Starting a Medical Billing Business > Starting Your Own Medical Billing Business
E & O Ins
Christy:
thank you, ladies! I just got off the phone with the ins rep and she mentioned "cyber liability..." do you have this to protect against PHI becoming breached over the internet?
thanks!
PMRNC:
--- Quote ---thank you, ladies! I just got off the phone with the ins rep and she mentioned "cyber liability..." do you have this to protect against PHI becoming breached over the internet?
--- End quote ---
Don't waste your money. In our business you are required to use ALL of the very top levels of security offered, Your breaches and what you do about them come from your compliance plan. As long as you have a good compliance plan in place with steps to protect you and updated to reflect the addition of HITECH which added penalties to even business associates of covered entities (that would be us) and notification process of breaches. Your general E/O, Quai Tam, or business liability should blanket cover you. Do not make the mistake of thinking E/O or ANY other insurance releases you of liability, it's there to assist with legal fees. It's also like other policies where it excludes certain things like the obvious, fraud/abuse, and even cases where federal or state regs say "YOU should have known", and of course pre-existing conditions/situations. I have a good friend of mine who owned a collection and billing company and one of her employee's was pocketing money and her liability did not cover her or protect her, she ended up losing her surety bond and that led to her having to close her business.
Christy:
thank you, Linda...I will see what the ins rep comes up with in terms of coverage...my main concerns are lawsuit from provider or patient.....and breach of info (cyber or not)
what is more likely to get you in trouble:
the breach itself? or the lack of notification procedures?
If I breached and did everything to the letter regarding notification, etc....could I still get in trouble? less trouble?
PMRNC:
--- Quote ---what is more likely to get you in trouble:
the breach itself? or the lack of notification procedures?
If I breached and did everything to the letter regarding notification, etc....could I still get in trouble? less trouble?
--- End quote ---
Keep in mind these are questions you want to verify with your attorney. BOTH could land you in trouble. NOT doing anything with any breach of course is much worse. It is all according to HOW the breach occured. For example, if you happen to talk to someone about someone elses PHI who does not have the "need to know" that certainly is a purposeful breach much worse than, say, a stolen laptop. If your computer does NOT have login credentials for EACH user in accordance for their "need to know" THAT is a problem that can be corrected BEFORE a breach. A stolen laptop might not be as preventable. So it really depends on the circumstances. Again, this is all to be in your compliance plan. Stating said breaches and how YOUR company handles it on YOUR end.
QueenAlicia:
Linda, you have a good policy! I was looking at mine and I was like I need to upgrade it but the cost of mine for lower coverage is the same price that you are paying :-\
Navigation
[0] Message Index
[#] Next page
[*] Previous page
Go to full version