<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>HIPAA.com &#187; Red Flags Rules</title>
	<atom:link href="http://www.hipaa.com/category/red-flags-rules/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.hipaa.com</link>
	<description>Know your 5010 from your ICD-10</description>
	<lastBuildDate>Fri, 30 Jul 2010 16:22:02 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.4</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>FTC Delays Enforcement of FTC Red Flags Rule Fifth Time</title>
		<link>http://www.hipaa.com/2010/06/ftc-delays-enforcement-of-ftc-red-flags-rule-fifth-time/</link>
		<comments>http://www.hipaa.com/2010/06/ftc-delays-enforcement-of-ftc-red-flags-rule-fifth-time/#comments</comments>
		<pubDate>Thu, 03 Jun 2010 13:50:33 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Enforcement]]></category>
		<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[American Medical Association]]></category>
		<category><![CDATA[American Osteopathic Association]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[Congress]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[deadline]]></category>
		<category><![CDATA[defer payments]]></category>
		<category><![CDATA[delay]]></category>
		<category><![CDATA[doctor-patient relationship]]></category>
		<category><![CDATA[effective date]]></category>
		<category><![CDATA[Enforcement Policy Statement]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[H.R. 3763]]></category>
		<category><![CDATA[ID theft]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[lawsuit]]></category>
		<category><![CDATA[legislation]]></category>
		<category><![CDATA[Medical Society of the District of Columbia]]></category>
		<category><![CDATA[patient care]]></category>
		<category><![CDATA[physicians]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[S.3416]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=2210</guid>
		<description><![CDATA[The original FTC Red Flags Rule compliance date deadline was extended three times from the original date of November 1, 2008, with an expected compliance date of November 1, 2009.  Just prior to that date, the FTC extended for the fourth time the deadline for compliance to June 1, 2010.  On May 28, 2010, the June 1, 2010, compliance date was extended a fifth time to December 31, 2010.]]></description>
			<content:encoded><![CDATA[<p>The original FTC Red Flags Rule compliance date deadline was extended three times from the original date of November 1, 2008, with an expected compliance date of November 1, 2009.  Just prior to that date, the FTC extended for the fourth time the deadline for compliance to June 1, 2010.  On May 28, 2010, the June 1, 2010, compliance date was extended a fifth time to December 31, 2010<a href="#_ftn1">[1]</a>:</p>
<p>“At the request of several Members of Congress, the Federal Trade Commission is further delaying enforcement of the ‘Red Flags’ Rule through December 31, 2010, while Congress considers legislation that would affect the scope of entities covered by the Rule.  Today’s announcement and the release of an Enforcement Policy Statement do not affect other federal agencies’ enforcement of the original November 1, 2008 deadline for institutions subject to their oversight to be in compliance….</p>
<p>“The Commission urges Congress to act quickly to pass legislation that will resolve any questions as to which entities are covered by the Rule and obviate the need for further enforcement delays.  If Congress passes legislation limiting the scope of the Red Flags Rule with an effective date earlier than December 31, 2010, the Commission will begin enforcement as of that effective date.”</p>
<p>The issue regarding the delays in FTC enforcement relates to “scope of entities covered by the Rule,” as indicated in the FTC news release.  Congress is taking action<a href="#_ftn2">[2]</a>:</p>
<p>“House lawmakers in October [2009] passed H.R. 3763<a href="#_ftn3">[3]</a>, which would exclude from the Red Flags guidelines meaning of ‘creditor’ any healthcare, accounting, or legal practice with 20 or fewer employees, as well as any other business which the FTC determines knows all its customers or clients individually; only performs services in or around the residences of its customers; or hasn’t experienced incidents of ID theft, and identity theft is rare for businesses of that type.  An identical bill, S.3416 was introduced in the Senate on May 25 [2010].”</p>
<p>A lawsuit was filed in federal court on May 21, 2010, to accomplish a similar objective of narrowing scope of entities covered by the Rule.  “[T]he American Medical Association, American Osteopathic Association and the Medical Society of the District of Columbia filed a lawsuit in federal court  challenging the decision to classify physicians as ‘creditors’ because they allow patients to defer payments.  The medical groups also said the implementation of the Red Flags Rule could threaten doctor-patient relationships and negatively affect patient care (Sorrel, <em>American Medical News</em>, 5/31).”<a href="#_ftn4">[4]</a></p>
