resourcesABOUT MT AUTHOR GUIDELINES CLASSIFIEDS EDITORIAL CALENDAR MEDIA GUIDE MASSAGE MART SCHOOLS & EDUCATION FEEDBACK
TCM Congress in Rothenburg is Largest in Western World
In the medieval town of Rothenburg, deep set within the Bavarian countryside in Southern Germany, the TCM Kongress Rothenburg each year draws around 1.200 participants from more than 40 different countries to attend the biggest TCM conference in the Western world.
Recreational Cannabis Use and TCM
Many people are drawn to cannabis for its effects physically, mentally and emotionally. Medically, cannabis has some legitimate uses, however the scope of this article is limited to the recreational use of cannabis.
An Excerpt from TCM Case Studies: Pediatrics
This excerpt is reprinted with permission from Jamie Wu. TCM Case Studies: Pediatrics was released in 2014 by People's Medical Publishing House.
Talking to Patients About Lumbar Facet Denervation (Medial Branch Neurotomy)
Lumbar facet denervation, more appropriately termed medial branch neurotomy (MBN), is a procedure that may be considered when patients suffer from recalcitrant non-radicular axial back and/or leg pain.
There Really is No Room for Sexism
Recently, Matteo* (a transgender male) approached me during a break in an advanced shiatsu class in Berlin where he was one of two men in a group of 20 women. "Pamela. Don't forget to remind the translator to include male endings."
Turning a Blind Eye to History – and Reality
The American Medical Association is taking the Supreme Court's Feb. 25, 2015 decision exactly as it always does – by turning a blind eye to history, legal precedent and reality.
Low Back Pain in Professional Golf: A Common Muscular Relationship
Every sport creates its own unique demands on the body. Some sports require such a myriad of body positions that assessing pathology is often difficult and unpredictable.
Synergy Doesn't Happen in Silos: Acupuncture in Hospitals and Other Healthcare Settings
As acupuncture and traditional East Asian medicine continue to intersect and integrate with biomedical approaches, the conversation about integration expands and becomes richer.
Sleep, Less Sleep or No Sleep?
I had a dream I wasn't getting enough sleep. It was a very realistic dream, even though I was probably slightly awake and not really deep dreaming. Most likely I had been dozing, caught in that twilight of sleep and wakefulness.
Applying the Thin Skull Principle
The "thin skull" principle, also known as the "you take your victim as you find them" principle, is a legal principle that can be summed up by the following statement.
Term Limits: What's in a Word?
It was the French historian and philosopher Voltaire who once declared the Holy Roman Empire was neither holy nor Roman nor an empire.
The Way We Are Designed: A Conversation with Gil Hedley, PhD
I was first introduced to the work of Gil Hedley by Tom DiFerdinando. He gifted me Gil's DVD series.
Treating Beyond Pain
More often than not, when a patient presents to the office, it is for a pain complaint. Headache, neck pain, low back pain, sciatica, carpal tunnel... The pain is often the focus of the patient's mindset, and they don't often have any thought of what comes after the pain.
Converting More Patients to Your Practice
In 2013 and 2014, the theme was "the money is in the list." This meant that if you had a big email list, you were really making some "cha-ching." Unfortunately, having thousands of emails doesn't equate to thousands of dollars in profit.
The Need for a New Medical Model: A Challenge for Biopsychosocial and Ecopsychologica Medicine
Chinese medicine speaks of alignment between humans, heaven and earth. It is a complex view with a focus upon relationship. These are comprehensive ideas with no specific terms in contemporary medical practice.
Optimism = Compassion = Trust
A randomized clinical trial recently published online in JAMA Oncology examined how patients viewed their doctor based upon how the practitioner presented bad news to the patient.
Functional Hip Impingement (Part 1)
Every time I sit down to write an article, I realize how much more there is to know about musculoskeletal pain. I also learn something new every time. (I want to give special thanks to Lucy Whyte Ferguson for assisting with this article.)
A View From the ER
The University of Western States has inked an innovative agreement with local nonprofit health system Legacy Health whereby UWS sports-medicine fellows can experience observational clinical rotations in emergency-room settings within the Legacy system.
A House Divided?
The American Chiropractic Association's House of Delegates voted on 30 resolutions at its annual business meeting in Washington D.C., but two in particular took immediate center stage due to their controversial nature.
Will You Be an Amplifer or a Mute?
These times are changing, and changing quickly. There have been many challenges to this profession throughout the past few years. The challenge is to talk, then talk and talk some more about this medicine.
The Dietary Supplement Research Dilemma
I do not care what the truth is, one way or another; I just want to know it. And when it comes to dietary supplements, the truth can be hard to find for a number of reasons.
