Thursday, June 18, 2009

Red Flags Rule:  Another Delay

 

 

            The April 30, 2009 edition of the Long Term Care Newsletter contained an article regarding the new “Red Flags Rule” being implemented by the Federal Trade Commission (FTC).  The Red Flags Rule will affect nearly half of the healthcare providers in America, and will require written procedures and policies pertaining to identity theft.  The implementation date had previously been extended from November of 2008 until May 1, 2009.  Late on April 30, 2009, after the Long Term Care Newsletter had been mailed, the FTC announced that it was extending the implementation three months from May 1, 2009 to August 1, 2009.  The announcement did not affect other federal agencies’ enforcement of the original November 2008 compliance deadline. 

 

            The FTC explained that it was delaying enforcement of the new “Red Flags Rule” until August 1, 2009 so as to give creditors and financial institutions more time to develop and implement the written identify theft prevention programs, which we described in the April 30, 2009 Long Term Care Newsletter.

 

            Notably, the FTC also indicates that for entities with a low risk of identity theft, such as business that know their customers personally, it will soon release a template to help with compliance. 

 

            The FTC’s explanation further questions whether or not Congress intended to write its rule as broadly as it has been interpreted, and in a very frank statement, the FTC Chairman Leibowitz said that the extension was also designed to give Congress and opportunity to reexamine the issue. 

 

            Long term care clients should continue preparing to implement the Red Flags Rule, and should now be targeting the August 1, 2009 date.  The reprieve is welcome considering many entities had yet to finalize their written program.  Additional information should be reviewed at:  www.ftc.gov/redflagsrule, including the FTC’s templates for “low risk” entities.

 

Tammy Schroeder

Paralegal
  Office: 402-475-7011

Fax: 402-475-8912

tschroeder@knudsenlaw.com

 

 Knudsen, Berkheimer, Richardson & Endacott LLP
 3800 VerMaas Place, Suite 200, Lincoln, NE 68502

 http://www.knudsenlaw.com

 

 

 

 

 

 

 

 

 

 

 

 

 

Tammy Schroeder

Paralegal
  Office: 402-475-7011

Fax: 402-475-8912

tschroeder@knudsenlaw.com

 

 Knudsen, Berkheimer, Richardson & Endacott LLP
 3800 VerMaas Place, Suite 200, Lincoln, NE 68502

 http://www.knudsenlaw.com

 

 

 

 

 

 

 

 

 

 

 

Circular 230 Disclosure:  Pursuant to recently-enacted U.S. Treasury Dept. Regulations, we are now required to advise you that, unless otherwise expressly indicated, any federal tax advice contained in this communication, including attachments and enclosures, is not intended or written to be used, and may not be used, for the purpose of (i) avoiding tax-related penalties under the Internal Revenue Code or (ii) promoting, marketing or recommending to another party any tax-related matters addressed herein.

 

(visit our website: www.knudsenlaw.com)

This electronic message transmission contains information from the law firm of Knudsen, Berkheimer, Richardson & Endacott, LLP which may be confidential or privileged.  DO NOT FORWARD THIS E-MAIL WITHOUT ASSURING PROTECTION OF PRIVILEGED MATERIAL.  If you have questions about forwarding this message, contact us first.  All clients are advised that communication by e-mail may not be secure and may be subject to interception.  The information in this e-mail is intended solely for the use of the individual or entity named above.  If you are not the intended recipient, be aware that any disclosure, copying, distribution or use of the contents of this information is prohibited.  If you have received this electronic transmission in error, please notify us by telephone (402-475-7011) or by electronic mail (postmaster@knudsenlaw.com) immediately.

 

Thursday, May 7, 2009

Nursing Home Transparency Bill Reintroduced

Senators Chuck Grassley (R-IA) and Herb Kohl (D-WI) have decided to give
the Nursing Home Transparency & Improvement Act of 2009 another try at
passing. Their goal with the bill...increase accountability in the
nursing home industry and sort out the network of owners that run many
facilities.

The bill comes out of growing concerns about homes owned by
large private equity firms who often build complex corporate structures
to shield them from liability. Under this legislation nursing homes
would have to name the members of the groups that own them, give the
organizational structures of all affiliated entities and give
information about those involved in the management, operation and
financing

The bill would require a real time system for reporting
staffing information to the US DHHS cutting down on a facility trying to
manipulate its staffing numbers. The CMS website would be able to
provide more information on its Nursing Home Compare website including
the ownership information, staffing data and a standardized complaint
reporting form.

The legislation would also give the government more
enforcement options including flexibility in assessing penalties and
collecting money sooner. It would require facilities to come up with
compliance and ethics plans to prevent civil, criminal and
administrative violations. Facilities would also have to develop
internal quality assurance standards.