<p>Please visit the FTC Red Flags Rule Web site: <a href="http://www.ftc.gov/redflagsrule">http://www.ftc.gov/redflagsrule</a> or the American Medical Association (AMA) Web site: <a href="http://www.ama-assn.org/ama/no-index/physician-resources/red-flags-rule.shtml">http://www.ama-assn.org/ama/no-index/physician-resources/red-flags-rule.shtml</a> for additional information. (20100603)</p>
<hr size="1" /><a href="#_ftnref">[1]</a> Federal Trade Commission, “FTC Extends Enforcement Deadline for Identity Theft Red Flags Rules,” news release, May 28, 2010, which is available online at:  <a href="http://www.ftc.gov/opa/2010/05/redflags.shtm">http://www.ftc.gov/opa/2010/05/redflags.shtm</a>.</p>
<p><a href="#_ftnref">[2]</a> Melissa Klein Aguilar, “Another Delay for FTC Red Flags Enforcement,” in <em>Compliance Week</em>, June 1, 2010, which is available online at: <a href="http://www.complianceweek.com/blog/aguilar/2010/06/01/once-again-ftc-delays-red-flags-enforcement/">http://www.complianceweek.com/blog/aguilar/2010/06/01/once-again-ftc-delays-red-flags-enforcement/</a>.</p>
<p><a href="#_ftnref">[3]</a> The House passed H.R. 3763 by a vote of 400-0.</p>
<p><a href="#_ftnref">[4]</a> California HealthCare Foundation, “FTC Delays Enforcement of ‘Red Flags Rule’ Until End of 2010,” <strong><em>iHealth</em></strong><em>Beat</em>, June 1, 2010, which is available online at: <a href="http://www.ihealthbeat.org/articles/2010/6/1/ftc-delays-enforcement-of-red-flags-rule-until-end-of-2010.aspx">http://www.ihealthbeat.org/articles/2010/6/1/ftc-delays-enforcement-of-red-flags-rule-until-end-of-2010.aspx</a>.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2010/06/ftc-delays-enforcement-of-ftc-red-flags-rule-fifth-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC Delays &#8220;Red Flags&#8221; Rule for Third Time</title>
		<link>http://www.hipaa.com/2009/07/ftc-delays-red-flags-rule-for-third-time/</link>
		<comments>http://www.hipaa.com/2009/07/ftc-delays-red-flags-rule-for-third-time/#comments</comments>
		<pubDate>Wed, 29 Jul 2009 19:18:15 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[August 1]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[dleayed payment plans]]></category>
		<category><![CDATA[Fair and Accurate Credit Transaction Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[identity theft prevention]]></category>
		<category><![CDATA[November 1]]></category>
		<category><![CDATA[policies and procedures]]></category>
		<category><![CDATA[Red Flags Rule]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=1640</guid>
		<description><![CDATA[The Federal Trade Commission announced a third delay for compliance, from August 1, 2009, to November 1, 2009, for compliance with the identity theft prevention red flags rule. The delay is for another three months.  Entities affected are creditors and financial institutions. Healthcare providers that extend delayed payment plans to patients are deemed "creditors" under the red flags rule. ]]></description>
			<content:encoded><![CDATA[<p>The Federal Trade Commission announced a third delay, from August 1, 2009, to November 1, 2009, for compliance with the identity theft prevention <em>red flags </em>rule. The delay is for another three months.  Compliance originally was scheduled for November 1, 2008, then delayed the first time until May 1, 2009.  Entities affected are creditors and financial institutions. Healthcare providers that extend delayed payment plans to patients are deemed &#8220;creditors&#8221; under the <em>red flags </em>rule. This delay was to give affected entities more time to develop and implement written identity theft prevention policies and procedures for compliance with the rule, which is based on enabling regulations of provisions in the Fair and Accurate Credit Transactions Act of 2003. You can visit www.ftc.gov/redflagsrule  for additional information. HIPAA.com has outlined provisions of the rule <a href="http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/" target="_self">in an earlier posting</a>, and has <a href="http://www.hipaa.com/2009/04/identity-theft-red-flags-and-address-discrepancies/" target="_self">available for download</a> a copy of FTC&#8217;s &#8220;Fighting Fraud with the Red Flags Rule:  A How-To Guide for Business.&#8221;  Just click on &#8220;Red Flags Rule&#8221; to the right to access this information online.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/07/ftc-delays-red-flags-rule-for-third-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC Delays Identity Theft Prevention Red Flags Rule for Second Time</title>
		<link>http://www.hipaa.com/2009/05/ftc-delays-identity-theft-prevention-red-flags-rule-for-second-time/</link>
