 

 |  |  |
An Update on Inter-County's HIPAA Compliance
Electronic Transactions and Code Sets
In July 2002, Inter-County Hospitalization Plan and Inter-County Health Plan (collectively referred to as “Inter-County”) filed a compliance plan with the Department of Health and Human Services (“HHS”) in accordance with the Administrative Simplification Compliance Act. By filing this plan, Inter-County has a one-year extension, until October 16, 2003, for implementing the Electronic Health Care Transactions and Code Sets requirements which are part of HIPAA’s Administrative Simplification regulations.
While Inter-County filed for an extension in its capacity as a Covered Entity, Inter-County is ready to receive and send HIPAA-compliant transactions. We have completed all internal system changes and processes to handle the required electronic transactions and have started external testing of these transactions.
HIPAA is dramatically affecting all health care organizations and will touch most customers and employees of Inter-County. HIPAA regulates many aspects of health care, including access, portability, and renewability requirements when consumers change jobs (“health insurance portability”), and the way patient information is treated (“Administrative Simplification”).
The electronic transactions and code sets provisions of HIPAA were established to:
- Standardize the methods that insurance companies and other health care organizations use when performing electronic transactions, such as the submission of claims; and
- Standardize the code sets used in electronic transactions so, for example, a health care provider will use one code for all claims for a specific procedure.
HIPAA requires that all Covered Entities must be able to perform transactions electronically if requested by another Covered Entity, i.e. a health care provider, a health care clearinghouse, or a health plan, and that transactions must use a standard “HIPAA-compliant” format. Examples of transactions that fall under this regulation include enrollment records, premium payments, and claim submissions. After October 16, 2003, Inter-County will no longer accept or process transactions not in compliance with HIPAA.
Am I a Covered Entity?
Click here to go to CMS’s Covered Entity Decision Tools to find out if an individual, business, or government entity is a Covered Entity.
Identifiers
HIPAA will create unique identifiers to promote uniformity and security in electronic transactions among Covered Entities. Identifiers are classified as: national provider identifier, national employer identifier, and national health plan identifier. The final rule for the National Employer Identification Standard was effective July 30, 2002, and, in general, Covered Entities must be in compliance within 24 months after the effective date. The proposed rule for the National Provider Identifier was issued in May 1998 and has not yet been finalized. A proposed rule on a National Health Plan Identifier is still in development.
Privacy & Security
On August 14, 2002, HHS released modifications to the final HIPAA privacy regulations (the “Privacy Rule”). HHS considered an estimated 60,000 comments before issuing the final Privacy Rule. All Covered Entities (group health plans, providers, and clearinghouses) are required to be compliant with the Privacy Rule by April 14, 2003.
The Privacy Rule protects certain individually identifiable health information, and allows an individual access to his or her medical records, while not creating care and treatment obstacles. It applies to information that is transmitted electronically, orally, or on paper. For the complete regulation, visit www.hhs.gov/ocr/hipaa/finalreg.html.
The proposed HIPAA security regulation was issued in August 1998. It is expected that the final security regulation could be released in early 2003. In general, the compliance date would be 24 months after the effective date of the final regulation.
Inter-County’s Privacy and Security Project Team is reviewing corporate policies and procedures, and the impact of the Privacy Rule and proposed security regulation on how we do business with member, groups, brokers, and other external business entities. The Project Team is also designing a program to train the Inter-County workforce on how the Privacy Rule and proposed security regulation will affect the way they do their jobs. Inter-County is assessing business contracts to identify relationships that will require amendments, and will continue to communicate with entities about the impact of the Privacy Rule and proposed security regulation.
Click here for links to more information about HIPAA
|