Learn more
No work was submitted before the submission deadline. You will not be able to evaluate the work of your peers or receive an evaluation.

Medicare Billing Fraud Reduction ASP

Ñ You are the Director of Security (reporting to the CFO) for HackMeCo subsidiary which HIPAA covered healthcare providers use to examine medical billings and payments for evidence of fraud. All of their billing information flows through you (but you don’t do billing).

Ñ You aren’t collecting this information, so assume that you are not required to adopt PCI (technically, this may not be true, but let’s use that as a baseline assumption)

Ñ You DID have to sign a Business Associate agreement (sample available) to get Protected Health Information (PHI)

 

The Issue of the day

Ñ Nobody is demanding anything, we are operating performing the service we advertise.

Ñ Customers have asked our salespeople if we are PCI compliant. Our salespeople said “Gee, I expect that we are, but I’ll ask”

Ñ The truth is, we are not PCI compliant, nor is there a legal requirement for it

Ñ In a short email, we explained this to the salesperson, who then asked why not (and CCed the CIO and CEO) Not adversarial, just wants a discussion since she sees it as a potential negative.

 

Our Situation

Ñ No legal requirement (remember, PCI is industry based, not legal regulation)

Ñ Even the Payment Card Industry says we don’t have to be compliant

Ñ We have billing data from our clients regarding health care billing, which includes HIPAA protected data as well as credit card info and billing histories

Ñ You suspect the sales person asking for this is the one stealing your lunch out of the fridge

 

Choose Your Response

Ñ So far, it’s just an email conversation – but the CIO has called for a meeting of the COO, CIO, Director of Marketing, Director of Operations, You and the Salesperson to discuss.

Ñ The CFO (your boss) has asked that you research the topic and present your findings to the meeting with your recommendations.

Ñ Draft an outline of your presentation to the management team

 

Suggestions for the assignment

Ñ Remember, just because you are not forced to comply doesn’t mean it’s necessarily a bad idea

Ñ Weigh the benefits and costs of compliance or lack of compliance

Ñ Put a mousetrap in your lunchbox

 

 

Complete the Following

Ñ Research the situation. Provide an analysis of the pros and cons to compliance. (500 words or less)

Ñ Provide a well-supported recommendation on whether the organization should become compliant. (500 words or less)

Research the situation. Provide an analysis of the pros and cons to compliance.

Evaluation/feedback on the above work

Note: this section can only be filled out during the evaluation phase.
Comments regarding this question:
You've written 0 words
Provide a well-supported recommendation on whether the organization should become compliant.

Evaluation/feedback on the above work

Note: this section can only be filled out during the evaluation phase.
Comments regarding this question:
You've written 0 words

Overall evaluation/feedback

Note: this section can only be filled out during the evaluation phase.
How well was the paper written? For example, was the writing clear and easy to follow?
Overall comments:
You've written 0 words