Posted by Mark Brousseau
Beginning Aug. 1, 2009, hospitals and health care providers that extend any sort of credit to their customers - even something as simple as sending a bill at the end of the month - will need to have a documented, board-approved Red Flag compliance strategy in place to help combat medical identity theft.
Grant Thornton, LLP notes that the Red Flags Rule, a component of the Fair and Accurate Credit Transactions (FACT) Act signed into law in December 2003, requires that financial institutions and creditors in a number of industries implement a plan to identify, detect and respond to attempts to use stolen identity information.
"This rule is completely different from policies you have in place to protect sensitive information," says Randy Green, a principal in Grant Thornton LLP's Advisory Services group. "Instead, this regulation is designed to prevent thieves who have somehow acquired another person's identity - via medical records or otherwise - from using it to commit fraud. The rule requires you to identify all of the indicators that might tip you off to possible identity theft, implement appropriate preventive and detective controls, and react appropriately."
While the Rule has been in effect since November 2008, enforcement by the Federal Trade Commission (FTC) will begin Aug. 1 of this year. Initially, the FTC may assess retroactive penalties for violations, require additional compliance reporting from companies and obtain an injunctive compliance order. Further violations could result in a visit to federal district court and a fine of up to $16,000 per individual occurrence of identity theft.
"After Aug. 1, 2009, any occurrence of medical identity theft at your hospital or business exposes you to an FTC investigation," said Green. "We believe that enforcement of this rule will be complaint-driven, and given the staggering number of identity thefts, there will be no shortage of complaints."
"In summary, the Red Flags Rule is likely to become the standard of care that all hospitals and health care providers will need to provide to prevent medical identity theft," concluded Green. "Skipping red flags compliance will expose you to real regulatory, reputational and litigation risks."
How has your organization prepared for the Red Flags Rule?
Showing posts with label Red Flag. Show all posts
Showing posts with label Red Flag. Show all posts
Thursday, July 30, 2009
Wednesday, March 11, 2009
Identity Theft in Healthcare
By Mark Brousseau
As we move closer to the effective date of the FTC’s new Red Flag Rules, identity theft is still a problem in the healthcare industry, Nancy Vickroy, director, healthcare product development and management, TransUnion, LLC, said today at the Seventh National Medical Banking Institute.
Vickroy cited a survey that found medical identity theft accounts for 3 percent of all U.S. identity theft cases each year, and represents an estimated cost of $468,000 annually. She also pointed to a recent study from the Identity Theft Resource Center finding that 13 of the 100 breaches reported this year involved a medical provider or insurance company, and could have impacted 98,000 people.
Vickroy offered attendees some tips for developing an identity theft prevention program:
… Choose red flags that make sense in your environment
… Identify departments that interact with individuals with covered accounts
… Determine types of information gathered and how it is verified
… Develop procedures to detect red flags during the life of the account
… Implement identity verification at every step
… Integrate automate solutions to ensure standardized verification processes
… Train staff in policies, procedures and responses to ensure consistent patient experience
… Develop procedures for triggered red flag accounts for exception handling
… Periodically evaluate for effectiveness and modify as needed
… Track down known incidents of identity theft that occurred despite the program and monitor trends
… Use data to make meaningful modifications over time
What do you think? Post your comments below.
As we move closer to the effective date of the FTC’s new Red Flag Rules, identity theft is still a problem in the healthcare industry, Nancy Vickroy, director, healthcare product development and management, TransUnion, LLC, said today at the Seventh National Medical Banking Institute.
Vickroy cited a survey that found medical identity theft accounts for 3 percent of all U.S. identity theft cases each year, and represents an estimated cost of $468,000 annually. She also pointed to a recent study from the Identity Theft Resource Center finding that 13 of the 100 breaches reported this year involved a medical provider or insurance company, and could have impacted 98,000 people.
Vickroy offered attendees some tips for developing an identity theft prevention program:
… Choose red flags that make sense in your environment
… Identify departments that interact with individuals with covered accounts
… Determine types of information gathered and how it is verified
… Develop procedures to detect red flags during the life of the account
… Implement identity verification at every step
… Integrate automate solutions to ensure standardized verification processes
… Train staff in policies, procedures and responses to ensure consistent patient experience
… Develop procedures for triggered red flag accounts for exception handling
… Periodically evaluate for effectiveness and modify as needed
… Track down known incidents of identity theft that occurred despite the program and monitor trends
… Use data to make meaningful modifications over time
What do you think? Post your comments below.
Sunday, December 21, 2008
2009: A Year of Risk and Reward
By Mark Brousseau
There can be no question that 2008 has been a horrific year for business. Yet as bad as this year has been, 2009 is shaping up to be a year of both risk and reward for many forward thinking companies.
That’s according to Rob Haberman (rhaberman@pure-pay.com), senior product manager for Purepay Receivables Automation. Haberman notes that governments worldwide are pouring money into their economies, to kick-start recovery. Savvy companies will be shoring up their balance sheets and preparing for the inevitable upturn, he says.
Haberman shared a few thoughts on some of the process opportunities we will see in 2009.
