Thursday, July 20, 2017
OIG decides to inquire $15B in meaningful use payments
Medicare incentive payments were authorized over a 5-year period to hospitals that adopted electronic health record (EHR) technology. From January 1, 2011, through December 31, 2016, the Centers for Medicare and Medicaid Services made Medicare EHR incentive payments to hospitals totaling $14.6 billion, the OIG stated.
The Government Accountability Office recognized wrong incentive payments as the primary risk to the Medicare EHR incentive program. An OIG report described the obstacles that CMS faces in overseeing the Medicare EHR incentive program. In addition, previous OIG reviews of Medicaid EHR incentive payments found that state agencies overpaid hospitals by $66.7 million and would in the future overpay these hospitals an additional $13.2 million, the OIG claimed.
“These overpayments resulted from inaccuracies in the hospitals’ calculations of total incentive payments,” the OIG said. “We will review the hospitals’ incentive payment calculations to identify potential overpayments that the hospitals would have received as a result of the inaccuracies.”
On another front, the OIG will be analyzing the precision of telemedicine payments under Medicare.
Medicare Part B covers expenses for telehealth services on the telehealth list when those services are delivered via an interactive telecommunications system, provided few conditions are met. To support rural access to care, Medicare pays for telehealth services provided through live, interactive videoconferencing between a beneficiary located at a rural originating site and a practitioner situated at a distant site.
Tuesday, June 27, 2017
Medicaid data not still available for system and oversight
Information from the Transformed Medicaid Statistical Information System (T-MSIS) was supposed to assist ensures the effective administration and oversight of the Medicaid data program, involving enhancing the ability to recognize potential fraud while improving program efficiency.
Although, while the CMS (Centers for Medicare and Medicaid Services) had planned to implement T-MSIS with states on a rolling basis, with the aim of having all states submitting data monthly by July 2014, the OIG notes in its report that early implementation challenges have resulted in delays with T-MSIS.
“These delays were caused by technological issues during data testing and by competing priorities for states' IT resources,” according to the OIG’s audit. “As a result, the goal for when T-MSIS will contain data from all state Medicaid programs has been repeatedly postponed.”
Previous year, the federal government and states spent $574 billion on Medicaid, benefitting more than 74 million enrollees. But, without T-MSIS data, the ability to recognize trends or patterns demonstrating potential fraud, waste, and abuse in the program—as well as stop or mitigate the impact of these activities—is primarily diminished.
However, CMS expects that all states will be reporting to T-MSIS by the end of 2017, auditors reveal that just 21 of 53 state programs were submitting data to T-MSIS as of December 2016, and that it is unclear whether an end-of-the-year target date can be met.
“As states and CMS sustain to work together to submit Medicaid data into T-MSIS, they continue to raise concerns about the completeness and reliability of the data,” the report warns. “Particularly, states indicate that they are unable to report Medicaid data for all the T-MSIS data elements. Furthermore, even with a revised data dictionary that gives definitions for each data element, states and CMS report concerns about states’ varying interpretations of data elements. If states don’t have uniform interpretations of data elements, the data they submit for these elements won’t be consistent across states, making any analysis of national trends or patterns inherently unreliable.”
“Successfully getting all states’ data into T-MSIS needs states and CMS to prioritize T-MSIS implementation,” summarizes the report. “Because of CMS’s history of delaying target dates for execution, OIG is concerned that CMS and states will delay further instead to assign the resources required to deal the outstanding challenges.”
Auditors continue to suggest that CMS develop a deadline for when T-MSIS data will be available for program analysis and other management functions, contending that “without a fixed deadline, some states and CMS may not make the full implementation of T-MSIS a management priority.”
CMS officials weren’t immediately available for comment. However, in its written response to the OIG, the agency reported that since December 2016 more states—40 altogether—have successfully started submitting data to T-MSIS.
Nevertheless, while progress has been made on the number of states submitting data to T-MSIS, CMS concurred with OIG on the requirement for reliable data. In its written comments, the agency highlighted its ongoing work to improve data quality.