		<comments>http://www.hipaa.com/2009/05/ftc-delays-identity-theft-prevention-red-flags-rule-for-second-time/#comments</comments>
		<pubDate>Tue, 05 May 2009 16:02:41 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[August 1]]></category>
		<category><![CDATA[compliance delay]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[delayed payment plans to patients]]></category>
		<category><![CDATA[Fair and Accurate Credit Transaction Act of 2003]]></category>
		<category><![CDATA[fighting fraud]]></category>
		<category><![CDATA[financial institutions]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[Guide for business]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[policies and procedures]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[second delay]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=1016</guid>
		<description><![CDATA[The Federal Trade Commission announced a second delay on Friday, May 1, 2009, for compliance with the identity theft prevention red flags rule. The delay is for three months, with compliance now scheduled for August 1, 2009. Entities affected are creditors and financial institutions. Healthcare providers that extend delayed payment plans to patients are deemed "creditors" under the red flags rule.]]></description>
			<content:encoded><![CDATA[<p>The Federal Trade Commission announced  a second delay on Friday, May 1, 2009, for compliance with the identity  theft prevention <em>red flags </em>rule. The delay is for three  months, with compliance now scheduled for August 1, 2009. Entities  affected are creditors and financial institutions. Healthcare  providers that extend delayed payment plans to patients are deemed &#8220;creditors&#8221;  under the <em>red flags </em>rule. This delay was to give affected  entities more time to develop and implement written identity theft prevention  policies and procedures for compliance with the rule, which is based  on enabling regulations of provisions in the Fair and Accurate Credit  Transactions Act of 2003. You can visit the <a href="http://www.ftc.gov/redflagsrule" target="_blank">FTC website</a> for additional information. HIPAA.com  has outlined provisions of the rule <a href="http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/" target="_self">in an earlier posting</a>, and has <a href="http://www.hipaa.com/2009/04/identity-theft-red-flags-and-address-discrepancies/" target="_self">available  for download</a> a copy of FTC&#8217;s &#8220;Fighting  Fraud with the Red Flags Rule:  A How-To Guide for Business.&#8221;</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/05/ftc-delays-identity-theft-prevention-red-flags-rule-for-second-time/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Flags Rules Compliance Countdown: Today</title>
		<link>http://www.hipaa.com/2009/05/red-flags-rules-compliance-countdown-today/</link>
		<comments>http://www.hipaa.com/2009/05/red-flags-rules-compliance-countdown-today/#comments</comments>
		<pubDate>Fri, 01 May 2009 13:00:40 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[billing and payment procedures]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[Business Guide]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[covered account]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[detect red flags]]></category>
		<category><![CDATA[Fair and Accurate Credit Transactions Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Four Steps Process]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[HIPAA Administrative Simplification]]></category>
		<category><![CDATA[identify relevant red flags]]></category>
		<category><![CDATA[Identifying information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[October 2008]]></category>
		<category><![CDATA[prevent and mitigate identity theft]]></category>
		<category><![CDATA[Privacy Rule]]></category>
		<category><![CDATA[protected health information]]></category>
		<category><![CDATA[Publication 800-66 Revision 1]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[Security Rule]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[Theft Prevention Program]]></category>
		<category><![CDATA[Toporoff]]></category>
		<category><![CDATA[update your Program]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=966</guid>
		<description><![CDATA[Today is the May 1, 2009 Red Flags Rule compliance deadline. ]]></description>
			<content:encoded><![CDATA[<p><span>The Federal Trade Commission&#8217;s (FTC&#8217;s) red flags rules for financial institutions and creditors to fight identity theft require compliance by most healthcare providers <strong>today</strong>, Friday, May 1, 2009. </span></p>
<p><span>See <a href="http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/" target="_self">this post</a> for more information on how to prepare for today&#8217;s deadline.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/05/red-flags-rules-compliance-countdown-today/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Flags Rules Compliance Countdown: 1 day</title>
