Administrative Simplification: Adoption of a Standard for a Unique Health Plan Identifier; Addition to the National Provider Identifier Requirements; and a Change to the Compliance Date for ICD-10-CM and ICD-10-PCS Medical Data Code Sets

Federal RegisterApr 17, 2012

Ask Donna

What actually matters in this document.

Text

DEPARTMENT OF HEALTH AND HUMAN SERVICES

Office of the Secretary

45 CFR Part 162

[CMS-0040-P]

RIN 0938-AQ13

Administrative Simplification: Adoption of a Standard for a Unique Health Plan Identifier; Addition to the National Provider Identifier Requirements; and a Change to the Compliance Date for ICD-10-CM and ICD-10-PCS Medical Data Code Sets

AGENCY:

Office of the Secretary, HHS.

ACTION:

Proposed rule.

SUMMARY:

This proposed rule would implement section 1104 of the Patient Protection and Affordable Care Act (hereinafter referred to as the Affordable Care Act) by establishing new requirements for administrative transactions that would improve the utility of the existing Health Insurance Portability and Accountability Act of 1996 (HIPAA) transactions and reduce administrative burden and costs. It proposes the adoption of the standard for a national unique health plan identifier (HPID) and requirements or provisions for the implementation of the HPID. This rule also proposes the adoption of a data element that will serve as an other entity identifier (OEID), an identifier for entities that are not health plans, health care providers, or “individuals,” that need to be identified in standard transactions. This proposed rule would also specify the circumstances under which an organization covered health care provider must require certain noncovered individual health care providers who are prescribers to obtain and disclose an NPI. Finally, this rule proposes to change the compliance date for the International Classification of Diseases, 10th Revision, Clinical Modification (ICD-10-CM) for diagnosis coding, including the Official ICD-10-CM Guidelines for Coding and Reporting, and the International Classification of Diseases, 10th Revision, Procedure Coding System (ICD-10-PCS) for inpatient hospital procedure coding, including the Official ICD-10-PCS Guidelines for Coding and Reporting, from October 1, 2013 to October 1, 2014.

DATES:

Comment Date:

To be assured consideration, comments must be received at one of the addresses provided, no later than 5 p.m. on May 17, 2012.

ADDRESSES:

In commenting, please refer to file code CMS-0040-P. Because of staff and resource limitations, we cannot accept comments by facsimile (FAX) transmission.

You may submit comments in one of four ways (please choose only one of the ways listed):

1.

Electronically.

You may submit electronic comments on this regulation to

http://www.regulations.gov.

Follow the “Submit a comment” instructions.

2.

By regular mail.

You may mail written comments to the following address ONLY:

Centers for Medicare & Medicaid Services, Department of Health and Human Services, Attention: CMS-0040-P, P.O. Box 8013, Baltimore, MD 21244-8013.

Please allow sufficient time for mailed comments to be received before the close of the comment period.

3.

By express or overnight mail.

You may send written comments to the following address ONLY:

Centers for Medicare & Medicaid Services, Department of Health and Human Services, Attention: CMS-0040-P, Mail Stop C4-26-05, 7500 Security Boulevard, Baltimore, MD 21244-1850.

4.

By hand or courier.

Alternatively, you may deliver (by hand or courier) your written comments ONLY to the following addresses prior to the close of the comment period:

a. For delivery in Washington, DC—

Centers for Medicare & Medicaid Services, Department of Health and Human Services, Room 445-G, Hubert H. Humphrey Building, 200 Independence Avenue SW., Washington, DC 20201.

(Because access to the interior of the Hubert H. Humphrey Building is not readily available to persons without Federal government identification, commenters are encouraged to leave their comments in the CMS drop slots located in the main lobby of the building. A stamp-in clock is available for persons wishing to retain a proof of filing by stamping in and retaining an extra copy of the comments being filed.)

b. For delivery in Baltimore, MD—

Centers for Medicare & Medicaid Services, Department of Health and Human Services, 7500 Security Boulevard, Baltimore, MD 21244-1850.

If you intend to deliver your comments to the Baltimore address, call telephone number (410) 786-1066 in advance to schedule your arrival with one of our staff members.

Comments erroneously mailed to the addresses indicated as appropriate for hand or courier delivery may be delayed and received after the comment period.

For information on viewing public comments, see the beginning of the

SUPPLEMENTARY INFORMATION

section.

FOR FURTHER INFORMATION CONTACT:

Kari Gaare (410) 786-8612, Matthew Albright (410) 786-2546, and Denise Buenning (410) 786-6711.

SUPPLEMENTARY INFORMATION:

Inspection of Public Comments:

All comments received before the close of the comment period are available for viewing by the public, including any personally identifiable or confidential business information that is included in a comment. We post all comments received before the close of the comment period on the following Web site as soon as possible after they have been received:

http://www.regulations.gov.

Follow the search instructions on that Web site to view public comments.

Comments received timely will also be available for public inspection as they are received, generally beginning approximately 3 weeks after publication of a document, at the headquarters of the Centers for Medicare & Medicaid Services, 7500 Security Boulevard, Baltimore, Maryland 21244, Monday through Friday of each week from 8:30 a.m. to 4 p.m. To schedule an appointment to view public comments, call 1-800-743-3951.

I. Executive Summary and Background

A. Executive Summary

1. Purpose of the Regulatory Action

a. Need for the Regulatory Action

This rule proposes the adoption of a standard unique health plan identifier (HPID) and the adoption of a data element that will serve as an other entity identifier (OEID). This rule also proposes an addition to the National Provider Identifier (NPI) requirements. Finally, this rule proposes to change the compliance date for the ICD-10-CM and ICD-10-PCS medical data code sets (hereinafter “code sets”) from October 1, 2013 to October 1, 2014.

(1) HPID

Currently, health plans and other entities that perform health plan functions, such as third party administrators and clearinghouses, are identified in Health Insurance Portability and Affordability Act of 1996 (HIPAA) standard transactions with multiple identifiers that differ in length and format. Covered health care providers are frustrated by various problems associated with the lack of a

standard identifier, such as: improper routing of transactions; rejected transactions due to insurance identification errors; difficulty in determining patient eligibility; and challenges resulting from errors in identifying the correct health plan during claims processing.

The adoption of the HPID and the OEID will increase standardization within HIPAA standard transactions and provide a platform for other regulatory and industry initiatives. Their adoption will allow for a higher level of automation for health care provider offices, particularly for provider processing of billing and insurance related tasks, eligibility responses from the health plans, and remittance advice that describes health care claim payments.

(2) NPI

In January 2004, the U.S. Department of Health and Human Services (HHS) published a final rule establishing the standard for a unique health identifier for health care providers for use in the health care system and adopting the National Provider Identifier (NPI) as that standard. The rule also established the implementation specifications for obtaining and using the standard unique health identifier for health care providers. Since that time, pharmacies have encountered situations where they need to include the NPI of a prescribing health care provider in a pharmacy claim, but where the prescribing health care provider has been a noncovered health care provider who did not have an NPI because he or she was not required to obtain one. This situation has become particularly problematic in the Medicare Part D program. The proposed addition to the NPI requirements seeks to address this issue.

(3) ICD-10-CM and ICD-10-PCS Code Sets.

On January 16, 2009, HHS published a final rule (74 FR 3328) in which the Secretary of HHS (the Secretary) adopted the ICD-10-CM and ICD-10-PCS (ICD-10) code sets as the HIPAA standards to replace the previously adopted International Classification of Diseases, 9th Revision, Clinical Modification, Volumes 1 and 2, including the Official ICD-9-CM Guidelines for Coding and Reporting (ICD-9-CM Volumes 1 and 2) and the International Classification of Diseases, 9th Revision, Clinical Modification, Volume 3, including the Official ICD-9-CM Guidelines for Coding and Reporting (ICD-9-CM Volume 3) for diagnosis and procedure codes, respectively. The compliance date set by the final rule was October 1, 2013.

Since that time, some provider groups have expressed strong concern about their ability to meet the October 1, 2013 compliance date and the serious claims payment issues that might then ensue. Some providers' concerns about being able to meet the ICD-10 compliance date are based, in part, on difficulties they have had meeting HHS' compliance deadline for the adopted Associated Standard Committee's (ASC) X12 Version 5010 standards (Version 5010) for electronic health care transactions. Compliance with Version 5010 and ICD-10 by all covered entities is essential to a smooth transition to the updated medical data code sets, as the failure of any one industry segment to achieve compliance would negatively impact all other industry segments and result in returned claims and provider payment delays. We believe the change in the compliance date for ICD-10, as proposed in this rule, would give providers and other covered entities more time to prepare and fully test their systems to ensure a smooth and coordinated transition by all industry segments.

b. Legal Authority for the Regulatory Action

(1) HPID

This proposed rule implements section 1104(c) of the Affordable Care Act and section 1173(b)(1) of the Social Security Act (the Act) which require the adoption of a standard unique health plan identifier (HPID).

(2) NPI

This proposed rule would impose an additional requirement on covered organization health care providers under the authority of sections 1173(b)(1) and 1175(b) of the Act. It would also accommodate the needs of certain types of health care providers in the use of the covered transactions, as required by section 1173(a)(3) of the Act.

(3) ICD-10-CM and ICD-10-PCS

This proposed rule would set a new compliance date for the ICD-10 code sets, in accordance with section 1175(b)(2) of the Act, under which the Secretary determines the date by which covered entities must comply with modified standards and implementation specifications.

2. Summary of the Major Provisions

a. HPID

This rule proposes the adoption of the HPID as the standard for the unique identifier for health plans and definitions for “Controlling Health Plan” and “Subhealth Plan.” The proposed definitions of these two terms seek to differentiate between health plan entities that would be required to obtain an HPID, and those that would be eligible, but not required, to obtain an HPID. This rule also proposes to require all covered entities to use an HPID whenever a covered entity identifies a health plan in a covered transaction. Because health plans today have many different business structures and arrangements that affect how health plans are identified in standard transactions, these two proposed definitions also seek to enable health plans to obtain HPIDs to reflect differing business arrangements so they can be identified appropriately in standard transactions.

This rule also proposes the adoption of a data element that would serve as an other entity identifier (OEID). The OEID would serve as an identifier for entities that are not health plans, health care providers, or “individuals” (as defined in 45 CFR 160.103), but that need to be identified in standard transactions (including, for example, third party administrators, transaction vendors, clearinghouses, and other payers). Under this proposed rule, these other entities would not be required to obtain an OEID, but they could obtain and use one if they needed to be identified in covered transactions. Because other entities are identified in standard transactions in a similar manner as health plans, we believe that establishing a data element to serve as an identifier for these entities will increase efficiency by encouraging the use of a uniform identifier.

The most significant benefit of the HPID and the OEID is that they will increase standardization within HIPAA standard transactions by establishing uniform identifiers.

b. NPI

This rule proposes that an organization covered health care provider require certain noncovered individual health care providers who are prescribers to: (1) Obtain NPIs and; (2) to the extent the prescribers write prescriptions while acting within the scope of the prescribers' relationship with the organization, disclose them to any entity that needs the NPIs to identify the prescribers in standard transactions. This addition to the NPI requirements would address the issue that pharmacies are encountering when the NPI of a prescribing health care provider needs to be included on a pharmacy claim, but the prescribing

health care provider does not have, or has not disclosed an NPI.

c. ICD-10-CM and ICD-10-PCS

This rule proposes that the compliance date for ICD-10-CM and ICD-10-PCS be changed from October 1, 2013 to October 1, 2014. We believe this change will give covered entities the additional time needed to synchronize system and business process preparation and changeover to the updated medical data code sets.

3. Costs and Benefits

a. HPID

The HPID is expected to yield the most benefit for providers, while health plans will bear most of the costs. Costs to all commercial and government health plans together (Medicare, Medicaid programs, IHS, VHA) are estimated to be $650 million to $1.3 billion. However, commercial and government health plans are expected to make up those costs in savings. Further, it is our understanding that the industry will not find that the HPID is overly burdensome. Many entities have indicated that they have delayed regular system updates and maintenance, as well as the issuance or adoption of new health plan identification cards, to accommodate the adoption of the HPID.

Health care providers can expect savings from two indirect consequences of HPID implementation: (1) The cost avoidance of decreased administrative time spent by providers interacting with health plans; and (2) a material cost savings through automation of processes for every transaction that moves from manual to electronic implementation. HPID's anticipated 10-year return on investment for the entire health care industry is expected to be between $1 to $4.6 billion. (This estimate includes savings resulting from the foundational effect of the HPID rather than a precise budgetary prediction.)

b. NPI

The addition to the requirements for the NPI would have little impact on health care providers and on the health industry at large because few health care providers do not already have an NPI. In addition, covered organization health care providers may comply by various means. For example, a covered organization could use a simple verbal directive to prescribers whom they employ or contract with to meet the requirements. Alternately, a covered organization could update employment or contracting agreements with the prescribers. For these reasons, we believe the additional NPI requirements do not impose spending costs on State government or the private sector in any 1-year of $136 million or more.

c. Change of Compliance Date of ICD-10

According to a recent survey conducted by CMS, up to one quarter of health care providers believe they will not be ready for the October 1, 2013 compliance date.

1

While the survey found no significant differences among practice settings regarding the likelihood of achieving compliance before the deadline, based on recent industry feedback we believe that larger health care health plans and providers generally are more prepared than smaller entities. The uncertainty about provider readiness is confirmed in another recent readiness survey in which nearly 50 percent of the 2,140 provider respondents did not know when they would complete their impact assessment of the ICD-10 transition.

2

1

“Version 5010 and ICD-10 Readiness Assessment: Conducted among health Care providers, payers and Vendors for the Centers for Medicare & Medicaid Services (CMS), December 2011 (OMB Approval No: 09938-1149). The assessment surveyed 404 providers, 101 payers, and 90 vendors, which represents 0.1% of all physician practices, 3% of hospitals, and 5% of health plans.

2

An impact assessment for ICD-10 is performed by a covered entity to determine business areas, policies, processes and systems, and trading partners that will be affected by the transition to ICD-10. An impact assessment is a tool to aid in planning for implementation. “Survey: ICD-10 Brief Progress,” February 2012, conducted by the Workgroup for Electronic Data Interchange (WEDI).

By delaying the compliance date of ICD-10 from October 1, 2013 to October 1, 2014, we would be allowing more time for covered entities to prepare for the transition to ICD-10 and to conduct thorough testing. By allowing more time to prepare, covered entities may be able to avoid costly obstacles that would otherwise emerge while in production.

Savings would come from the avoidance of costs that would occur as a consequence of significant numbers of providers being unprepared for the transition to ICD-10. In the Regulatory Impact Analysis (RIA) of this proposed rule, we estimate that there would be a cost avoidance of approximately $3.6 to nearly $8 billion in this regard. This range of estimates reflects the avoidance of two costly consequences that may occur should the compliance date remain October 1, 2013: (1) Both health care providers and health plans may have to process health care claims manually in order for claims to be paid; and (2) small health care providers may have to take out loans or apply for lines of credit in order to continue to provide health care in the face of delayed payments.

In terms of costs, commercial health plans, medium and large hospitals, and large physician practices are far along in their ICD-10 implementation planning, and therefore have devoted funds, resources, and staff to the effort. According to our estimates, a 1-year delay of the ICD-10 compliance date would add 10 to 30 percent to the total cost that these entities have already spent or budgeted for the transition—an additional cost to commercial entities of approximately $1 to $6.4 billion. Medicare and State Medicaid Agencies have also reported estimates of costs of a change in the compliance date in recent informal polls. Accordingly, the calculations in the RIA in this proposed rule demonstrate that a 1-year delay in the compliance date of ICD-10 would cost the entire health care industry approximately $1 billion to $6.5 billion.

