SlideShare a Scribd company logo
1 of 2
Ophthalmic Associates of Fort Washington
Business Associate Policy and Procedure
Reference: Administrative safeguards standards section 164.308(b)(1)—Business
Associate Contract and other Arrangements
Issued: 01/01/2014
Effective Date: 01/01/2014
Policy Number: 10
Approved by: Tara Kresge
_____________________________________________________________________________
_
Policy
Ophthalmic Associates of Fort Washington will establish Business Associate Agreements to
ensure that organizations that 1) create, maintain, receive, or transmit electronic protected health
information (ePHI) for Ophthalmic Associates of Fort Washington or 2) provide legal, actuarial,
consulting, data aggregation, management, administrative, accreditation, or financial services for
Ophthalmic Associates of Fort Washington will appropriately safeguard this information.
Ophthalmic Associates of Fort Washington will update the Business Associate Agreements
implemented in accordance with the Privacy Rule to incorporate the requirements of the Security
Rule.
Procedures
Written Contract or Other Arrangement
The security officer will determine all organizations that are considered business associates.
Agreements with all business associates will be documented via a written contract. All business
associates will be required to implement “reasonable and appropriate” safeguards to protect ePHI
and to notify the practice if they become aware of a “security incident.” Business associates will
also be required to enter into similar agreements with subcontractors to whom they delegate a
function, activity, or service they have agreed to perform for Ophthalmic Associates of Fort
Washington that involves the creation, receipt, maintenance, or transmission of protected health
information.
Examples of business associates include:
• Billing companies
• Software vendors
• Transcription services
• Medical record storage companies
• Answering services
• Accountants
• Consultants
• Health information organizations
• ePrescribing gateways
• Personal health record companies
© Pennsylvania Medical Society, 2013. Reproduction and use of this example policy by physician practices that
purchase the HIPAA Security Toolkit is permitted, but it should be customized for your use. Any other use,
duplication, or distribution of this example policy by any other party requires the prior written approval of PAMED.

More Related Content

What's hot

Nividous rpa bots for patients' claims eligibility check automation nividous
Nividous rpa bots for patients' claims eligibility check automation   nividousNividous rpa bots for patients' claims eligibility check automation   nividous
Nividous rpa bots for patients' claims eligibility check automation nividousSwapnil Kanage
 
HIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business AssociatesHIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business AssociatesJose Ivan Delgado, Ph.D.
 
Eligibility and Enrollment
Eligibility and EnrollmentEligibility and Enrollment
Eligibility and EnrollmentVee Technologies
 
Sample Hospital Compliance Program
Sample Hospital Compliance ProgramSample Hospital Compliance Program
Sample Hospital Compliance ProgramCraig B. Garner
 
Keeping Community Hospitals Thriving and Independent
Keeping Community Hospitals Thriving and IndependentKeeping Community Hospitals Thriving and Independent
Keeping Community Hospitals Thriving and Independentathenahealth
 
Sean Cassidy: The Naked Health Information Exchange
Sean Cassidy: The Naked Health Information ExchangeSean Cassidy: The Naked Health Information Exchange
Sean Cassidy: The Naked Health Information ExchangeNashville Technology Council
 
Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...
Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...
Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...Epstein Becker Green
 
Strengthening financial performance (b)
Strengthening financial performance (b)Strengthening financial performance (b)
Strengthening financial performance (b)GE Healthcare - IT
 
Compliance for Health Care Organizations
Compliance for Health Care OrganizationsCompliance for Health Care Organizations
Compliance for Health Care OrganizationsGlass Jacobson
 
Healthcare Compliance
Healthcare ComplianceHealthcare Compliance
Healthcare Compliancealok gupta
 
Digital Health Unit to be Created by the FDA
Digital Health Unit to be Created by the FDADigital Health Unit to be Created by the FDA
Digital Health Unit to be Created by the FDAJeremy Barbera
 
Developing a Practice Compliance Plan
Developing a Practice Compliance PlanDeveloping a Practice Compliance Plan
Developing a Practice Compliance Planshelvan1967
 
How valuable is a patient referral management software to primary care physic...
How valuable is a patient referral management software to primary care physic...How valuable is a patient referral management software to primary care physic...
How valuable is a patient referral management software to primary care physic...GaryRichards30
 
Ultra overviewflyer 3 1 14
Ultra overviewflyer 3 1 14Ultra overviewflyer 3 1 14
Ultra overviewflyer 3 1 14Ben Newman
 
Convergence of Compliance & Technology: How Technology Has Changed Regulatory...
Convergence of Compliance & Technology: How Technology Has Changed Regulatory...Convergence of Compliance & Technology: How Technology Has Changed Regulatory...
Convergence of Compliance & Technology: How Technology Has Changed Regulatory...MasterControl
 