		<link>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-1-day/</link>
		<comments>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-1-day/#comments</comments>
		<pubDate>Thu, 30 Apr 2009 13:00:34 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[billing and payment procedures]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[Business Guide]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[covered account]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[detect red flags]]></category>
		<category><![CDATA[Fair and Accurate Credit Transactions Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Four Steps Process]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[HIPAA Administrative Simplification]]></category>
		<category><![CDATA[identify relevant red flags]]></category>
		<category><![CDATA[Identifying information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[October 2008]]></category>
		<category><![CDATA[prevent and mitigate identity theft]]></category>
		<category><![CDATA[Privacy Rule]]></category>
		<category><![CDATA[protected health information]]></category>
		<category><![CDATA[Publication 800-66 Revision 1]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[Security Rule]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[Theft Prevention Program]]></category>
		<category><![CDATA[Toporoff]]></category>
		<category><![CDATA[update your Program]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=963</guid>
		<description><![CDATA[One day left until the May 1, 2009 Red Flags Rule compliance deadline. ]]></description>
			<content:encoded><![CDATA[<p><span>The Federal Trade Commission&#8217;s (FTC&#8217;s) red flags rules for financial institutions and creditors to fight identity theft require compliance by most healthcare providers on Friday, May 1, 2009. </span></p>
<p><span>See <a href="http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/" target="_self">this post</a> for more information on how to prepare for tomorrow&#8217;s deadline.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-1-day/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Flags Rules Compliance Countdown: 2 days</title>
		<link>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-2-days/</link>
		<comments>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-2-days/#comments</comments>
		<pubDate>Wed, 29 Apr 2009 13:00:06 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[billing and payment procedures]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[Business Guide]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[covered account]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[detect red flags]]></category>
		<category><![CDATA[Fair and Accurate Credit Transactions Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Four Steps Process]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[HIPAA Administrative Simplification]]></category>
		<category><![CDATA[identify relevant red flags]]></category>
		<category><![CDATA[Identifying information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[October 2008]]></category>
		<category><![CDATA[prevent and mitigate identity theft]]></category>
		<category><![CDATA[Privacy Rule]]></category>
		<category><![CDATA[protected health information]]></category>
		<category><![CDATA[Publication 800-66 Revision 1]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[Security Rule]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[Theft Prevention Program]]></category>
		<category><![CDATA[Toporoff]]></category>
		<category><![CDATA[update your Program]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=959</guid>
		<description><![CDATA[Two days left until the May 1, 2009 Red Flags Rule compliance deadline. ]]></description>
			<content:encoded><![CDATA[<p><span>The Federal Trade Commission&#8217;s (FTC&#8217;s) red flags rules for financial institutions and creditors to fight identity theft require compliance by most healthcare providers on Friday, May 1, 2009. </span></p>
<p><span>See <a href="http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/" target="_self">this post</a> for more information on how to prepare for Friday&#8217;s deadline.</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-2-days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Red Flags Rules Compliance Countdown: 3 days</title>
		<link>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-3-days/</link>
		<comments>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-3-days/#comments</comments>
		<pubDate>Tue, 28 Apr 2009 13:00:43 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[billing and payment procedures]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[Business Guide]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[covered account]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[detect red flags]]></category>
