Get Full Government Meeting Transcripts, Videos, & Alerts Forever!
Get email alerts on the Compliance topic
No spam. Unsubscribe anytime.
Staff flags cybersecurity and mental-health parity compliance risks
Summary
The commission was warned that cybersecurity/data breaches are considered fiduciary issues and that complying with Mental Health Parity and Addiction Equity Act rules will require non-quantitative treatment limitation analyses, contractual changes and data review by plan sponsors.
Get email alerts on the Compliance topic
No spam. Unsubscribe anytime.
Staff told the commission that cybersecurity and data breaches are a fiduciary concern for plan sponsors and that Health and Human Services has issued guidance for HIPAA-covered entities. They also said new MHPAEA rules (if finalized) would impose substantial compliance requirements, including NQTL comparative analyses and additional data and contract language obligations.
Staff recommended plan sponsors and vendors review service-provider contracts and prepare comparative analyses to identify compliance red flags. The report emphasized that achieving parity-compliance documentation and process changes would require work across plan sponsors and vendors.