January, 2003, Vol. 03, Issue 01
Everything You Ever Wanted to Know About HIPAA
An Interview With HIPAA Authority Howard Ross
By Editorial Staff
HIPAA, short for the Health Insurance Portability and Accountability Act, is an important piece of legislation intended to make the American health care system more efficient and productive.Signed into law by President Clinton in 1996, several provisions of HIPAA are just now going into effect, most of them related to insurance, billing procedures, privacy and protection of patient records.
Once fully implemented, HIPAA will have a profound impact on patient information and how it can be accessed and collected. Not only will patients expect providers to protect their privacy, but many third-party payers (such as insurance companies) will require providers to follow HIPAA regulations as part of a standard business agreement. While the idea of hundreds of thousands of health care practitioners suddenly becoming compliant with HIPAA sounds like fantasy, the consequences of not being HIPAA-compliant are quite real; providers can face stiff penalties, including jail sentences and fines of up to $250,000.
What effect will HIPAA have on the massage profession? To get a better understanding of the situation, Massage Today spoke with Howard Ross, a noted health insurance and office management expert.
Massage Today (MT): Many health care practitioners are hearing and talking about HIPAA, but are uncertain about their obligations. Can you give us your background on HIPAA, and your level of authority?
Howard Ross (HR): I have been a health insurance and health management consultant since 1972. For the last three months, I have been working specifically on the issues HIPAA from the standpoint of the management of the practitioner's office relative to HIPAA. My office has been assembling and coordinating all the HIPAA documents available from the public and private sectors, so that we have a decent database of information and briefs.
I'm working with a number of groups, including the Maryland Health Care Commission, which was sanctioned in 1999 as a consortium under a state grant, and also has a contract grant through the Department of Health and Human Services (DHHS) for the assistance and implementation of HIPAA. I'm on the commission's structure committee, which consists of about 30 people.
I'm also on the North Carolina Health Information and Communications Alliance. In both of these relationships, I worked on and assisted in the preparation of the Guide to Privacy Readiness, which was produced by the Maryland Health Care Commission, and a program developed by the Communications Alliance called Early View, which was sold to its member doctors to determine if they were in compliance with policies and procedures.
I'm on a committee of the Workgroup for Electronic Data Interchange (WEDI) out of Virginia, a large consortium of different types of organizations, including insurance companies and electronic data facilities. They are the ones who have created the majority of the work. They are also under a DHHS contract and created the ASCX Electronic Data Interchange standards for claims submission process, and the other eight claims standards that were created by HIPAA. They've also created the Strategic National Implementation Process (SNIP). In a subcommittee of the SNIP, we created a small practice implementation discussion draft (SPIDD), which we have now disseminated over the last month or two to members of SNIP. I'm also on a subcommittee for Georgetown and Columbia universities, which have DHHS grants for implementing HIPAA.
MT: Can you give us a brief overview of HIPAA and its general objective?
HR: HIPAA was passed by Congress in 1996, and was meant to make insurance portable for employees changing jobs. People were losing their health care benefits when going from one employer to another. There needed to be a law to prevent loss of benefits, since each state had a different set of laws on how pre-existing conditions affected new policies. They changed pre-existing condition clauses and created an accountability section. There are four things that a practitioner needs to be concerned about:
MT: What are the really big issues to worry about?
HR: The first two of these provisions (national standards and identifiers) are just going to happen to the practitioner; they [DHHS] have created eight different kinds of national standards for submitting insurance information electronically. These are electronic:
If you do any of these eight things electronically, you qualify as a "covered entity" under HIPAA.
MT: At what level is the health care provider liable when privy to patient information under HIPAA?
HR: Faxing, for example, falls under the security and privacy provision of the act. The cost of administering health care is currently 25 cents on every dollar. When Congress worked on this, it asked, "What are some of the ways we can simplify administration and cut costs?" One solution was a design such that each insurance company doesn't have different claim forms or other qualifications, and no company can request a different claim form, or request to verify eligibility one way as opposed to another. With this plan, they basically standardize the submission process.
MT: For massage therapists to take advantage of this, will they have to be under HIPAA jurisdiction?
HR: You are a covered entity if you utilize any one of the eight standards mentioned earlier. I don't usually worry about things like national HIPAA standards, because once practitioners submit something that is wrong, they will get the claim back unpaid, saying that it doesn't fit in with the correct standards - either that, or you're running a free clinic! Whether it's in paper or electronic form, it won't make a bit of difference to the insurance company.
The national HIPAA standards also include some coding issues. Everybody will use the CPT codebook, the ICD-9 diagnosis codebook and the federal medical devices codebook. Since October 16, practitioners have no longer been able to use what's called a "local code." If they fail to comply with these standards, they will find out real quickly (what the penalties are)!