We assume that the costs and cost avoidance calculated in the RIA will be incurred roughly over a 6- to 12-month period, from October 1, 2013 to October 1, 2014. For simplicity sake, however, both the costs and the cost avoidance that result from a change in the compliance date of ICD-10 are calculated over the calendar year, 2014.

We solicit comments on our assumptions and conclusions as described in the RIA.

B. Introduction

The following discussion presents a partial statutory and regulatory history related only to the statutory provisions and regulations that are relevant for purposes of this proposed rule. For additional statutory background and regulatory history, see the proposed rule entitled “Health Insurance Reform; Modifications to the Health Insurance Portability and Accountability Act (HIPAA) Electronic Transaction Standards,” published in the

Federal Register

on August 22, 2008 (73 FR 49742); “HIPAA Administrative Simplification: Modification to Medical Data Code Set Standards To Adopt ICD-10-CM and ICD-10-PCS: Proposed Rule,” published in the

Federal Register

on August 22, 2008 (73 FR 49796) (hereinafter referred to as the ICD-10 proposed rule); and “HIPAA Administrative Simplification: Modification to Medical Data Code Set Standards To Adopt ICD-10-CM and ICD-10-PCS,” published in the

Federal Register

on January 16, 2009 (74 FR 3328) (hereinafter referred to as the ICD-10 final rule).

The Congress addressed the need for a consistent framework for electronic health care transactions and other administrative simplification issues through the Health Insurance Portability

and Accountability Act of 1996 (HIPAA), (Pub. L. 104-191), enacted on August 21, 1996. HIPAA amended the Act by adding Part C-Administrative Simplification—to Title XI of the Act requiring the Secretary to adopt standards for certain electronic transactions to enable health information to be exchanged more efficiently and to achieve greater uniformity in the transmission of health information exchange.

In the August 17, 2000

Federal Register

(65 FR 50312), we published a final rule entitled “Health Insurance Reform: Standards for Electronic Transactions” (hereinafter referred to as the Transactions and Code Sets final rule). That rule implemented some of the HIPAA Administrative Simplification requirements by adopting standards developed by standard development organizations (SDOs) for certain electronic health care transactions and medical code sets to be used in those transactions. We adopted the Accredited Standards Committee (ASC) X12 standards Version 4010/4010A1 and the National Council for Prescription Drug Programs (NCPDP) Telecommunication standard Version 5.1, which is specified at 45 CFR part 162, subparts K through R. All health plans, health care clearinghouses, and health care providers that transmit health information in electronic form in connection with a covered transaction (referred to as covered entities) are required to comply with these adopted standards.

In the January 16, 2009

Federal Register

(74 FR 3296), we published a final rule entitled, “Health Insurance Reform; Modifications to the Health Insurance Portability and Accountability Act (HIPAA) Electronic Transaction Standards” (the Modifications final rule), that, among other things, adopted updated versions of the standards for the electronic health care transactions for which the Department originally adopted standards in the Transactions and Code Sets final rule. These updated standards for electronic health care transactions included ASC X12 Version 5010 and NCPDP Telecommunication Standard Implementation Guide, Version D. Release 0 (Version D.0), and equivalent Batch Standard Implementation Guide, Version 1, Release 2 (Version 1.2). In the Modifications final rule, the Department also adopted the Medicaid pharmacy subrogation transaction, a new standard—the Batch Standard Medicaid Subrogation Implementation Guide, Version 3, Release 0). Covered entities are required to conduct as standard transactions all electronic transactions for which the Secretary has adopted a standard. From March 17, 2009 through December 31, 2011, covered entities were required to comply either with the ASC X12 Version 4010/4010A1 and NCPDP Telecommunications standard Version 5.1 standards or the updated Version 5010 and NCPDP D.0 standards. Effective January 1, 2012, covered entities were required to comply with Version 5010 and NCPDP D.0, and (except for small health plans) the Version 3.0 standard for Medicaid pharmacy subrogation transactions. Small health plans must comply with Version 3.0 on or after January 1, 2013.

Also on January 16, 2009, we published a final rule entitled “HIPAA Administrative Simplification: Modification to Medical Data Code Set Standards to Adopt ICD-10-CM and ICD-10-PCS” (74 FR 3328). In the ICD-10 final rule, we adopted the International Classification of Diseases, 10th Revision, Clinical Modification (ICD-10-CM), including the Official ICD-10-CM Guidelines for Coding and Reporting, as maintained and distributed by HHS, for the following conditions: (1) diseases; (2) injuries; (3) impairments; (4) other health problems and their manifestations; and (5) causes of injury, disease, impairment, or other health problems. We also adopted the International Classification of Diseases, 10th Revision, Procedure Coding System (ICD-10-PCS), including the Official ICD-10-PCS Guidelines for Coding and Reporting, as maintained and distributed by HHS, for the following procedures or other actions taken for diseases, injuries, and impairments of hospital inpatients reported by hospitals: (1) prevention; (2) diagnosis; (3) treatment; and (4) management.

Table 1 summarizes the full set of transaction standards adopted in the Transactions and Code Sets final rule and as modified in the Modifications final rule. The table uses abbreviations of the standards and the names by which the transactions are commonly referred, while the official nomenclature and titles of the standards and transactions related to the provisions of this proposed rule are provided later in this preamble.

TABLE 1—Transactions Standards Adopted Under HIPAA

Standard

Transaction

ASC X12 837 D

Health care claims—Dental.

ASC X12 837 P

Health care claims—Professional.

ASC X12 837 I

Health care claims—Institutional.

NCPDP D.0 and Version 1.2

Health care claims—Retail pharmacy drug.

ASC X12 837 P and NCPDP D.0 and Version 1.2

Health care claims—Retail pharmacy supplies and professional services.

NCPDP D.0 and Version 1.2

Coordination of Benefits—Retail pharmacy drug.

ASC X12 837 D

Coordination of Benefits—Dental.

ASC X12 837 P

Coordination of Benefits—Professional.

ASC X12 837 I

Coordination of Benefits—Institutional.

ASC X12 270/271

Eligibility for a health plan (request and response)—Dental, professional, and institutional.

NCPDP D.0

Eligibility for a health plan (request and response)—Retail pharmacy drugs.

ASC X12 276/277

Health care claim status (request and response).

ASC X12 834

Enrollment and disenrollment in a health plan.

ASC X12 835

Health care payment and remittance advice.

ASC X12 820

Health plan premium payment.

ASC X12 278

Referral certification and authorization (request and response).

NCPDP D.0 and Version 1.2

Referral certification and authorization (request and response)—Retail pharmacy drugs.

NCPDP D.0 and Version 1.2

Retail pharmacy drug claims (telecommunication and batch standards).

NCPDP 3.0

Medicaid pharmacy subrogation (batch standard).

In the July 8, 2011

Federal Register

(76 FR 40458), we published an interim final rule with comment period, “Administrative Simplification: Adoption of Operating Rules for Eligibility for a Health Plan and Health Care Claim Status Transactions” (Eligibility and Claim Status Operating Rules IFC). That rule adopted operating rules for two HIPAA covered transactions: (1) Eligibility for a health plan; and (2) health care claim status. The Eligibility and Claim Status Operating Rules IFC also defined the term, “operating rules,” revised the definition for “standard transaction,” revised specific related regulatory provisions, and described the relationship between operating rules and standards.

In general, the transaction standards adopted under HIPAA enable electronic data interchange (EDI) using a common interchange structure, thus minimizing the industry's need to rely on multiple formats. The standards significantly decrease administrative burden on covered entities by creating greater uniformity in data exchange, and reducing the amount of paper forms needed for transmitting data, which remains an obstacle to achieving greater health care industry administrative simplification.

Section 1172(a) of the Act states that “[a]ny standard adopted under [Part C—Administrative Simplification—of Title XI of the Social Security Act, as amended by section 262 of HIPAA] shall apply, in whole or in part, to the following persons: (1) A health plan; (2) A health care clearinghouse; and (3) A health care provider who transmits any health information in electronic form in connection with a [HIPAA transaction].”

Section 1173(b) of the Act directs the Secretary to adopt standards providing for a standard unique health identifier for each individual, employer, health plan, and health care provider for use in the health care system. In the May 31, 2002

Federal Register

(67 FR 38009), we published a final rule entitled, “Health Insurance Reform: Standard Unique Employer Identifier,” which adopted the standard for a unique employer identifier in HIPAA electronic health care transactions. In the January 23, 2004

Federal Register

(69 FR 3434), we published a final rule entitled, “HIPAA Administrative Simplification: Standard Unique Health Identifier for Health Care Providers” (the 2004 NPI final rule), in which the Secretary adopted the National Provider Identifier (NPI) as the standard unique health care provider identifier and the requirements for obtaining and using the NPI. Health care providers that transmit any health information in electronic form in connection with a transaction for which the Secretary has adopted a standard (known as “covered health care providers”), are required to obtain NPIs and use them according to the NPI regulations at 45 CFR part 162, subpart D. Specifically, under the requirements for health care providers at 45 CFR 162.410, a covered health care provider must obtain an NPI for itself and some of its subparts, use the NPI in standard transactions it conducts, and disclose its NPI to any entities that need it for standard transactions. The Secretary has not adopted a standard patient identifier.

Under section 1172(c)(2)(B) of the Act, if no standard setting organization has developed, adopted, or modified any standard relating to a standard that the Secretary is authorized or required to adopt under the Administrative Simplification provisions of HIPAA, then the Secretary may adopt a standard, relying upon recommendations of the NCVHS. In such a case, the Secretary shall publish in the

Federal Register

any recommendation of the NCVHS regarding the adoption of a standard under the HIPAA Administrative Simplification provisions. Further, the Secretary must consult with the National Uniform Billing Committee (NUBC), the National Uniform Claim Committee (NUCC), the Workgroup for Electronic Data Interchange (WEDI), and the American Dental Association (ADA), other appropriate private organizations, and appropriate Federal and State agencies regarding such standard adoption.

In this proposed rule, we address the adoption of a unique health plan identifier, the adoption of a data element that would serve as an identifier for other entities, an addition to the NPI requirements, and a change to the compliance date for the ICD-10-CM and ICD-10-PCS code sets.

C. The Unique Health Plan Identifier (HPID) and the Affordable Care Act

Section 1104(c)(1) of the Affordable Care Act, enacted on March 23, 2010, directs the Secretary to promulgate a final rule establishing a unique health plan identifier that is based on the input of a Federal advisory committee, the National Committee on Vital and Health Statistics (NCVHS). Section 1104 of the Affordable Care Act authorizes the Secretary to promulgate the rule on an interim final basis and indicates that such rule shall be effective not later than October 1, 2012.

Health plans are currently identified for different purposes using different identifiers that have different sources, formats, and meaning. A health plan may have multiple identifiers, each assigned by a different organization for a different purpose. The following discussion focuses on the types of identifiers that currently may be used to identify health plans in standard transactions. State regulators, for instance, use the National Association of Insurance Commissioners' (NAIC) Company code to identify health plans when a health plan is licensed to sell or offer health insurance in a particular State. The U.S. Department of Labor (DOL) and the Internal Revenue Service (IRS) use the 9-digit Employer Identification Number (EIN) and a 1-digit alphabetic or a 3-digit plan number to identify health plans. Employers, sole proprietorships, corporations, partnerships, non-profit associations, trusts, estates of decedents, government agencies, certain individuals, and other business entities, use EINs to identify health plans for a host of purposes and transactions. The IRS uses the EIN to identify taxpayers that are required to file various business tax returns. Health care clearinghouses assign proprietary identifiers to health plans for use in standard transactions. Multiple clearinghouses may identify the same health plan using different proprietary identifiers in different covered transactions. Health plans may use other existing identifiers, such as a tax identification number (TIN) or an EIN, to identify themselves in the standard transactions, to more easily integrate into existing proprietary systems, or for use on health insurance cards that they issue to health plan enrollees.

Not only are health plans identified using a variety of identifiers, but these identifiers have different formats. For instance, some identifiers are alphanumeric while other identifiers are only numeric. Identifiers also differ in length; for example, NAIC codes are typically five digits while an EIN is nine digits.

The current versions of the adopted standards (ASC X12N and NCPDP) allow health plans to use these and other identifiers in standard transactions. Therefore, for the covered transactions there is no requirement for consistency in the use of identifiers for health plans. Health care providers, health plans, and healthcare clearinghouses may use EINs, TINs, NAIC numbers, healthcare clearinghouse, or health plan assigned proprietary numbers to identify health plans in standard transactions. Industry stakeholders, especially health care providers, have indicated that the lack of a standard unique health plan identifier has resulted in increased costs and inefficiencies in the health care system. Health care providers are frustrated by problems with: the routing of transactions; rejected transactions due to insurance identification errors; difficulty determining patient eligibility; and challenges resolving errors identifying the health plan during claims processing.

The Affordable Care Act specifically calls for the establishment of a unique identifier for health plans. There are however, other entities that are not health plans but that perform certain health plan functions and are currently identified in the standard transactions in the same fields using the same types of identifiers as health plans. For

example, health care clearinghouses, third party administrators (TPAs), and repricers often contract with insurance companies, self-funded employer health care plans, and provider- or hospital-run health plans to perform claims administration, premium collection, enrollment, and other administrative functions. In some cases, TPAs or other entities are identified in the same fields as health plans in the transactions, depending on the contractual relationships. As explained later in this proposed rule, we propose to adopt a data element—an other entity identifier—to serve as an identifier for these other entities.

D. The National Committee on Vital and Health Statistics (NCVHS)

In section 1104 of the Affordable Care Act, the Secretary is directed to conduct its rulemaking to establish a unique health plan identifier based on input of the NCVHS. Congress created the NCVHS to serve as an advisory body to the Secretary on health data, statistics, and national health information policy. The NCVHS has been assigned a significant role in the Secretary's adoption of all standards, code sets, and operating rules under HIPAA, including the unique health plan identifier. In section 1104(c)(1) of the Affordable Care Act, Congress reiterated that the NCVHS would retain its role in providing input on the establishment of the health plan identifier.

The NCVHS Subcommittee on Standards fulfilled these duties by conducting public hearings on the health plan identifier on July 19 through 21, 2010. Industry stakeholders, including representatives from health plans, health care provider organizations, health care clearinghouses, pharmacy industry representatives, standards developers, professional associations, representatives of Federal and State public programs, the Workgroup on Electronic Data Interchange (WEDI), the National Uniform Billing Committee (NUBC), the National Uniform Claim Committee (NUCC), and individuals with health plan identifier proposals provided in-person and written testimony. Stakeholder testimony at the hearings focused on the use and need for an HPID to: facilitate the appropriate routing of transactions; reduce the cost of managing financial and administrative information; improve the accuracy and timeliness of claims payment; and reduce dissatisfaction among health care providers and patients/members by improving communications with health plans and their intermediaries. Stakeholders provided suggestions on the types of entities that need to be identified in standard transactions, those that should be eligible to obtain an HPID, and the level of enumeration for each plan (for example the legal entity, product, benefit package etc). We discuss the specifics of key issues in more detail later in this proposed rule.

1. Eligibility for an HPID

There was substantial testimony on the types of entities that should obtain an identifier and a request that HHS clearly indicate the organizations that would be required to obtain and use an identifier in standard transactions. Testifiers also offered extensive input on the need to provide an identifier for entities that do not meet the definition of health plan under HIPAA, but have a need to be identified in standard transactions. The majority of those testifying recommended that these entities, such as TPAs and health care clearinghouses, be eligible to obtain an identifier for use in the standard transactions.

