Small Providers May Not Have to Deal With Red Flags Rule
If the bill passes, it would remove a large burden for small facilities to comply, says William M. Miaoulis, CISA, CISM, of Phoenix Health Systems, whose corporate offices are located in Texas, Maryland, and Hawaii.
However, it should not eliminate the need to protect patients' identity.
"Identity theft can certainly occur at organizations of any size and all organizations should take steps to enhance security and minimize the threat of identity theft," Miaoulis says. "Removal of the stringent requirements of the Red Flag Rules for small organizations would remove the burden of meeting the specifics of the rule, but should not eliminate the need for them to consider identity theft prevention."
John C. Parmigiani, MS, BES, president, John C. Parmigiani & Associates, LLC, in Ellicott City, MD, says the bill mirrors HIPAA with small providers with less than 10 people who do not file claims electronically.
"I still believe the major determinant is whether the provider is a 'creditor,' not its size or if it knows everybody that it deals with," Parmigiani says. "Of greater concern is how it is protecting the digital information of the patient to whom it extends credit.
Dom Nicastro is a senior managing editor at HCPro, Inc. in Danvers, MA. He edits the Briefings on HIPAA newsletter and manages the HIPAA Update Blog. E-mail him at dnicastro@hcpro.com.

- CMS Reveals Central Line Infection Rates, Finally
- Keeping Readmission Rates Low with Treatment Guidelines
- 5010 Logjam Means No Pay for Physicians
- Medicare Physician Payment Rule Factors in GPCI
- Leading Change is Tough from the Back of a Limo
- Feds Release Final Rules on Health Plan Language
- Getting to the Heart of Cardiology Alignment
- Engineering a High-Performance Emergency Department
- UnitedHealth will tie doctors' payments to quality of care
- Parkland Keeping Consultant's Analysis Under Wraps

