43,753 sections across 2,186 Washington regulatory chapters.
R.182-600-182-600-0500 Program integrity—Activities.
1.8K chars
(1) The health care authority (HCA) ensures preauthorized LTSS services are provided through service verification and audits and recoups any inappropriate payments and refers potential fraud to law enforcement.(2) Methods. Program integrity activity methods include, but are not l…
R.182-600-182-600-0600 Program integrity—Outcomes.
1.0K chars
(1) When the health care authority (HCA) completes the review under WAC 182-600-0500, HCA may do any of the following:(a) Deny and recover improperly paid claims;(b) Instruct the LTSS provider to submit additional information or submit a new claim;(c) Issue a final notice assessi…
R.182-600-182-600-0700 Administrative hearing.
0.8K chars
(1) The administrative hearing process is governed by chapters 34.05 RCW and 182-526 WAC.(2) An LTSS provider who disagrees with the health care authority's (HCA) action to recoup inappropriate payments under RCW 50B.04.020 (2)(b) may request an administrative hearing under chapt…
R.182-70-182-70-010 Purpose.
1.3K chars
(1) Chapter 43.371 RCW establishes the framework for the creation and administration of a statewide all-payer health care claims database.(2) RCW 43.371.020 directs the health care authority to establish a statewide all-payer health care claims database to support transparent pub…
R.182-70-182-70-020 Definitions required by chapter 43.371 RCW.
3.7K chars
The following definitions apply throughout this chapter unless the context clearly indicates another meaning."Allowed amount" means the maximum dollar amount contractually agreed to for an eligible health care service covered under the terms of an insurance policy, health benefit…
R.182-70-182-70-030 Additional definitions authorized by chapter 43.371 RCW.
6.8K chars
The following additional definitions apply throughout this chapter unless the context clearly indicates another meaning."Authority" means the Washington state health care authority."Capitation payment" means a payment model where providers receive a payment on a per "covered pers…
R.182-70-182-70-040 Registration requirements.
2.1K chars
(1) Washington covered persons threshold for data suppliers. Any carrier, third-party administrator, public program, or other potential data supplier identified in RCW 43.371.030 with 1000 or more Washington covered persons, as defined in WAC 182-70-030, as of December 31st of th…
R.182-70-182-70-050 Data submission schedule.
3.5K chars
(1) Data suppliers shall submit the required health care data in accordance with the schedule provided in this section.(2) Test file.(a) At least sixty calendar days prior to the data suppliers' first required submission, the lead organization will notify the data supplier in wri…
R.182-70-182-70-060 Historical data submission.
1.9K chars
(1) The purpose of collecting historical data into the WA-APCD is to permit the systematic analysis of the health care delivery system including evaluation of the effectiveness of the Patient Protection and Affordable Care Act signed into law on March 23, 2010.(2) The lead organi…
R.182-70-182-70-070 Data submission guide.
1.3K chars
(1) Data files and claim files shall be submitted to the WA-APCD in accordance with the requirements set forth in this chapter and the data submission guide.(2) The lead organization shall develop the data submission guide with input from stakeholders. The lead organization shall…
R.182-70-182-70-080 Waivers and extensions.
3.3K chars
(1) The authority may grant a waiver of reporting requirements or an extension of time to a reporting requirement deadline based on extenuating circumstances.(2) Waivers.(a) A data supplier may request a waiver from submission for a period of time due to extenuating circumstances…
R.182-70-182-70-090 Penalties for failure to comply with reporting requirements.
2.9K chars
(1) The authority may assess fines for failure to comply with the requirements of this chapter including, but not limited to:(a) General reporting requirements.(b) Health care claim files and data files requirements.(c) Health care claim files and data files submission requiremen…
R.182-70-182-70-100 Administrative review.
1.4K chars
(1) Data suppliers may request an administrative review of an authority decision to deny a request for an extension or waiver, or an assessment of a fine.(2) A request for an administrative review may be initiated by a written petition filed with the authority within thirty calen…
R.182-70-182-70-110 Appeals.
0.6K chars
A data supplier may request an appeal of a denial of its administrative review conducted in accordance with WAC 182-70-100. See WAC 182-526-0205.[Statutory Authority: RCW 41.05.021, 41.05.160, 43.71C.110, and 2019 c 334. WSR 21-11-039, § 182-70-110, filed 5/12/21, effective 6/12/…
R.182-70-182-70-200 General data request and release procedures.
1.5K chars
(1) The lead organization must adopt clear policies and procedures for data requests and data release. At a minimum, the lead organization, in coordination with the data vendor, must develop procedures for making a request for data, how data requests will be reviewed, how decisio…
R.182-70-182-70-210 Procedures for data requests.
3.3K chars
(1) The lead organization must use an application process for data requests.(2) In addition to the requirements in RCW 43.371.050(1), at a minimum, the application must require the following information:(a) Detailed information about the project for which the data is being reques…
R.182-70-182-70-220 Data management plan.