The last thing the legislation would do is require HHS to
come up with a national monitoring program to watch over multi-state and
large intrastate nursing home chains.

The goal is more transparency, better enforcement and
improved staff training according to Sen. Grassley. Currently the bill
is pending before the Finance Committee.

Tammy Schroeder

tjs@knudsenlaw.com

www.knudsenlaw.com

Nursing Assistant Regulations Updates

The State of Nebraska has recently revised its Nursing
Assistant Regulations. (For continuity with licensure regulations, they
have also been transferred to the Health Professional and Occupational
Licensure Title of the Nebraska Administrative Code (172 NAC).) The new
regulations pertain primarily to training, approval of training courses,
and the Nursing Assistant Registry. A summary follows.

Nursing assistant training programs must now be approved
through application to the Department (using the Department's form)
outlining the curriculum of the course. The curriculum must be in
compliance with the regulations, including 75 hours of instruction, 16
hours of supervised practical training and focus on the prescribed
topics including at least one hour of instruction on the responsibility
to report suspected abuse or neglect. (The specifics are outlined in
172 NAC 108-003.01.)

The application for approval of a training course must
include the names and authors of all textbooks to be used (including
publisher and edition), or if no textbooks will be used, a list of
written materials that will be used including the source of such
materials. Applicants must specify the specific topic units to be
covered in the course as set forth in the regulations, and the hours to
be spent on each. The method of instruction for each unit has to be
specified (e.g. lecture, demonstration, simulation, slide presentation,
film strip, etc.) as well as a description of the practical training
provided for each unit required by the regulations. Reading
assignments, evaluation methods (written exams, demonstrations,
competency check-off, etc.), an explanation of the grading system to be
used, and other matters must be specified in the application, which must
be submitted by the Executive Director at least 30 days prior to when
the courses are to start.

Once approved, the courses do not require re-approval unless
the course, or the law, are changed. If a nursing assistant training
course is not approved, or such approval is suspended or revoked, the
regulations provide notice and opportunity to be heard for the
applicants. Attendance records are subject to review by the Department
upon request and must be maintained for at least two years from the date
of completion of each course. The nursing assistant training courses
are also subject to on-site periodic review by the Department, and
sponsors must provide written notices to the Department of the dates and
location that a basic course will be held at least five working days
before it is scheduled to begin.

In addition to other requirements, Nursing Assistants have
to successfully complete an approved training course within 120 days of
employment. Interestingly, a Nursing Assistant who becomes a Licensed
Practical Nurse or a Registered Nurse his/her Nursing Assistant
registration become null and void. Subsequently, if the Registered
Nurse or a Licensed Practical Nurse nurse's license is revoked,
suspended, or voluntarily suspended in lieu of discipline, he/she cannot
act as a Nursing Assistant in a nursing home either.

Of course, Nursing Assistants cannot have been convicted of
a crime involving moral perpitude rationally related to his/her
practice, and the Department documents such convictions on its Registry,
making the Nursing Assistant ineligible for employment in a nursing
home. The Department will give written notice of the reasons for the
proposed finding and will place the name on the Registry 30 days after
receipt of the notice unless a hearing is requested. Notably, after a
year has passed from the date the Nursing Assistant was placed on the
Registry, he/she may petition the Department to have the finding
removed.

Nursing homes should become fully conversant with the
training approval program requirements and organize accordingly. For a
copy of the regulations, or to discuss any of the implications, feel
free to contact the Knudsen Law Firm.

Kevin McManaman

krm@knudsenlaw.com

www.knudsenlaw.com

Tuesday, April 28, 2009

Jeanelle Lust to speak at upcoming seminar

Prince Charming has left the building... becoming your own money hero.

June 13, 2009

10:30 am to 3:30 pm

1523 N. 33rd

Lincoln NE

This workshop is designed for women facing the life transition of
divorce or the death of a husband. Despite the swirl of uncertainty that
can sometimes surround you at this time, your life's journey continues.
Some of that uncertainty can be dealing with the financial end of
things. This workshop will help clarify what truly matters to you right
now, right here in this moment of your life. You will discover that you
have the courage and ability to make wise decisions in regards to your
money and how to begin to take action using your natural strengths and
virtues. No matter what you're dealing with financially and emotionally
there is a way to move forward and see all sorts of possibilities.
Attend this workshop and you will:

1. Learn why worry about money is normal and what you can do about it.

2. Discover how to take the easiest course of action when moving towards
your own personal money goals.

3. Discover ways to make decisions about money that are based on what's
truly important to you.

4. Learn how to create a support team that will guarantee your success.

Location:

This workshop will be held at the International Quilt Study Center and
Museum. The Quilt Museum is located on the northwest corner of the
intersection of 33rd and Holdrege Streets. Enter off 33rd Street.
Parking is north of the building (west of the fire station). Parking is
free in the entire lot north of the building (not just those spots
specifically reserved for museum visitors). Jot down your license plate
number to note at the admissions desk. For more information, to find
a map, or to link to the Quilt museum's website go to
www.beamoneyhero.com


MONEY HERO TEAM

Members Kris Thaller, Maria Pruitt, and Jeanelle Lust are dedicated to
empowering women in regards to their life's journey with money. Their
one of a kind interactive workshops acknowledge the incredible journey
women are on while facing life transitions such as getting married,
divorce, the death of a husband, retirement or career change. Each
workshop is a unique blend of life coaching, financial advice and legal
expertise.

Jeanelle Lust is the managing partner at the Knudsen Law Firm where she
practices in general commercial law with an emphasis on litigation.

Maria Pruitt is the District Manager of United First Financial, and is a
Certified Financial Budgeting Coach.

Kris Thaller is Owner of Coaching Dimensions and a Certified Life Coach
and Organizational Coach.

Special Guest Speaker:

Jody Hunke is a Financial Advisor for Smith Barney and a Certified
Divorce Financial Analyst. She works with clients to financially plan
for retirement, college expenses, and wealth management

Registration:

Name____________________________________

Address___________________________________

City _____________________________________

State_____________________________________

Zip______________________________________

Phone____________________________________

Return with check for registration fee to:

Coaching Dimensions, 10200 Weeks Dr., Lincoln, NE 68516

Register on-line at www.beamoneyhero.com.

Credit cards accepted on-line via PayPal

Questions -call 402.890.5741

Early bird registration: $59.95.

After May 31, 2009: $69.95 (no later than June 7, 2009)

Registration fee includes Quilt museum tour and a box lunch

Email jlust@knudsenlaw.com if you have questions.

Jeanelle Lust

Wednesday, April 15, 2009

NSHHRA Update 4-1-09 (use of SSNs)

http://www.knudsenlaw.com/Att_Bio_KRM.htm
http://www.knudsenlaw.com/

Employer Use of Social Security Numbers

Many Nebraska employers are unaware they now have restrictions on the use of social security numbers. See Neb. Rev. Stat. § 48-237.

Under Nebraska law employers may not:

(a) Publicly post or publicly display in any manner more than the last four digits of an employee's social security number, including intentional communication of more than the last four digits of the social security number or otherwise making more than the last four digits of the social security number available to the general public or to an employee's coworkers;

(b) Require an employee to transmit more than the last four digits of his or her social security number of the Internet unless the communication is secure or the information is encrypted;

(c) Require an employee to use more than the last four digits of his or her social security number to access an Internet web site unless a password, unique personal identification number, or other authentication device is also required to access the Internet web site; or

(d) Require an employee to use more than the last four digits of his or her social security number as an employee number for any type of employment-related activity.

Employers may still use more than the last four digits of a social security number for:

(i) Compliance with state or federal laws, rules, or regulations;

(ii) Internal administrative purposes, including provision of more than the last four digits of social security numbers to third parties for such purposes as administration of personnel benefit provisions for the employer and employment screening and staffing; and

(iii) Commercial transactions freely and voluntarily entered into by the employee with the employer for the purchase of goods or services.

However, in using the social security numbers for internal administrative purposes, employers may not use the:

(i) As an identification number for occupational licensing;

(ii) As an identification number for drug-testing purposes except when required by state or federal law;

(iii) As an identification number for company meetings;

(iv) In files with unrestricted access within the company;

(v) In files accessible by any temporary employee unless the temporary employee is bonded or insured under a blanket corporate surety bond or equivalent commercial insurance; and

(vi) For posting any type of company information.

A violation of the statute is guilty of a Class V misdemeanor, and evidence of such a conviction is admissible in a civil trial as evidence of the employer's negligence.

As a consequence of § 48-237, employers are cautioned to only collect, retain and use social security numbers for legitimate purposes. Employer procedures should restrict access to documents containing social security number, and use should be limited as set forth in this law.