Top 6 reasons why you need a referral management system even though you have ...
Top 6 reasons why you need a referral management system even though you have ...Top 6 reasons why you need a referral management system even though you have ...
Top 6 reasons why you need a referral management system even though you have ...GaryRichards30
 
Software Advice BuyerView: Physical Therapy Software Report 2014
Software Advice BuyerView: Physical Therapy Software Report 2014Software Advice BuyerView: Physical Therapy Software Report 2014
Software Advice BuyerView: Physical Therapy Software Report 2014Software Advice
 
Web Page Prime Suite
Web Page Prime SuiteWeb Page Prime Suite
Web Page Prime SuiteRealtimeIT
 

What's hot (20)

Nividous rpa bots for patients' claims eligibility check automation nividous
Nividous rpa bots for patients' claims eligibility check automation   nividousNividous rpa bots for patients' claims eligibility check automation   nividous
Nividous rpa bots for patients' claims eligibility check automation nividous
 
HIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business AssociatesHIPAA Omnibus Rule for Business Associates
HIPAA Omnibus Rule for Business Associates
 
Eligibility and Enrollment
Eligibility and EnrollmentEligibility and Enrollment
Eligibility and Enrollment
 
Sample Hospital Compliance Program
Sample Hospital Compliance ProgramSample Hospital Compliance Program
Sample Hospital Compliance Program
 
Keeping Community Hospitals Thriving and Independent
Keeping Community Hospitals Thriving and IndependentKeeping Community Hospitals Thriving and Independent
Keeping Community Hospitals Thriving and Independent
 
Sean Cassidy: The Naked Health Information Exchange
Sean Cassidy: The Naked Health Information ExchangeSean Cassidy: The Naked Health Information Exchange
Sean Cassidy: The Naked Health Information Exchange
 
Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...
Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...
Choosing Initial and Expansion States for Your Telehealth Practice – Essentia...
 
Strengthening financial performance (b)
Strengthening financial performance (b)Strengthening financial performance (b)
Strengthening financial performance (b)
 
Samanatha Gavel
Samanatha GavelSamanatha Gavel
Samanatha Gavel
 
Compliance for Health Care Organizations
Compliance for Health Care OrganizationsCompliance for Health Care Organizations
Compliance for Health Care Organizations
 
Healthcare Compliance
Healthcare ComplianceHealthcare Compliance
Healthcare Compliance
 
Digital Health Unit to be Created by the FDA
Digital Health Unit to be Created by the FDADigital Health Unit to be Created by the FDA
Digital Health Unit to be Created by the FDA
 
Understanding about features and functions of electronic medical record software
Understanding about features and functions of electronic medical record softwareUnderstanding about features and functions of electronic medical record software
Understanding about features and functions of electronic medical record software
 
Developing a Practice Compliance Plan
Developing a Practice Compliance PlanDeveloping a Practice Compliance Plan
Developing a Practice Compliance Plan
 
How valuable is a patient referral management software to primary care physic...
How valuable is a patient referral management software to primary care physic...How valuable is a patient referral management software to primary care physic...
How valuable is a patient referral management software to primary care physic...
 
Ultra overviewflyer 3 1 14
Ultra overviewflyer 3 1 14Ultra overviewflyer 3 1 14
Ultra overviewflyer 3 1 14
 
Convergence of Compliance & Technology: How Technology Has Changed Regulatory...
Convergence of Compliance & Technology: How Technology Has Changed Regulatory...Convergence of Compliance & Technology: How Technology Has Changed Regulatory...
Convergence of Compliance & Technology: How Technology Has Changed Regulatory...
 
Top 6 reasons why you need a referral management system even though you have ...
Top 6 reasons why you need a referral management system even though you have ...Top 6 reasons why you need a referral management system even though you have ...
Top 6 reasons why you need a referral management system even though you have ...
 
