3 New Unintended Consequences of Health Care Reform
As the Affordable Care Act (ACA) continues its gradual and bumpy rollout, health care providers are utilizing various strategies to comply and adapt. Many of these approaches, some of which include M&A activity, IT upgrades and shared service agreements are now creating new risks of their own.
1. Continuity of Care
Many aspects of the ACA and other healthcare trends are driving M&A or shared service agreements among hospitals, physicians and other providers. These new relationships can present serious challenges for managing a patient’s treatment across different organizations.
“There’s a risk that one organization might not provide care consistent with the other,” said Dan Nash, national healthcare practice leader, Zurich in North America. “Oftentimes, it’s not contractually required for them to do so.”
Patients being transferred from system to system might be exposed to different approaches to care and different levels of treatment.
Care managers can do a lot to help alleviate risks associated with continuity of care. Having a “concierge” that knows how each system operates can make transitions much easier for patients and explain why treatments differ from system to system.
“There’s a risk that one organization will not provide care consistent with the standards of the other. Oftentimes, it’s not contractually required for them to do so.”
— Dan Nash, National Healthcare Practice Leader, Zurich North America
“It creates a feeling that they’re working together,” said Dan Nash, national healthcare practice leader, Zurich in North America. “If you have a care manager through the process, it can give the patient a level of comfort that takes away anxiousness,” said Nash. “Then they feel like they’re being taken care of.”
Between the Health Insurance Portability and Accountability Act, the U.S. Department of Health and Human Services and a long list of other government organizations and mandates, there are serious demands on health systems.
“Real estate may be all about location, location, location but healthcare is all about compliance, compliance, compliance,” said Nash.
A lot of risk managers are focused on digital-related exposures, but a significant amount of serious data breaches are still the result of “paper losses.”
“One example happened on a subway in 2009 when a hospital worker left records for 192 patients on a train,” said Nash about an incident involving a mid-Atlantic hospital “It led to the hospital paying $1 million to the government in 2011 to settle the potential HIPAA violations.”
Despite the risks, health care providers are still reluctant to buy coverage around it.
“People used to look at banks with an eye toward their brick-and-mortar locations. ‘My money is safe because it’s housed within those walls,’ they’d think. While that thinking is antiquated when dealing with finances, it still rings true in the health care world,” said Nash.
“Often customers we talk to say it’s important, but not in budget this year,” said Nash. Furthermore, their IT departments seem to think they’ve got the problem figured out on the digital side and companies generally don’t pay enough attention to the possibility of paper losses.
To help combat the risk, Zurich offers to qualified customers a Breach Coach consulting service, during which an experienced cyber breach risk engineering consultant can assess where businesses are most vulnerable to a data loss.
3. Outpatient Treatment
Currently, 60% of hospital services are delivered inpatient with 40% of care delivered through outpatient facilities. Under the Affordable Care Act, the proportion will likely be reversed, so that 60% of care is delivered through outpatient facilities.
“It’s risky because patients generally see hospitals as places where they are safer in the event of an adverse reaction,” said Nash. “They might not have that same sense of security with an outpatient facility.
Nash compared that notion to the way many Americans thought about banks 20 or 30 years ago.
“People used to look at banks with an eye toward their brick-and-mortar locations. ‘My money is safe because it’s housed within those walls,’ they’d think. While that thinking is antiquated when dealing with finances, it still rings true in the health care world,” said Nash. “People feel safer and think they’re getting better care if they’re in a large hospital. At an outpatient facility, that comfort level isn’t the same.”
Another risk of having more outpatient procedures is that the health care provider has less time for observing patients. With patients going home after their procedure, it becomes even more important for the patient to carefully follow instructions: like taking medicine at scheduled times and doing proper rehab. Any health care provider can tell you that’s never guaranteed. But even if they don’t follow the care instructions, the hospital is still responsible.
This article was produced by Zurich and not the Risk & Insurance® editorial team.
Note: This content is provided for informational purposes only. Please consult with qualified legal counsel to address your particular circumstances and needs. Neither Risk & Insurance® nor Zurich are providing legal advice and assume no liability concerning the information set forth above.
Coping with Cancellations
Airlines typically can offset revenue losses for cancellations due to bad weather either by saving on fuel and salary costs or rerouting passengers on other flights, but this year’s revenue losses from the worst winter storm season in years might be too much for traditional measures.