Kevin McManaman

krm@knudsenlaw.com

www.knudsenlaw.com

Red Flags Rule

<http://www.knudsenlaw.com/Att_Bio_KRM.htm>
<http://www.knudsenlaw.com/>

The Red Flags Rule

By some estimates, nearly half of the health care providers in America
will soon be in violation of new federal identity theft rules. The
so-called "Red Flags Rule" was developed pursuant to the Fair and
Accurate Credit Transactions (FACT) Act of 2003, under the authority of
the Federal Trade Commission (FTC). See 16 CFR 681 (which can be found
at:
http://ecfr.gpoaccess.gov/cgi/t/text/text-dx?c=ecfr&tpl=/ecfrbrowse/Titl
e16/16cfr681_main_02.tpl
). Many health care providers have still never
heard of the Red Flags Rule, and many others are nevertheless unsure
whether the law applies. Even fewer are ready now to comply. Quick
action may be needed.

Under the rule, financial institutions and other "creditors" with
covered accounts must have implemented written identity theft prevention
programs designed to identify, detect and respond to patterns, practices
or specific activities that could indicate identify theft. The
definition of "creditor" is very broad and can be read to apply to many
healthcare companies (recent AMA challenges to this interpretation
failed - see attached FTC letter). Any entity that provides goods or
services and then later bills for the goods and services is a
"creditor," so incidental bills to patients, private pay, and insurance
claims can all fall under the rule because they often defer payment for
goods or services. As a creditor with covered accounts, health care
providers need to comply.

The FTC issued relatively little pre-implementation guidance
compared to entities that typically regulate health care (such as CMS).
In fact, the FTC delayed enforcement of the Red Flag Rules because of
reports that numerous companies were not even aware they were covered.
Originally, the plan was set to be implemented November 1, 2008 but the
six month delay until May 1, 2008, was put into place to give
non-financial institutions an opportunity to develop a program. Despite
further attempts to delay implementation, May 1, 2009 remains the
deadline for compliance, and fines can range from $2,500.00 to
$11,000.00 per violation. While it is unlikely enforcers will be at
your door on May 2, eventually you will probably be asked to present
your plan, either during an audit or in a courtroom, and in any event it
would be best to present a plan that was at first initially implemented
on time.

A program designed to identify and prevent identity theft must
be in writing, and tailored to the particular institution. The red
flags in the program may include, for example, unusual account activity,
fraud alerts on a consumer report, or attempted use of suspicious
account application documents. When a patient claims they are receiving
a bill for a provider that never served them or even a service that was
never provided, for example, a red flag has likely been raised. The
program must also describe the appropriate responses that would prevent
and/or mitigate the crime and a detailed plan to update the program.
Furthermore, senior employees or the Board of Directors should provide
oversight, staff and training.

In the health care setting, it is possible that existing HIPAA
required mechanisms can satisfy some of the requirements given the
purported FTC "flexibility" of what a written program should be. HIPAA
rules primarily address medical records, however, the Red Flag Rules
also focus on financial matters. Moreover, the Red Flag Rules require
an affirmative attempt by the creditors to respond to evidence of
medical identity theft. A mere document will not due when a written
program is called for, and HIPAA is merely a supplement, not a
substitute for a proper program.

The FTC insists that that Red Flags Rule is flexible and allow creditors
the opportunity to design a program appropriate to their size and
complexity, as well as to the nature of the operations. In some
circumstances, the FTC says, a "simple streamlined" program would be
adequate, such as a requirement of checking a photo identification when
services are sought, and having procedures designed to appropriately
respond if alerted by law enforcement to some identity misuse. Such
procedures might be common-sense. For example, when learning of
identity theft, a creditor should not try to collect the debt from the
person whose identity was stolen, nor reporting the debt to a credit
agency, and medical providers must keep the medical information separate
from the tainted financial information. It must be remembered, however,
the program must be written.

Larger institutions will likely need correspondingly more robust
programs given the larger likelihood of identity theft. Robust programs
for larger institutions may require a privacy committee headed by a
privacy officer, with members chosen from discrete departments
including, for example, representatives from a pharmacy, administration,
nursing, admissions, billing, etc. Formal risk assessments would likely
be needed, along with reporting mechanisms, action plans, formalized
procedures, employee training, oversight and periodic review.

More information can be obtained from the Federal Trade Commission
website, including guidelines that the FTC believes should be helpful in
assisting covered entities in designing their programs. On April 2, the
FTC provided additional guidance on its new Red Flags Rule website
<http://ftc.gov/redflagsrule> , including a new "How To"
<http://ftc.gov/bcp/edu/microsites/redflagsrule/link-to-us.shtm> guide.


Kevin R. McManaman

krm@knudsenlaw.com <mailto:krm@knudsenlaw.com>

Knudsen, Berkheimer, Richardson & Endacott, LLP

3800 VerMaas Place, Suite 200

Lincoln, NE 68502

402/475-7011 (office)

402/475-8912 (fax)

402/440-2982 (cell)

www.knudsenlaw.com