| name | healthcare-law |
| description | Healthcare law skill for medical and health industry legal matters. Use when the user needs assistance with HIPAA compliance, healthcare regulations, medical malpractice, FDA matters, healthcare transactions, or provider licensing. Triggers on keywords like "HIPAA", "healthcare", "medical", "hospital", "physician", "malpractice", "FDA", "PHI", "patient", "provider", "Medicare", "Medicaid", "Stark", "Anti-Kickback". |
Healthcare Law
This skill provides expert guidance for healthcare regulatory compliance, transactions, and litigation.
Core Capabilities
1. Regulatory Compliance
- HIPAA Privacy and Security
- Fraud and abuse laws
- Licensing and credentialing
- Medicare/Medicaid compliance
2. Healthcare Transactions
- Provider acquisitions
- Joint ventures
- Management agreements
- Ancillary service arrangements
3. Litigation
- Medical malpractice defense
- Regulatory investigations
- Qui tam defense
- Peer review matters
4. Life Sciences
- FDA compliance
- Clinical trials
- Drug/device approvals
- Product liability
HIPAA Compliance
HIPAA Components
| Rule | Scope | Key Requirements |
|---|
| Privacy Rule | Use/disclosure of PHI | Notice, authorization, minimum necessary |
| Security Rule | Electronic PHI safeguards | Administrative, physical, technical |
| Breach Notification | Notification requirements | Individual, HHS, media notification |
| Enforcement Rule | Penalties and procedures | Civil and criminal penalties |
Protected Health Information (PHI)
Individually Identifiable Health Information:
- Past, present, or future physical/mental health
- Provision of healthcare
- Payment for healthcare
- Identifies individual or reasonable basis to identify
18 HIPAA Identifiers:
- Names
- Geographic data
- Dates (except year)
- Phone numbers
- Fax numbers
- Email addresses
- Social Security numbers
- Medical record numbers
- Health plan beneficiary numbers
- Account numbers
- Certificate/license numbers
- Vehicle identifiers
- Device identifiers
- Web URLs
- IP addresses
- Biometric identifiers
- Full-face photographs
- Any other unique identifying number
Privacy Rule Requirements
Permitted Uses Without Authorization:
- Treatment, payment, healthcare operations (TPO)
- Required by law
- Public health activities
- Abuse/neglect reporting
- Health oversight activities
- Judicial proceedings
- Law enforcement (limited)
- Research (with IRB/Privacy Board approval)
Patient Rights:
- Access to PHI
- Amendment of PHI
- Accounting of disclosures
- Request restrictions
- Confidential communications
- Notice of privacy practices
Security Rule Safeguards
Administrative Safeguards:
Physical Safeguards:
Technical Safeguards:
Breach Notification Requirements
| Affected Individuals | Notification Deadline |
|---|
| 1-499 | 60 days of discovery |
| 500+ | 60 days (immediate to media/HHS) |
| HHS | Annual log (under 500); immediate (500+) |
HIPAA Penalties
| Violation Level | Per Violation | Annual Maximum |
|---|
| Did not know | $137-$68,928 | $2,067,813 |
| Reasonable cause | $1,379-$68,928 | $2,067,813 |
| Willful neglect (corrected) | $13,785-$68,928 | $2,067,813 |
| Willful neglect (not corrected) | $68,928 | $2,067,813 |
Healthcare Fraud and Abuse
False Claims Act (31 U.S.C. §3729)
Prohibited Conduct:
- Knowingly presenting false claims
- Knowingly making false statements
- Concealing/avoiding obligation to pay
Scienter: Actual knowledge, deliberate ignorance, or reckless disregard
Penalties:
- Civil penalties: $13,946-$27,894 per claim (2024)
- Treble damages
- Exclusion from federal programs
Anti-Kickback Statute (42 U.S.C. §1320a-7b)
Prohibited: Knowingly and willfully offering, paying, soliciting, or receiving remuneration to induce referrals for services covered by federal healthcare programs.
