Friday, August 20, 2010

The “Red Flags” Rule: What Health Care Providers Need to Know About Complying with New Requirements for Fighting Identity Theft

by Steven Toporoff
As many as nine million Americans have their identities stolen each year. The crime takes many forms. But when identity theft involves health care, the consequences can be particularly severe.

Medical identity theft happens when a person seeks health care using someone else’s name or insurance information. A survey conducted by the Federal Trade Commission (FTC) found that close to 5% of identity theft victims have experienced some form of medical identity theft. Victims may find their benefits exhausted or face potentially life-threatening consequences due to inaccuracies in their medical records. The cost to health care providers — left with unpaid bills racked up by scam artists — can be staggering, too.

The Red Flags Rule, a law the FTC will begin to enforce on August 1, 2009, requires certain businesses and organizations — including many doctors’ offices, hospitals, and other health care providers — to develop a written program to spot the warning signs — or “red flags” — of identity theft. Is your practice covered by the Red Flags Rule? If so, have you developed your Identity Theft Prevention Program to detect, prevent, and minimize the damage that could result from identity theft?

WHO MUST COMPLY

Every health care organization and practice must review its billing and payment procedures to determine if it’s covered by the Red Flags Rule. Whether the law applies to you isn’t based on your status as a health care provider, but rather on whether your activities fall within the law’s definition of two key terms: “creditor” and “covered account.”

Health care providers may be subject to the Rule if they are “creditors.” Although you may not think of your practice as a “creditor” in the traditional sense of a bank or mortgage company, the law defines “creditor” to include any entity that regularly defers payments for goods or services or arranges for the extension of credit. For example, you are a creditor if you regularly bill patients after the completion of services, including for the remainder of medical fees not reimbursed by insurance. Similarly, health care providers who regularly allow patients to set up payment plans after services have been rendered are creditors under the Rule. Health care providers are also considered creditors if they help patients get credit from other sources — for example, if they distribute and process applications for credit accounts tailored to the health care industry.

On the other hand, health care providers who require payment before or at the time of service are not creditors under the Red Flags Rule. In addition, if you accept only direct payment from Medicaid or similar programs where the patient has no responsibility for the fees, you are not a creditor. Simply accepting credit cards as a form of payment at the time of service does not make you a creditor under the Rule.

The second key term — “covered account” — is defined as a consumer account that allows multiple payments or transactions or any other account with a reasonably foreseeable risk of identity theft. The accounts you open and maintain for your patients are generally “covered accounts” under the law. If your organization or practice is a “creditor” with “covered accounts,” you must develop a written Identity Theft Prevention Program to identify and address the red flags that could indicate identity theft in those accounts.

SPOTTING RED FLAGS

The Red Flags Rule gives health care providers flexibility to implement a program that best suits the operation of their organization or practice, as long as it conforms to the Rule’s requirements. Your office may already have a fraud prevention or security program in place that you can use as a starting point.
If you’re covered by the Rule, your program must:

Identify the kinds of red flags that are relevant to your practice;
Explain your process for detecting them;
Describe how you’ll respond to red flags to prevent and mitigate identity theft; and
Spell out how you’ll keep your program current.

What red flags signal identity theft? There’s no standard checklist. Supplement A to the Red Flags Rule — available at ftc.gov/redflagsrule — sets out some examples, but here are a few warning signs that may be relevant to health care providers:

Suspicious documents. Has a new patient given you identification documents that look altered or forged? Is the photograph or physical description on the ID inconsistent with what the patient looks like? Did the patient give you other documentation inconsistent with what he or she has told you — for example, an inconsistent date of birth or a chronic medical condition not mentioned elsewhere? Under the Red Flags Rule, you may need to ask for additional information from that patient.

Suspicious personally identifying information. If a patient gives you information that doesn’t match what you’ve learned from other sources, it may be a red flag of identity theft. For example, if the patient gives you a home address, birth date, or Social Security number that doesn’t match information on file or from the insurer, fraud could be afoot.

Suspicious activities. Is mail returned repeatedly as undeliverable, even though the patient still shows up for appointments? Does a patient complain about receiving a bill for a service that he or she didn’t get? Is there an inconsistency between a physical examination or medical history reported by the patient and the treatment records? These questionable activities may be red flags of identity theft.

Notices from victims of identity theft, law enforcement authorities, insurers, or others suggesting possible identity theft. Have you received word about identity theft from another source? Cooperation is key. Heed warnings from others that identity theft may be ongoing.

SETTING UP YOUR IDENTITY THEFT PREVENTION PROGRAM

Once you’ve identified the red flags that are relevant to your practice, your program should include the procedures you’ve put in place to detect them in your day-to-day operations. Your program also should describe how you plan to prevent and mitigate identity theft. How will you respond when you spot the red flags of identity theft? For example, if the patient provides a photo ID that appears forged or altered, will you request additional documentation? If you’re notified that an identity thief has run up medical bills using another person’s information, how will you ensure that the medical records are not commingled and that the debt is not charged to the victim? Of course, your response will vary depending on the circumstances and the need to accommodate other legal and ethical obligations — for example, laws and professional responsibilities regarding the provision of routine medical and emergency care services. Finally, your program must consider how you’ll keep it current to address new risks and trends.

