Practical knowledge from people who do the work.
Medical billing, coding, denials, credentialing, PCMH and practice operations, written to be useful on Monday morning.
HIPAA Security Risk Analysis for a Small Practice: How to Do One That Holds Up
OCR says a missing or inadequate risk analysis shows up in most of its Security Rule enforcement actions, and since October 2024 it has run an initiative aimed at that failure. Here is how a small practice actually does one: the inventory, the threat list, the scoring, the document and the plan.
MIPS 2026 Final Policies: The 75-Point Threshold Stays and Six New MVPs Arrive
The 2026 Quality Payment Program policies were finalized with the Physician Fee Schedule on October 31, 2025. The performance threshold stays at 75 points through 2028, six new MVPs arrive, and traditional MIPS survives for now. Here is what to decide before January and what the 2025 submission window looks like.
MIPS 2025 Midyear Checkpoint: Eligibility, PI Window and Quality Completeness
The 2025 MIPS performance year has a 75-point threshold and a penalty of up to 9 percent on 2027 Medicare payments. Late July is the last realistic moment to fix eligibility, Promoting Interoperability and quality data problems. Here is the checklist we run with practices.
MIPS 2024 Data Submission Closes March 31, 2025: A Last-Month Checklist
The 2024 MIPS performance year submission window closes March 31, 2025 at 8 p.m. Eastern, and a missed submission can mean a payment cut of up to 9 percent on 2026 Medicare Part B claims. Here is how we work through the last four weeks without surprises, including what small practices get automatically.
OCR's Proposed HIPAA Security Rule: What Small Practices Should Know and Do
HHS published a proposed rewrite of the HIPAA Security Rule on January 6, 2025, with comments due March 7. Mandatory multifactor authentication, required encryption, a documented asset inventory and a 72-hour restore target are on the list. Here is what it means for an independent practice.
Telehealth Extended to March 31 and a Proposed HIPAA Security Rule Overhaul
Congress extended Medicare telehealth flexibilities through March 31, 2025 in the December 21 funding law, three months instead of the two years an earlier draft promised. Six days later OCR proposed the first major HIPAA Security Rule update since 2013. Here is what each means for the first quarter.
Change Healthcare Breach Notifications Have Begun: What to Decide Now
Change Healthcare started mailing breach letters on June 20 and posted a substitute notice on its website. OCR has said covered entities may delegate notification to Change, but the obligation stays with you. Here is the decision to make, the clock that runs, the record to keep, and what to tell patients who call.
Two Rules in Two Days: HIPAA Reproductive Privacy and the FTC Noncompete Vote
On April 22, 2024, HHS finalized new HIPAA privacy protections for reproductive health information with a December 23 compliance date. On April 23, the FTC voted 3 to 2 to ban most noncompete clauses. Here is what each rule requires, who it reaches, and what a practice should do before summer.
The HHS Cybersecurity Concept Paper: What a Small Practice Should Take From It
On December 6, 2023, HHS published a concept paper on cybersecurity for the health sector: voluntary performance goals, hospital incentives, a HIPAA Security Rule update and enforceable standards. Most of it targets hospitals. Here is what an independent practice should do anyway.
Page 5 of 6 · 46 articles
Want this level of attention on your own revenue cycle?
The same people who write these articles run billing, coding, denial management and credentialing for practices nationwide.