2. HPID Enumeration Level

Stakeholders offered extensive input on the appropriate level of health plan enumeration. Testifier suggestions ranged from requiring health plans to enumerate at the highest level (that is the parent company), to enumerating every health plan benefit package (for example “HMO Gold”). Some testifiers proposed that there be two types of health plan identifiers, and they used the term “plan” to mean both the health plan products and health plan organizations—Type 1 and Type 2 identifiers, respectively. As reflected in written testimony submitted to the NCVHS, they proposed that the Type 1 identifier identify patient-specific health plan products, for instance, a particular health insurance product, or an employee health benefit plan or other product defining the patient's coverage. The Type 2 identifier would identify organizations that perform health plan functions, such as entities issuing long-term care policies, plan organizations paying for the cost of medical care for specified populations, or entities responsible for funding high risk pools offering coverage to eligible individuals. Some testifiers also suggested that the Type 2 identifier also identify entities other than health plans that perform certain administrative or contracting functions on behalf of health plans, such as TPAs or health care clearinghouses. In addition, some of these testifiers recommended the creation of a fee schedule identifier so health care providers could download the appropriate fee schedule, just as the entity that is administering the claims transaction must do to price the claim.

Other testifiers opined that enumeration should occur at a health plan organization level and should support the ability to obtain and utilize a more granular enumeration scheme if there is a business need for further differentiation to appropriately route transactions. This proposal was based on the premise that the purpose of the HPID is to identify entities that meet the regulatory definition of health plan and are conducting the covered transactions. The HPID will be used to identify a health plan that sends or receives the covered transactions. These testifiers cautioned that requiring fee schedule, reimbursement information, or product level information in the HPID would create a level of complexity that would greatly increase the number of identifiers needed, resulting in significant health plan maintenance requirements, increased cost, and inefficiencies. These testifiers recommended that associating product information with particular identifiers should not be a goal of the HPID, although it could be addressed in future versions of the standards, implementation guides, or operating rules.

3. Timing

Stakeholders at the NCVHS hearings also stressed the importance of a smooth transition from current plan identifiers to the HPID during the enumeration process, given its potential impact on the industry. For example, they noted that health plan and health care provider information systems will need to be reprogrammed to accommodate the HPID, including the possible expansion of data fields and the creation of crosswalks between existing proprietary identifiers and the HPID. Health care clearinghouses and health IT vendors will need to update their systems to accommodate the new identifiers, and may also need to create identifier crosswalks to match current health plan identifiers to the HPID and vice versa. Health plans will need to conduct an analysis of their organizations and structure to determine, if they have subsidiaries, which of their entities qualify as health plans and need to be enumerated. The HPID may also impact information systems that involve Health Level 7 (HL7) standard protocols. Testimony from the HL7 SDO noted that it is likely that the HPID may require changes to existing scheduling, registration, pre-admission, admission, and other information systems and their screens,

work flows, and data elements collected, stored, displayed, and processed by those applications. In addition, testifiers pointed out other regulatory requirements with similar, converging compliance dates, such as: January 1, 2012 for complying with Version 5010, Version D.0 and Version 3.0; October 1, 2013 for complying with the ICD-10-CM and ICD-10-PCS medical code sets requirements; January 1, 2013 for implementing the first set of operating rules for two of the standard transactions; and other changes under the Affordable Care Act all require limited industry resources.

Finally, there was testimony related to the use of health plan identifiers in the retail pharmacy transactions, and we address this topic later in this proposed rule. (For transcripts and testimony of the July 19 and 20, 2010 NCVHS Subcommittee on Standards hearings, go to

http://www.ncvhs.hhs.gov.

)

E. The NCVHS Recommendation to the Secretary on HPID

On September 30, 2010, following the July 2010 NCVHS Subcommittee on Standards hearing, the NCVHS sent a letter to the Secretary with its recommendations for the adoption of a standard for a health plan identifier. The nine NCVHS observations addressed the following topics: (1) The definitions and types of entities eligible for enumeration with an HPID; (2) the level of entity enumeration; (3) the format and content of the HPID; (4) the directory database to support the HPID enumeration system and process; (5) the implementation of the HPID in retail pharmacy; (6) the implementation process and timing; (7) applicable testing of the HPID enumeration process; (8) the use of the HPID on health plan identification cards, and (9) the improvement in the use of standards and operating rules. The specific recommendations are as follows:

“HHS should:

• 1.1 clarify the definition of health plan as specified in the HIPAA regulations (45 CFR 160.103) for purposes of HPID eligibility and enumeration, including that property and casualty insurers and workers' compensation plans could be eligible for such enumeration even though they are not covered entities.

• 1.2 work with stakeholders to reach consensus on names and definitions for intermediary entities. Consider making these intermediary entities eligible to obtain an HPID where there is a clear use case for them to be enumerated.

• 1.3 request stakeholder input through groups such as Workgroup on Electronic Data Interchange (WEDI), America's Health Insurance Plans (AHIP), National Association of Insurance Commissioners (NAIC), and the Designated Standards Maintenance Organizations (DSMO) Committee for definitions of products to be used in plan enumeration by October 31, 2010 (or other date as deemed feasible by CMS).

• 1.4 collaborate across Federal agencies and departments to develop or identify consensus definitions affecting the identification of health plans, including Indian Health Service (IHS), Department of Veterans Affairs (VA), Department of Defense (DoD), and the Federal Employee Health Benefit Program (FEHBP).

• 1.5 coordinate, to the maximum extent feasible, the development and implementation of the HPID with other plan related requirements in the Affordable Care Act, including, for example, the consumer health insurance web portal, the health insurance exchanges and the regulatory requirements for health plans.

• 2.1 initially enumerate all health plan legal entities as defined in the HIPAA legislation and further clarified in regulations at 45 CFR 160.103.

• 2.2 determine at what level, including product (benefit package) level or other categorization, a health plan should also be enumerated, using input from stakeholders, and identify these in regulation.

• 3.1 adopt an HPID that follows the ISO Standard 7812, with Luhn check-digit as the tenth digit.

• 3.2 adopt an HPID that contains no embedded intelligence.

• 4.1 establish an HPID enumeration system and process supported by a robust online directory database.

• 4.2 direct CMS to work with stakeholders including other Federal agencies to identify the minimum necessary data elements for the directory database. Consideration should be given to including the Employer Identification Number (EIN), Taxpayer Identification Number (TIN), National Association of Insurance Commissioners (NAIC) identifier, Source of Payment Typology, and other identifiers that may assist in supporting the need to appropriately identify health plans in administrative transactions and in the updating, development and/or effective use of standards and operating rules. The database should be sufficiently flexible to enable additional information to be added initially at the discretion of the entity, and potentially in the future, as a requirement by HHS.

• 4.3 require the entity enumerated to maintain all information according to a published schedule of updates or more often as appropriate, to maintain accuracy. If there are no changes at the time of a scheduled update, the date information was validated should signify that the entity has reviewed and is confirming the data as being current.

• 4.4 make available appropriate information from the HPID directory database to support the efficient and accurate exchange of information.

• 4.5 consider, for the future, requiring that the HPID system enable electronic transactions with the directory database for users or their systems to obtain information and route transactions more efficiently and effectively.

• 5.1 not require the HPID to be used in place of the existing RxBIN/PCN identifier in retail pharmacy business and transactions.

• 5.2 require the use of HPID on the HIPAA-named standard transactions for retail pharmacy, where appropriately defined by industry through the ASC X12 and NCPDP processes.

• 6.1 consider that the effective date of October 1, 2012 be interpreted as the date to begin registering for an HPID. As such, subsequent phases should include time for enumeration and testing before a final implementation date when the HPID must be used in compliant transactions. This will ensure sufficient time for publication of the regulation and development of the enumeration system and process. Phases should include:

• October 1, 2012—March 31, 2013: Enumeration

• April 1, 2013—September 30, 2013: Testing

• October 1, 2013: Implementation

• 6.2 describe in regulation the potential purposes and uses of the HPID, including its uses in standard transactions, potential uses for health information exchange, and others. While purposes should not be restricted, the initial focus should be on enumerating entities for use in the financial and administrative transactions required under HIPAA.

• 6.3 accommodate bulk enumeration of HPID as applicable.

• 7.1 provide sufficient time and guidance for testing the HPID in transactions prior to use.

• 7.2 allow for a period during which dual use of legacy health plan identifiers and the new HPID is permitted in the transactions as appropriate.

• 8.1 encourage the use of the HPID in health plan identification cards.

• 9.1 strongly encourage the industry to collaborate to enhance operating rules for the financial and

administrative transactions to support the use of the HPID.”

For the complete text of the NCVHS' observations and recommendations, go to

http://www.ncvhs.hhs.gov/100930lt1.pdf.

We agree in principle with the spirit and intent of the NCVHS' recommendation to the Secretary for a health plan identifier standard as relayed in the September 30, 2010 letter. In this proposed rule, we propose to adopt a health plan identifier based in large part upon the NCVHS' recommendations, with some minor departures. In section II. of this proposed rule, we itemize our proposals and, where necessary, explain the differences between the HHS proposal and the NCVHS' recommendations.

F. Definition of Health Plan

The regulatory definition of health plan at 45 CFR 160.103 was initially adopted in the Transactions and Code Sets final rule. The basis for the additions to, and clarifications of, the statutory definition of health plan is further discussed in the preamble to the December 28, 2000 final rule (65 FR 82478 and 82576) entitled “Standards for Privacy of Individually Identifiable Health Information” (hereinafter referred to as the Privacy Rule). The term “health plan” is defined at 45 CFR 160.103.

This definition of “health plan” references group health plans, health insurance issuers, and health maintenance organizations that are also defined in 45 CFR 160.103. These definitions are included here:

Group health plan (also see definition of health plan in this section) means an employee welfare benefit plan (as defined in section 3(1) of the Employee Retirement Income and Security Act of 1974 (ERISA), 29 U.S.C. 1002(1)), including insured and self-insured plans, to the extent that the plan provides medical care (as defined in section 2791(a)(2) of the Public Health Service Act (PHS Act), 42 U.S.C. 300gg-91(a)(2)), including items and services paid for as medical care, to employees or their dependents directly or through insurance, reimbursement, or otherwise, that:

(1) Has 50 or more participants (as defined in section 3(7) of ERISA, 29 U.S.C. 1002(7)); or

(2) Is administered by an entity other than the employer that established and maintains the plan.

Health insurance issuer (as defined in section 2791(b)(2) of the PHS Act, 42 U.S.C. 300gg-91(b)(2) and used in the definition of health plan in this section) means an insurance company, insurance service, or insurance organization (including an HMO) that is licensed to engage in the business of insurance in a State and is subject to State law that regulates insurance. Such term does not include a group health plan.

Health maintenance organization (HMO) (as defined in section 2791(b)(3) of the PHS Act, 42 U.S.C. 300gg-91(b)(3) and used in the definition of health plan in this section) means a Federally qualified HMO, an organization recognized as an HMO under State law, or a similar organization regulated for solvency under State law in the same manner and to the same extent as such an HMO.

II. Provisions of the Proposed Rule To Adopt a Standard for a Unique Health Plan Identifier (HPID)

This rule proposes an HPID as the standard for the unique identifier for health plans. We are also proposing instructions and guidance concerning how health plans may obtain an HPID. We further propose requirements that covered entities will have to meet to use the unique health plan identifier in standard transactions. This proposed rule would add provisions specific to the HPID in a new subpart (subpart E) to 45 CFR part 162.

A. The Health Plan Identifier

1. Definition of “Controlling Health Plan” and “Subhealth Plan”

Health plans today have many different business structures and arrangements that affect how health plans are identified in standard transactions. There is often a “parent” corporation that meets the definition of health plan, which may be controlled by entities, such as holding companies, that do not meet the definition of health plan. This “parent” health plan may own and operate several other entities and organizations, which may also meet the definition of a health plan. While these individual health plans that are owned by the same “parent” corporation may have their own EIN or NAIC number, they may all use a single identifier in covered transactions because of data processing arrangements. In these situations, some health plans may not need to be identified separately in covered transactions, and may not need their own health plan identifier. To differentiate between health plan entities that would be required to obtain an HPID, and those that would be eligible, but not required, to obtain an HPID, we are proposing definitions for controlling health plan (CHP) and subhealth plan (SHP) in proposed 45 CFR 162.103 as follows.

a. Controlling Health Plan (CHP)

We would define a CHP as a health plan (as defined at 45 CFR 160.103) that—(1) controls its own business activities, actions, or policies; or is controlled by an entity that is not a health plan (2) and if it has a subhealth plan(s) (SHPs) (see definition of SHP in subpart b), exercises sufficient control over the subhealth plan(s) to direct its/their business activities, actions, or policies.

The following factors would need to be considered when determining if an entity is a CHP:

• Does the entity itself meet the definition of health plan at 45 CFR 160.103?

• Does either the entity itself or a non health plan organization control the business activities, actions, or policies of the entity?

If the answer to both questions is “yes,” then the entity meets the definition of CHP. We propose that an entity that meets the definition of CHP would be required to obtain a health plan identifier.

b. Subhealth Plan (SHP)

A SHP would mean a health plan (as defined in 45 CFR 160.103) whose business activities, actions, or policies are directed by a CHP. The following considerations may be helpful in determining whether an entity is a SHP:

• Does the entity meet the definition of health plan at § 160.103?

• Does a CHP direct the activities, actions, or policies of the health plan entity?

If the answer to both questions is “yes,” then the entity meets the definition of SHP. We propose that a SHP would not be required to obtain an HPID, but may choose to obtain an HPID, or its CHP may obtain an HPID on its behalf.

2. Proposed Use of the HPID

In proposed 45 CFR 162.510, we propose HPID usage requirements for all covered entities. We propose to require all covered entities to use an HPID wherever a covered entity identifies a health plan in a covered transaction. Covered entities would obtain the HPIDs of health plans from the health plans themselves or from the Enumeration System, which we describe later in this proposed rule. If a covered entity uses a business associate to conduct standard transactions on its behalf, the covered entity must require that its business associate use an HPID in each field where the business

associate identifies a health plan in all covered transactions.

The HPID may also be used for any other lawful purpose that requires the identification of health plans.

Some examples of permitted uses include the following:

• Health plans may use HPIDs in their internal files to facilitate processing of health care transactions.

• A health plan may use an HPID on a health insurance card.

• The HPID may be used as a cross-reference in health care fraud and abuse files and other program integrity files.

• Health care clearinghouses may use HPIDs in their internal files to create and process standard and non-standard transactions, and in communications with health plans and health care providers.

• HPIDs may be used in patient medical records to help specify patients' health care benefit package(s).

• HPIDs may be used to identify health plans in electronic health records (EHRs).

• HPIDs may be used to identify health plans in Health Information Exchanges (HIEs).

• HPIDs may be used to identify health plans in Federal and State health insurance exchanges.

• HPIDs may be used to identify health plans for public health data reporting purposes.

3. Proposed Health Plan Identifier Requirements for Health Plans

In 45 CFR 162.512, we propose HPID implementation specifications for health plans. We propose to require all CHPs, as defined in 45 CFR 162.103, to obtain HPIDs from the Enumeration System in accordance with the enumeration process, which is described later in this proposed rule. In addition, CHPs could obtain HPIDs from the Enumeration System on behalf of their SHPs, as defined in 45 CFR 162.103, or direct their SHPs to obtain HPIDs directly from the Enumeration System. Any SHP would be eligible to obtain an HPID regardless of whether or not its CHP directs it to obtain an HPID. A CHP could only obtain one HPID for itself.