No matter how good your program looks on paper, the true test is how it works. According to the Red Flags Rule, your program must be approved by your Board of Directors, or if your organization or practice doesn’t have a Board, by a senior employee. The Board or senior employee may oversee the administration of the program, including approving any important changes, or designate a senior employee to take on these duties. Your program should include information about training your staff and provide a way for you to monitor the work of your service providers — for example, those who manage your patient billing or debt collection operations. The key is to make sure that all members of your staff are familiar with the Rule and your new compliance procedures.

WHAT’S AT STAKE

Although there are no criminal penalties for failing to comply with the Rule, violators may be subject to financial penalties. But even more important, compliance with the Red Flags Rule assures your patients that you’re doing your part to fight identity theft.

Looking for more information about the Red Flags Rule? The FTC has published Fighting Fraud with the Red Flags Rule: A How-To Guide for Business, a plain-language handbook on developing an Identity Theft Prevention Program. For a free copy of the Guide and for more information about compliance, visit ftc.gov/redflagsrule.

In addition, the FTC has released a fill-in-the-blank form for businesses and organizations at low risk for identity theft. The online form offers step-by-step instructions for creating your own written Identity Theft Prevention Program. You can fill it out online and print it. The do-it-yourself form is available at ftc.gov/redflagsrule.
Questions about the Rule? Email RedFlags@ftc.gov.
Steven Toporoff is an attorney with the FTC’s Division of Privacy & Identity Protection.

Labels: ,

Friday, May 14, 2010

Sleuthing Your Own Employees


Are you sure your very own employees are not divulging non-public information on social networking sites such as Facebook, Twitter, MySpace or LinkedIn? There are certainly potential issues relating to the appropriateness of social networking while on-the-job (addressed in an earlier article on this blog), but more and more employers have a presence on these trendy sites and in many instances, encourage it. However, there may need to be protections for your business from your very own employees according to a Blogger News Network, April 6, 2010 article on the topic. (http://www.bloggernews.net/124226)
Really -- who needs thieves, when our own employees can be duped by users of crafty social networking sites to share logins and passwords to our company network. The above-referenced article describes one test of such a fact pattern which found nearly half of all the employees tested fell for the demands of a well-crafted, illegitimate duplicate site of their employer’s.
It’s nevertheless hard to put too much blame on the vulnerable employees – the duplicate site looked like very credible outreach from their HR department. And a recent Time Magazine article reported 70% of US HR officers reported utilizing social networking sites to screen employees. (“Social Networking Sites Can Lead to Legal Pitfalls,” http://www.bizjournals.com/dayton/stories/2010/04/05/focus3.html?b=1270440000^3132331) This begs the point that internal policies for any workplace can only help give guidance in this situation.
Because we can’t expect the social networking sites to do our sleuthing for us! As the Blogger News Network story suggests, employers ought best appoint a site administrator to oversee work-related online employee interfacing for the time being. And the best legal defense remains the best offensive strategy and taking extra measures to protect access to company websites and having a corporate policy/training on the topic just makes sense.
Sue B Martines, J.D.

Labels: , , , , , , , , ,

Wednesday, May 05, 2010

Educate Girls and Reduce ID Theft Risk


Arguably , if you better educate anyone about risk, you reduce the potential harm. So why focus on girls? Pick the highest risk group, and generate exponentially greater potential payoff is why. One recent study found women to be 26 percent more likely to be victims of identity theft and fraud than men. (Javelin Strategy & Research’s, 2009 Identity Fraud Survey Report, http://www.mybackgroundcheck.com/blog/post/2009/02/Why-Women-Suffer-More-Identity-Theft-and-Fraud-than-Men.aspx.)
That same study attributes the results to women making purchases more frequently “in-person,” as opposed to online, than men, and to their being three times more likely to report being a victim than men!
In Greg Mortenson’s book Stones Into Schools (the sequel to #1 bestseller Three Cups of Tea), wherein it’s undertaken to build schools for girls in outlying parts of Afghanistan and Pakistan, it’s noted that the education of girls leads to increased income for not only the girls themselves but for their entire nation.
Knowing how identity theft can lead to losing the next most valuable asset after one’s health, it’s really not that far of a cry to see that focusing on girls’ education can not only improve basics like income level and health, but the ability to keep what is so hard gotten, like one’s identiy. Identity theft need not disproportionately impact women in any part of the globe when education can be a potential cure.
Sue B Martines, J.D.

Labels: , , , , , , , ,

Wednesday, February 11, 2009

Employers offering ID Theft Services as a Voluntary Benefit. Finally!!

Below, I share a small portion of a recent article written in Business Insurance Magazine. You will find in this article additional statistics and quotes that backup our findings in "The Silent Crime" in regards to more employers and employees today are seeking identity theft services as a voluntary benefit.
The article also shares a new survey that states more people see identity theft as more then just a financial problem, they actually see it as a legal issue. As our subscribers know we have been trying to educate the consumer for many years of this fact, in our books, on our blog, and in our workshops around the world.
Maybe collectively we are all starting to make a difference.