On national identifiers, every practitioner will be given:
As far as the provision of privacy, this is related to the HIPAA concern over patient rights. You are in control of confidential patient information, and starting April 14, 2003, this privacy law goes into effect. Here is a brief introduction to those rights:
Among the many forms the massage therapist must use is an authorization form that must be signed by the patient any time information is given out about the patient for purposes other than billing. This also applies to insurance companies, attorneys in P.I. cases or anybody dealing with outgoing or incoming patient paperwork (for example, with specific timelines for using the information). There will be a "Request to View Patient Records" form and forms for patients to request and amend those records, as well as those for denial of requests and disagreement of denials.
MT: Can you address some of the things a practitioner might be liable for in an office under HIPAA?
HR: The therapist, whether considered a "covered entity" or not, must maintain privacy, because the privacy issue isn't going to go away. Therapists must make sure they have established policies and procedures, and are training their staff to protect patient privacy. Two examples are computer monitors with patient information on them, or the recent question answered by the DHHS and OCR concerning public sign-in sheets that can state a patient's name, but not a condition. Also, charts and records left on the door of a practitioner's office are permissible, but come with the responsibility of the staff making sure those records are not left in the hands of those unauthorized to see them.
There is also a "chain of trust," which applies to those contracted with a provider to send and receive patient records. Such contractors are covered entities, business associates, and all must meet the same requirements for privacy and security as if they were covered entities.
MT: In other words, if therapists don't comply, they can be denied payment.
HR: That could be one of the outcomes, but I'm not going to say that this is automatic. An insurance company is required under the gigantic federal law to make people business associates. You can rest assured they're not going to pay a therapist who's not a business associate.
MT: So one way or another, the practitioner must comply with the HIPAA privacy provisions.
HR: Yes. The associated business is under the chain of trust contract; even a company such as a janitorial service may have to sign a statement of confidentiality or a chain of trust form.
Let's say you faxed something out, and it went to the wrong person. The patient files a complaint, and it goes to OCR. Representatives come to your office. You show how your equipment proves that the fax went to the right phone number, and that you have authorization on a patient disclosure form to use a fax or e-mail. You have only made a mistake, and you won't be fined or penalized. Without that manual that is specific to you or your office (and if it looks like a "boiler-plated" manual, the OCR and DHHS won't consider it applicable to your office), this complaint could result in a fine or worse. We saw this in the past, when a number of offices copied manuals, and they found that no work was done to make the manual applicable.
MT: It looks as if the practitioners are going to have to go after this proactively.
HR: One important thing to remember about this is that if you read too much into it, it becomes extremely complicated. Once you put into writing what is necessary, you don't have a lot of work to do. If a step-by-step procedure is written, one doesn't have to worry. For the small practitioner, manuals can be less than 100 pages. Requirements for matters such as privacy will just boil down to a simple procedure, involving such things as firewalls to protect computer systems and passwords to protect information. Common sense says that one doesn't have to tear an office up and buy thousands of dollars' worth of equipment.
Many people have asked me about information transmitted through copy machines, fax machines and computers, and we have adopted all these in our practices. Some computer viruses are specifically designed to enter and find patient names and diagnoses. The massage profession doesn't know much about this; it doesn't know about the pharmaceutical companies attempting to obtain names and addresses of patients, and the marketing that goes on in that area. Yet, that is a large issue, and one of the main reasons that HIPAA's privacy and security will go into effect. Your systems are vulnerable; the diagnoses of your patients are vulnerable. Once the diagnosis can be tied to your patient's name and address, you have a problem.
We have more laws protecting credit information than laws protecting patient diagnosis information. Now you're seeing the first law for patient protection. Instead of having patchwork state laws do it, we have a baseline federal law. This is going to be implemented locally, allowing states to individually implement it, with the states' rules generally being tougher than those of HIPAA. An example of this is the time deadline for giving a patient a copy of records, which is five days in California, but 30 days under HIPAA. Of course, the five-day deadline would apply in this case.
MT: What about security issues?
HR: Inside the security provision, the act requires that four issues be addressed:
The last issue is one that many practitioners get really bogged-down in, but as a small practitioner, you have a very limited set of resources that need to be dealt with. There is no specific implementation of security in HIPAA, but I feel that by the end of this year we will see an implementation date for HIPAA security requirements. You really can't have the privacy without the security.
MT: Thank you for the information. We anticipate a large number of responses and questions from your interview. Would you be willing to answer questions from our readers in another article?
HR: I will be glad to answer any questions from your readers, and provide a consortium of others available to readers.
Editor's note: Readers with HIPAA-related questions may submit them to . We will compile your questions, and have Mr. Ross answer them in a future article.
Join the conversation
Comments are encouraged, but you must follow our User Agreementcomments powered by Disqus
Keep it civil and stay on topic. No profanity, vulgar, racist or hateful comments or personal attacks. Anyone who chooses to exercise poor judgement will be blocked. By posting your comment, you agree to allow MPA Media the right to republish your name and comment in additional MPA Media publications without any notification or payment.