In May of this year ’09, new federal regulations entitled: The Identity Theft Red Flags and Address Discrepancies Under the Fair and Accurate Credit Transactions Act of 2003 (a/k/a “Red Flag Regulations”) will be enacted. The Federal Trade Commission (FTC) has taken the stance that it applies to all financial organizations and creditors including physicians and other healthcare providers for safe guarding patient’s financial information. It requires these entities to enact policies and procedures to protect, detect and respond to identity theft. Some of the requirements may have already been addressed through providers addressing protected health information (PHI) of their patients. Nevertheless, one needs to consult with appropriate experts not to be caught out of compliance with this federal regulation.

The FTC has stated that Red Flag Regulations apply to any entity that establishes an on-going relationship to provide goods or services for personal, family, or household purposes with the expectation of subsequent payment or allowances for multiple payments for services rendered or goods previously provided. Generally, healthcare services are rendered with the reasonable expectation of subsequent payment. Therefore, healthcare services involve more than a single encounter, and providers often accept multiple payments. Given these general guidelines and characteristics of a typical healthcare transaction, nearly all healthcare providers (both for-profit and N-F-P) will meet the definition of a “creditor” that maintains on-going accounts and will be subject to the Red Flag Regulations.

Specifically the regulations requires all covered entities to implement a written program approved by the board of directors tailoring its program to address their specific operations, circumstances, and risks. However, at a minimum each program must contain: (i) identify relevant Red Flags for covered accounts and incorporate those Red Flags into the program; (ii) detect Red Flags that have been incorporated into the program; (iii) respond appropriately to any Red Flags that are detected to prevent and mitigate against identity theft; and (iv) ensure that the program is updated periodically, to ensure ongoing reasonable prevention, detection and response to identity theft.

All that being said it’s time to get with your Managers, Software providers, and other consultants to steer your organizations around the rocky shoal these new regulations present to your organization.