image_pdfimage_print

Cures Act Provides World of Opportunity for Healthcare Innovation but Requires Providers to Read the Fine Print

Main Points:
• On Dec. 13, President Obama signed the 21st Century Cures Act (the Cures Act) into law, boosting healthcare research dollars, streamlining the Food and Drug Administration (FDA)’s drug and medical device approvals processes, and advancing mental health and addiction treatments.
• The Cures Act included $500 million in funding to the FDA to:
– modernize clinical trials and the ways safety and efficacy data is analyzed
– streamline regulations so the process for securing approvals on medical devices, technologies, vaccines and regenerative medicine therapies is more efficient and
– provide the FDA with greater flexibility in reviewing and approving medical devices if they provide first-of-a-kind technologies.
• It also allocated resources aimed at improving the interoperability of electronic health records (EHR) systems and improving providers’ education on the latest medical technologies.
 
BDO’s Diagnosis
The law underlined the government’s focus on expediting the development of cures for serious diseases that are not only devastating to patients, but also add up to a significant share of the total cost of healthcare nationally.
 
It also continues to warrant special attention where compliance is concerned, and providers should closely monitor and address certain components more than others. In the context of patient care innovation, these include:
• Expedited FDA approvals: While Cures opened new (and quicker) avenues to secure drug and medical device approvals—and knocked down the regulatory obstacle to quicker medical innovation—it also left greater risk for product discrepancies to slip through the cracks.
• Cybersecurity: With new types of risk to medical devices stemming from cybersecurity and greater regulatory scrutiny under the False Claims Act, providers should put internal controls in place to adequately assess the quality of drugs and devices before prescribing them to patients. Because the law requires the FDA to consider real-world evidence in making approval decisions, providers should incorporate this data into their internal controls and choose their partners accordingly. The new law promotes innovation in the medical device area, and thus, the industry will see a significant increase in new vendors. While organizations should continue to pursue partnerships with vendors who can provide innovative ways to enhance patient treatment and satisfaction, they should do so with a healthy dose of cautious optimism. With a proliferation of new opportunities to expedite innovation, not all vendors will have appropriate policies, procedures and internal controls in place to ensure compliance with the CMS and state regulations, and, most importantly, patient safety.
 
Today’s BDO Pulse Check
In this environment of technology infiltration and faster innovation, health organizations—private and public alike—share the responsibilities of improving the quality of outcomes, bringing down care costs and collaborating within and beyond their traditional supply chains.
 
But they must not forget the importance of managing risk, and protecting patient safety, in the process.
With no warning system to communicate health alerts and recalls to patients and health providers across national borders, due diligence is a critical step when partnering with vendors to identify new innovative techniques and devices to pursue.
 
Looking into approval processes for new products, quality control management and process for securing FDA approvals are key. They must also take a closer look at their internal compliance controls, paying close attention to potential FCA and cybersecurity scrutiny. Typical examples of false claims include improper billings, paying physicians for referrals or kickbacks, ghost patients, up-coding of services and services not rendered but billed. But the expanse of the FCA has been considerable since its inception.
 
Under the cybersecurity lens, if an organization bills for services rendered but the quality of those services is non-compliant with security requirements—or if it is aware of a potential vulnerability but fails to disclose it—the organization might be deemed non-compliant with the FCA. For an FDA-regulated medical device manufacturer, consequences could also include a costly device recall and having to resubmit the device for FDA approval.
 
When it comes down to it, the consumer is the epicenter of all concern. Medical devices alone were linked to almost 83,000 deaths and 1.7 million injuries in the last 10 years, the ICIJ found. The ultimate cost of non-compliance—and the goal of improving innovation while still maintaining the proper level of risk management—is patient safety.