MACRA – Are There Additional HIPAA Concerns for Providers?

By Jay Hodes, President – Colington Consulting 

I am not claiming to be an expert on the Medicare Access and CHIP Reauthorization Act of 2015 (MACRA), other than the inherent emphasis this Act places on HIPAA requirements. The U.S. Department of Health and Human Services, which has a number of internal agencies that deal with patient privacy concerns, is starting to see the need to further enforce required health record safeguards.  For better or worse, this is what HIPAA is all about. It appears parts of MACRA continue this trend.

Here is a little background on MACRA. On April 14, 2015, a large bipartisan majority in Congress passed the MACRA. President Obama signed the MACRA into law on April 16, 2015. It repeals the Sustainable Growth Rate (SGR) formula, which linked Medicare annual payment updates for physicians and other professionals to prior year spending and gross domestic product (GDP) growth. MACRA contains scheduled Physician Fee Schedule (PFS) updates, a new Merit-Based Incentive Payment System (MIPS), a new Technical Advisory Committee for assessing Physician Focused Payment Model (PFPM) proposals, and incentive payments for participation in Alternative Payment Models (APMs).

The Act also includes strict privacy and security requirements for all entities receiving Medicare analyses or data, as well as new annual reporting requirements.

Obviously there is much more to this Act, but I wanted to address it from the HIPAA compliance perspective. Simply stated, MACRA requirements to maximize payments will require practitioners to meet certain requirements to protect the health information of patients by implementing certified electronic medical records technology.  

If your healthcare organization already carries the designated title of being a Covered Entity, you should be doing this already. This is the foundation of the safeguards under the HIPAA Security Rule, and MACRA makes a number of strongly worded references to privacy and security requirements. 

This means Covered Entities must be conducting HIPAA Risk Assessments and have an overall risk management plan in place. A HIPAA Risk Management Plan is the foundation of any compliance program. Regardless of the size of your practice, a plan is the most essential component for implementing compliance. Contained within the plan must be a policy and procedure on how your organization is going to conduct the risk assessment process. MACRA will put more emphasis on the assessment process in determining vulnerabilities and threats to electronic health information maintained, transmitted and created by Covered Entities.  

If organizations have a comprehensive compliance program in place then there should be no additional HIPAA concerns that MACRA will pose. But for many small to mid-size healthcare providers, it is still a struggle meeting all the HIPAA compliance requirements. And now with some MACRA formulas designed to maximize payments tied to safeguards, the burden will be even greater for these providers. 

With the MACRA roll out in place, there is still time for Covered Entities to have risk assessments conducted. Do not delay — start the process soon to maximize those future payments. 

This blog was previously posted August 10, 2016