Compliance & HIPAA in Your Private Practice
The MD Academy · Washington County, OR · 3 wk ago
HealthcareFull-time
Here’s the clean, semantic HTML fragment for the course description:
About the Course
This is a practical, CME-style course designed for physicians and owners running or building an independent practice. It covers the two critical bodies of law governing private practices: federal fraud-and-abuse compliance and HIPAA. Topics include the False Claims Act, Anti-Kickback Statute, Stark Law, billing integrity, compliance program development, HIPAA Privacy/Security/Breach rules, business associates, and enforcement. Note: This is educational content, not legal advice.
Course includes 11 lessons, lifetime access, and a certificate of completion.
Curriculum
-
The Compliance Landscape: Why Compliance Is Existential — and Who's Watching (23 min)
- Learning objectives:
- Explain why compliance is critical for independent practices.
- Identify the four federal enforcers (DOJ, HHS-OIG, CMS, OCR) and their roles.
- Describe the financial and operational risks of non-compliance, including the 7 elements of a compliance program.
- Key takeaway: Compliance is vital for small practices due to enforcement risks. A seven-element compliance program mitigates these risks.
- Learning objectives:
-
The Big Four Fraud & Abuse Laws: False Claims Act, Anti-Kickback, Stark, and the Civil Monetary Penalties Law (23 min)
- Learning objectives:
- Name the four laws and their prohibitions.
- Distinguish intent standards (strict liability vs. knowing vs. specific intent) and civil vs. criminal penalties.
- Identify safe harbors/exceptions and penalties for violations.
- Key takeaway: Intent standards vary by law (e.g., Stark is strict liability; Anti-Kickback requires intent). Violations can trigger multiple laws simultaneously.
- Learning objectives:
-
Stark & Anti-Kickback in Practice: ASCs, Ancillary Services, and Referrals — Structured to Survive a Look (23 min)
- Learning objectives:
- Explain Stark’s self-referral loop and the need for exceptions.
- Name the two most relevant Stark exceptions for groups: group practice and in-office ancillary services.
- Identify AKS safe harbors for surgical practices and the three tests for compliance (fair market value, commercially reasonable, no referral ties).
- Key takeaway: Stark requires exact exceptions; AKS relies on safe harbors. Document arrangements thoroughly.
- Learning objectives:
-
Billing & Coding Compliance: Clean Claims, the 60-Day Rule, and the Audit Ecosystem (23 min)
- Learning objectives:
- Tie claims to medical necessity and supporting documentation.
- Recognize coding traps (upcoding, unbundling, modifier abuse).
- Identify audit contractors (RAC, MAC, UPIC, OIG, CERT) and the 60-day overpayment rule.
- Key takeaway: Clean claims require documentation and adherence to rules. Self-audits and prompt overpayment returns prevent False Claims Act issues.
- Learning objectives:
-
Building a Compliance Program: Operationalizing the 7 OIG Elements — Exclusion Screening and Self-Disclosure (23 min)
- Learning objectives:
- Convert the OIG’s seven elements into a practice-specific checklist.
- Set up exclusion screening (LEIE and SAM.gov) at hire and monthly.
- Understand the OIG Self-Disclosure Protocol and when to use it.
- Key takeaway: A compliance program is a cyclical process (assess, train, monitor, respond). Exclusion screening is mandatory.
- Learning objectives:
-
Reporting & Self-Disclosure: Internal Channels and the Duty to Report (24 min)
- Learning objectives:
- Run internal reports (hotlines, non-retaliation policies, investigations).
- Choose the right disclosure path (60-day rule, OIG SDP, CMS SRDP).
- Understand False Claims Act whistleblower processes and mandatory colleague reporting.
- Key takeaway: Compliance is tested by how you respond to issues. Internal channels and timely disclosures mitigate risks.
- Learning objectives:
-
HIPAA Foundations: The Rules, the PHI, and Who Is Bound (23 min)
- Learning objectives:
- Name the three HIPAA rules (Privacy, Security, Breach Notification) and HITECH’s role.
- Define PHI and its 18 identifiers.
- Distinguish Covered Entities from Business Associates and apply the minimum-necessary principle.
- Key takeaway: HIPAA binds covered entities and business associates. PHI includes health data tied to identifiers. Minimum necessary applies to all disclosures.
- Learning objectives:
-
The HIPAA Privacy Rule: TPO, Patient Rights, the Notice, and When You Need a Signed Authorization (23 min)
- Learning objectives:
- Explain disclosures allowed under Treatment, Payment, and Operations (TPO).
- List patient rights (e.g., access deadlines) and when authorizations are required.
- Apply minimum-necessary at the front desk.
- Key takeaway: TPO disclosures don’t require authorization, but minimum necessary still applies. Patient rights (e.g., 30-day access) must be honored.
- Learning objectives:
-
The HIPAA Security Rule: Protecting Electronic PHI — Safeguards, the Risk Analysis, and Practical Controls (23 min)
- Learning objectives:
- Name the three safeguard categories (Administrative, Physical, Technical).
- Explain "Required" vs. "Addressable" specifications.
- Describe the security risk analysis and core technical controls (encryption, MFA, audit logs).
- Key takeaway: Addressable doesn’t mean optional. A documented risk analysis is critical to avoid enforcement actions.
- Learning objectives:
-
Business Associates & Vendors: BAAs, the Subcontractor Chain, Cloud & EHR Vendors, and AI Tools (23 min)
- Learning objectives:
- Determine when a vendor is a Business Associate.
- List required BAA terms and the importance of flow-down clauses.
- Apply the "no BAA, no PHI" rule to cloud, EHR, and AI tools.
- Key takeaway: Business Associates must sign BAAs. Subcontractors require flow-down protections. AI tools handling PHI need BAAs.
- Learning objectives:
-
Breaches, Enforcement (Duration not specified)
Content for this lesson was not provided in the input.