection with the offering or maintenance of a PHR or to a PHR Related Entity in connection with a product or service offered by that entity; and accesses, maintains, retains, modifies, records, stores, destroys, or otherwise holds, uses, or discloses unsecured PHR identifiable health information as a result of such services. The FTC states that an example of a Third Party Service Provider might be a company that provides billing, debt collection, or data storage services relating to health information for a PHR. In light of the GoodRx complaint and the FTC’s enforcement of the Health Breach Notification Rule, all entities that utilize or maintain personal health information—and especially those offering healthcare apps, connected devices, and wearables, that often do not fall under the definitions of Covered Entities and Business Associates—should evaluate the applicability of the Health Breach Notification Rule to their organization and its business practices. Entities that fall under the definitions of PHR Vendor, PHR Related Entity, and Third Party Service Provider, should be sure to have an effective privacy and security program in place, including procedures for conducting regular risk assessments and risk management trainings to ensure proper identification of and response to a breach of personal health information. Such entities should also review their privacy policies, both internally and externally-facing, to ensure they reflect current data-sharing practices, and should review their vendor contracts to take inventory of any permissions or restrictions on how personal health information is used and disclosed to ensure they are obtaining the necessary consent. For more information on the Health Breach Notification Rule, the FTC’s Health Privacy webpage offers a variety of resources—including a simplified explainer of the rule, compliance tips, and an interactive tool geared toward mobile health apps. For more tailored guidance, or with any questions, please do not hesitate to reach out to one of the authors or your regular Dorsey & Whitney attorney.
February 15, 2023
Employment
Updates Regarding New Iowa Law That Impacts Health Care Staffing Agencies and Contracts with Health Care Entities
On March 17, 2022, Iowa Governor Kim Reynolds signed House File 2521, “Relating to Health Care Employment Agencies, and Providing Penalties” into law. We previously discussed the new law on a June 10, 2022 blog post. At that time, a looming question was how Iowa’s administrative agencies would draft rules to clarify and implement the law. On November 30, 2022, the Iowa Department of Inspections and Appeals (DIA) submitted the final administrative rules to implement House File 2521 to final publication. By way of brief background, administrative rules are the regulations that help to implement laws passed by the Iowa Legislature. After a bill is signed by the Governor, state agencies may propose rules to implement the statute the agencies are tasked with enforcing. Rules are first drafted within an agency, then reviewed by the agency head, and then published in the Iowa Administrative Bulletin. At that time, the public is allowed to comment on the proposed rules for a certain period of time. After the public comment period, the agency head adopts the rules (with additions as appropriate) and sends them for final publication. Even after final publication, the rules are subject to legislative review by the Administrative Rules Review Committee (ARRC). That committee can object to rules and delay effective dates. So, what do the final rules for House File 2521 say? First, the rules clarify the definition of a “health care employment agency” for the purpose of this law. House File 2521 broadly defined “health care employment agency” to mean “an agency that contracts with a health care entity in this state to provide agency workers for temporary, temporary-to-hire, direct hire, or other contract or employee placements.” The rules expressly provide that “a recruitment firm that contracts with a health care entity to identify and screen potential candidates for hire and does not provide agency workers for temporary, temporary-to-hire, direct hire, or other contract employee placements” are not covered by the statute. The rules also carve out an exception for “physical therapists licensed under Iowa Code chapter 148A, occupational therapists licensed under chapter 148B, or speech pathologists or audiologists licensed under Iowa Code chapter 154F,” meaning those professions are not considered “health care employment agencies” under this law. Under these rules, it’s status quo for those professions: employers may still include certain covenants not to compete, finder’s fees, and other contract provisions that the law otherwise prohibits. Second, the rules also confirm the language of House File 2521 in defining “direct services” to exclude the practice of “medicine and surgery or osteopathic medicine and surgery by an individual licensed under Iowa Code chapter 148 or 148C or the practice of nursing by an advanced registered nurse practitioner or an advanced practice registered nurse licensee under Iowa Code chapter 152 or 152E.” Again, for these positions, the pre-House File 2521 status quo appears to be the law going forward. Finally, the rules provide some exceptions to the general prohibition against non-competes and other contract provisions in healthcare employment agency contracts. Specifically, these contracts can contain non-competes and finder’s fees when: (1) the health care worker has been sponsored by or is otherwise assisted in obtaining work authorization in the United States by the employment agency, (2) the contract contains an initial term of “no less than 24 months and has a total duration, including any renewals or extensions, of no longer than 36 months,” and (3) the contract requires the agency worker to work at a single health care entity for the duration of the contract. At first glance, the rules appear to narrow the scope of the statute considerably. It remains to be seen how the ARRC will respond (e.g. whether the rules change the House File too significantly). The next meeting of the ARRC on December 12, 2022 may provide some insight into what concerns, if any, legislators have with the final rule. As always, we will be closely monitoring the upcoming 2023 session of the Iowa General Assembly for further action on health care staffing issues.