We propose to require each health plan to disclose its HPID to any entity, upon request, that needs the HPID to identify that health plan in a standard transaction. We propose to require each health plan to ensure that its own data in the Enumeration System is correct and that each health plan submits changes (updates, corrections, etc.) to its own data to the Enumeration System within 30 days of the date the change took place. A SHP would ultimately be responsible for submitting updates for its own data in the Enumeration System regardless of whether it obtained its HPID independently or the CHP obtained the HPID on its behalf. We are requesting comments on whether a SHP should be responsible for submitting updates to its own data if a CHP obtained the HPID on its behalf.

This proposed rule provides a discussion on how CHPs and SHPs will obtain an HPID from the Enumeration System. Health plans would be able to begin to apply for an HPID on or after the effective date of the final rule, which we expect to be October 1, 2012, and must use it in standard transactions by the compliance date of the final rule.

a. Requirements and Options for Obtaining and Using a Health Plan Identifier

While a CHP would be required to obtain a health plan identifier, there would be different options available for the enumeration of SHPs based on a CHP's organizational structure and business needs. The CHP may analyze its organizational structure to determine if and which of its SHPs need a HPID based on whether the SHP needs to be identified in covered transactions. The CHP may obtain HPIDs on behalf of its SHP, or it may direct the SHPs to obtain the HPIDs. While a CHP could only obtain 1 HPID for itself, a CHP could use the HPID of its SHPs for any lawful purpose, including in the transactions.

Self-insured group health plans are included in the definition of health plan in § 160.103. Because of this, self-insured group health plans will need to obtain a health plan identifier if they meet the definition of a CHP. We specifically mention self-insured group health plans as there was industry discussion about whether these health plans should be required to obtain HPIDs because they do not always need to be identified in the standard transactions. As discussed, the primary purpose of the HPID is for use in the standard transactions. Many self-insured group health plans contract with third party administrators or other entities to perform health plan functions on their behalf and those entities, not the self-insured group health plans, may be identified in the standard transactions. Some in the industry thus suggested not requiring self-insured group health plans to obtain HPIDs as they may not need to be identified in the standard transactions, while others recommended requiring these plans to obtain HPIDs as they may be the financially responsible party. Given that self-insured group health plans are included in the definition of health plan and there is a potential need to be identified in the standard transactions, we propose that they be required to obtain a HPID if they meet the definition of a CHP. We are soliciting comment on this issue.

A SHP would be able to obtain an HPID even if its CHP does not obtain one on its behalf or does not direct the SHP to obtain an HPID. We encourage CHPs and SHPs to coordinate their HPID applications to prevent duplicative and unnecessary numbers. See Table 2 for a comparison of requirements for obtaining an HPID.

Table 2—Proposed Enumeration Requirements and Options for CHPs and SHPs

Entity

Enumeration requirements

Enumeration options

CHPs

Must obtain an HPID for itself

May obtain an HPID(s) for its SHP(s).

May direct its SHP(s) to obtain an HPID(s).

SHPs

Not required to obtain an HPID

May obtain an HPID at the direction of its CHP.

May obtain an HPID on its own initiative.

Using Illustration A and B, we provide examples of enumeration options to demonstrate the ways a CHP could choose to enumerate itself and its SHPs, if applicable. For these options, we are assuming that CHP “Z” and the SHPs Z-1, Z-2, Z-3, and Z-4 each meets the definition of health plan at 45 CFR 160.103.

EP17AP12.020

(1) Illustration A. Enumeration Option 1: CHP and Each SHP Obtain HPIDs

CHP “Z” meets the definition of a health plan and controls its own business activities, actions, and policies. Therefore CHP “Z” would be required to obtain an HPID. CHP “Z” would then analyze its organizational structure and business needs to determine if and which of its SHPs need an HPID for use in standard transactions. CHP “Z” may determine that SHPs Z-1, Z-2, Z-3, and Z-4 each need their own HPID for use in the standard transactions as CHP “Z” and each of its SHPs may have separate data processing centers or arrangements. Thus, CHP “Z” would obtain an HPID, and each of the SHPs, from Z-1 to Z-4 would obtain their own HPIDs. SHPs could obtain HPIDs in one of two ways as described in the following scenarios:

• Scenario 1—CHP “Z” obtains all the HPIDs. It obtains one HPID for itself and it obtains an HPID on behalf of each SHP. In total there are five HPIDs.

• Scenario 2—CHP “Z” directs its SHPs to obtain HPIDs: CHP “Z” obtains its own HPID and each of the SHPs would obtain their own HPIDs individually. Ultimately, the result would be the same as scenario 1: The CHP and each of the four SHPs would have their own HPIDs and there would be a total of five HPIDs.

Other possible scenarios would involve CHP “Z” obtaining fewer than all five HPIDs, or directing fewer than all four SHPs to obtain an HPID. Each of the SHPs may also decide on its own to obtain an HPID without direction from the CHP to do so.

(2) Illustration A. Enumeration Option 2: CHP Obtains HPID. SHPs Do Not Obtain HPIDs

As in the first example, CHP “Z” would be required to obtain an HPID, as it meets the definition of health plan and controls its own business activities, actions, and policies.

CHP “Z” may determine that none of its SHPs needs to be identified in standard transactions, and therefore none of the SHPs needs its own HPID. Instead, CHP “Z” may direct SHPs Z-1, Z-2, Z-3, and Z-4 to use the CHPs' HPID in the standard transactions.

(3) Illustration A. Enumeration Option 3: CHP obtains HPID. Some, But Not All SHPs Obtain HPIDs

Again, CHP “Z” would be required to obtain an HPID, as it meets the definition of health plan and controls its own business activities, actions, and policies.

CHP “Z” may then examine its organizational structure to determine which of its SHPs need an HPID for use in a standard transaction. CHP “Z” may determine that SHPs Z-3 and Z-4 must be uniquely identified in the covered transaction because, for example, they do not share the same data processing centers as CHP “Z” and would each want to use their own HPID. SHPs Z-3 and Z-4 would use their own HPIDs in standard transactions. SHPs Z-3 and Z-4 could obtain their HPIDs in one of the following ways:

• CHP “Z” could direct SHPs Z-3 and Z-4 to obtain their own HPIDs.

• CHP “Z” could obtain HPIDs on behalf of SHPs Z-3 and Z-4. CHP “Z” may determine that based on its organizational structure SHPs Z-1 and Z-2 do not need separate HPIDs for use in standard transactions as they may share data processing systems with CHP Z, SHP Z-3, or SHP Z-4. CHP “Z” may direct SHP Z-1 and Z-2 to use CHP “Z”'s HPID, SHP Z-3's HPID, or SHP Z-4's HPID in the transactions. CHP “Z” may make this determination based on the relevant data processing systems.

EP17AP12.021

(4) Illustration B. Enumeration Option 1: CHP and Each SHP Obtain HPIDs

Illustration B provides an example of a health plan being controlled by Company A, which is a holding company. Holding companies are examples of entities that control the business, activities, actions, or policies of other legal entities such as health plans, but typically do not meet the definition of a health plan as defined in 45 CFR 160.103. Assuming Company A does not meet the definition of a “health plan” under the relevant definition in 45 CFR 160.103, it would not be eligible to obtain an HPID.

CHP “Z” meets the definition of health plan as found in 45 CFR 160.103, is controlled by an entity that is not a health plan, and exercises sufficient control over the subhealth plans to direct their business activities, actions, or policies. Therefore, it meets the definition of “controlling health plan” as proposed in 45 CFR 162.103, and would be required to obtain an HPID for itself.

A similar analysis as discussed in Illustration A would need to be done to determine how subhealth plans Z-1, Z-2, Z-3, and Z-4 would be enumerated. CHP “Z” must examine its organizational structure to determine which of its SHPs need an HPID for use in standard transactions, and the same enumeration options for subhealth plans that existed for Illustration A would exist in this example.

b. Examples of Use of HPID in Standard Transactions

Within each transaction, a health plan may need to be identified in fields that do not specifically require the use of a health plan identifier. A health plan could need to be identified, for instance, in data fields that indicate the payer of the claim or the intended recipient of the transaction, or the information source for a particular request. To illustrate how the HPID could be used in standard transactions, we will look at a specific segment from one transaction standard. This example illustrates how covered entities would be required to identify a health plan in a standard transaction. This example is not meant to state who or what must be identified in the fields in the transaction, change what entities can be identified in specific loops or segments in the transaction standards, or affect the use of identifiers for non-health plans. It is important to note that the implementation of the HPID would not prohibit or affect the identification of other entities in these loops or segments if entities other than health plans need to be identified in those loops or segments.

For this example, we will look at a specific segment from one transaction standard—the ASC X12 Version 5010 health care eligibility benefit inquiry and response (also known as the 271). In this example, the segment is the NM1-Information Source Name in the 2100A loop—Information Source. The standard provides the following definition of information source: “The information source is the entity that has the answer to the questions being asked in a 270 Eligibility or Benefit request transaction. The information source is typically the insurer or payer. In a managed care environment, the information source could possibly be a primary care physician or gateway health care provider. Regardless of the information source's actual role in the healthcare system, they are the entity who maintains the information regarding the patient's coverage.” The information source is identified in loop 2100A. The NM1 segment, information source name, provides specific details about the information source through data elements. The NM1 segment is comprised of nine reference descriptors. These reference descriptors provide information about a specific data element. For instance, NM101—Entity ID Code—is the code identifying the organizational entity, a physical location, property or an individual. For NM101, there are specific codes that can be used to describe the information source. Table 3 represents the NM1 segment. The chart is meant to demonstrate how the identification of a health plan in the NM1 segment will change after use of the HPID is mandated. For this example, the information source is the health plan.

In Table 3, Column I, the reference descriptor provides the data element being described in the NM1 segment. Table 3, Column II provides the name of the reference descriptor in Table 3, Column I and describes what is being conveyed in that data element. Table 3, Column III lists the codes that the standard permits to be used to describe

the information source. Table 3, Column IV provides the definition of the corresponding code in Table 3, Column III. Table 3, Column V shows what could have been used to identify a health plan prior to the HPID implementation. Table 3, Column VI shows what will be used to identify a health plan after implementation of the HPID.

Table 3—Example 1, Eligibility Response Transction, Loop 2100A, Segment NM1—Information Source Name (Version 5010)

I

Reference

description

II

Name

III

Code

IV

Definition

V

Content of the field before HPID compliance date

VI

Content of the field after HPID compliance date

NM101

Entity identifier Code

2B

Third-Party Administrator

If a health plan is to be identified as the information source, then Entity Code Qualifier “PR” will be used

If a health plan is to be identified as the information source, then Entity Code Qualifier “PR” will be used.

36

Employer

GP

Gateway Provider

P5

Plan Sponsor

PR

Payer

NM108

Identification Code Qualifier

24

Employer's Identification Number (EIN)

If a health plan is to be identified as the information source, Identification Code Qualifier 24, 46, FI, NI, or PI can be used

If a health plan is to be identified as the information source, only Identification Code Qualifier XV can be used.

46

Electronic Transmitter Identification Number (ETIN)

FI

Federal Taxpayer's Identification Number

NI

National Association of Insurance Commissioner's (NAIC) Identification

PI

Payer Identification

XV

Centers for Medicare & Medicaid Services Plan ID

XX

Centers for Medicare & Medicaid Services Provider Identifier

NM109

Identification Code

Depending on the Identification Code Qualifier, this could be the EIN, ETIN, Tax Id, the NAIC, or any Proprietary Id

HPID only (if a health plan is to be identified as the information source).

Currently, if the health plan is the information source and needs to be identified in the transactions, it may be identified using a number of different identifiers as shown in Table 3, Column V. If this proposal is finalized and the HPID is adopted, and if a health plan is identified as the information source, it must be identified using an HPID as shown in Table 3, Column VI.

As discussed earlier in this proposed rule, stakeholders at the NCVHS hearings expressed different viewpoints on the appropriate level of health plan enumeration. Some industry stakeholders encouraged health plan enumeration at a very high level (for example, at the level of the health plan's legal entity), while other stakeholders supported enumeration at the benefit package level. We analyzed and considered these viewpoints when we developed the HPID policy proposed herein.

We began by exploring the purpose of the HPID. While we considered multiple uses for the HPID, we determined that the primary purpose of the HPID is for use in standard transactions in order to identify health plans in the appropriate loops and segments and to provide a consistent standard identifier so a health plan no longer uses multiple identifiers in the HIPAA covered transactions. Therefore, we analyzed the transaction standards to determine the existing segments and loops where a health plan may need to be identified, what identifiers are currently used in those loops and segments to identify health plans, and what information that loop or segment is providing when a health plan is being identified. We also carefully considered the information that industry stakeholders reported was missing in covered transactions and suggested could be provided using a health plan identifier. We determined that much of the information testifiers wanted to obtain through the health plan identifier might already be available in other parts of the transaction standards and associated operating rules.

The CAQH CORE 154 eligibility content and operating rule, to be used with the ASC X12 Version 5010 Standard for Electronic Data Interchange Technical Report Type 3—Health Care Eligibility Benefit Inquiry and Response

(270/271) (hereinafter referred to as the Version 5010 270/271 eligibility inquiry/response standard), was adopted through an interim final rule with comment period published in the July 8, 2011

Federal Register

(76 FR 40458), with a compliance date of January 1, 2013. These operating rules require that more information be provided in the Version 5010 270/271 eligibility inquiry/response standard, including information about a patient's health plan name, coinsurance, copayment, and deductibles including in-network and out-of-network, as well as remaining deductible amounts. The loops, segments, and codes within the transaction standards are already available vehicles for providing this information today. Future versions of standards, as well as the adoption of operating rules to supplement the standards, can address many of the other issues raised by stakeholders and can continue to address issues or problems in the transactions as they arise. Therefore, we do not believe that the HPID needs to provide the level of detail that some testifiers suggested.

In addition, requiring health plans to enumerate to a more granular level may prove burdensome to the industry as benefit package information and offerings change frequently and would require constant updates by health plans. Health care providers may also need to update their software and systems frequently to ensure the accuracy of information. This could result in increased time spent by health plan and health care provider staff to ensure appropriate information is being used for eligibility determination and claim payments.

We developed the proposed HPID policy after considering stakeholder testimony, analyzing transaction standards' loops and segments where the health plan identifier will be used, and taking into account newer versions of the standards and the adoption of operating rules to complement the standards.

4. HPID Standard Format

a. Introduction

Per the NCVHS recommendations, which were based on stakeholder testimony from a wide range of potential HPID users, we propose to adopt an HPID that is a 10-digit, all-numeric identifier with a Luhn check-digit as the tenth digit. (See § 162.510). The Luhn check-digit is an algorithm used most often on credit cards as a check sum to validate that the card number issued is correct. See

http://www.merriampark.com/anatomycc.htm

for more information. We seek public and stakeholder comments on the feasibility and utility of this format for the HPID.

b. The International Organization for Standardization (ISO) Standard

The International Organization for Standardization (ISO) is the world's largest developer and publisher of international standards. National standards institutes from 160 nations comprise the ISO. The ISO has published more than 16,500 standards for numerous industries such as agriculture, electrical engineering, and other information technology industries. For more information on the ISO, refer to the Web site at

http://www.iso.org.

