Oscislawski LLC

Latest from Oscislawski LLC - Page 6

On May 1, modifications to the Medicare Conditions of Participation (“CoPs”) went into effect, requiring certain electronic event notifications for admissions, discharges and transfers (“ADTs”) to and from hospitals, critical access hospitals and psychiatric hospitals. To provide guidance to hospitals and state surveyors, CMS released several FAQs as well as interpretive guidance last week

  • The 21st Century Cures Act already establishes the penalties that will apply to Actors that engage in prohibited Information Blocking
  • ONC will exercise enforcement discretion and not assess penalties until CMP rules are final, however compliance by April 5, 2021 is still required
  • ONC already maintains a live webpage and portal through which anyone can report information

  • On and after April 5, 2021, any Actor’s agreements, arrangements, or contracts are subject to and may implicate the Information Blocking Rule.
  • The Communications Condition of Certification (CCOC) requirements must be revised to remove or void the contractual provision that contravenes the CCOC requirements whenever the contract is next modified for any reason.
  • A Business Associate Agreement should generally not

  • Your vendor is not “taking care of it.” Compliance with the Information Blocking rule is about more than just the technology.
  • Assemble a “task team” to tackle operational decisions that need to be made to comply with Information Blocking.
  • Use a checklist to begin “ticking off” boxes to ensure that your organization is moving towards compliance

How can an Actor/covered entity provider comply with both the Information Blocking Rule & HIPAA when access to EHI/PHI needs to be denied based on harm that arises from corrupted data?

  • Delay access to EHI/PHI instead of denying access completely.
  • Have a licensed health care professional confirm the denial of access due to data issues.

The Information Blocking (IB) Rule is intended to work in sync with HIPAA, including the “right of access” granted to patients with regard to their own protected health information (PHI).  However, as I continue to analyze how to implement the various standards that overlap between these two regulations, questions about how to thread the needle