December 5, 2022
Recent DOJ Settlements Involving DME Manufacturers Highlight Important Anti-Kickback Considerations
The Department of Justice (“DOJ”) recently announced two settlement agreements, both involving durable medical equipment (“DME”) companies, following allegations that the companies had violated the Anti-Kickback Statute (“AKS”). The AKS, found at 42 U.S.C. § 1320a-7b, prohibits the exchange of anything of value (i.e., remuneration) with any intent to induce referrals for services or products reimbursable by federal health care programs. These settlements highlight two important reminders when it comes to complying with the AKS: (1) illegal remuneration can come in many forms and need not be monetary; and (2) commission-based compensation, while allowed for employees, is improper remuneration with regard to independent contractors. The first settlement involved a DME manufacturer that allegedly misled federal health care programs, including Medicare, Medicaid, and TRICARE, by paying kickbacks to DME suppliers. Specifically, the manufacturers provided DME suppliers with data about physician prescribing practices to aid their marketing efforts. In exchange, those suppliers then marketed the manufacturer’s products to providers. This resulted in DME suppliers submitting false claims for respiratory-related equipment following Respironics’ illegal inducements. Under the settlement terms, Respironics agreed to pay over $24 million in total to the United States and various affected states. Respironics also entered into a five-year corporate integrity agreement (“CIA”) with the U.S. Department of Health & Human Services Office of Inspector General (“HHS-OIG”). This settlement agreement makes clear that anything of value – even data – can be considered illegal remuneration under the AKS. Even if there is no marginal cost involved from the perspective of the data provider, data nonetheless can have value to the recipient. Consequently, product manufacturers, health care providers and others should recognize that value in any form can be the basis for anti-kickback allegations. The second settlement involved a DME manufacturer that produces knee braces and related products. It was alleged that the supplier paid an independent sales representative and the representative’s company commission payments ranging from 20-35% of VQ’s net revenue on every knee brace ordered by a particular set of providers. The providers then submitted claims for the braces allegedly contaminated by these kickbacks. The sales representative was able to “establish itself as the exclusive brace supplier” for several providers and collect millions of dollars in annual brace sales, according to the DOJ press release. Notably, this settlement was the result of an independently-prompted government investigation of Medicare claims data. Under the settlement terms, the DME manufacturer agreed to pay $2.25 million and entered into a five-year CIA with HHS-OIG. The issue of commission payments was also addressed early last year in United States v. Mallory, 988 F.3d 730 (4th Cir. 2021), wherein a federal court ordered a blood testing laboratory and its contracted sales agents to pay more than $100 million in damages after finding that the lab’s commission-based compensation to its contractors violated the AKS. These recent events illustrate that commission-based compensation arrangements with independent contractors are still an issue whenever federal health care programs are involved. And while there is an AKS safe harbor for commission payments to employees (42 C.F.R. § 1001.952(i)), the Department of Health and Human Services has made clear that commission payments for contracted services are not likewise protected. The DOJ has established its intent to aggressively scrutinize and prosecute such arrangements. In summary, these DME manufacturer settlements underscore two important AKS guidelines for all health care service and equipment providers: (1) be aware of untraditional items of value, such as data, that could be considered illegal remuneration; and (2) avoid commission-based compensation arrangements with independent contractors whenever federal program provide reimbursement for the products or services.