Based on stakeholder testimony, the NCVHS recommendations, and our review, we propose that the ISO 7812 standard format, ISO/IEC 7812-1:2006 and ISO/IEC 7812-2:2007, which consists of a 10-digit, all-numeric identifier with a Luhn check-digit as the tenth digit, be adopted as the standard for the HPID. This standard incorporates the same format that is used for the enumeration of health care providers via the National Provider Identifier (NPI), adopted in the NPI final rule, published in the January 23, 2004

Federal Register

(69 FR 3434). Like the proposed standard for the HPID, the standard for the NPI is a 10-position all numeric identifier with a numeric check digit to assist in identifying erroneous or invalid NPIs. The HPID format would essentially be an intelligence-free identifier as the start digit of the number would provide the only piece of intelligence, signaling that the identifier had been provided to a health plan and not to an “other entity” or a health care provider. The OEID will have a different start digit than the HPID. The number of digits of the HPID would not exceed the number permitted for identifiers in the relevant data fields of the standard transactions. If additional capacity for HPIDs were needed in the future, the relevant data fields would permit additional numeric digits to be added at that time. Also, an all-numeric identifier: is more quickly and accurately keyed in data-entry applications; is more easily used in telephone keypad applications; does not require translation before application of the check digit algorithm and thus uses the full ability of the check digit algorithm to detect keying errors; will require less change for systems that currently use a numeric identifier; and is compatible with ISO identification card standards for a card issuer identifier, while Alphanumeric identifiers do not possess these important characteristics.

B. Adoption of the Other Entity Identifier (OEID)

In addition to proposing the adoption of an identifier for health plans, we are also proposing to adopt a data element in the form of an optional identifier for other entities for use in standard transactions, consistent with the recommendations of the NCVHS. Section 1104(c) of the Affordable Care Act provides in relevant part that the Secretary “shall promulgate a final rule to establish a unique health plan identifier (as described in section 1173(b) of the Act (42 U.S.C. 1320d-2(b))) based on the input of the National Committee on Vital and Health Statistics.” Section 1173(a)(1)(A) of the Act states in relevant part that “[t]he Secretary shall adopt standards for transactions, and data elements for such transactions, to enable health information to be exchanged electronically, that are appropriate for—(A) the financial and administrative transactions described in paragraph (2)* * *, ” which contains a list of the transactions for which the Secretary has to adopt a standard.

The OEID would serve as an identifier for entities that are not health plans, health care providers, or “individuals”,

3

yet they need to be identified in standard transactions. Under this proposed rule, these other entities would not be required to obtain an OEID, but they could obtain and use one if they needed to be identified in covered transactions. If they obtained an OEID, these entities would be expected to use it and disclose it upon request to entities that need to identify such entities for covered transactions.

3

Individual is defined at 45 CFR 160.103 as “the person who is the subject of protected health information.”

We are proposing to make obtaining and using the OEID voluntary. Stakeholders expressed a strong interest in being able to obtain an identifier, and the NCVHS agreed and recommended that such an identifier would be beneficial to the industry. We believe that voluntary obtaining and using is appropriate at this time, although we recognize that the OEID may be more beneficial if obtaining and using an OEID were required. We could do this, for example, by requiring health plans that have business relationships with other entities that perform certain functions on their behalf to direct in a contract or other arrangement these other entities to obtain and use an OEID. Alternatively, covered entities could on

their own initiative require their trading partners or business associates obtain OEIDs as part of their own agreed upon business arrangements. This rule does not propose to preclude such a business practice. We are interested in industry opinions about our proposal to make obtaining and using the OEID voluntary, and we also welcome comments about whether and how it should be made mandatory.

1. The Other Entity Identifier (OEID)

As discussed in section I. of this proposed rule, health plans often use the services of other entities to conduct certain financial and administrative transactions on their behalf. Rental networks, benefit managers, third party administrators, health care clearinghouses, repricers, and other third parties often perform functions similar to, or on behalf of, health plans. In many cases, these other entities are currently being identified in standard transactions in the same fields and using the same type of identifiers used by health plans. For example, when a covered health care provider conducts a transaction to determine eligibility for a health plan (referred to as an “eligibility for a health plan transaction”), the health care provider may send an electronic request to obtain information about a patient's eligibility for health care services to an entity referred to as an “information source.” This “information source” provides information back to the health care provider about a specific patient's health care coverage that a particular health plan provides. The “information source” for the patient's eligibility information may be a health plan or one of these other entities that perform financial and administrative services on behalf of that health plan. Currently, in the transaction standard for the eligibility for a health plan transaction, health plans, and the other covered entities may use the same type of identifiers, such as a Payer Identifier (PAYERID) or an EIN, to identify themselves as the “information source.”

In its September 30, 2010 letter to the Secretary, the NCVHS explained the integral role other entities play in health care administrative and financial electronic transactions. The NCVHS acknowledged that while these other entities may not meet the definition of “health plan” under HIPAA, they nevertheless need to be identified in the transactions to ensure successful, efficient communication. The reality is that these entities often need to be identified in the same fields in which a health plan would need to be identified because they perform very similar functions. These other entities are using many of the same identifiers health plans currently use in covered transactions. In addition, the NCVHS recommended that HHS consider allowing these entities to obtain HPIDs as they may be the actual recipients of eligibility queries or claims on behalf of the health insurance issuer or the entity ultimately responsible for payment. The NCVHS stressed the importance of enabling these entities to be enumerated, and recommended that HHS consider making these entities eligible to obtain an HPID where there is a clear use case for them to be enumerated. Based on the testimony NCVHS heard, information we have received, and for the reasons stated previously, we believe that a clear use case does exist for these other entities to be enumerated. Moreover, we anticipate that with the recent advances in health information exchange and the development of health information networks, the need to identify these other entities in financial and administrative electronic transactions will only increase.

Offering the OEID as an adopted data element to identify other entities that need to be identified in covered transactions should reduce costs and improve efficiency for covered entities. Because other entities are identified in the transaction standards in a similar manner as health plans, we believe that establishing a data element to serve as an identifier for these entities will increase efficiency by encouraging the use of a uniform identifier and promote compliant use of the HPID for health plans. Like the standard for HPID we are proposing to adopt, the OEID that we are proposing would follow ISO standard 7812, and be a 10-digit, all-numeric identifier with a Luhn check-digit as the tenth digit. Consequently, entities that have implemented the HPID and are seeking to implement the OEID would not need to significantly modify their information technology systems to accommodate the use of the OEID.

Therefore, we are proposing to establish the OEID for use in standard transactions to identify entities that are not eligible to obtain an HPID or NPI and are not individuals (as defined at 45 CFR 160.103). The OEID would be used to identify these other entities where these other entities need to be identified in the standard transactions, and for any other lawful purpose. These entities would be eligible, but not required, to obtain an OEID for themselves. An OEID would be obtained by the other entity from the Enumeration System identified in 45 CFR 162.508 as discussed in this proposed rule. Changes to its required data elements would need to be communicated to the Enumeration System within 30-days of the change. We solicit industry and stakeholder comments on our proposed enumeration of other entities and adoption of the OEID for use in the standard transactions.

C. Assignment of the HPID and OEID

1. The Enumeration System

We propose that in 45 CFR 162.508, the Enumeration System would assign unique HPIDs and OEIDs to eligible health plans and eligible other entities, respectively. The Enumeration System would be a comprehensive system for uniquely identifying and enumerating all eligible health plans and other entities. It would collect and maintain certain identifying and administrative information about CHPs, SHPs, and other entities. The Enumeration System would also disseminate information through a publicly available searchable database or through downloadable files. Entities may also obtain a CHP's or SHP's HPID or an entity's OEID by requesting the HPID from the health plan or the OEID from the other entity.

HPIDs and OEIDs would only be assigned by the Enumeration System through an online application process. A health plan or other entity, when applying online for an HPID or OEID, would be required to provide certain identifying and administrative information. We anticipate this information will be used to verify the identity and eligibility of health plans and other entities during the application process. We anticipate further that a help desk will be available to assist health plans and other entities with the online application process as necessary and to notify health plans or other entities about problems associated with their online applications.

The Enumeration System would also be able to deactivate or reactivate an HPID or OEID based on receipt of sufficient information. Examples of situations justifying deactivation of an HPID may include the fraudulent use of the HPID by the health plan itself or an other entity, the change of ownership of a health plan, or the restructuring of a health plan's data processing systems such that the SHP determines that its HPID would no longer be needed. Deactivation of an OEID may also occur in similar situations, for example the fraudulent use of an OEID by itself or an other entity, the change of ownership of the other entity, or if the other entity no longer exists.

Reactivation of an HPID or OEID could occur, for instance, if there were a change of ownership of a health plan or other entity, or for health plans if there were a restructuring of a health plan's data processing systems and the SHP determines that it again needs its HPID.

We solicit stakeholder comments on our proposals regarding the enumeration system and process.

D. Other Considerations

1. Pharmacy Transactions

During the July 2010 NCVHS hearings on the health plan identifier, industry stakeholders also expressed views on the use of the HPID in retail pharmacy transactions. Currently, the pharmacy industry utilizes two unique identifiers in retail pharmacy transactions, the Bank Identification Number/Issue Identification Number (BIN/IIN) and the Processor Control Number (PCN). These identifiers are programmed into the pharmacy's software and identify the route for processing the transaction from the pharmacy to the entity responsible for administering the claim, which could be the health plan or the pharmacy benefit manager. A pharmacy benefit manager is a third party administrator for prescription drug programs and is responsible for processing and paying claims on behalf of the health plan or drug plan sponsor.

The BIN/IIN is a 6-digit number, requested by the pharmacies from either the American National Standards Institute (ANSI) or the National Council for Prescription Drug Programs (NCPDP), for use by retail pharmacies to route prescription drug claims to the entity responsible for processing the transaction, usually the pharmacy benefit manager. The PCN is an identifier of up to 10 characters that is assigned by pharmacy benefit claim processors if there is a need to further define benefits and routing. For instance, the Medicare Part D prescription drug benefit plan Coordination of Benefits (COB) contractor has unique requirements for processing Medicare Part D claims. To accommodate those requirements, many administrators or processors have created PCNs to further differentiate the Medicare Part D prescription drug plan benefit COB business from their other (commercial or Medicaid) COB business. Both the BIN/IIN and PCN are embedded into pharmacies' software programs, and identify the entity for processing claims. The identifiers are tied to the entity that will be processing the transaction, or where the transaction is to be sent. These identifiers are included in information from pharmacy benefit managers and/or health plans that are distributed to pharmacies to provide details on who will be processing the transaction, where to route the transaction and what rules are expected to be applied during transaction processing. The use of the BIN/IIN and PCN allow pharmacy claims to be adjudicated and responded to by the pharmacy benefit manager or health plan within seconds. According to the NCPDP, the use of these two identifiers has been very effective in ensuring efficient, timely prescription claim processing. Both pharmacy and non-pharmacy stakeholders testified at the July 2010 NCVHS Subcommittee on Standards hearings that the HPID, BIN/IIN and PCN identifiers convey different information and serve different purposes. The BIN/IIN and PCN identifiers cannot provide the information needed about the health plan, nor can the information in the HPID provide the information inherent in the BIN/IIN and PCN identifiers.

A representative of the retail pharmacy industry testified that if the health plan identifier were required to replace the BIN/IIN and/or PCN, such a change would be extremely costly to the retail pharmacy industry. For example, combination medical and/or prescription drug plan identification cards would need to be re-issued with the HPID, with no direct patient or pharmacy benefit. The NCPDP also noted that an HPID-only requirement would require a substantive change to the NCPDP D.0. In Version D.0, the Plan ID field is either not used or its use is optional, meaning its use was not intentionally defined in the standard. However, the use of the BIN and PCN fields is mandatory.

In its September 30, 2010 recommendation letter to the Secretary, the NCVHS observed that based on the testimony presented at the July 2010 hearings, retail pharmacy transactions utilize the BIN/IIN and/or PCN identifier to facilitate their transaction processing and that changing to an other identifier would significantly affect existing data flows in the retail pharmacy industry that currently work effectively. As such, the pharmacy industry requested an exemption from the requirement to use only HPID in retail pharmacy transactions because of the current success with the BIN/IIN and PCN identifiers for routing purposes. The NCVHS recommended that use of the HPID in place of the existing BIN/IIN and PCN identifier in retail pharmacy business transactions not be required, but that the HPID be required on the HIPAA-named standard transactions for retail pharmacy. We are not proposing any changes to the NCPDP Version D.0 standard, and we do not believe that the HPID should be required in place of the existing BIN/IIN and PCN identifier in retail pharmacy transactions.

2. Definition of Covered Health Care Provider

We are proposing to move the definition of “covered health care provider” from 45 CFR 162.402 to 45 CFR 162.103 because the term “covered health care provider” has a broader application beyond just Subpart D.

E. Effective and Compliance Dates for the HPID

In section 1104(c)(1) of the Affordable Care Act, Congress specified that “the Secretary shall establish a standard for a unique health plan identifier based on the input of the National Committee on Vital and Health Statistics.” Congress further provided that the rule shall be “effective” not later than October 1, 2012. Therefore, we are planning for the effective date of this rule to be October 1, 2012. The effective date would mark the beginning of the implementation period for the HPID, which we expect would be the first day health plans may apply to obtain an HPID and the first day an entity may apply to obtain an OEID from the Enumeration System. We propose that the compliance date for all covered entities, except small health plans, to use the HPID in standard transactions be 2 years after the effective date of the final rule which, if the effective date is October 1, 2012 as we are planning, would be October 1, 2014. The compliance date for small health plans would be October 1, 2015. Small health plans would not be prohibited from complying earlier and using the HPID in their transactions at any time before October 1, 2015.

The Congress uses the terms “effective” and “adoption” in the Affordable Care Act as applied to both the rules that the Secretary must promulgate to adopt the various standards as well as to the standards themselves. In these provisions of the Affordable Care Act, Congress consistently uses the term “effective date” to mean the time when the relevant provision—either the rule or an adopted standard—must go into effect.

In line with our previous interpretations, we have interpreted the “effective date” of this rule to mean the date the Secretary adopts the HPID as the Unique Health Plan Identifier. In the NPI final rule, for instance, the effective date of the rule was the date the Secretary adopted a standard unique

health identifier for health care providers, and the compliance date marked the time by which an entity had to obtain and use an NPI in the standard transactions. We consequently interpret this section of the Act as specifying October 1, 2012 as the effective date of the final rule, when the policies take effect and the implementation period for the HPID begins.

Understanding that Congress intended the effective date for the HPID final rule to be October 1, 2012, we note that this date marks the first day that a health plan will be able to apply to obtain an HPID. The 2-year implementation period for this new standard sets the date by which health plans (excluding small health plans) must obtain and covered entities (excluding small health plans) must use an HPID in the standard transactions as October 1, 2014. The compliance date for small health plans would be October 1, 2015.

We are soliciting comment on the effective and compliance dates for the HPID.

III. Proposed Addition to the National Provider Identifier Requirements

A. Background

As discussed in section I of this proposed rule, the final rule adopting the NPI as the standard unique health identifier for health care providers was published on January 23, 2004 (69 FR 3434) (“2004 NPI final rule”). While the 2004 NPI final rule requires covered health care providers to obtain NPIs for themselves and certain subparts and use them in standard transactions, it does not require a health care provider who is not a covered entity to obtain an NPI. Even if a noncovered health care provider chooses to obtain an NPI, the provider is not required to comply with certain NPI requirements, which means the provider does not have to disclose its NPI to entities who may need it for standard transactions. When a noncovered health care provider does not obtain an NPI or does not disclose it, certain problems arise for entities that need to identify that noncovered health care provider in standard transactions. We are proposing an addition to the requirements for the NPI regulations to address such problems.