		<category><![CDATA[Fair and Accurate Credit Transactions Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Four Steps Process]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[HIPAA Administrative Simplification]]></category>
		<category><![CDATA[identify relevant red flags]]></category>
		<category><![CDATA[Identifying information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[October 2008]]></category>
		<category><![CDATA[prevent and mitigate identity theft]]></category>
		<category><![CDATA[Privacy Rule]]></category>
		<category><![CDATA[protected health information]]></category>
		<category><![CDATA[Publication 800-66 Revision 1]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[Security Rule]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[Theft Prevention Program]]></category>
		<category><![CDATA[Toporoff]]></category>
		<category><![CDATA[update your Program]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=957</guid>
		<description><![CDATA[Three days left until the May 1, 2009 Red Flags Rule compliance deadline. ]]></description>
			<content:encoded><![CDATA[<p><span>The Federal Trade Commission&#8217;s (FTC&#8217;s) red flags rules for financial institutions and creditors to fight identity theft require compliance by most healthcare providers on Friday, May 1, 2009. </span></p>
<p><span>See <a href="http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/" target="_self">this post</a> for more information on how to prepare for Friday&#8217;s deadline.<br />
</span></p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/04/red-flags-rules-compliance-countdown-3-days/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>FTC&#8217;s &#8220;Red Flags&#8221; Rule to Prevent Identity Theft Requires Compliance by Healthcare Providers on Friday, May 1, 2009</title>
		<link>http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/</link>
		<comments>http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 17:15:45 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[billing and payment procedures]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[Business Guide]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[covered account]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[detect red flags]]></category>
		<category><![CDATA[Fair and Accurate Credit Transactions Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Four Steps Process]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[HIPAA Administrative Simplification]]></category>
		<category><![CDATA[identify relevant red flags]]></category>
		<category><![CDATA[Identifying information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[October 2008]]></category>
		<category><![CDATA[prevent and mitigate identity theft]]></category>
		<category><![CDATA[Privacy Rule]]></category>
		<category><![CDATA[protected health information]]></category>
		<category><![CDATA[Publication 800-66 Revision 1]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[Security Rule]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[Theft Prevention Program]]></category>
		<category><![CDATA[Toporoff]]></category>
		<category><![CDATA[update your Program]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=936</guid>
		<description><![CDATA[The Federal Trade Commission's (FTC's) "red flags" rules for financial institutions and creditors to fight identity theft require compliance by most healthcare providers on Friday, May 1, 2009. HIPAA.com recommends that healthcare providers examine three documents, which we have available at HIPAA.com, to determine their responsibilities with respect to compliance with the red flag rules]]></description>
			<content:encoded><![CDATA[<p>The Federal Trade Commission&#8217;s (FTC&#8217;s) &#8220;red flags&#8221; rules for financial institutions and creditors to fight identity theft require compliance by most healthcare providers on Friday, May 1, 2009. HIPAA.com recommends that healthcare providers examine three documents, which we have available at HIPAA.com, to determine their responsibilities with respect to compliance with the red flag rules. These documents are:</p>
<p style="padding-left: 30px;"><span><span><span><span><span style="color: #000000;">» </span></span></span></span></span><a href="http://static.hipaa.com/documents/071109redflags.pdf" target="_blank">Identity Theft Red Flag Flags and Address Discrepancies Under the Fair and Accurate Credit Transactions Act of 2003</a>; Final Rule, published in the Federal Register on November 9, 2007. The preamble of the Final Rule, which discusses the purpose, intent, and scope of coverage, appears on pages 63718-63733. Of particular importance are pages 63771-63774, which is the text of the FTC Final Rule.</p>