At least one broker said the time may be right for airlines to consider crafting custom insurance programs to account for such devastating seasons.
For a good part of the country, including many parts of the Southeast, snow and ice storms have wreaked havoc on flight cancellations, with a mid-February storm being the worst of all. On Feb. 13, a snowstorm from Virginia to Maine caused airlines to scrub 7,561 U.S. flights, more than the 7,400 cancelled flights due to Hurricane Sandy, according to MasFlight, industry data tracker based in Bethesda, Md.
Roughly 100,000 flights have been canceled since Dec. 1, MasFlight said.
Just United, alone, the world’s second-largest airline, reported that it had cancelled 22,500 flights in January and February, 2014, according to Bloomberg. The airline’s completed regional flights was 87.1 percent, which was “an extraordinarily low level,” and almost 9 percentage points below its mainline operations, it reported.
And another potentially heavy snowfall was forecast for last weekend, from California to New England.
The sheer amount of cancellations this winter are likely straining airlines’ bottom lines, said Katie Connell, a spokeswoman for Airlines for America, a trade group for major U.S. airline companies.
“The airline industry’s fixed costs are high, therefore the majority of operating costs will still be incurred by airlines, even for canceled flights,” Connell wrote in an email. “If a flight is canceled due to weather, the only significant cost that the airline avoids is fuel; otherwise, it must still pay ownership costs for aircraft and ground equipment, maintenance costs and overhead and most crew costs. Extended storms and other sources of irregular operations are clear reminders of the industry’s operational and financial vulnerability to factors outside its control.”
Bob Mann, an independent airline analyst and consultant who is principal of R.W. Mann & Co. Inc. in Port Washington, N.Y., said that two-thirds of costs — fuel and labor — are short-term variable costs, but that fixed charges are “unfortunately incurred.” Airlines just typically absorb those costs.
“I am not aware of any airline that has considered taking out business interruption insurance for weather-related disruptions; it is simply a part of the business,” Mann said.
Chuck Cederroth, managing director at Aon Risk Solutions’ aviation practice, said carriers would probably not want to insure airlines against cancellations because airlines have control over whether a flight will be canceled, particularly if they don’t want to risk being fined up to $27,500 for each passenger by the Federal Aviation Administration when passengers are stuck on a tarmac for hours.
“How could an insurance product work when the insured is the one who controls the trigger?” Cederroth asked. “I think it would be a product that insurance companies would probably have a hard time providing.”
But Brad Meinhardt, U.S. aviation practice leader, for Arthur J. Gallagher & Co., said now may be the best time for airlines — and insurance carriers — to think about crafting a specialized insurance program to cover fluke years like this one.
“I would be stunned if this subject hasn’t made its way up into the C-suites of major and mid-sized airlines,” Meinhardt said. “When these events happen, people tend to look over their shoulder and ask if there is a solution for such events.”
Airlines often hedge losses from unknown variables such as varying fuel costs or interest rate fluctuations using derivatives, but those tools may not be enough for severe winters such as this year’s, he said. While products like business interruption insurance may not be used for airlines, they could look at weather-related insurance products that have very specific triggers.
For example, airlines could designate a period of time for such a “tough winter policy,” say from the period of November to March, in which they can manage cancellations due to 10 days of heavy snowfall, Meinhardt said. That amount could be designated their retention in such a policy, and anything in excess of the designated snowfall days could be a defined benefit that a carrier could pay if the policy is triggered. Possibly, the trigger would be inches of snowfall. “Custom solutions are the idea,” he said.
“Airlines are not likely buying any of these types of products now, but I think there’s probably some thinking along those lines right now as many might have to take losses as write-downs on their quarterly earnings and hope this doesn’t happen again,” he said. “There probably needs to be one airline making a trailblazing action on an insurance or derivative product — something that gets people talking about how to hedge against those losses in the future.”
Hot Hacks That Leave You Cold
Thousands of dollars lost at the blink of an eye, and systems shut down for weeks. It might sound like something out of a movie, but it’s becoming more and more of a reality thanks to modern hackers. As technology evolves and becomes more sophisticated, so do the occurrence of cyber breaches.