The 2004 NPI final rule (69 FR 3445) recognized that, “[s]ituations exist in which a standard transaction must identify a health care provider that is not a covered entity. * * * A noncovered health care provider may or may not have applied for and received an NPI. In the latter case, * * * an NPI would not be available for use in the standard transaction. We encourage every health care provider to apply for an NPI, and encourage all health care providers to disclose their NPIs to any entity that needs that health care provider's NPI for use in a standard transaction. Obtaining NPIs and disclosing them to entities so they can be used by those entities in standard transactions will greatly enhance the efficiency of health care transactions throughout the health care industry. * * * The absence of NPIs when required in * * * claims by the implementation specifications may delay preparation or processing of those claims, or both. Therefore, we strongly encourage health care providers that need to be identified in standard transactions to obtain NPIs and make them available to entities that need to use them in those transactions.”

The 2004 NPI final rule (69 FR 3445) provided the following example of a situation where a health care provider is not a covered entity but its NPI is needed for a standard transaction: “A pharmacy claim that is a standard transaction must include the identifier (which, as of the compliance date, would be the NPI) of the prescriber. Therefore, the pharmacy needs to know the NPI of the prescriber in order to submit the pharmacy claim. The prescriber may be a physician or other practitioner who does not conduct standard transactions. The prescriber is encouraged to obtain an NPI so it can be furnished to the pharmacy for the pharmacy to use on the standard pharmacy claim.”

Within just a few months after implementation of the 2004 NPI final rule, this issue had been raised so frequently to HHS that, on September 23, 2008, it published a Frequently Asked Question to address questions about pharmacy claims rejected by payers for lack of an individual prescriber NPI (Answer ID 9419) (

https://questions.cms.hhs.gov/app/answers/detail/a_id/9419/~/does-the-national-provider-identifier-(npi)-final-rule-require-individual

).

Due to recurring issues, we believe this scenario described in the 2004 NPI final rule needs to be addressed. Pharmacies are encountering situations where the NPI of a prescribing health care provider needs to be included in the pharmacy claim, but the prescribing health care provider does not have an NPI or has not disclosed it. This situation has become particularly problematic in the Medicare Part D program, as we explain more fully later in this proposed rule.

By way of background, every prescriber has at least one identifier that may be submitted on a pharmacy claim. These identifiers include the NPI, Drug Enforcement Administration (DEA) number, uniform provider identification number (UPIN), or State license number. The Medicare Part D program is an optional prescription drug benefit for all Medicare beneficiaries. Medicare Part D contracts with private companies, called plan sponsors, to administer the benefit through Part D drug plans. In the Medicare Part D program, plan sponsors must submit a prescription drug event (PDE) record to Medicare Part D every time a beneficiary's prescription is filled under the program. Plan sponsors use information from the claim generated by the pharmacy to complete the PDE record, which contains summary information. These PDE records, which currently must contain a prescriber identifier are necessary to support accurate payments to plan sponsors by Medicare Part D.

The use of multiple and invalid prescriber identifiers in the Medicare Part D program has been identified as a concern. In a June 2010 report titled, “Invalid Prescriber Identifiers on Medicare Part D Drug Claims” (“June 2010 report”), the HHS Office of the Inspector General (OIG) reported the findings of its review of prescriber identifiers on 2007 Part D PDE records. The OIG reported finding 18.4 million PDE records that contained 527,749 invalid identifiers, including invalid NPIs, DEA registration numbers, and UPINs. Payments by Part D drug plans and enrollees for prescriptions associated with these PDE records totaled $1.2 billion. Prescriber identifiers are valuable Part D program safeguards. These identifiers are the only data on Part D drug claims to represent that licensed practitioners have written prescriptions for Medicare enrollees. Although invalid prescriber identifiers are not an automatic indication of erroneous or fraudulent prescriptions or pharmacy claims, the lack of valid prescriber identifiers on Part D drug claims hampers Medicare's program integrity efforts.

To address these concerns raised by the June 2010 report, in the “Medicare Program; Changes to the Medicare Advantage and the Medicare Prescription Drug Benefit Programs for Contract Year 2013 and Other Changes” final rule (which was filed for public inspection onApril 2, 2012 (hereinafter referred to as April 2012 final rule). CMS requires Part D sponsors to include an active and valid prescriber National Provider Identifier (NPI) on prescription drug event records (PDEs) that they submit to CMS, which will assist the Federal government in fighting possible fraudulent activity in the Part D

program, because prescribers will be consistently and uniformly identified. This policy will not interfere with beneficiary access to needed medications because Part D sponsors must validate the NPI at point of sale, and if this is not possible, permit the prescription to be dispensed and obtain the valid NPI afterwards.”

Pharmacies that contract with Part D sponsors may be involved in obtaining a prescriber's NPI depending on the agreement between the pharmacies and Part D sponsors. Because Part D sponsors and pharmacies generally have no regulatory leverage or other recourse over prescribers who fail or refuse to disclose NPIs, they must resort to using provider information databases to determine if a prescriber has an NPI or contact the prescriber, if known. If a Part D sponsor or network pharmacy is unable to obtain a prescriber NPI for use on the claim and PDE, the reimbursement from Medicare Part D to the sponsor (or alternatively, from the sponsor to the pharmacy depending on the agreement between the parties), could be negatively affected. We seek to address both current and future problems described previously that are presented by prescribers who do not have NPIs or do not disclose them, by proposing an additional requirement for the NPI regulations.

B. Provisions for a Proposed Requirement To Obtain and Use NPIs

We are proposing an additional requirement for organization covered health care providers that have as a member, employ, or contract with, an individual health care provider who is not a covered entity and is a prescriber. Organization health care providers are health care providers that are not individuals. Our proposal would require an organization to require such a prescriber to: (1) obtain an NPI; and (2) to the extent the prescriber writes a prescription while acting within the scope of the prescriber's relationship with the organization, disclose the NPI upon request to any entity that needs it to identify the prescriber in a standard transaction.

Organization covered health care providers would be required to implement the requirement within 180 days after the effective date of the final rule, which would be reflected in 45 CFR 162.404(a)(2) with regulation text stating that an organization covered health care provider must comply with the implementation specifications in 45 CFR 162.410(b). We expect the final rule to be effective on October 1, 2012, in which case covered organization health care providers would have to meet the requirement by April 7, 2013.

The requirement would be reflected in the regulation text in 45 CFR 162.410(b) by adding the following new language. “An organization covered health care provider that has as a member, employs, or contracts with an individual health care provider who is not a covered entity and is a prescriber, must require such health care provider to: (1) obtain an NPI from the National Plan and Provider Enumeration System (NPPES) and (2) to the extent the prescriber writes a prescription while acting within the scope of the prescriber's relationship with the organization, disclose the NPI upon request to any entity that needs it to identify the prescriber in a standard transaction.”

This proposed requirement represents a narrow exception to the position we took in the 2004 NPI final rule. The 2004 NPI final rule (69 FR 3440), we stated “[w]e do not consider individuals who are health care providers * * * and who are members or employees of an organization health care provider to be “subparts” of those organization health care providers, as described earlier in this section. Individuals who are health care providers are legal entities in their own right. The eligibility for an “Entity type code 1” NPI of an individual who is a health care provider and a member or an employee of an organization health care provider is not dependent on a decision by the organization health care provider as to whether or not an NPI should be obtained for, or by, that individual. The eligibility for an “Entity type code 1” NPI of a health care provider who is an individual is separate and apart from that individual's membership or employment by an organization health care provider.”

By virtue of this proposed rule, we are still not considering noncovered health care providers that are prescribers to be subparts of organization health care providers, nor are we proposing that they are not legal entities in their own right. Rather, our proposal would close a gap in the NPI rule by virtue of the relationships that covered organization health care providers have with noncovered individual health care providers.

The providers we seek to reach are prescribers who are not required to obtain and disclose an individual NPI under the current NPI regulations. To the best of our understanding, these prescribers are largely hospital-based providers who staff clinics and emergency departments, or otherwise provide on-site medical services, such as medical residents and interns, as well as prescribers in group practices, whose services are billed under a group or “Entity type code 2” NPI regardless of whether they have obtained an individual, or “Entity type code 1,” NPI. These prescribers are using the “Entity type code 2” to identify themselves on prescriptions, or an other or no identifier, which does not identify them as individuals. We believe this proposal describes the various relationships that organization health care providers have with such prescribers, and that the relationship is one in which organizations can exercise control over these prescribers and require them to do something.

For instance, a physician or dentist who prescribes may be a member of a group practice. As noted in the 2004 NPI final rule (69 FR 3439 and 3440), “group health care providers are entities composed of one or more individuals (members), generally created to provide coverage of patients' needs in terms of office hours, professional backup and support, or range of services resulting in specific billing or payment arrangements.” For purposes of this rule, we consider group health care providers to be organization health care providers.” By virtue of the contractual or other relationship between a group and a member, a group can require the member to do certain things, such as work certain on-call hours. Likewise, a resident or nurse practitioner who performs medical services at a hospital can be required to do certain things, such as to abide by medical staff by-laws and hospital policies and procedures, as a hospital employee or contractor. This proposed rule does not specify how organization covered health care providers should impose the requirement to obtain an NPI and disclose it on prescribers. Organization covered health care providers may have a number of alternatives by which they may accomplish this, for example, through a written agreement, an employment contract, or a directive to abide by the organization health care provider's policies and procedures.

The requirement for a prescriber to disclose his or her NPI would apply for prescriptions written pursuant to the prescriber's relationship with the covered health care organization provider. For example, if a physician works for two group practices, A and B, group practice A would be required to require the physician to disclose his or her NPI for pharmacy claims that are for prescriptions written by the prescriber for a patient of group practice A, and group practice B would be required to do the same for pharmacy claims for

prescriptions written by the prescriber for a patient of that group practice.

We considered expanding our proposal to organization covered health care providers that grant clinical privileges to individual health care providers who are not covered entities and are prescribers, so that we would be certain to encompass hospital residents and interns under our proposal (to the extent they are not otherwise required to obtain Type 1 NPIs). However, it is our belief such prescribers will be encompassed under our proposal as drafted, as we further believe our proposal would encompass virtually all prescribers who are not currently required to obtain and disclose an individual NPI. Exceptions may include, by way of example, a self-employed physician who does not bill insurance plans and does not have a member, employee or contractual relationship with an organization covered health care provider (or has one with a noncovered organization health care provider), such as a psychiatrist or plastic surgeon who only accepts cash from patients. Even with respect to these prescribers, we hope this rule highlights the importance of voluntarily obtaining NPIs to facilitate their patients' access to prescribed items. We seek comment regarding the extent to which residents, interns, and any other prescribers would not be reached under our proposal and any alternative approach that would encompass them.

We believe this proposal furthers several goals and purposes identified in the Act. First, the statutory purpose of the Administrative Simplification provisions of HIPAA (see section 261 of the Act (42 U.S.C. 1320d note)) is,

To improve the Medicare program under title XVIII of the Social Security Act, the Medicaid program under title XIX of such Act, and the efficiency and effectiveness of the health care system, by encouraging the development of a health information system through the establishment of uniform standards and requirements for the electronic transmission of certain health information and to reduce the clerical burden on patients, health care providers, and health plans.

In accord with this statutory purpose, our proposal would improve the Medicare program by virtually ensuring the availability of an NPI as a prescriber identifier on pharmacy claims in the Part D program because virtually all prescribers would have to obtain an NPI and disclose it to entities that need it for use in standard transactions. That in turn would support program integrity efforts described in the April 2012 final rule noted previously which requires Part D sponsors to submit PDEs that contain only individual NPIs as prescriber identifiers, effective January 1, 2013. As noted in the April 2012 final rule, “[w]hen multiple prescriber identifiers, not to mention dummy or invalid identifiers, are used, authorities must take an additional step in their data analysis before even achieving a refined data set to use for further analysis to identify possible fraud. For example, having to cross-reference multiple databases that update on different schedules to be certain of the precise prescribers involved when multiple identifiers were used, would necessitate several additional steps of data pre-analysis and also would introduce potential errors in correctly matching prescribers among databases.”

Invalid identifiers are generally those that do not appear as current in any prescriber identifier registry. Dummy or default identifiers have never appeared in any prescriber identifier registry but have been used successfully on pharmacy claims in place of valid prescriber identifiers (for instance, when the prescriber's NPI was not available), because they met the length and format requirements of a prescriber identifier. Default identifiers present additional challenges to authorities, since the actual prescription must be researched to identify the prescriber. Valid prescriber identifiers are essential to conducting claims analyses to identify aberrant claims prescribing patterns that may indicate fraudulent activity, such as drug diversion schemes or billing for prescription drugs not provided, which includes circumstances with active prescriber participation and those involving forged prescriptions. Improving the accuracy and dependability of the prescriber identifier on Part D claims and PDEs, improves the ability to identify fraud and, in turn, protects and improves the Medicare program.

This proposal would further improve the Medicare program by nearly eliminating the instances in which Part D sponsors' reimbursement (or possibly their network pharmacies' reimbursement, depending on the contractual relationship between the sponsors and the pharmacies) would be negatively impacted due to the actions of prescribers with whom they may have no business relationship. Part D sponsors would be expected to price any measurable expectation of financial risk, if any, due to nonreimbursement by CMS into their Part D bids, thus possibly increasing premiums and subsidies paid under the program. This proposal would make such action by Part D sponsors unnecessary by virtually ensuring the availability of prescriber NPIs.

This proposal also accords with the purpose of HIPAA as amended by the Affordable Care Act. Section 1104(a)(2) of the Affordable Care Act revised the statutory purpose of HIPAA Administrative Simplification by adding, at the end, that its purpose is to “reduce the clerical burden on patients, health care providers, and health plans.” To the extent pharmacies only have to accept one identifier—the NPI—rather than four possible identifiers from prescribers for the majority of their claims, the administrative burden on all parties involved in the processing and payment of these claims would be lessened. Pharmacies and payers would no longer have to cross-check provider identifier databases to determine if the prescriber had an NPI when an alternate identifier was used, or contact the prescriber. Moreover, pharmacies and prescribers would no longer have to respond to inquiries from payers regarding the existence of an NPI when an alternate prescriber identifier was used.

The proposal is also supported by section 1173(a)(3) of the Act, which requires the transaction standards adopted by the Secretary to accommodate the needs of different types of health care providers. Our proposal would accommodate the needs of pharmacies, a type of health care provider, by ensuring that a prescriber NPI is available to them when needed for their claims and reducing the instances in which they must cross-reference provider information databases or research a prescription. Similarly, section 1173(b)(1) of the Act states that,

[t]he Secretary shall adopt standards providing for a standard unique health identifier for each individual, employer, health plan, and health care provider for use in the health care system. In carrying out [this requirement] for each health plan and health care provider, the Secretary shall take into account multiple uses for identifiers and multiple locations and specialty classifications for health care providers.

Our proposal takes into account the particular needs of pharmacies by addressing a problem they have under HIPAA.

While some prescribers will have to apply to obtain an NPI under this proposed requirement, the NPI is free of charge and requires only the completion of a three-page application form that seeks primarily identifying and location information. Thus, we believe the reduction in administrative burden that will be achieved by our proposal outweighs the minimal burden placed on prescribers who will have to obtain NPIs.