Elements:
- Remuneration (anything of value)
- Knowingly and willfully
- To induce referrals
- For items/services covered by federal programs
Safe Harbors (Selected):
| Safe Harbor | Key Requirements |
|---|
| Employment | Bona fide employment relationship |
| Personal services | Written agreement, FMV, specified services |
| Space rental | Written agreement, FMV, one year term |
| Equipment rental | Written agreement, FMV, one year term |
| Discounts | Properly disclosed and reflected |
| EHR | ONC-certified technology, conditions met |
| Referral services | Written agreement, conditions met |
Stark Law (42 U.S.C. §1395nn)
Prohibited: Physician referral of designated health services (DHS) to entities with which physician (or family member) has financial relationship, unless exception applies.
Designated Health Services:
- Clinical laboratory services
- Physical therapy
- Occupational therapy
- Radiology and imaging
- Radiation therapy
- Durable medical equipment
- Parenteral and enteral nutrients
- Prosthetics, orthotics, prosthetic devices
- Home health services
- Outpatient prescription drugs
- Inpatient and outpatient hospital services
Exceptions (Selected):
| Exception | Key Requirements |
|---|
| In-office ancillary | Services in same building, supervised |
| Employment | Bona fide employment, FMV compensation |
| Personal services | Written agreement, FMV, commercially reasonable |
| Rental | Written agreement, FMV, exclusive use |
| Isolated transactions | One-time payment, FMV, commercially reasonable |
| Group practice | Meeting all group practice requirements |
Civil Monetary Penalties
| Violation | Per-Violation Penalty |
|---|
| False claim | $11,000-$22,000 |
| Anti-kickback | $100,000 |
| Stark violation | $15,000-$100,000 |
| EMTALA violation | $50,000-$100,000 |
Compliance Programs
OIG Compliance Program Elements
- Written policies and procedures
- Compliance officer and committee
- Training and education
- Communication lines (hotline)
- Internal monitoring and auditing
- Enforcement and discipline
- Response to detected offenses
Compliance Risk Areas
Medical Malpractice
Elements of Medical Malpractice
- Duty: Physician-patient relationship
- Breach: Violation of standard of care
- Causation: Breach caused injury
- Damages: Compensable harm
Standard of Care
- Care that a reasonably prudent healthcare provider would provide
- Same or similar circumstances
- Same specialty and training level
- Expert testimony typically required
Common Defenses
- No breach of standard of care
- No causation (injury would have occurred anyway)
- Comparative negligence
- Statute of limitations
- Assumption of risk
- Good Samaritan laws
- Peer review immunity
Damages
| Type | Description |
|---|
| Economic | Medical expenses, lost wages, future care |
| Non-economic | Pain and suffering, loss of consortium |
| Punitive | Gross negligence or intentional misconduct |
FDA Regulatory Framework
Product Categories
| Category | Regulation | Key Requirements |
|---|
| Drugs | FDCA, NDA/ANDA | Safety and efficacy |
| Biologics | PHSA, BLA | Same + manufacturing |
| Medical devices | FDCA, Class I/II/III | Risk-based regulation |
| Food | FDCA | Safety, labeling |
| Cosmetics | FDCA | Safety, no disease claims |
Drug Approval Process
Preclinical Testing → IND Application →
Phase 1 (Safety) → Phase 2 (Efficacy) → Phase 3 (Confirmation) →
NDA Submission → FDA Review → Approval
Medical Device Classification
| Class | Risk | Regulatory Pathway |
|---|
| I | Low | General controls, most exempt |
| II | Moderate | 510(k) premarket notification |
| III | High | PMA (premarket approval) |
Integration with Other Skills
- compliance-tracking: Healthcare regulatory monitoring
- litigation: Medical malpractice, regulatory defense
- corporate-ma: Healthcare transactions
- contract-lifecycle: Provider agreements
- employment-labor: Credentialing, employment matters
Reference Files
For detailed guidance:
references/hipaa-compliance.md - HIPAA implementation guide
references/stark-analysis.md - Stark exception checklist
references/fda-pathways.md - FDA approval processes