2.7K chars
(1)(a) The lead organization must require data requestors to submit data management plans with the data request application. Data management plans must comply with the Washington state office of chief security officer standards.(b) Additional organizations that are involved in us…
R.182-70-182-70-230 Review of data requests.
2.9K chars
(1) The lead organization must establish a transparent process for the review of data requests, which includes a process for public review for specific requests. The process must include a timeline for processing requests, and notification procedures to keep the requestor updated…
R.182-70-182-70-240 Data release.
2.1K chars
(1) Upon approval of a request for data, the lead organization must provide notice to the requestor. The notice must include the following:(a) The data use agreement (DUA). The DUA will include a confidentiality statement to which the requesting organization or individual must ad…
R.182-70-182-70-250 Data use agreement.
3.0K chars
(1) The lead organization must develop a standard data use agreement. The authority must approve the final form of the DUA, and all substantial changes to the form.(2) At a minimum, the DUA shall include the following provisions:(a) A start date and end date. The end date must be…
R.182-70-182-70-260 Confidentiality agreement.
1.7K chars
(1) The lead organization must develop a standard confidentiality agreement, as required, before data may be released. The authority must approve the final form for confidentiality agreement, and all substantial changes to the form.(2) The confidentiality agreement must be signed…
R.182-70-182-70-270 Data procedures at the end of the project.
1.0K chars
(1) Upon the end of the project or the termination of the data use agreement, the data recipient shall destroy all WA-APCD data. The data recipient must provide to the lead organization an attestation that the data has been destroyed according to the required standards set forth …
R.182-70-182-70-280 Reasons to decline a request for data.
2.7K chars
The lead organization may decline a request for data for any of the following reasons:(1) The requestor has violated a data use agreement, nondisclosure agreement or confidentiality agreement within three years of the date of request.(2) Any person, other than the requestor, who …
R.182-70-182-70-290 Process to review a declined data request.
1.6K chars
(1) A data requestor may request an administrative review of the lead organization's decision to deny a request for data.(2) A request for an administrative review may be initiated by a written petition filed with the authority and also provided to the lead organization within th…
R.182-70-182-70-300 Process to appeal of final denial of data request.
2.9K chars
(1) A data requestor may appeal the denial of its administrative review conducted in accordance with WAC 182-70-290.(2) Request for an appeal must be submitted in writing to the authority within fifteen calendar days after receipt of written notification of denial of its administ…
R.182-70-182-70-400 Privacy and security.
0.8K chars
(1) RCW 43.371.070 (1)(d) authorizes the director of the health care authority to adopt rules providing procedures for ensuring that all data received from data suppliers are securely collected and stored in compliance with applicable state and federal law.(2) RCW 43.371.070 (1)(…
R.182-70-182-70-410 Requirements for data vendor.
2.9K chars
(1) The data vendor must enter into an agreement with the lead organization that contains the following requirements:(a) A provision that the data vendor is responsible for ensuring compliance of all aspects of WA-APCD operations with all applicable federal and state laws, and th…
R.182-70-182-70-420 Data submission.
1.2K chars
(1) All data suppliers must submit data to the WA-APCD using a secure transfer protocol and transmission approach approved by the office of the state chief information security officer.(2) All data suppliers must encrypt data using the latest industry standard methods and tools f…
R.182-70-182-70-430 WA-APCD infrastructure.
1.0K chars
(1) The data vendor must limit access to the secure site. Personnel allowed access must be based on the principle of least privilege and have an articulable need to know or access the site.(2) The data vendor must conduct annual penetration testing and have specific requirements …
R.182-70-182-70-440 Accountability.
1.2K chars
(1) The data vendor must submit an annual report to the lead organization, the authority, and the office of the state chief information security office that includes the following information:(a) Summary results of its independent security assessment; and(b) Summary of its penetr…
R.182-70-182-70-450 Data vendor and lead organization compliance with privacy and security requirements.
2.2K chars
(1) To ensure compliance with privacy and security requirements, the data vendor must immediately report to the authority and the office of the state chief information security officer any data breach of the WA-APCD or knowledge that a data recipient is not complying with confide…
R.182-70-182-70-460 Additional requirements.
0.6K chars
(1) The data vendor will ensure access to the WA-APCD data is strictly controlled and limited to authorized staff with appropriate training, clearance, background checks, and confidentiality agreements.(2) All data vendor employees who are provided access to data submitted to the…
R.182-70-182-70-470 State oversight of compliance with privacy and security requirements.
0.8K chars
In order to ensure compliance with privacy and security requirements and procedures, the authority or the office of chief information officer or both may request from the lead organization any or all of the following:(1) Audit logs pertaining to accessing the WA-APCD data;(2) Com…
R.182-70-182-70-500 Additional definitions related to the format for the calculation and display of data.
1.8K chars
The following additional definitions apply throughout this chapter unless the context clearly indicates another meaning. These definitions are related to the rules regarding the format for the calculation and display of cost data.(1) "Aggregate cost data" means data collected fro…
R.182-70-182-70-510 Data formatting rules apply to proprietary financial information.