The 2004 NPI final rule, as noted previously, foretold the issues that could arise if noncovered health care providers did not obtain NPIs, and therefore encouraged them to do so. The preamble of the 2004 NPI final rule stated that disclosing NPIs to entities for use in standard transactions will greatly enhance the efficiency of health care transactions throughout the health care industry, and that the absence of NPIs when required in those claims by the implementation specifications may delay preparation or processing of those claims, or both. Health care providers responded by obtaining NPIs in large numbers even when not required to, and we believe the vast majority of prescribers already have NPIs. CMS data shows that approximately 90 percent of Medicare Part D claims as reported in PDEs currently submitted contain valid prescriber NPIs even though alternate prescriber IDs are permitted at this time. But, while the vast majority of Medicare Part D claims contain individual NPIs, 10 percent do not. This proposal would help ensure this last 10 percent is addressed. After discussions with representatives of the provider data industry, we estimate there are approximately 1.4 million active prescribers in the United States, of which approximately 160,000 do not have an NPI. It is these prescribers who would have to obtain an NPI if this rule is finalized as proposed.

C. Effective and Compliance Dates

We propose that the date by which an organization covered health care provider must comply is 180 days after the effective date of the final rule. In other words, if the final rule is effective on October 1, 2012, then by April 7, 2013, organization covered health care providers that have a prescriber as a member, employ, or contract with a prescriber who is not a covered entity, must require him or her to (1) obtain an NPI and; (2) to the extent the prescriber writes a prescription while acting within the scope of the prescriber's relationship with the organization, to disclose the NPI upon request to any entity that needs it to identify the prescriber in a standard transaction.

IV. Proposed Change to the Compliance Date for ICD-10-CM and ICD-10-PCS

A. Background

As discussed in section I. of this proposed rule, the final rule adopting ICD-10-CM and ICD-10-PCS (collectively, “ICD-10”) as HIPAA standard medical data code sets was published in the

Federal Register

on January 16, 2009 (74 FR 3328) (the “ICD-10 final rule”). The ICD-10 final rule requires covered entities to use ICD-10 beginning October 1, 2013.

In late 2011 and early 2012, three issues emerged that led the Secretary to reconsider the compliance date for ICD-10: (1) The industry transition to Version 5010 did not proceed as effectively as expected; (2) providers expressed concern that other statutory initiatives are stretching their resources; and (3) surveys and polls indicated a lack of readiness for the ICD-10 transition.

1. The Transition to Version 5010 and Its Effect on ICD-10 Readiness

Concurrent with the publication of the ICD-10 final rule, HHS published in the

Federal Register

the Modifications final rule which set January 1, 2012 as the compliance date for Version 5010 (74 FR 3296). As the industry approached the January 1, 2012 Version 5010 compliance date, a number of implementation problems emerged, some of which were unexpected. These included—

• Trading partners were not ready to test the Version 5010 standards due to vendor delays in delivering and installing Version 5010-compliant software to their provider clients;

• Version 5010 errata were issued to correct typographical mistakes and other maintenance issues that were discovered as the industry began its internal testing of the standards, which delayed vendor delivery of compliant products and external testing;

• Differences between address requirements in the “provider billing address” and “pay to” address fields adversely affected crossover claims processing;

• Inconsistent payer interpretation of standard requirements at the front ends of systems resulted in rejection of claims, as well as other technical and standard misinterpretation issues;

• Edits made in test mode that were later changed when claims went into production without adequate notice of the change to claim submitters; and

• Insufficient end to end testing with the full scope of edits and business rules in place to ensure a smooth transition to full production.

Given concerns that industry would not be compliant with the Version 5010 standards by the January 1, 2012 compliance date, we announced on November 17, 2011 that we would not initiate any enforcement action against any covered entity that was not in compliance with Version 5010 until March 31, 2012, to enable industry adequate time to complete its testing and software installation activities. On March 15, 2012, this date was extended an additional 3 months, until June 30, 2012.

The ICD-10 final rule set October 1, 2013 as the compliance date, citing industry testimony presented to NCVHS and many of the over 3,000 industry comments received on the ICD-10 proposed rule. The analysis in the ICD-10 final rule with regard to setting a compliance date emphasized the interdependency between implementation of ICD-10 and Version 5010, and the need to balance the benefits of ICD-10 with the need to ensure adequate time for preparation and testing before implementation. As noted in the ICD-10 final rule, “[w]e cannot consider a compliance date for ICD-10 without considering the dependencies between implementing Version 5010 and ICD-10. We recognize that any delay in attaining compliance with Version 5010 would negatively impact ICD-10 implementation and compliance.” (74 FR 3334) Based on NCVHS recommendations and industry feedback received on the proposed rule, we determined that “24 months (2 years) is the minimum amount of time that the industry needs to achieve compliance with ICD-10 once Version 5010 has moved into external (Level 2) testing.” (74 FR 3334) In the ICD-10 final rule, we concluded that the October 2013 date provided the industry adequate time to change and test systems given the 5010 compliance date of January 1, 2012.

As implementation of ICD-10 is predicated on the successful transition of industry to Version 5010, we are concerned that the delays encountered in Version 5010 have affected ICD-10 planning and transition timelines.

2. Providers have Expressed Concern That Other Statutory Initiatives Are Stretching Their Resources

Since publication of the ICD-10 and Modifications final rules, a number of other statutory initiatives were enacted, requiring health care provider compliance and reporting. Providers are concerned about their ability to expend limited resources to implement and participate in the following initiatives that all have similar compliance timeframes.

The EHR Incentive Program was established under the Health Information Technology for Economic and Clinical Health (HITECH) Act, a part of the American Recovery and Reinvestment Act of 2009 (Pub. L. 111-5). Medicare and Medicaid incentive payments are available to eligible professionals and hospitals for adopting electronic health record (EHR)

technology and demonstrating meaningful use of such technology. Eligible professionals and hospitals that fail to meaningfully use EHR technology could be subject to Medicare payment adjustments beginning in FY 2015. The Physician Quality Reporting System is a voluntary reporting program that provides incentives payments to eligible professionals and group practices that satisfactorily report data on quality measures for covered Physician Fee Schedule services furnished to Medicare Part B Fee-for-Service beneficiaries. The eRx Incentive Program is a reporting program that uses a combination of incentive payments and payment adjustments to encourage electronic prescribing by eligible professionals. Beginning in 2012 through 2014, eligible professionals who are not successful electronic prescribers are subject to a payment adjustment. Finally, section 1104 of the Affordable Care Act imposes additional HIPAA Administrative Simplification requirements on covered entities, shown in Chart 1.

Chart 1: HIPAA Compliance Dates From the Affordable Care Act

Covered entity compliance date

HIPAA requirements from the Affordable Care Act

January 1, 2013

• Operating rules for eligibility for a health plan and health care claim status transactions.

December 31, 2013

• Health plan compliance certification requirements for health care electronic funds transfers (EFT) and remittance advice, eligibility for a health plan, and health care claim status transactions.

January 1, 2014

• Standards and operating rules for health care electronic funds transfers (EFT) and remittance advice transactions.

December 31, 2015

• Health plan compliance certification requirements for health care claims or equivalent encounter information, enrollment and disenrollment in a health plan, health plan premium payments, health care claims attachments, and referral certification and authorization transactions.

January 1, 2016

• Standard for health care claims attachments.

• Operating rules for health care claims or equivalent encounter information, enrollment and disenrollment in a health plan, health plan premium payments, referral certification and authorization transactions

Proposed October 1, 2014.

• Unique health plan identifier.

3. Current State of Industry Readiness for ICD-10

It is crucial that all segments of the health care industry transition to ICD-10 at the same time because the failure of any one industry segment to successfully implement ICD-10 has the potential to affect all other industry segments. Ultimately, such failure could result in returned claims and provider payment delays that disrupt provider operations and negatively impact patient access to care.

In early 2012, it became evident that sectors of the health care industry would not be prepared for the October 1, 2013 ICD-10 compliance date. Providers in particular voiced concerns about their ability to meet the ICD-10 compliance date as a result of a number of factors, including obstacles they experienced in transitioning to Version 5010 and the other initiatives that stretch their resources. A CMS survey conducted in November and December 2011 (hereinafter referred to as the CMS readiness survey) found that 26 percent of providers surveyed indicated that they are at risk for not meeting the October 1, 2013 compliance date.

4

4

“Version 5010 and ICD-10 Readiness Assessment: Conducted among Health Care Providers, payers, and Vendors for the Centers for Medicare & Medicaid Services (CMS),” December, 2011, Prepared by CMS. Survey responses received from 404 health care providers, 101 payers, and 90 vendors.

In February 2012, the Workgroup for Electronic Data Interchange (WEDI) conducted a survey on ICD-10 readiness, hereinafter referred to as the WEDI readiness survey.

5

WEDI received responses from more than 2,600 providers, health plans, and vendors showing that the industry is uncertain about its ability to meet ICD-10 compliance milestones. Data from the WEDI survey indicated that nearly 50 percent of the provider respondents did not know when they would complete their impact assessment.

6

In addition, the survey found that approximately 33 percent of providers did not expect to begin external testing in 2013, while approximately 50 percent of providers did not know when testing would occur.

7

5

“Survey: ICD-10 Brief Progress,” February 2012, conducted by the Workgroup for Electronic Data Interchange (WEDI).

6

An impact assessment for ICD-10 is performed by a covered entity to determine business areas, policies, processes and systems, and trading partners that will be affected by the transition to ICD-10. An impact assessment is a tool to aid in planning for implementation.

7

For providers, the CMS ICD-10 Implementation Guide recommends that they complete their impact assessments by Winter 2012 and begin external testing in the Fall of 2012. CMS provides implementation guides for providers, payers, and vendors to assist with the transition from ICD-9 to ICD-10 codes. It is a resource for covered entities providing detailed information for planning and executing the ICD-10 transition process. CMS recommends industry use the guide as a reference.

Other segments of the industry, such as health plans and software vendors, also reported that they would benefit from additional time for implementation. While the CMS ICD-10 Implementation Guide recommends that payers begin external testing in the fall of 2012, the WEDI readiness survey found that most health plans do not expect to begin external testing until 2013. In addition, about 50 percent of vendors are not yet halfway through development of ICD-10 products. Vendor delays in product development can result in provider and payer delays in implementing ICD-10.

Given the evidence that segments of the health care industry will likely not meet the October 1, 2013 compliance date, the reasons for that likelihood, and the likelihood that a compliance date delay would significantly improve the successful and concurrent implementation of ICD-10 across the health care industry, we are proposing to extend the compliance date for ICD-10.

B. One-Year Delay

We are proposing to extend the compliance date for ICD-10 for 1 year, from October 1, 2013 to October 1, 2014. This change would be reflected in the regulations at 45 CFR 162.1002. While we considered a number of alternatives for the delay, as discussed in the Impact Analysis of this proposed rule, we believe a 1-year delay would provide sufficient time for small providers and small hospitals to become ICD-10 compliant and would be the least financially burdensome to those who had planned to be compliant on October 1, 2013.

To determine the new compliance date for ICD-10, we balanced the need for additional time for small providers and small hospitals to become compliant with the financial burden of

a delay on entities that have developed budgets and planned process and system changes around the October 1, 2013 compliance date. Entities that have started planning and working toward an October 1, 2013 implementation would incur costs by having to reassess and adjust implementation plans and maintain contracts to manage the transition beyond October 1, 2013. We concluded that a 1-year delay would strike a reasonable balance by providing sufficient time for small providers and small hospitals to become compliant and would minimize the financial burden on those entities that have been actively planning and working toward being compliant on October 1, 2013.

Data from two surveys helped us in our determination to propose 1 additional year for compliance. First, the CMS readiness survey revealed that 26 percent of providers reported that they are at risk for non-compliance on October 1, 2013, citing insufficient time as one risk factor.

8

Second, an informal survey conducted by Edifecs, a health care IT company, of 50 senior health care officials representing a wide range of organizations found that thirty-seven percent of respondents stated that a 1-year delay would be beneficial to them.

9

8

“Version 5010 and ICD-10 Readiness Assessment: Conducted among Health Care Providers, payers, and Vendors for the Centers for Medicare & Medicaid Services (CMS),” December, 2011, Prepared by CMS.

9

“Survey: Industry Reaction to Potential Delay of ICD-10—A Delay will be Costly, but Manageable * * * Unless it's more than a Year,” February 27, 2012, conducted by Edifecs. The survey's participants included commercial payers (25%), Blue Cross Blue Shield plans (25%), healthcare providers (18%), government entities such as State Medicaids (9%), medical claim clearinghouses (6%), and other healthcare industry organizations (17%).

While we considered a 2-year delay, we determined that the financial burden could be too significant for those entities that would otherwise be ready on October 1, 2013. As discussed further in the Impact Analysis of this proposed rule, we estimate it will cost health plans up to an additional 30 percent of their current ICD-10 implementation budgets for a 1-year delay and therefore, we assume that a 2-year delay would be at least double the cost of a 1-year delay; that is, a 2-year delay would cost at least $13 billion for all commercial and government health plans. In addition to financial concerns, industry has suggested that a 2-year delay may stop the implementation of ICD-10 completely. The Edifecs poll found that nearly 70 percent of respondents believe that a 2-year delay would be either “potentially catastrophic or cause an unrecoverable failure,” and that “a delay of longer than a year will likely freeze budgets, slow down schedules, or stop work altogether.”

10

Only 2 percent of Edifecs respondents said there would be a benefit to a 2-year delay.

10

Edifecs poll, 2012.

Finally, in its March 2, 2012 letter to the Secretary on a possible delay of the ICD-10 compliance date, the NCVHS urged that any delay should be announced as soon as possible and should not be for more than 1 year. The NCVH made this recommendation in consideration of its belief that a delay would cause a significant financial burden “that accrues with each month of delay.”

11

11

Letter to Kathleen G. Sebelius, Secretary, U.S. Department of Health and Human Services, from the National Committee of Vital and Health Statistics (NCVHS), “Possible Delay of Deadline for Implementation of ICD-10 Code Sets,” March 2, 2012.

We believe that a 1-year delay would benefit all covered entities, even those who had are actively planning and striving for a 2013 implementation. A 1-year delay would enable the industry as a whole to test more robustly and implement simultaneously, which would foster a smoother and more coordinated transition to ensure the continued and uninterrupted flow of health care claims and payment. Therefore, we are proposing that covered entities must comply with ICD-10 on October 1, 2014.

V. Collection of Information Requirements

Under the Paperwork Reduction Act of 1995 (PRA), agencies are required to provide a 60-day notice in the

Federal Register

and solicit public comment on a collection of information requirement submitted to the Office of Management and Budget (OMB) for review and approval. In order to fairly evaluate whether an information collection should be approved by OMB, section 3506(c)(2)(A) of the PRA requires that we solicit comment on the following issues:

• Whether the information collection is necessary and useful to carry out the proper functions of the agency.

• The accuracy of the agency's estimate of the information collection burden.

• The quality, utility, and clarity of the information to be collected.

• Recommendations to minimize the information collection burden on the affected public, including automated collection techniques.

A. Information Collection Requirements (ICRs) Regarding HPID/OEID on Health Plan and Other Entities (§ 162.512 and § 162.514)

In order to apply for an HPID or OEID, there is an initial one-time requirement for information from health plans that seek to obtain an HPID and other entities that elect to obtain an OEID. In addition, health plans and other entities may need to provide updates to information.

With respect to the collection of information requirements for the HPID, it is important to bear in mind that: (1) Systems modifications necessary to implement the HPID/OEID may overlap with the other systems modifications needed to implement other Affordable Care Act standards; (2) some modifications may be made by contractors such as practice management vendors, in a single effort for a multitude of affected entities; and (3) identifier fields are already in place and HPID/OEID will, in many instances, simply replace the multiple identifiers currently in use.