“The more we rely on technology, the more everything becomes interconnected,” said Jackie Lee, associate vice president, Cyber Liability at Nationwide. “We are in an age where our car is a giant computer, and we can turn on our air conditioners with our phones. Everyone holds data. It’s everywhere.”
Phishing Out Fraud
According to Lee, phishing is on the rise as one of the most common forms of cyber attacks. What used to be easy to identify as fraudulent has become harder to distinguish. Gone are the days of the emails from the Nigerian prince, which have been replaced with much more sophisticated—and tricky—techniques that could extort millions.
“A typical phishing email is much more legitimate and plausible,” Lee said. “It could be an email appearing to be from human resources at annual benefits enrollment or it could be a seemingly authentic message from the CFO asking to release an invoice.”
According to Lee, the root of phishing is behavior and analytics. “Hackers can pick out so much from a person’s behavior, whether it’s a key word in an engagement survey or certain times when they are logging onto VPN.”
On the flip side, behavior also helps determine the best course of action to prevent phishing.
“When we send an exercise email to test how associates respond to phishing, we monitor who has clicked the first round, then a second round,” she said. “We look at repeat offenders and also determine if there is one exercise that is more susceptible. Once we understand that, we can take the right steps to make sure employees are trained to be more aware and recognize a potentially fraudulent email.”
Lee stressed that phishing can affect employees at all levels.
“When the exercise is sent out, we find that 20 percent of the opens are from employees at the executive level,” she said. “It’s just as important they are taking the right steps to ensure they are practicing what they are preaching.”
Locking Down Ransomware
Another hot hacking ploy is ransomware, a type of property-related cyber attack that prevents or limits users from accessing their system unless a ransom is paid. The average ransom request for a business is around $10,000. According to the FBI, there were 2,400 ransomware complaints in 2015, resulting in total estimated losses of more than $24 million. These threats are expected to increase by 300% this year alone.
“These events are happening, and businesses aren’t reporting them,” Lee said.
In the last five years, government entities saw the largest amount of ransomware attacks. Lee added that another popular target is hospitals.
After a recent cyber attack, a hospital in Los Angeles was without its crucial computer programs until it paid the hackers $17,000 to restore its systems.
Lee said there is beginning to be more industry-wide awareness around ransomware, and many healthcare organizations are starting to buy cyber insurance and are taking steps to safeguard their electronic files.
“A hospital holds an enormous amount of data, but there is so much more at stake than just the computer systems,” Lee said. “All their medical systems are technology-based. To lose those would be catastrophic.”
And though not all situations are life-or-death, Lee does emphasize that any kind of property loss could be crippling. “On a granular scale, you look at everything from your car to your security system. All data storage points could be controlled and compromised at some point.”
The Future of Cyber Liability
According to Lee, the Cyber product, which is still in its infancy, is poised to affect every line of business. She foresees underwriting offering more expertise in crime and becoming more segmented into areas of engineering, property, and automotive to address ongoing growing concerns.”
“Cyber coverage will become more than a one-dimensional product,” she said. “I see a large gap in coverage. Consistency is evolving, and as technology evolves, we are beginning to touch other lines. It’s no longer about if a breach will happen. It’s when.”
About Nationwide’s Cyber Solutions
Nationwide’s cyber liability coverage includes a service-based solution that helps mitigate losses. Whether it’s loss prevention resources, breach response and remediation expertise, or an experienced claim team, Nationwide’s comprehensive package of services will complement and enhance an organization’s cyber risk profile.
Nationwide currently offers up to $15 million in limits for Network Security, Data Privacy, Technology E&O, and First Party Business Interruption.
Products underwritten by Nationwide Mutual Insurance Company and Affiliated Companies. Not all Nationwide affiliated companies are mutual companies, and not all Nationwide members are insured by a mutual company. Subject to underwriting guidelines, review, and approval. Products and discounts not available to all persons in all states. Home Office: One Nationwide Plaza, Columbus, OH. Nationwide, the Nationwide N and Eagle, and other marks displayed on this page are service marks of Nationwide Mutual Insurance Company, unless otherwise disclosed. © 2016 Nationwide Mutual Insurance Company.
This article was produced by the R&I Brand Studio, a unit of the advertising department of Risk & Insurance, in collaboration with Nationwide. The editorial staff of Risk & Insurance had no role in its preparation.