October 19, 2022
Employment
CDC Issues Major Updates for Healthcare Providers and Eases Masking and Other Infection Control Requirements – Important Information for Employers
For the last few months, we have been fielding calls from clients in the healthcare industry asking about things such as whether they still needed to screen patients upon entry to facilities, whether employees must still wear masks at all times, and whether they still had to treat vaccinated employees differently from unvaccinated employees. We saw an uptick in these calls following the CDC’s August 11, 2022, updated masking guidance for the general public (“the Updated Guidance”). The CDC’s masking guidance in non-healthcare settings The CDC’s Updated Guidance for anyone not in a healthcare setting bases masking recommendations not on vaccination status, but on COVID-19 Community Levels. Those levels measure “the impact of COVID-19 in terms of hospitalizations and healthcare system strain, while accounting for transmission in the community.” Notably, the Updated Guidance explicitly stated that it did not apply in healthcare settings. The Updated Guidance used Community Levels to make masking and testing recommendations without regard to vaccination status. The CDC’s prior guidance in healthcare settings Unlike the Updated Guidance, employers in healthcare were required to utilize source control based instead on COVID-19 Community Transmission, which differs from the Community Level measurement as it “refers to measures of the presence and spread of SARS-COV-2.” In addition, the CDC guidelines for source control in health care settings differentiated between those who were and were not “up to date” with their COVID-19 vaccinations, defining “up to date” as having all recommended boosters. This resulted in many frustrated and confused healthcare employers. The CDC’s updated guidance for healthcare settings On September 23, 2022, the CDC issued long-awaited updated infection prevention and control recommendations for healthcare settings (“the Healthcare Update”). The Healthcare Update applies to “all U.S. settings where healthcare is delivered, including nursing homes and home health.” While healthcare employers must still utilize COVID-19 Community Transmission metrics to determine source control, the CDC’s recommendations for healthcare settings no longer use COVID-19 vaccination status in source control guidance. The CDC provided the following summary of the Healthcare Update: Updated to note that vaccination status is no longer used to inform source control, screening testing, or post-exposure recommendations Updated circumstances when use of source control is recommended Updated circumstances when universal use of personal protective equipment should be considered Updated recommendations for testing frequency to detect potential for variants with shorter incubation periods and to address the risk for false negative antigen tests in people without symptoms Clarified that screening testing of asymptomatic healthcare personnel, including those in nursing homes, is at the discretion of the healthcare facility Updated to note that, in general, asymptomatic patients no longer require empiric use of Transmission-Based Precautions following close contact with someone with SARS-CoV-2 infection Archived the Interim Infection Prevention and Control Recommendations to Prevent SARS-CoV-2 Spread in Nursing Homes and special considerations for nursing homes not otherwise covered in Sections 1 and 2 were added to Section 3: Setting-specific considerations Updated screening testing recommendations for nursing home admissions Clarified the types of long-term care settings for whom the healthcare infection prevention and control recommendations apply What are the key differences for employers? As evidenced by the above list, the CDC made quite a few changes in the Healthcare Update. Because our calls from clients have been primarily focused on masking and screening, we will focus on what is different with regard to those two topics. Healthcare employers, particularly those in specific settings referenced by the Healthcare Update (Dialysis Facilities, Emergency Medical Services, Dental Facilities, Nursing Homes, and Assisted Living, Group Homes, and Other Residential Care Settings), should review the new guidance carefully and consult a healthcare attorney with questions. With regard to what is commonly referred to as “surveillance testing,” the CDC does not recommended that testing decisions be based on vaccination status or Community Transmission levels. Screening and masking changes are highlighted below: Topic Prior Recommendations Healthcare Update Recommendations Screening for COVID-19 Encourage everyone to remain up-to-date with all recommended COVID-19 vaccine doses Post visual alerts in entrances and high-traffic areas outlining current infection prevention and control practices and recommendations Establish a process that should be followed by anyone entering the facility that either: (1) has a positive viral test for SARS-CoV-2, (2) has symptoms of COVID-19, or (3) has had close contact with someone infected by COVID-19 or for healthcare personnel with a higher-risk exposure Suggested options for could include (but were not limited to): individual screening on arrival at the facility; or implementing an electronic monitoring system in which individuals can self-report any of the