What is an OIG Corporate Integrity Agreement?
An OIG Corporate Integrity Agreement in healthcare is a contract between the Department of Health and Human Services (HHS) Office of Inspector General (OIG) and an organization that has violated a fraud and abuse law, that outlines the future compliance obligations of the organization. The OIG Corporate Integrity Agreement is often part of a civil settlement for violating a fraud and abuse law that prevents the organization from being added to the HHS OIG Exclusions List. HHS OIG investigates cases of potential fraud and misconduct related to HHS programs, operations, and beneficiaries. When violations of a fraud and abuse law (i.e., the False Claims Act, the Stark Law, the Anti-Kickback Statute, etc.) are identified, the HHS OIG has the authority to pursue a criminal prosecution, a civil prosecution, and/or administrative penalties such as license penalties, revocation of billing privileges, or exclusion from Medicare, Medicaid, and other federal health care programs. When a civil prosecution results in a civil monetary penalty (or settlement) AND exclusion from federal health...
Is Ademero HIPAA Compliant?
Content Central by Ademero is HIPAA compliant and organizations in the healthcare sector can use the cloud-based document management system to streamline document-intensive processes and workflows when documents contain Protected Health Information (PHI). Ademero has told us the company is willing to enter into a Business Associate Agreement with HIPAA covered entities and business associates as necessary. What is Content Central? Content Central is an enterprise document management system that works by capturing documents and files from scanners, network folders, and email accounts, and converting them into searchable PDF files. The PDF files can be grouped together according to administrator-defined values and are stored in a secure cloud server for remote retrieval by authorized users. The process can significantly accelerate workflows by eliminating delays attributable to searching for and retrieving documents. Once retrieved, documents can be shared with or among other authorized users via the Content Central platform without using external solutions. Alternatively, Content...
Memorial Mission Hospital Warned of Imminent Loss of Medicare Funding for Noncompliance
The Department of Health and Human Services (HHS) Centers for Medicare and Medicaid Services (CMS) has warned Memorial Mission Hospital in North Carolina that it is at risk of losing Medicare funding as it is not compliant with the Conditions of Participation in Medicare. The CMS wrote to Memorial Mission Hospital and Asheville Surgery Center CEO, Chad Patrick, explaining that in order to receive Medicare funding, hospitals must be in compliance with the regulatory Conditions of Participation as detailed in 42 C.F.R. Part 482. Section 1864. The North Carolina State Survey Agency concluded a complaint survey on December 9, 2023, at Memorial Mission Hospital and Asheville Surgery Center and identified non-compliance with six Conditions of Participation: 42 C.F.R. § 482.12 Governing Body 42 C.F.R. § 482.13 Patient’s Rights 42 C.F.R. § 482.21 Quality Assessment and Performance Improvement Program 42 C.F.R. § 482.23 Nursing Services 42 C.F.R. § 482.27 Laboratory Services 42 C.F.R. § 482.55 Emergency Services Non-compliance has put Memorial Mission Hospital and Asheville Surgery Center...
Malicious Insider Incident at Montefiore Medical Center Results in $4.75 Million HIPAA Penalty
The Department of Health and Human Services (HHS) Office for Civil Rights (OCR) has announced its first financial penalty of the year to resolve alleged violations of the Health Insurance Portability and Accountability Act (HIPAA). Montefiore Medical Center has agreed to settle the investigation and has paid a $4.75 million penalty to resolve the alleged HIPAA violations. With this one penalty, OCR has already exceeded its total collections from its HIPAA enforcement actions in 2023 and this is the largest financial penalty to be imposed by OCR since January 2021’s $5.1 million penalty for Excellus Health Plan. Like the Excellus investigation, OCR uncovered multiple failures to comply with the HIPAA Security Rule; however, the Excellus investigation was in response to a breach of the PHI of 9.35 million individuals. Montefiore Medical Center’s penalty stemmed from a report of a breach of the PHI of 12,517 patients. The scale of a data breach is taken into consideration by OCR when determining an appropriate penalty, but it is the nature of the underlying HIPAA violations that...
Des Moines Orthopaedic Surgeons Notifies Patients About February 2023 Data Breach
Des Moines Orthopaedic Surgeons (DMOS) in Iowa has recently notified 307,864 current and former patients that some of their protected health information (PHI) was exposed in a cyberattack almost a year ago. DMOS explained that the incident occurred on or around February 17, 2023, and allowed an unauthorized third party to access and/or remove files containing the PHI of DMOS patients. DMOS said the breach was due to the failure of one of its vendors. DMOS said it immediately contained the threat and engaged third-party cybersecurity experts to investigate the incident to determine the extent of compromise. According to the notification letters, “DMOS devoted considerable time and effort to assessing the extent and scope of the incident and to determine what information may have been accessible to the unauthorized users.” It took 10 months to determine that patient data was present in the documents and records involved, with PHI exposure not confirmed until December 6, 2023. The types of data involved included names along with one or more of the following: Social Security number,...