Under this proposed rule, a CHP, as defined in 45 CFR 162.103, will have to obtain an HPID from a centralized electronic Enumeration System. A SHP, as defined in 45 CFR 162.103, would be eligible but not required to obtain an HPID. If a SHP obtains an HPID, it would apply either directly to the Enumeration System or its CHP would apply to the Enumeration System on its behalf. Other entities may apply to obtain an OEID from the Enumeration System. Health plans that obtain an HPID and other entities that obtain an OEID would have to communicate any changes to their information to the Enumeration System within 30 days of the change. A covered entity must use an HPID to identify a health plan in a standard transaction.

We estimate that there will be up to 15,000 entities that will be required to, or will elect to, obtain an HPID or OEID. We based this number on the following data in Chart 2.

Chart 2: Number and Type of Entities That May Obtain an HPID or OEID

Type of entity

Number of entities

Self insured group health plans

12,000*

Health insurance issuers, individuals and group health markets, HMOs, including companies offering Medicaid managed care

1,827**

Medicare, Veterans Health Administration (VHA), Indian Health Service (IHS), TRICARE, and State Medicaid programs

60

Clearinghouses and Transaction Vendors

162***

Third Party Administrators

750 ****

Total

~15,000

*“Report to Congress: Annual Report on Self -Insured Group Health Plans,” by Hilda L. Solis, Secretary of Labor, March 2011.

** “Patient Protection and Affordable Care Act; Standards Related to Reinsurance, Risk Corridors, and Risk Adjustment, 2011

Federal Register

(Vol. 76), July, 2011,” referencing data from

www.healthcare.gov.

*** Health Insurance Reform; Modifications to the Health Insurance Portability and Accountability Act (HIPAA) Electronic Transaction Standards; Proposed Rule

http://edocket.access.gpo.gov/2008/pdf/E8-19296.pdf,

based on a study by Gartner.

**** Summary of Benefits and Coverage and the Uniform Glossary; Notice of Proposed

Rulemaking

http://www.gpo.gov/fdsys/pkg/FR-2011-08-22/pdf/2011-21193.pdf.

Note that the number of health plans that will be required, or have the option, to obtain an HPID is considerably larger than the number of health plans for which we used in the calculations in section V. of this proposed rule. This is because self-insured health plans are required to obtain HPIDs if they meet the requirements of a Controlling health plan under this proposed rule. However, we assume that very few self-insured group health plans conduct standard transactions themselves; rather, they typically contract with TPAs or insurance issuers to administer the plans. Therefore, there will be significantly fewer health plans that use HPIDs in standard transactions than health plans that are required to obtain HPIDs, and only health plans that use the HPIDs in standard transactions will have direct costs and benefits.

To comply with these requirements, health plans and other entities will complete the appropriate application/update form online through the Enumeration System. This online form serves two purposes: applying for an identifier and updating information in the Enumeration System.

Most health plans and other entities will not have to furnish updates in a given year. However, lacking any available data on rate of change, we elected to base our assumptions on information in the Medicare program that approximately 12.6 percent of health care providers provide updates in a calendar year. We anticipate this figure would be on the high end for health plans and other entities. Applying this assumption, we can expect that 1,764 health plans will need to complete and submit the HPID application update form in a given year.

Applying for HPID or OEID is a one-time burden. In future years, this burden would apply only to new health plans and as an option for other entities as described in the section V of this proposed rule. From 2013 to 2018, industry trends indicate that the number of health plans will remain constant, or even decrease.

12

We assume that the number of new health plans will be small, and that the costs will be negligible. Therefore, our calculations reflect that there will be no statistically significant growth in the number of health plans or other entities and we calculate zero growth in new applications.

12

See

Robinson, James C., “Consolidation and the Transformation of Competition in Health Insurance,” Health Affairs, 23, no.6 (2004):11-24; “Private Health insurance: Research on Competition in the Insurance Industry,” U.S. Government Accountability Office (GAO), July 31, 2009 (GAO-09-864R); American Medical Association, “Competition in Health Insurance: A Comprehensive Study of US Markets,” 2008 and 2009.

We estimate it will take 30 minutes to complete the application form and use an hourly labor rate of approximately $23/hour, the average wage reported for professional and business and services sector, based on data from the Department of Labor, Bureau of Labor Statistics, June 2011, “Average hourly and weekly earnings of production and nonsupervisory employees (1) on private nonfarm payrolls.” (

ftp://ftp.bls.gov/pub/suppl/empsit.ceseeb11.txt

). This represents a unit cost of $11.50 per application for both HPID and OEID.

Because our initial estimate for the number of applications for OEID is small (162 Clearinghouses and Transaction Vendors + 750 TPAs = 912) and the costs negligible, we do not include separate calculations. We have elected instead to offer the unit cost figure as a baseline if commenters demonstrate that the universe of applications for OEID is likely to expand significantly.

To further reduce burden and plan for compliance with the Government Paperwork Elimination Act, we propose accepting electronic applications and updates over the internet. We explicitly solicit comment on how we might conduct this activity in the most efficient and effective manner, while ensuring the integrity, authenticity, privacy, and security of health plan and other entity information.

B. ICRs Regarding Implementation Specifications: Health Care Providers (§ 162.410)

We are proposing to put an additional requirement on covered organization health care providers that employ, have as members, or have contracts with individual health care providers who are not covered entities but who are prescribers. By 180 days after the effective date of the final rule, such organizations must require such health care providers: (1) To obtain, by application if necessary, an NPI from the National Plan and Provider Enumeration System (NPPES); (2) to the extent the prescriber writes a prescription while acting within the scope of the prescriber's relationship with the organization, disclose his or her NPI, upon request to any entity that needs the NPI to identify the prescriber in a standard transaction.

The burden associated with the addition to the requirements of § 162.410 as discussed in this proposed rule is the one-time application burden, and later update burden as necessary, on prescribers who do not already have an NPI, who have a relationship with a covered health care provider, and who must be identified in a standard transaction. We estimate that there are approximately 1.4 million prescribers in the United States, of which approximately 160,000 do not have an NPI. It is these prescribers who would have to obtain an NPI if this rule is finalized as proposed. Based on the estimations in the NPI final rule, we estimate that it will take 20 minutes to complete an application for an NPI and use an hourly labor rate of approximately $23/hour, the average wage reported for professional and business and services sector, based on data from the Department of Labor, Bureau of Labor Statistics, June 2011, “Average hourly and weekly earnings of production and nonsupervisory employees (1) on private nonfarm payrolls.” (

ftp://ftp.bls.gov/pub/suppl/empsit.ceseeb11.txt

). Additionally, we have calculated an increase of 3 percent for labor costs for each of the years 2013 through 2016 for an hour rate of approximately $24/hour for year 2013.

Table 4 shows the estimated annualized burden for the HPID and NPI PRA in hours.

Table 4—Annual Information Collection Burden*

Regulation section

OMB control No.

Respondents

Responses

Burden per response (hours)

Total annual burden

Hourly labor cost of reporting ($)

Total labor cost

Total capital/maintenance costs ($)

Total cost ($)

§ 162.410

0938-New

160,000

160,000

0.33

52,800

24

1,267,200

0

1,267,200

§ 160.512

0938-New

15,000

15,000

0.50

7,500

24

180,000

0

180,000

Total

175,000

175,000

60,300

1,447,200

*2013 dollars.

To obtain copies of the supporting statement and any related forms for the proposed paperwork collections referenced previously, access our Web Site address at

http://www.cms.hhs.gov/PaperworkReductionActof1995,

or Email your request, including your address, phone number, OMB number, and CMS document identifier, to

Paperwork@cms.hhs.gov,

or call the Reports Clearance Office on (410) 786-1326. If you comment on these information collection and recordkeeping requirements, please do either of the following:

1. Submit your comments electronically as specified in the

ADDRESSES

section of this proposed rule; or

2. Submit your comments to the Office of Information and Regulatory Affairs, Office of Management and Budget, Attention: CMS Desk Officer, CMS-0040-P Fax: (202) 395-6974; or Email:

OIRA_submission@omb.eop.gov

VI. Regulatory Impact Analysis

A. Need for Regulatory Action

1. NPI for Non-Covered Health Care Providers

The compliance date for use of the NPI by health care providers was May 23, 2007. At this point, we believe there are 160,000 health care providers who do not already have an NPI. For these health care providers, obtaining an NPI is not a burdensome endeavor, as it is free of charge and takes approximately 20 minutes to file an application to obtain one. However, the availability of these additional prescriber NPIs will greatly assist entities who need them for use in standard transactions, including for the Medicare Part D program, as described previously. See section V.B. of this proposed specifically for a summary of the time costs associated with obtaining an NPI. We have included the costs associated with obtaining an NPI detailed in section V.B in the summary Tables 32 and 33 of the RIA. Because there are few health care providers who do not already have an NPI, we estimate that the addition to the NPI requirements will have little impact on health care providers and on the health industry at large. We solicit comment on this.

2. HPID

As noted in section I of this proposed rule, health plans and other payers are identified in a number of different ways in covered transactions by the health care industry. Health plan identifiers are currently used to facilitate routing of covered transactions or, in other words, “to determine either where the standard electronic transactions are to be sent if the receiver is [a] health plan or from where they came from if the sender is a health plan.”

13

The primary function of the HPID proposed in this rule is to create a standard data element for covered entities to identify health plans in HIPAA covered transactions.

13

J. Daley, “Testimony before the NCVHS Subcommittee on Standards on the National Health Plan Identifier on behalf of America's Health Insurance Plans and the Blue Cross and Blue Shield Association,” July 19, 2010,

http://www.ncvhs.hhs.gov.

Different segments in each HIPAA standard transaction require an identifier to identify the payer or sender/recipient of a particular transaction. (See Table 1 for a list of HIPAA standard transactions, and Table 3 for an example of a segment that requires a payer identifier.) Currently, when a covered entity, for business reasons, inputs an identifier that identifies a health plan into a transaction segment, the identifier is proprietary or based on the NAIC code, EIN, or TIN of the health plan or other entity. Some health plans use multiple identifiers to identify themselves in transactions.

Standardization of the health plan identifier is expected to ameliorate some routing issues. It is expected to clarify, to some extent, the sender or recipient of standard transactions, when the sender or recipient is a health plan. For instance, a health plan that uses different identifiers to identify itself in covered transactions creates inefficiencies and potential confusion among its trading partners. Participating health care providers that are its trading partners, for instance, could be required to use different identifiers for different transactions, even to identify the same health plan. If the HPID is adopted, such a health plan would likely use one identifier, thereby making it easier for the covered health care provider to identify the health plan as the sender or recipient of the standard transaction.

By ameliorating routing issues, the HPID and OEID will add consistency to identifiers, which will provide for a higher level of automation, particularly for provider processing of the X12 271 (eligibility response) and X12 835 (remittance advice). In the case of the X12 835, the HPID and OEID will allow reconciliation of claims with the claim payments to be automated at a higher level.

However, according to testimony and industry studies, the most significant value of the HPID and what is being proposed as the OEID is that they will serve as foundations for other regulatory and industry initiatives. The implementation of HPID, in and of itself, may not provide significant monetary savings for covered entities, with the exception of providing time savings by immediately solving certain routing issues. Instead, financial benefits are expected to be realized mostly downstream, when the HPID is used in coordination with other regulatory and industrial administrative simplification initiatives. Testimony from the July 19, 2010 NCVHS hearing reinforced this idea.

As an analogy, the standardization of the width of railroad tracks does not, in and of itself, result in monetary savings. However, such standardization has ensured connectivity between diverse railroad systems that has resulted in time and cost savings in the movement of freight across the country. In a like manner, standardization of a single data element in health care transactions does not, in and of itself, produce substantial time or cost savings. However, the diverse identifiers currently used by multiple health plans are akin to the different track widths used by various railroad systems. Like the standardization of railroad track widths, the HPID serves as a foundation for more efficient and cost effective transmission of health care information.

In an industry white paper, one health care provider association echoed the foundational importance of the HPID and stated that a standard identifier for health plans is “viewed by many as a crucial step toward one-stop, automated billing.” In the same paper, that association stated that, in order to begin the movement toward automated billing, standard identifiers were needed for more entities with “payer” function than just “health plans,” including entities with primary financial responsibility for paying a particular claim, entities responsible for administering a claim, entities that have the direct contract with the health care provider, and secondary or tertiary payers for the claim.

14

The association went on to contend that fee schedules and plan and product types would need to be identified with this health plan identifier.

14

“National Health Plan Identifier White Paper,” prepared by the American Medical Association (AMA) Practice Management Center (PMC), September 22, 2009.

In this rule, we are not proposing that the HPID or the OEID contain intelligence that would include fee schedules or benefit plans or product types. However, we are proposing that entities other than health plans may get an OEID. We view the adoption of the HPID and the suggested option of an OEID as foundations for the “one-stop, automated billing” that this professional association advocated.

This impact analysis will take these foundational benefits of HPID and, for the sake of illustration, attribute some of the monetary savings from the downstream results to implementation and use of the HPID. It is important to view these estimates as an attempt to illustrate the foundational effect of the HPID rather than as a precise budgetary prediction.

3. Need for a Delay in Implementation of ICD-10, and General Impact of Implementation

The ICD-10 final rule requires covered entities to comply with ICD-10 on October 1, 2013. The provisions of this proposed rule would change the compliance date to October 1, 2014.

The process of transitioning from ICD-9 to ICD-10, if not carefully coordinated, poses significant risk to provider reimbursement. Should health care entities' infrastructure not be ready or thoroughly tested, providers may experience returned claims and delayed payment for the health care services they render to patients. There has been mounting evidence over the past several months that a significant percentage of providers believe they do not have sufficient resources or time to be ready to meet the October 1, 2013 ICD-10 compliance deadline.

Two distinct types of issues are implicated by a transition of this magnitude, and the costs associated with both might be avoided if the ICD-10 compliance date is delayed as proposed in this rule. First, there may be entities that have not readied their systems, personnel, or processes to achieve compliance by October 1, 2013. For example, vendor practice management and/or other software must be updated to process claims with ICD-10 codes, then installed and tested internally. Likewise, staff needs to be trained and systems and forms prepared for the new code set. In a CMS survey conducted in November and December 2011 (hereinafter referred to as the CMS readiness survey), 25% of providers surveyed indicated that they are at risk for not meeting the October 1, 2013 compliance date.

15

In February 2012, the Workgroup for Electronic Data Interchange (WEDI) conducted a survey on ICD-10 readiness (WEDI readiness survey) that indicated that nearly 50 percent of the 2,140 provider respondents did not know when they would complete their impact assessment.

16

An illustration of what could occur if elements of industry are not prepared for the transition to ICD-10 can be seen by the January 1, 2012 transition to Version 5010, where we have heard from several provider organizations reporting numerous practices have not been paid for long periods due to the Version 5010 transition.

15

“Version 5010 and ID-10 Readiness Assessment: Conducted among Health Care Providers, payers, and Vendors for the Centers for Medicare & Medicaid Services (CMS),” December, 2011, Prepared by CMS.

16

“Survey: ICD-10 Brief Progress,” February 2012, conducted by the Workgroup for Electronic Data Interchange (WEDI).

Second, beyond “readine

This text is long and has been trimmed here. Open the source document for the complete record.

This is a copy of a public record, reproduced as it was published. It is not legal advice, and it may not be the version a court would rely on. Check the official source before you cite it.

A word about cookies

We need a few to keep you signed in and the library working. The rest help us see which pages people use and where they get stuck. They stay off unless you say yes.