<p style="padding-left: 30px;"><span><span><span><span><span style="color: #000000;">» </span></span></span></span></span><a href="http://static.hipaa.com/documents/bus23.pdf" target="_blank">Fighting Fraud With the Red Flags Rule: A How-To Guide for Business</a>, published by the FTC in March 2009.* The &#8216;Red Flags&#8217; Rule: What Health Care Providers Need to Know About Complying with New Requirements for Fighting Identity Theft, published by the FTC&#8217;s Steven Toporoff, Attorney, FTC&#8217;s Division of Privacy and Identity Protection, in April 2009.</p>
<p>The following is an excerpt from <a href="http://www.ftc.gov/bcp/edu/pubs/articles/art11.shtm" target="_blank">Toporoff&#8217;s The &#8216;Red Flags&#8217; Rule article</a>, in the section entitled: Who Must Comply, that discusses conditions under which healthcare providers would be covered by the Rule:</p>
<p>&#8220;Every healthcare organization and practice must review its billing and payment procedures to determine if it&#8217;s covered by the Red Flags Rule. Whether the law applies to you isn&#8217;t based on your status as a healthcare provider, but rather on whether your activities fall within the law&#8217;s definition of two key terms: &#8216;creditor&#8217; and &#8216;covered account.&#8217;</p>
<p>&#8220;Healthcare providers may be subject to the Rule if they are &#8216;creditors.&#8217; Although you may not think of your practice as a &#8216;creditor&#8217; in the traditional sense of a bank or mortgage company, the law defines &#8216;creditor&#8217; to include any entity that regularly defers payments for goods or services or arranges for the extension of credit. For example, you are a creditor if you regularly bill patients after the completion of services, including for the remainder of medical fees not reimbursed by insurance. Similarly, healthcare providers who regularly allow patients to set up payment plans after services have been rendered are creditors under the Rule. Healthcare providers are also considered creditors if they help patients get credit from other sources—for example, if they distribute and process applications for credit accounts tailored to the healthcare industry.</p>
<p>&#8220;On the other hand, healthcare providers who require payment before or at the time of service are not creditors under the Red Flags Rule. In addition, if you accept only direct payment from Medicaid or similar programs where the patient has no responsibility for the fees, you are not a creditor. Simply accepting credit cards as a form of payment at the time of service does not make you a creditor under the Rule.</p>
<p>&#8220;The second key term—&#8217;covered account&#8217;—is defined as a consumer account that allows multiple payments or transactions or any other account with a reasonably foreseeable risk of identity theft. The accounts you open and maintain for your patients are generally &#8216;covered accounts&#8217; under the law. If your organization or practice is a &#8216;creditor&#8217; with &#8216;covered accounts,&#8217; you must develop a written identity Theft Prevention Program to identify and address the red flags that could indicate identity theft in those accounts.&#8221;</p>
<p>Now, we refer you to the endnotes in Fighting Fraud With the Red Flags Rule business guide for definitions of identity theft and identifying information:</p>
<p style="padding-left: 30px;"><span><span><span><span><span style="color: #000000;">» </span></span></span></span></span>Identity Theft. &#8220;[A] fraud committed or attempted using the identifying information of another person without authority.<br />
<span><span><span><span><span style="color: #000000;">» </span></span></span></span></span>Identifying Information. &#8220;&#8216;[A]ny name or number that may be used, alone or in conjunction with any other information, top identify a specific person, including any—</p>
<p style="padding-left: 60px;">1. Name, Social Security number, date of birth, official State or government issued driver&#8217;s license or identification number, alien registration number, government passport number, employer or taxpayer identification number;<br />
2. Unique biometric data, such as fingerprint, voice print, retina or iris image, or other unique physical representation;<br />
3. Unique electronic identification umber, address, or routing code; or<br />
4. Telecommunication identifying information or access device (as defined in 18 U.S.C. 1029(e)).&#8217;&#8221;</p>
<p>If you are familiar with the HIPAA Administrative Simplification Privacy and Security Rules, you will note that these identifiers also are pertinent to the definition of protected health information in oral, written, or electronic formats.</p>
<p>Again, we refer you to the Fighting Fraud With the Red Flags Rule business guide for an outline of a Four Step Process for compliance with the red flags rule. These steps, outlined here and in more detail in the business guide, are:</p>
<p style="padding-left: 30px;">1. Identify Relevant Red Flags. Identify the red flags of identity theft you&#8217;re likely to come across in your business.<br />
