Skip to Content

HIPAA, Privacy, and Risk Management

Overview
Garfunkel Wild’s HIPAA, Privacy, and Risk Management Practice Group assists health care providers, insurance plans and their vendors (e.g., Independent Practice Associations, billing and software companies, Health Information Exchanges) in preparing for, and addressing, complex regulatory and operational issues.  Our objective is to assist our clients in implementing programs to avoid government interventions, and to support our clients when surveys, investigations, and settlement demands by federal and state regulatory and accreditation agencies occur. 

HIPAA and Privacy

Information has become the foundation of providing quality health care, and therefore, a significant focus of health care providers and their vendors.  The Health Insurance Portability and Accountability Act of 1996 (HIPAA) as amended by the Health Information Technology for Economic and Clinical Health Act (HITECH) establishes – at a national level – the minimum requirements for protecting and ensuring the availability of patient information.  Other federal and state laws and regulations, however, add additional requirements for certain types of information and technology.  Garfunkel Wild has mastered this ever-changing and complex regulatory landscape and has assisted clients in: 
 
  • Assessing and implementing HIPAA privacy and security compliance plans, including model policies/forms and training in a manner that also includes consideration of state requirements and accreditation standards
  • Responding to breaches of confidentiality of unsecured patient information including patient, federal and state notifications
  • Preparing responses to investigations by the Federal Department of Health and Human Services, Office of Civil Rights (OCR), and similar state agencies;
  • Defending entities in governmental investigations/actions and private causes of action for alleged federal and state privacy violations
  • Identifying appropriate strategies to allow for sharing of patient information for operational purposes (e.g., quality assurance, value based programs, research)
  • Negotiating business associate agreements
  • Implementing procedures to avoid allegations of Information Blocking
  • Responding to federal and state subpoenas and other discovery requests involving protected health and other patient-identifying information

Our HIPAA and Privacy team can assist in addressing all of the challenges of protecting patient information, while allowing for appropriate use and sharing of such information to improve and develop our clients’ health care services.

Risk Management

Health care providers are faced with a plethora of regulatory and litigation concerns; more so than most industries.   Garfunkel Wild has a deep understanding of the risks that our clients face, and assists our clients and their clinical leadership to navigate these regulatory complexities. Our Risk Management team has extensive experience in:
 
  • Preparing plans of correction to address findings identified by the Center for Medicare and Medicaid Services (CMS), state departments of health and the Joint Commission
  • Drafting Medical Staff Bylaws
  • Preparing admission forms and informed consents for operative procedures, off label use of medications and other unique treatment scenarios
  • Providing guidance and counsel to address professional misconduct and abuse reporting situations, as well as internal disciplinary decisions regarding licensed health care professionals
  • Implementing quality assurance and performance improvement programs, including consideration of applicable privileges and immunities
  • Drafting policies and procedures to address regulatory and accreditation requirements
  • Assisting providers across the healthcare spectrum through multifaceted licensure processes (e.g., laboratory permits and CLIA certification, radiology permits, pharmacy licenses, pharmaceutical wholesaler and manufacturing registrations)
  • Providing comprehensive review of regulatory compliance for merger and acquisition transactions

Our Risk Management team is standing by to assist our clients in taking the steps necessary to protect against unintended mishaps, and to address incidents if they occur.