above before entering the facility Removes suggestion that healthcare facilities utilize individual screening on arrival at the facility or electronic monitoring systems Source Control (i.e., masking) Masking exceptions for employees up-to-date with all recommended COVID-19 vaccine doses, particularly in non-patient facing scenarios, provided Community Transmission was low to moderate Healthcare employers may choose not to require universal source control when COVID-19 Community Transmission levels are not high, regardless of whether employees are up-to-date with all recommended COVID-19 vaccine doses, even when patient-facing Source control still recommended for employees who have symptoms of COVID-19, have tested positive for COVID-19, been exposed to the virus, are treating COVID-19 patients, are performing certain procedures, etc. Source control for everyone recommended when Community Transmission levels are high Obviously, employees in healthcare settings can choose to continue wearing masks even if it is not required by their employer or recommended by the CDC, and healthcare employers should not discourage such voluntary usage. Don’t forget about the CMS vaccine mandate Even though the Healthcare Update may be currently driving the news and front of mind, healthcare employers must not forget that CMS’s November 4, 2021, Interim Final Rule (“CMS Mandate”) requiring staff at certain Medicare or Medicaid providers and suppliers to be fully vaccinated against COVID-19 (unless they qualify for a medical or religious exemption) is still in effect. The Healthcare Update slightly affects the CMS Mandate, particularly with regard to mitigation strategies for employees who are not “fully vaccinated” (which the CMS Mandate does not define to include boosters). There appears to be some tension between the Healthcare Update and the CMS Mandate. For example, under the CMS Mandate, if an employee is not fully vaccinated because of a medical or religious exemption, employers are required to implement additional precautions to mitigate the transmission and spread of COVID-19. One obvious precaution to mitigate transmission is to require source control for those unvaccinated employees, something the CDC says is no longer required in areas where Community Transmission levels are not high. Because the CMS Mandate is in fact still in effect, and because surveyors are still surveying facilities for compliance with the CMS Mandate, our best advice is that facilities subject to the CMS Mandate be able to demonstrate some kind of additional precautions for unvaccinated staff (as defined by the CMS Mandate), even if the additional precautions do not include universal source control. What healthcare employers should do now Pay close attention to SARS-CoV-2 Community Transmission levels in your county of operation and make source control decisions accordingly. Ensure you have some form of additional precautions to mitigate the transmission and spread of COVID-19 for unvaccinated staff in order to demonstrate compliance with the CMS Mandate (if not required masking or other source control). If in-person or electronic screening is eliminated, ensure there are processes for infection prevention and control in place and that all who enter the facility are aware of those processes. Finally, encourage everyone to remain up-to-date with all recommended COVID-19 vaccine doses, including boosters.
September 27, 2022
Eighth Circuit Analyzes Scope of FCA Liability Under Anti-Kickback Statute
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Scott Mah and Charles Pults for the following post on the FCA Now blog: On July 26, 2022, the Eighth Circuit Court of Appeals issued an opinion interpreting the standard for the causal link the government must show to establish that a “false or fraudulent” claim under the False Claims Act (“FCA”) included “items or services resulting from a violation” of 42 U.S.C. § 1320a-7b(g), the federal anti-kickback statute. United States ex rel. Cairns v. D.S. Med. LLC, 2022 U.S. App. LEXIS 20584 (8th Cir. Jul. 26, 2022) (emphasis added). Read more here.
September 26, 2022
DOJ Paving a More Structured Path for Corporate Criminal Enforcement
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s RJ Zayed and Katherine Chaves for the following publication: On September 15, 2022, Deputy Attorney General Lisa Monaco laid out the DOJ’s first substantive changes to white-collar criminal investigations and enforcement under the Biden administration. This comes on the heels of Deputy AG Monaco’s announcement last October to crackdown on corporate wrongdoing. In a speech at NYU law and in a memo distributed across the DOJ, Deputy AG Monaco reemphasized that DOJ’s corporate enforcement policy focuses on individual accountability, corporate responsibility, predictability and transparency, and ways corporate enforcement policies must square with the realities of the modern economy. In an exclusive interview with the New York Times previewing her speech, Deputy AG Monaco stated that, “I wanted very much to arm and empower chief compliance officers and general counsel to be able to go into the boardrooms and say to the C.E.O., to the chair of the board, ‘We need to make these investments in compliance. When I was out of government, I sat on some corporate boards and I saw that those are hard decisions and you have hard trade-off discussions.” Read more here.