2. Detect Red Flags. Set up procedures to detect those red flags in your day-to-day operations.<br />
3. Prevent and mitigate identity theft. If you spot the red flags you&#8217;ve identified, respond appropriately to prevent and mitigate the harm done.<br />
4. Update your Program. The risks of identity theft can change rapidly, so it&#8217;s important to keep your Program current and educate your staff.</p>
<p>As a healthcare covered entity, you will note that these steps accord with the risk analysis that a covered entity is required to complete and update periodically as part of the HIPAA Security Rule. As such, for information on conducting a risk analysis, HIPAA.com recommends that you consult the excellent An Introductory Resource Guide for Implementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule, National Institute of Standards and Technology (NIST) Special Publication 800-66 Revision 1 (October 2008), which is available for download on HIPAA.com under &#8220;Security&#8221;.</p>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/04/ftcs-red-flags-rule-to-prevent-identity-theft-requires-compliance-by-healthcare-providers-on-friday-may-1-2009/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Identity Theft Red Flags and Address Discrepancies</title>
		<link>http://www.hipaa.com/2009/04/identity-theft-red-flags-and-address-discrepancies/</link>
		<comments>http://www.hipaa.com/2009/04/identity-theft-red-flags-and-address-discrepancies/#comments</comments>
		<pubDate>Mon, 27 Apr 2009 14:33:26 +0000</pubDate>
		<dc:creator>Ed Jones</dc:creator>
				<category><![CDATA[Red Flags Rules]]></category>
		<category><![CDATA[2009]]></category>
		<category><![CDATA[billing and payment procedures]]></category>
		<category><![CDATA[biometric]]></category>
		<category><![CDATA[Business Guide]]></category>
		<category><![CDATA[compliance]]></category>
		<category><![CDATA[covered account]]></category>
		<category><![CDATA[creditor]]></category>
		<category><![CDATA[creditors]]></category>
		<category><![CDATA[detect red flags]]></category>
		<category><![CDATA[Fair and Accurate Credit Transactions Act of 2003]]></category>
		<category><![CDATA[Federal Trade Commission]]></category>
		<category><![CDATA[Four Steps Process]]></category>
		<category><![CDATA[FTC]]></category>
		<category><![CDATA[healthcare providers]]></category>
		<category><![CDATA[HIPAA Administrative Simplification]]></category>
		<category><![CDATA[identify relevant red flags]]></category>
		<category><![CDATA[Identifying information]]></category>
		<category><![CDATA[Identity Theft]]></category>
		<category><![CDATA[May 1]]></category>
		<category><![CDATA[National Institute of Standards and Technology]]></category>
		<category><![CDATA[NIST]]></category>
		<category><![CDATA[October 2008]]></category>
		<category><![CDATA[prevent and mitigate identity theft]]></category>
		<category><![CDATA[Privacy Rule]]></category>
		<category><![CDATA[protected health information]]></category>
		<category><![CDATA[Publication 800-66 Revision 1]]></category>
		<category><![CDATA[Red Flags Rule]]></category>
		<category><![CDATA[Security Rule]]></category>
		<category><![CDATA[telecommunication]]></category>
		<category><![CDATA[Theft Prevention Program]]></category>
		<category><![CDATA[Toporoff]]></category>
		<category><![CDATA[update your Program]]></category>

		<guid isPermaLink="false">http://www.hipaa.com/?p=943</guid>
		<description><![CDATA[The OCC, Board, FDIC, OTS, NCUA and FTC (the Agencies) are jointly issuing final rules and guidelines implementing section 114 of the Fair and Accurate Credit Transactions Act of 2003 (FACT Act) and final rules implementing section 315 of the FACT Act. The rules implementing section 114 require each financial institution or creditor to develop and implement a written Identity Theft Prevention Program (Program) to detect, prevent, and mitigate identity theft in connection with the opening of certain accounts or certain existing accounts.]]></description>
			<content:encoded><![CDATA[<p><span>DEPARTMENT OF THE TREASURY<br />
12 CFR Part 41, 222, 334, 364, 571 and 717<br />
16 CFR Part 681<br />
Idendity Theft Red Flags and Address Discrepancies Under the Fair and Accurate Credit Transactions Act of 2003<br />
AGENCY: Office of the Secretary, HHS.<br />
ACTION: Joint Final Rules and Guidelines.</span></p>
<ul>
<li><a href="http://static.hipaa.com/documents/071109redflags.pdf" target="_blank"><img src="/wp-content/themes/HIPAA/images/download-icon.gif" border="0" alt="" width="13" height="16" /> Download</a> (Requires <a href="http://get.adobe.com/reader/" target="blank">Acrobat Reader</a>)</li>
</ul>
]]></content:encoded>
			<wfw:commentRss>http://www.hipaa.com/2009/04/identity-theft-red-flags-and-address-discrepancies/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