1.6K chars
(1) The format rules apply to all proposed uses of proprietary financial information submitted to the WA-APCD. The format rules apply to three categories of users for which proprietary financial information may be disclosed in accordance with chapter 43.375 RCW:(a) Lead organizat…
R.182-70-182-70-520 Elements to safeguard the use of proprietary financial information.
1.6K chars
All reports, analytics or other information drawn from the WA-APCD that an approved WA-APCD data user as defined in WAC 182-70-510(1) shares with any third party shall comply with the following restrictions.(1) Allowed amount data may be made available for public use.(2) Allowed …
R.182-70-182-70-550 Requirement for fee schedules and processes.
0.8K chars
(1) RCW 43.371.020 (5)(g) requires the lead organization to develop a plan for the financial sustainability of the database, and charge fees for reports and data files to fund the database.(2) The authority must approve any fee established by the lead organization.(3) RCW 43.371.…
R.182-70-182-70-560 Process to establish fee schedules.
2.8K chars
(1) The lead organization must develop a draft fee schedule consistent with the requirements in RCW 43.371.020 (5)(g). The lead organization must maintain documentation that supports the development of and final decisions regarding the fee schedule.(2) The lead organization must …
R.182-70-182-70-570 Process to modify fee schedules.
3.4K chars
(1) Fee schedules shall be reissued no less frequently than on an annual basis. The reissuance of the fee schedule can include maintaining the fee schedule without modification, modifying the fee schedule, or a combination of these two actions.(2) The lead organization shall revi…
R.182-70-182-70-600 Causes for penalties.
1.2K chars
(1) The authority may impose penalties for the inappropriate disclosure or use of direct patient identifiers, indirect patient identifiers, and proprietary financial information received from, provided to, or contained in the WA-APCD.(2) Any penalty imposed pursuant to this subch…
R.182-70-182-70-605 Alleging a violation.
0.9K chars
(1) Any person, as defined in WAC 182-70-030, may bring to the attention of the lead organization or the authority information concerning the inappropriate disclosure or use of protected information as set forth in RCW 43.371.050 and WAC 182-70-600.(2) The authority must conduct …
R.182-70-182-70-610 Complaints.
3.3K chars
(1) Any complaint filed pursuant to WAC 182-70-605 must be in writing and include the following information, if known:(a) The name and contact information of the complainant;(b) The specific facts supporting the violation alleged, including the dates, and locations for all events…
R.182-70-182-70-615 Investigation.
2.5K chars
(1) If the authority accepts a complaint and conducts an investigation, the authority will notify the person(s) that is the subject of the complaint in writing.(2) The notice will include the following information:(a) The factual allegations supporting each alleged inappropriate …
R.182-70-182-70-620 Notice of violation and recommended penalty.
2.3K chars
(1) If, based on the investigation, the WA-APCD program director determines that the facts support finding an inappropriate disclosure or use of protected information and imposition of a penalty as set forth in the investigation report, the WA-APCD program director shall notify t…
R.182-70-182-70-625 Monetary penalties that may be imposed upon finding a violation of inappropriate disclosures or uses.
1.2K chars
(1) If a person has been found to have made inappropriate disclosures or uses of direct patient identifiers, indirect patient identifiers, and proprietary financial information received from the WA-APCD, the director may impose one or more of the following monetary penalties:(a) …
R.182-70-182-70-630 Nonmonetary penalties that may be imposed upon finding a violation of inappropriate disclosures or uses.
2.0K chars
In addition to the monetary penalties set forth in WAC 182-70-625, if a person has been found to have made inappropriate disclosures or uses of direct patient identifiers, indirect patient identifiers, and proprietary financial information received from the WA-APCD, the director …
R.182-70-182-70-635 Penalty ranges based on culpability.
2.2K chars
(1) In determining the appropriate sanction, including the amount of any civil penalty, the director will consider the level of culpability associated with the violation. The levels of culpability, in the order of less severe to severe, are as follows:(a) Did not know. The person…
R.182-70-182-70-640 Other factors that may be considered in determining the penalty for a violation of this chapter.
3.3K chars
In addition to the culpability category set forth in WAC 182-70-635, to determine the penalty amount, the director may consider the following factors:(1) The nature and extent of the violation including, but not limited to, the number of persons affected, the duration of the viol…
R.182-70-182-70-645 Process to appeal determination of a violation and assessed penalties.
1.2K chars
(1) Each person to whom a notice of a violation and recommended penalty is issued may request a hearing to be conducted in accordance with WAC 182-70-655.(2) The request for a hearing must be submitted to the director in writing within thirty days after receipt of written notific…
R.182-70-182-70-650 Informal dispute resolution prior to a hearing.
2.1K chars
(1) The following procedures are available for informal dispute resolution prior to a hearing that may make more elaborate proceedings under the Administrative Procedure Act unnecessary.(2) Settlements. Any appeal of a notice of violation and recommended penalty before the direct…