September 22, 2022
COVID-19
Federal Contractor Vaccine Mandate: Federal Appeals Court Says Its Unlawful But You Might Have to Comply Anyway
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Alex Hontos, Katie Ervin Carlson, and Jillian Kornblatt for the following publication: Lately, litigation news related to public and private workplace COVID-19 vaccine mandates has quieted. That changed last Friday, when the Eleventh Circuit Court of Appeals narrowed a nationwide injunction against the Biden Administration’s federal contractor vaccination mandate (the “GovCon Vax Mandate”). Because the Court concluded that the GovCon Vax Mandate was likely an unlawful exercise of authority, it kept in place a lower court preliminary injunction against enforcement of the mandate. But, the decision reversed the lower court’s nationwide injunction, substantially narrowing the injunction’s affect. That means federal contractors that were not parties to the Eleventh Circuit litigation are potentially subject to the GovCon Vax Mandate. For those contractors, the focus now turns back to the federal government—and whether the Biden Administration will start to enforce the mandate piecemeal. The Safer Federal Workforce Task Force issued the GovCon Vax Mandate. As of this eUpdate, the Task Force’s website still indicates that, in light of various court orders and preliminary injunctions, the Government will take no action to enforce the GovCon Vax Mandate. Whether that will change in light of the Eleventh Circuit’s decision remains unknown, creating significant operational uncertainty for organizations with federal contracts or subcontracts. Read more here.
September 2, 2022
Anti-Kickback
A Hefty Speaking Fee: Biogen Inc. Agrees to Settle False Claims Act Suit In Violation of Anti-Kickback Statute for $900 Million
The Dorsey Health Law blog team keeps readers up-to-date on relevant topics in the health care industry. In order to do so, the members of the blog team communicate regularly with other practice groups within the firm for applicable updates from client publications. For this post, we would like to thank Dorsey’s Samuel Aduley for the following post on the FCA Now blog: On July 20, 2022, Biogen Inc. (“Biogen”) disclosed in a quarterly earnings report that it had agreed to pay $900 million to resolve a qui tam claim by a former employee that the company had violated the False Claims Act (“FCA”) and the Federal Anti-Kickback Statute (“AKS”). See Biogen Reports Second Quarter 2022 Results; see also United States ex rel. Bawduniak v. Biogen Idec, Inc., No. 12-cv-10601-IT, ECF No. 132 (Third Amended Complaint), ECF 615 (Notice of Settlement) (D. Mass. Apr. 27, 2018). Read more here.
September 1, 2022
Tax Exemption
Charitable Contribution and Donor Relation Considerations for 501(c)(3) Organizations
Donors that make contributions to charitable organizations recognized under Section 501(c)(3) of the Internal Revenue Code of 1986, as amended (the “Code”), may claim an individual income tax deduction under Section 170 (all subsequent references to “Section” shall mean Sections of the Code). For donors, this is often a persuasive factor in deciding whether to donate to a particular charitable organization. However, in order for donors to be eligible for a charitable deduction and for the recipient organizations to avoid penalties, certain requirements must be met depending on the amount and character of the contributed property. Section 501(c)(3) organizations should remain mindful of these requirements to ensure their donors are allowed the deductions they expect and to maintain donor relations. The following is an overview of important considerations for Section 501(c)(3) organizations to consider when pursuing fundraising initiatives or accepting charitable contributions. What is required of a Section 501(c)(3) organization if a donor makes a monetary or non-monetary contribution of $250 or more? Under Section 170(f)(8), for any single contribution of $250 or more, a donor must attach a contemporaneous written acknowledgement (“CWA”) from the Section 501(c)(3) organization to their income tax return. Although the donor is ultimately responsible for obtaining the CWA, Section 501(c)(3) organizations should maintain a CWA practice or policy for contributions of $250 or more. Any such practice or policy should ensure that the CWA includes the organization’s name and the amount of money or a description of the non-monetary property donated. The CWA must also contain a statement of whether the Section 501(c)(3) organization provided any good or service in return for the contribution as well as a description and estimated value of any such good or service. Recently, in Albrecht v. Commissioner,[1] the U.S. Tax Court reemphasized this “strict” requirement. The taxpayer, who donated Native American jewelry and artifacts to a museum, was ineligible for a deduction because the CWA failed to clarify whether the museum provided any goods or services in return for the donation. While an implicit statement (for example, “this donation is unconditional”) may be sufficient, the best practice is to include an explicit statement: “No goods or services were provided to you in return for your contribution.” The donor must receive the CWA by the date they file their tax return or the due date of the return, whichever is earlier. As such, a Section 501(c)(3) organization’s practice or policy should be to give the donors a CWA as soon as possible after the gift, but no later than by January 31 of the year following the contribution.