Specifically, CMS demonstrated that it has 2 major goals for T-MSIS data quality: transparency for users, and a continuous, ongoing improvement process with states to strengthen the Medicaid data quality. To realize these aims, the agency said it is undertaking a variety of actions, involving information for users on data quality, one-on-one technical assistance to states to ensure their data will be usable, as well as a post-production data quality review with a subset of states to establish an effective working process for improving data quality.
Additionally, CMS informed the OIG that it convened a Technical Evaluation Panel to gain initial feedback on data quality and usability. In accordance with the agency, the panel assessed a subset of T-MSIS data to identify anomalies in the data and potential challenges with using the data for analysis. CMS intends to use the panel’s findings to inform efforts to improve the states’ data quality.
Saturday, March 4, 2017
New scheme seems to use deceptive phone line to get personal information
The OIG hotline accepts tips and complaints about potential scam and mismanagement including HHS programs, which OIG inquires.
Although, HHS now is warning clients that scammers are altering the numbers that appear on caller ID devices; when the criminals call, devices display the HHS hotline phone number (1-800-HHS-TIPS). Victims who receive the calls are at risk for offering the scammers personal information that can be used to raid a bank account or perform other fraudulent activity.
New scheme seems to use deceptive phone line to get personal information.
The OIG affirms that it doesn’t use the hotline number to make outgoing calls; the organization is advising consumers not to answer phone calls that purportedly come from HHS. The agency further is asserting that it remains safe to call the hotline to report fraud or mismanagement, and it specifically motivates those who might have been victimized by the phone call hoax to contact the agency by straightly calling the hotline.
The agency counsels consumers to not provide data over the phone to a person posing as from HHS, like Social Security numbers, dates of birth, credit card numbers, driver license numbers, bank account numbers or mother’s maiden names.
When calling HHS to report fraud, involve date and time you got the phone call and details about the call. People also can file a complaint with the Federal Trade Commission.
Friday, August 19, 2016
OIG: CMS data center wireless systems susceptible
A wireless penetration test of data centers functioned by the Centers for Medicare and Medicaid Services (CMS) have recognized susceptibilities in network security controls.
The testing by the Department of Health and Human Services’ Office of Inspector General was performed at thirteen CMS data centers and services utilizing tools and techniques usually utilized by attackers to acquire unauthorized approach to wireless networks and sensitive information.
“However the Centers for Medicare and Medicaid Services (CMS) had security controls that were effective in stopping few kinds of wireless cyber-attacks, we recognized 3 major susceptibilities in security controls over its wireless systems,” claims an OIG report.
“The susceptibilities that we recognized were collectively and, in few cases, individually significant,” investigators stated. “However we didn’t recognize evidence that the susceptibilities had been exploited, exploitation could have resulted in unauthorized approach to and disclosure of personally identifiable data, as well as disruption of critical operations. Additionally, exploitation could have compromised the confidentiality, integrity, and presence of CMS’s information and wireless systems.”
In accordance to OIG, CMS demonstrated that these vulnerabilities were the outcome of “improper configurations and failure to complete essential upgrades that CMS initially identified and reported as having been presently underway.”
Auditors suggested that CMS should make better its security controls to deal the identified wireless system vulnerabilities. “When executed, these suggestions should further strengthen the data security of CMS’s wireless systems,” adding that “due to the sensitive nature of our findings, we’ve not listed the detailed suggestions in this summary report.”
In its written response to the report, CMS concurred with all of OIG’s findings and claimed that it had already dealt several of the problems and is in the procedure of taking care of the rest. The report points out that CMS commented separately on the more detailed information OIG sent to the organization, which demonstrated that it had accepted the responsibility for resolving the susceptibilities.
Friday, June 3, 2016
Will the DoD EHR Modernization Project Remains on Schedule?
Department of Defense Office of Inspector General earlier this week released an audit report of the EHR modernization that raises doubts about the federal agency's ability to meet the end-of-the-year goal for EHR implementation.
The intention of the audit was to make sure that "had approved system needs for the DoD Healthcare Management System Modernization (DHMSM) program and whether the acquisition strategy was properly approved and documented."
While the IG determined that procedure to have satisfied requirements for identifying its EHR technology needs and the EHR selection process, it expressed doubts about the EHR implementation schedule.