"Continue to educate the masses one at a time and we will make a difference."
______________________________________________________________
Employers offering ID theft protection as voluntary benefit
KAREN PALLARITO
Legal service plans also becoming more common choices
Reacting to national crime statistics and marketplace demand, many group life insurers and legal service plans are offering identity theft protection as a voluntary employee benefit, experts say.
ID theft protection began turning up in voluntary benefits plans about five years ago. It's typically bundled with other types of coverage or offered as a rider, but it also may be sold as a stand-alone product.


The Society for Human Resource Management's 2008 Employee Benefits Survey showed that 24% of employers offered legal assistance among other voluntary benefits ...

In a soon-to-be-released national consumer survey, 34% of employees cited identity theft as a top personal finance event in which they were personally concerned from a legal standpoint.

"When the economy goes bad, typically we see crime go up," said Michael McCoy, a consultant to Pre-Paid Legal Services Inc. in Des Moines, Iowa, and co-author of "The Silent Crime: What You Need to Know About Identity Theft." The thieves are getting smarter, too, he said. Instead of robbing banks, they're hacking into computers and they're grabbing purses for more than the cash. "You might have a hundred bucks in there, but I just made several thousand from stealing your identity," Mr. McCoy said.

Providers cited prices for employees ranging from lows of $8 to $16 per employee per month to highs of $23 to $26, depending on the employer's size, demographics and range of services in the policy. The higher-priced products often include other legal services, such as will preparation. While most of the business is employee-pay only, some employers share the cost.

full article found at: http://www.businessinsurance.com/cgi-bin/article.pl?article_id=27082
____________________________________________________________________

If you have an article you would like us to share with others or want us to comment on please send me an email at: insurancenow@hotmail.com
Also, if you have written an article and would like us to publish it on our blog or assist you with having it published in your local markets please email me at the above email.

Labels: , , , , , , , , ,

Wednesday, February 04, 2009

The Cost of A Data Breach - www.thesilentcrime.com

In this videocast I discuss with you what the real cost to a business if they fail to secure their customers information. This is done with a videocast, please join me at: WATCH VIDEO BLOG AT ---http://www.youtube.com/watch?v=8-JSV7WbMuE

You can find a copy of the article I discuss in my videocast by clicking on the following link -

http://www.washingtonpost.com/wp-dyn/content/article/2009/02/02/AR2009020203064.html

Thank you for joining me on the video and I will talk with you next week.

Michael McCoy

Labels: , , , , , ,

Thursday, April 03, 2008

New Book: "The Silent Crime"



To order the New Book please use the link to the right titled,
New Book: "The Silent Crime"

Labels: , , ,

Wednesday, November 28, 2007

Is Your iPhone Tracking You?

by: Dr. Steffen Schmidt
As if life were not insecure enough, every day there are new claims that our security and privacy are at risk. The following was posted just hours ago and raises some interesting privacy issues with iphone use. Of course, we have indicated in previous posts (and in our first book “Who is You”) that wireless phones and computing is not secure at all unless encrypted.

“As I sit here applying a new layer of Reynolds tin foil to my international hat of conspiracy, its been proven that Apple tracks iPhone usage and tracks IEMI numbers of all their iPhones worldwide. Hidden in the code of the “Stocks” and “Weather” widgets is a string that sends the IMEI of your phone to a specialized URL that Apple collects.

When the widgets perform a query an IMEI is handed off to Apple’s servers:

dgw?imei=%@&apptype=finance

This let[s] Apple knows which app you are using when connecting with your iPhone. Obviously, they know the IP address you were using, the stocks companies you are interested [in], and so they can track down their customers all around the world. This also proves that there are probably other apps that do the same. Weather.app is also acting the same way. (Offset 13AE0)

Any attempts to modify the URL to exclude the IMEI information will not allow you to retrieve any information in the “Stocks” and “Weather” apps. It is still unknown if any other applications leak information to Apple HQ.

And did you know you actually consented to this gross invasion of privacy?

When you interact with Apple, we may collect personal information relevant to the situation, such as your name, mailing address, phone number, email address, and contact preferences; your credit card information and information about the Apple products you own, such as their serial numbers and date of purchase; and information relating to a support or service issue.

Obviously “Weather” is kinda benign, but Apple knowing your Stock habits, isn’t that a little personal? What’s next, they read your email too? Now who thinks I’m crazy?”


This is posted on the following web site and while we cannot verify the accuracy we will be more careful using our iPhone until this is cleared up.

http://uneasysilence.com/archive/2007/11/12686/
The reality of life in the early 21st century is that we should suspect that most of what we do is being monitored, tracked, scrutinized, and recorded. Hopefully the privacy intruder is relatively benign such as we assume that Apple and iphone folks are,. Unfortunately often it is malignant and dangerous to our personal health, safety and financial protection.

Labels: , , , ,

  • All Material is Copyright © 2009 Michael McCoy and SEAS, L.L.C
  • Deter. Detect. Defend. Avoid ID Theft - www.ftc.gov/idtheft