[2] What about requirements for a monetary or non-monetary contribution of less than $250? Although a CWA is not required for contributions of less than $250, Section 501(c)(3) organizations should consider maintaining a CWA practice or policy for all contributions, regardless of the amount. At a minimum, the organization should provide an acknowledgement expressing gratitude and giving the organization’s name, the date of the contribution, whether the recipient organization provided any goods or services in return for the donation, and the amount donated. Not only can a “thank you” make a positive impact on individual donors as well as build long-lasting donor relationships, donors also need a record of each contribution in order to be eligible for a deduction. What should a Section 501(c)(3) organization consider if a donor makes a non-monetary contribution valued over $5,000? Under Section 170(f)(11), if a donor contributes non-monetary property valued over $5,000, they must attach a signed and dated qualified appraisal and a Form 8283 to their tax return. This requirement applies to collections of similar goods, such as books, coins, or jewelry. Although the donor is solely responsible for obtaining the appraisal, Section 501(c)(3) organizations should maintain a practice or policy of reminding their donors to obtain a qualified appraisal prior to their contribution (but no earlier than 60 days prior to their contribution). In addition, the receiving organization and any of its employees must decline to be the qualified appraiser, even if they would otherwise be a qualified appraiser. Can a Section 501(c)(3) organization provide any good or service in return for donations? It depends. Section 501(c)(3) organizations may solicit donations through fundraising events such as a gala or a golf tournament, or show gratitude through branded items such as a mug. Under Section 6115, if a donor contributes over $75 and receives any goods or services in exchange for their contribution (a “quid pro quo” contribution), the Section 501(c)(3) organization must provide a written disclosure to the donor. A failure to do so, or a failure to meet the requirements for a written disclosure, may result in monetary penalties on the Section 501(c)(3) organization. Therefore, Section 501(c)(3) organizations should maintain a written disclosure practice or policy for quid pro quo contributions. The written disclosure must inform the donor that their deduction is limited to the amount of their contribution less the value of the good or service received and provide an estimated valuation of any good or service. For example, a table at a charitable gala may require a minimum contribution of $10,000, but the price of the ticket also includes the cost of the gala dinner ($1,000). The ticket should explicitly state that the individual donor will receive food and entertainment valued at $1,000, and is therefore only entitled to a $9,000 charitable income tax deduction. However, a Section 501(c)(3) organization may not need to provide a written disclosure for certain types of goods or services. For example, if a donor contributes at least $56.50, the organization may provide branded items with their name or logo, such as a mug or a keychain, without a disclosure, as long as the item is valued at or below $11.30. There are also exceptions for: pre-paid return envelopes in donation solicitations, as long as the total for the calendar year is at or below $11.30; membership benefits to purchase tickets or attend low-cost, member-only events, as long as the membership fee is $75 or less; and other goods or services, as long as they are valued at or below 2% of the contribution, up to $113.[3] If you have any questions regarding your charitable contribution practices or policies, please contact the author or your regular Dorsey attorney. Summer Associate Laura C.S. Newberry provided substantial assistance researching and drafting this blog post. [1] Albrecht v. Commissioner, T.C. Memo. 2022-53. [2] IRS Publication 1771, Charitable Contributions-Substantiation and Disclosure Requirements. [3] The $11.30, $56.50, and $113 amounts are current for 2021 but are annually adjusted for inflation. Rev. Proc. 2020-45 § 3.34.
July 29, 2022