No, companies almost never manage the claims themselves. They underwrite the plans, but managing claims is cost-prohibitive, as it's outside the core competency of most large companies.
https://www.newyorker.com/news/amy-davidson/whose-distressed...
Self-insured doesn't mean they manage claims themselves. For most companies, managing claims would be cost-prohibitive and an absurdly wasteful use of resources.
Yes
> That doesn’t mean people in HR and Finance don’t have visibility into claims data.
I mean, this is technically a true statement - "A does not necessarily imply not-B" - but kind of irrelevant, because as it turns out, HR and finance generally do not have visibility into individual-level claims data (as opposed to aggregate data, which is necessary for underwriting).
I’m not suggesting that there’s a team of employees watching you every time you pick up a prescription, but of course they could access an individual claim if there was a legitimate reason to. Not sure why it’s so unbelievable to think that an insurer would be legally barred from doing so if they are literally taking on the risk themselves, even if it is to audit the TPA to make sure they aren’t stealing from them.
If you are an extremely ill employee and you’re using a lot of healthcare your employer will know without you needing to inform them.
I'm not debating with you but somehow, Tim Armstrong (then CEO of AOL) found out about healthcare claims for one of his employees.[1] The story isn't clear on whether the granularity of the claims data would reveal to Tim who the particular employee was. (Even if Tim didn't know the exact employee, I'm sure he could ask a few questions and/or look at employees' sick day records to figure out which employee it was. If the company pays $1 million in a health claim, that's not necessarily going to stay a secret.)
[1] https://slate.com/human-interest/2014/02/tim-armstrong-blame...
[1] https://slate.com/human-interest/2014/02/tim-armstrong-blame...
For the most part people can't seem to distinguish claims data vs healthcare records...its pretty scary as these are the most likely people to receive funding to "disrupt" the health care industry.
Claims data is not equal to medical records, but to your point it is extremely valuable data and can easily act as a proxy for medical care. Even more so when tied together with Rx claims data. Even providers (Doctors/hospitals) themselves don't have access to insurance claims data for patients...which unironically results in perhaps a million hospitalizations and billions of dollars in healthcare costs per year because of the lack of data sharing with providers.
Even if they all know the difference between claims data and healthcare records, that wouldn't show up in the commentariat at large.
Your fear is unfounded.
With that said, we actually do have access to claims data for a significant chunk of our patients now, and that percentage is growing fast. It's part of a big push towards shifting risk from payors to providers to incentivize cost reduction.
This is probably the lowest hanging fruit of all waste in Medicare. Consider the average Medicare patient has 7 prescribing physicians and 10 prescription therapies, yet not a single physician has access to the claims data to see what another physician has prescribed, leading to duplicate therapies and adverse drug interacts at ridiculous rates. These are generally for chronic care patients also, meaning complications with diabetes, blood pressure, cholesterol, etc... resulting in costly hospitalization.
MTM was a step to fixing these issues, I am guessing perhaps what you may be referencing in improvement in sharing claims data (maybe you use OutcomesMTM), but realistically MTM is just a program for insurers to monetize their claims data.
Basically it gives them access to more private healthcare options. If they don't get timely access, they are covered under any network.
> "We are offering them choice in the medical marketplace, and we now have, thanks to the president and thanks to choice, the highest veterans satisfaction rate in our history. We're sitting at about 89.7 percent"
- Robert Wilkie, U.S. Veterans Affairs Secretary
If you have to trust the government on this anyway, cutting private insurers out seems to be minimizing risk, no?
The government plays almost no role in keeping most health data confidential, since most PHI is held by private entities.
And it's not like the government has a great track record of what little PHI it is responsible for - there have been plenty of breaches against CMS and Medicare affecting large numbers of patients.
Why would for-profit companies keep the data confidential when they can make more money selling it?
The fact that the government has passed a law that requires private entities to keep PHI confidential says nothing about their competence in managing PHI of their own. The original claim is about the latter.
Our vote applies immediately, not to mention there are term limits, so I trust the government much more also.
It is such a relief to read this position on Hacker News, for once. I am continuously astonished by tech workers' refusal to recognize these conflicts between our interests as individuals, and our employers' interests in profitability. Work only gets done when these interests find an equilibrium.
I am especially concerned with how little my employer considers my long-term health. With tech job turnover rates universally understood to be a handful of years, I know my employer is unmotivated to maintain my long-term health, preferring to accrue "tech debt" in me, a jettisonable unit.
Edit: More damningly, if my employer has it multiple governments potentially have access to it. Companies generally aren't willing to stand up to requests from, for example, China.
"The government" isn't a single entity, and most of "the government" can't access your data via a subpoena any more easily than a private company can.
[1] https://en.wikipedia.org/wiki/Office_of_Personnel_Management... [2] https://www.usds.gov/projects [3] https://twitter.com/USDS/status/1192520880733208576
Huge companies like SAP or Microsoft or Oracle will do this, even though they may also hire a traditional branded health insurer to "manage" this large-bank-account health plan (i.e. give out cards, negotiate with hospitals, etc.). But the bank account (brokerage account, really) remains in control of the corporation, and the traditional plan premiums are not paid to the health insurance company named on the card. Fees for managing the plan are paid separately. Doctors and hospitals get paid from the corporation's account. This is what the parent means when they say that the corporation has visibility into employees' healthcare usage.
And while these companies do have access to detailed claim data in theory, in practice access to this data is typically heavily limited a small number of HR or finance employees who are responsible for healthcare accounting and financial management and the data presented is typically restricted to a large claim report within a monthly/quarterly reporting period.
"The Privacy Rule allows covered providers and health plans to disclose protected health information to these “business associates” if the providers or plans obtain satisfactory assurances that the business associate will use the information only for the purposes for which it was engaged by the covered entity, will safeguard the information from misuse, and will help the covered entity comply with some of the covered entity’s duties under the Privacy Rule."
https://www.hhs.gov/hipaa/for-professionals/privacy/guidance...
>>"Covered entities may disclose protected health information to an entity in its role as a business associate only to help the covered entity carry out its health care functions – not for the business associate’s independent use or purposes, except as needed for the proper management and administration of the business associate."
BAA's keep the chain of HIPAA in place but just because a BAA is in place does not allow for violation of privacy.
What you're saying simply is not true.
Do you have any source for your suggestions, or is this just a random hypothetical?
Self-insured plans means that the companies underwrite their own plans, but they almost never manage their own claims. That would be cost-prohibitive and absurdly disadvantageous. The employer never touches raw claims data at all.
Companies have access to aggregate claims data, but they absolutely do not have "complete visibility into every health care interaction you have while employed".
However, the employer would not have your medical records without consent of the employee, this works for self funded or fully insured.