Florida Suspends Third Party Administrator for Unlawful Offshoring of Medicare Enrollees’ Claims Data

An insurance regulator in Florida has suspended a third-party claims administrator for unlawfully transferring the sensitive data of Medicare enrollees to foreign companies in India and the Philippines. The suspension, issued by the Florida Office of Insurance Regulation, takes immediate effect and will last up to a year.

According to the Florida Office of Insurance Regulation’s investigation, Mirra Health unlawfully engaged offshore firms to assist with claims processing, which required access to Medicare enrollees’ data. The sensitive information of up to 23,119 state Medicare recipients was disclosed without the knowledge or written authorization of Mirra Health’s clients. Mirra Health had contracts with three Florida Health Management Organizations (HMOs) – Secure Inc., Solis Health Plans Inc., and Ultimate Health Plans Inc. – and under its contracts, Mirra Health performed certain administrative functions, including member enrollment, claims adjudication and payment, grievance and appeals processing, and utilization management.

In addition to the unlawful disclosure, Mirra Health failed to provide the Office of Insurance Regulation with all of its contracts with the unlicensed companies. The Office of Insurance Regulation said the disclosures of Medicare enrollees’ data jeopardized “the safety and welfare of Florida residents. The data predominantly related to Medicare enrollees with chronic condition special needs, including individuals with intellectual disabilities who required care in intermediate facilities and individuals in long-term skilled nursing facilities. Delegating certain aspects of contracted duties to offshore companies is not prohibited; however, prior written authorization is required.

In the case of Mirra Health, data was disclosed to four unlicensed offshore entities without authorization, in violation of the terms of its contracts. When sensitive data is disclosed to overseas companies that fall outside the jurisdiction of regulators, including the HHS Office for Civil Rights and the Florida Office of Insurance Regulation, the company disclosing the data is responsible for what happens to that data. “Mirra Health’s business practices are extremely reckless, especially when it comes to exposing the sensitive health information of vulnerable Florida residents,” said Florida Insurance Commissioner Mike Yaworsky in an announcement about the order suspending Mirra Health’s certificate of authority.  “I am ordering an immediate suspension of the company’s certificate of authority, as the company’s actions are not competent or trustworthy. The Office of Insurance Regulation will continue to aggressively investigate this matter and stand up for the more than 23,000 enrollees impacted by this careless behavior.”

The case serves as a reminder to HIPAA-covered entities and business associates of the importance of verifying state and federal regulations prior to engaging the services of offshore companies.

About Liam Johnson

Liam Johnson has produced articles about HIPAA for several years. He has extensive experience in healthcare privacy and security. With a deep understanding of the complex legal and regulatory landscape surrounding patient data protection, Liam has dedicated his career to helping organizations navigate the intricacies of HIPAA compliance. Liam focusses on the challenges faced by healthcare providers, insurance companies, and business associates in complying with HIPAA regulations. Liam has been published in leading healthcare publications, including The HIPAA Journal. Liam was appointed Editor-in-Chief of The HIPAA Guide in 2023. Contact Liam via LinkedIn: https://www.linkedin.com/in/liamhipaa/