Cyberattacks are a growing threat to healthcare organizations.  Ransomware is one form of a cyberattack which can cripple a healthcare provider’s services.  With ransomware, the attacker encrypts the victim’s system or data, holding it hostage until payment is received.  Paying the ransom to restore your system and recover your data is not a good emergency response plan.  What if the attacker demands more ransom?  Think about assessing your preparedness for a cyberattack; has your healthcare organization developed emergency response strategies, assigned a proper response team, conducted exercises, or planned for other health care providers to maintain continuity of care for your patients?

 

Federal regulations at 42 CFR § 485.727require Medicaid providers to  take an all-hazards approach to emergency preparedness planning, including cyberattacks.  In August, MMAC posted information regarding the final rule Emergency Preparedness Requirements for Medicare and Medicaid Participating Providers and Suppliers.  For your convenience, here are links directly related to the cybersecurity information:

 

Homeland Security Threats emergency preparedness general guidance, with downloads, at https://www.cms.gov/Medicare/Provider-Enrollment-and-Certification/SurveyCertEmergPrep/Homeland-Security-Threats.html How to Protect Your Networks from Ransomware: A letter from HHS Secretary Burwell at https://asprtracie.s3.amazonaws.com/documents/burwell-colleague-letter-ransomware-tipsheet.pdf

 

Taking steps to assess, plan for, and respond to a cyberattack will go a long way in warding off this man-made emergency.

Effectively immediately, the Missouri Medicaid Audit and Compliance Unit (MMAC) is changing our policy regarding the enrollment of Federally Qualified Health Centers (FQHCs) and “FQHC look-alikes”.  Previously, MMAC required FQHCs to be enrolled with Medicare before applying for enrollment with MO HealthNet.  Recent analysis determined there is no federal or state requirement for a FQHC to be enrolled with Medicare and Missouri’s policy was not consistent with how other states are enrolling FQHCs in their Medicaid programs.

 

Effective immediately, a FQHC applying for enrollment with MO HealthNet must submit, from among the following, a copy of the current Notice of Grant Award from Public Health Services (PHS): 1) Section 329-Migrant Health Centers, 2) Section 330-Community Health Centers or 3) Section 340-Services to Homeless Individuals.

 

Non-federally funded health centers, which the Secretary of the Department of Health and Human Services has designated as a FQHC (“FQHC look-alikes”), must submit a copy of the letter from PHS designating the facility as an “FQHC look-alike” or as a non-federally funded health center.

 

Non-federally funded health centers that the Secretary of the Department of Health and Human Services determines may, for good cause, qualify through waivers of the PHS requirements, must submit a copy of the letter from PHS designating the facility as an “FQHC look-alike.” Waivers may be granted for up to two (2) years.

 

All other requirements for a provider applying for enrollment with MO HealthNet as a FQHC remain the same.

 

Any questions regarding this change of policy for the enrollment of FQHCs should be directed to the MMAC Provider Enrollment Unit at 573-751-3399 or MMAC.ProvderEnrollment@dss.mo.gov

On November 30, 2017, a new state rule (13 CSR 65-3.050) will be effective for electronic signatures in the MO HealthNet Program.  The new rule establishes the basis on which health care providers and participants under Missouri Title XIX programs may use electronic signatures when validating services rendered and received.

 

As defined in the new rule, an “electronic signature” means  a  computer data compilation of any symbol or series of  symbols  executed,  adopted,  or  authorized by an individual with the intent to be the legally binding equivalent of the individual’s handwritten signature.  The use of biometrics does not constitute an electronic signature; however, biometrics may be used as part of electronic signature verification.  A signature stamp or typing the name of the provider or participant on a form does not constitute an electronic signature.  If a law or regulation requires a signature to be in writing,  an  electronic  signature  shall  satisfy such law for MO HealthNet purposes.

 

Providers are not required to conduct business electronically, but if they choose to do so – they need to comply with the requirements of the new electronic signature rule.  The new rule does not eliminate the requirement for certain Home and Community Based Services (HCBS) providers to utilize telephony/electronic visit verification.

 

All providers are encouraged to review the requirements of the new rule.  There are specific requirements for any electronic signature system, including (but not limited to) the tracking of:  (1) User log-in and log-out dates and times; (2) User identification; (3) Device Identification; (4) Dates and times when records are created, updated, viewed, or modified; and (5) The process of affixing an electronic signature shall require at  least two (2) distinct identification components, such as an identification code and a password.

 

Any questions regarding the proper use of electronic signatures for services that will be billed to MO HealthNet should be directed to Missouri Medicaid Audit & Compliance (MMAC) at 573-751-3399 or MMAC.General@dss.mo.gov