Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Centers for Medicare and Medicaid Services (CMS) just finalized rules to update attachment requirements for sending with insurance claims. The Divas discuss when these rules became final and the specific requirements of these new rules that apply to dental practices.
Resources:
Federal Register - Final Rule Administrative Simplification; Adoption of Standards for Health Care Claims Attachments Transactions and Electronic Signatures https://bit.ly/4m5u5gl
The HIPAA Journal - CMS Releases Final Rule Implementing HIPAA Standards for Health Care Claims Attachments https://bit.ly/4tnblvg
Welcome to the Compliance Divas podcast. I'm Mary Gavoni and I will be the moderator for this episode. And joining me today is our Diva Leslie Canum. The Divas are giving our listeners a heads up about some deadlines for implementation of and compliance with new HIPAA rules for attachments to healthcare claims. This comes under the security rules. And Leslie is going to give us a recap of what are the deadlines and enforcement and everything that we need to know about these new rules. Leslie?
SPEAKER_01
Well, thanks, Mary. According to the HIPAA journal, the final rule, which is called the Administrative Simplification of Standards for Healthcare Claims, Attachments, Transactions, and Electronic Signatures, final rule, was published in the Federal Register on March 24th of this year, 2026. It actually takes place on May 26, 2026. And the new standards apply to all HIPAA-covered entities, which is primarily most of our dental community and dental practices, health plans, healthcare providers, healthcare clearing houses, and compliance with the new standard is actually required by this deadline of May 26, 2028. And while HIPAA-covered entities have two years to ensure compliance, they're encouraged to read and review the final rule and start implementing new standards promptly. A link to the new rule is available in our show notes. And Mary, it's so important whenever there's a new rule that employee training takes place. I just want to emphasize two years goes by pretty quickly, and we want to make sure that our listeners are prepared in advance.
SPEAKER_00
You are so right, Leslie. This is one of those situations where we definitely need to have training updates with the team to know, but we do have a little bit of time. The one thing that is very important about these rules is that it establishes for the very first time standards for healthcare claims attachments under HIPAA. So this could be like radiographs or periodontal charts or images that are sent with claims to a claims clearing house. And although those entities that attach and process the claims are already in existence, we need to make sure as end users that those entities are HIPAA compliant and that we are HIPAA compliant at our end. So we'll be probably ramping up encryption. And another thing about this is that the rule will contain definitions of what attachments are. And in quickly reviewing the rule, it appears that an end user, a provider, will have to enter an electronic signature vouching for the security of the transmission of these documents, which is new. But this rule doesn't apply to prior authorizations. That was in the original standard before it was finalized, but that has been removed. So we don't have to go through extra steps for prior authorizations if we're doing those in the practice. So, Leslie, let's talk about what we're going to do in the future to bring a little bit more information about this. Because our intent today was just put people on notice and let them know that this is coming.
SPEAKER_01
Well, Mary, in future episodes, we hope to be interviewing experts from healthcare clearinghouses and tech experts to give us some additional guidance because it really does get to the edge of the abyss for most dental professionals when it comes to the cyber world and the techie stuff that we have to do. Now, in retrospect, I remember when we used to staple our images or our documentation or narratives to our insurance forms. And it was always so funny, Mary, when we would get a notice back from the insurance company that they didn't receive the document or the image or the x-ray. And sure enough, there would be that little staple mark right on that insurance claim form that we knew we had sent it. So this will hopefully be a way of making sure that that documentation gets to the insurance companies so that they can move forward with payment on claims.
SPEAKER_00
You're so right, Leslie. And thinking back to those days, if the insurance company said that they did not receive that attachment that we know, and like you say, the staple mark was right there, then where in the world did that X-ray go or that attachment go to? And in many cases, dental practices sent their one and only radiographic image. So now that radiographic image is lost forever if there's no identification on it to return it back, which seldom happened to the provider. So as many of these insurance companies now are not even accepting paper claims anymore, and we're trying to make this very seamless with being able to send attachments because we know that those attachments are important for documentation, like a radiograph of a tooth prior to a core buildup that justifies that the core buildup was necessary or a periodontal chart with all kinds of you know, bone depth and mobility and all of that helps to justify the periodontal therapy that's done. So to sort of recap this brief episode, we discussed that there is a new rule from the Center for Medicare and Medicaid Services regarding HIPAA privacy and security for healthcare claims attachments. And we're providing you in this episode with a very high-level view of what these new rules entail. They don't become effective until May of this year, and there's a grace period for implementation of two years. And again, we will be planning future episodes to discuss these rules in much more detail to help our listeners understand what exactly do they need to do, or maybe to help them find out if they're already compliant based on the services that they are using. The compliance divas bring clarity and simplicity to compliance by navigating the regulatory world to keep you on course. You may submit questions by email to support at the compliancedeevas.com. All the resources we mentioned in this episode are in the show notes section of your podcast app. And we invite you to subscribe to the podcast either on our website or from your podcast app so that you never miss an episode and leave us some feedback or a review on your podcast app. Thanks for listening.