Manage Your Costs and Your Customers’ Costs
Leveraging technology to reduce costs will be a major issue in 2009, Haberman says. Stripping waste out of your balance sheet and your customer’s balance sheet will be a key element for survival. One example is the use of remote deposit and capture.
With this, customers use small low-cost scanners to balance and transmit invoice coupons and cheques to your in-house remittance system, Haberman notes. Your customers reduce the need to manage and transport paper checks. On the other hand, you have the ability to scale your operations to meet demand variances, without major expense or disruptions. There is also the possibility for per-transaction revenue. Equally important, since transport and processing time is reduced, funds are available far sooner, Haberman explains.
Waving the Red Flag – Stopping Fraud
Fraud through identity theft has become a major issue and resource drain for many companies in 2008. In November of 2008, the US Government enacted a series of regulations, referred to as the “Red Flag Rules”. In May 2009, these rules will be fully enforced by the FTC, as well as federal and state financial regulators. These regulations are designed to make financial institutions and creditors more accountable, in protecting their customers against identity theft.
In the least, these rules are complex, requiring a wide range of companies to have written identity theft prevention programs. The penalties for not complying are considerable and avoidable, Haberman says. While there is no substitute for a fully developed program, creative use of existing remittance automation technologies can be valuable first line of defence.
As an example, hot file systems can be set up to flag suspicious names and addresses, for further investigation. Implementing this is a cost effective way to filter out fraudsters, while avoiding a corresponding growth in personnel, Haberman says.
Reworking Workflows
For remittance processors, workflow is everything. In too many cases, remittance automation systems have been added on to the current workflow, without consideration as to how to best leverage this technology. When the economy was strong, this was not an important issue, Haberman notes. However, in 2009, Haberman expects to see a revolution in work process.
Companies will be taking a long hard, look at how checks and invoices are handled and whether the old workflows are making the best use of current technology. We anticipate that many processors with find considerable savings by making common sense revisions to their environments.
In some cases this may require a simple tweak, in other cases an investment in new technology may be in order, Haberman concludes.
There is an old saw that states “In chaos, there is opportunity”. There is no question that 2009 will be a chaotic year, Haberman admits. However, we believe that sometime next year a corner will be turned and the recovery will begin. Those who have prepared for this recovery will reap rewards for years to come, he says.
What do you think? Post your comments below.
There can be no question that 2008 has been a horrific year for business. Yet as bad as this year has been, 2009 is shaping up to be a year of both risk and reward for many forward thinking companies.
That’s according to Rob Haberman (rhaberman@pure-pay.com), senior product manager for Purepay Receivables Automation. Haberman notes that governments worldwide are pouring money into their economies, to kick-start recovery. Savvy companies will be shoring up their balance sheets and preparing for the inevitable upturn, he says.
Haberman shared a few thoughts on some of the process opportunities we will see in 2009.
Manage Your Costs and Your Customers’ Costs
Leveraging technology to reduce costs will be a major issue in 2009, Haberman says. Stripping waste out of your balance sheet and your customer’s balance sheet will be a key element for survival. One example is the use of remote deposit and capture.
With this, customers use small low-cost scanners to balance and transmit invoice coupons and cheques to your in-house remittance system, Haberman notes. Your customers reduce the need to manage and transport paper checks. On the other hand, you have the ability to scale your operations to meet demand variances, without major expense or disruptions. There is also the possibility for per-transaction revenue. Equally important, since transport and processing time is reduced, funds are available far sooner, Haberman explains.
Waving the Red Flag – Stopping Fraud
Fraud through identity theft has become a major issue and resource drain for many companies in 2008. In November of 2008, the US Government enacted a series of regulations, referred to as the “Red Flag Rules”. In May 2009, these rules will be fully enforced by the FTC, as well as federal and state financial regulators. These regulations are designed to make financial institutions and creditors more accountable, in protecting their customers against identity theft.
In the least, these rules are complex, requiring a wide range of companies to have written identity theft prevention programs. The penalties for not complying are considerable and avoidable, Haberman says. While there is no substitute for a fully developed program, creative use of existing remittance automation technologies can be valuable first line of defence.
As an example, hot file systems can be set up to flag suspicious names and addresses, for further investigation. Implementing this is a cost effective way to filter out fraudsters, while avoiding a corresponding growth in personnel, Haberman says.
Reworking Workflows
For remittance processors, workflow is everything. In too many cases, remittance automation systems have been added on to the current workflow, without consideration as to how to best leverage this technology. When the economy was strong, this was not an important issue, Haberman notes. However, in 2009, Haberman expects to see a revolution in work process.
Companies will be taking a long hard, look at how checks and invoices are handled and whether the old workflows are making the best use of current technology. We anticipate that many processors with find considerable savings by making common sense revisions to their environments.
In some cases this may require a simple tweak, in other cases an investment in new technology may be in order, Haberman concludes.
There is an old saw that states “In chaos, there is opportunity”. There is no question that 2009 will be a chaotic year, Haberman admits. However, we believe that sometime next year a corner will be turned and the recovery will begin. Those who have prepared for this recovery will reap rewards for years to come, he says.
What do you think? Post your comments below.
Subscribe to:
Posts (Atom)