Software Advice BuyerView: Physical Therapy Software Report 2014
Software Advice BuyerView: Physical Therapy Software Report 2014Software Advice BuyerView: Physical Therapy Software Report 2014
Software Advice BuyerView: Physical Therapy Software Report 2014
 
Web Page Prime Suite
Web Page Prime SuiteWeb Page Prime Suite
Web Page Prime Suite
 

Viewers also liked

Juanita viaja en tren
Juanita viaja en trenJuanita viaja en tren
Juanita viaja en trenYdana
 
Jorge cardona eje2_acitviadad2.doc.
Jorge cardona eje2_acitviadad2.doc.Jorge cardona eje2_acitviadad2.doc.
Jorge cardona eje2_acitviadad2.doc.blogjorgecardona
 
Bebidas energéticas 1.
Bebidas energéticas 1.Bebidas energéticas 1.
Bebidas energéticas 1.luiscasta10
 
Jorge cardona eje2_acitviadad3.docx.
Jorge cardona eje2_acitviadad3.docx.Jorge cardona eje2_acitviadad3.docx.
Jorge cardona eje2_acitviadad3.docx.blogjorgecardona
 
Plan onse, práctica, experiencia
Plan onse, práctica, experiencia Plan onse, práctica, experiencia
Plan onse, práctica, experiencia Juan Carlos Sánchez
 
Censorship Timeline
Censorship TimelineCensorship Timeline
Censorship Timelineannamaycarey
 
4.0 SUMMER QTR 2014
4.0 SUMMER QTR 20144.0 SUMMER QTR 2014
4.0 SUMMER QTR 2014Cari Teague
 
IDCC 637 Accord dans la branche des industries
IDCC 637 Accord dans la branche des industries IDCC 637 Accord dans la branche des industries
IDCC 637 Accord dans la branche des industries Société Tripalio
 

Viewers also liked (12)

Rubrica
RubricaRubrica
Rubrica
 
Juanita viaja en tren
Juanita viaja en trenJuanita viaja en tren
Juanita viaja en tren
 
Jorge cardona eje2_acitviadad2.doc.
Jorge cardona eje2_acitviadad2.doc.Jorge cardona eje2_acitviadad2.doc.
Jorge cardona eje2_acitviadad2.doc.
 
Traditional games
Traditional gamesTraditional games
Traditional games
 
Bebidas energéticas 1.
Bebidas energéticas 1.Bebidas energéticas 1.
Bebidas energéticas 1.
 
Jorge cardona eje2_acitviadad3.docx.
Jorge cardona eje2_acitviadad3.docx.Jorge cardona eje2_acitviadad3.docx.
Jorge cardona eje2_acitviadad3.docx.
 
Plan onse, práctica, experiencia
Plan onse, práctica, experiencia Plan onse, práctica, experiencia
Plan onse, práctica, experiencia
 
Materia
MateriaMateria
Materia
 
Censorship Timeline
Censorship TimelineCensorship Timeline
Censorship Timeline
 
4.0 SUMMER QTR 2014
4.0 SUMMER QTR 20144.0 SUMMER QTR 2014
4.0 SUMMER QTR 2014
 
IDCC 637 Accord dans la branche des industries
IDCC 637 Accord dans la branche des industries IDCC 637 Accord dans la branche des industries
IDCC 637 Accord dans la branche des industries
 
Commendation Letter
Commendation LetterCommendation Letter
Commendation Letter
 

Similar to Business associate policy and procedure 10

hitech act
hitech acthitech act
hitech actpadler01
 
How to Get Medical Pre-approval or Prior Authorization Effectively
How to Get Medical Pre-approval or Prior Authorization EffectivelyHow to Get Medical Pre-approval or Prior Authorization Effectively
How to Get Medical Pre-approval or Prior Authorization EffectivelyOutsource Strategies International
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTControlCase
 
Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207
Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207
Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207Erik Ginalick
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Kimberly Simon MBA
 
Mastering Pharmacy Medical Billing + Claims Submission
Mastering Pharmacy Medical Billing + Claims SubmissionMastering Pharmacy Medical Billing + Claims Submission
Mastering Pharmacy Medical Billing + Claims Submissionkendall100
 
Critical Role of Insurance Verification Process in Orthopedic Practices
Critical Role of Insurance Verification Process in Orthopedic PracticesCritical Role of Insurance Verification Process in Orthopedic Practices
Critical Role of Insurance Verification Process in Orthopedic PracticesOutsource Strategies International
 
Align your compliance efforts with the 2014 oig strategy
Align your compliance efforts with the 2014 oig strategyAlign your compliance efforts with the 2014 oig strategy
Align your compliance efforts with the 2014 oig strategycomplianceonline123
 
Massachusetts Marketing Code of Conduct
Massachusetts Marketing Code of Conduct Massachusetts Marketing Code of Conduct
Massachusetts Marketing Code of Conduct Dickson Consulting
 
Physician Credentialing- Worth Getting Right to Get Paid.pptx
Physician Credentialing- Worth Getting Right to Get Paid.pptxPhysician Credentialing- Worth Getting Right to Get Paid.pptx
Physician Credentialing- Worth Getting Right to Get Paid.pptxalicecarlos1
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantCarbonite
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTKimberly Simon MBA
 
Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...
Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...
Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...Instapay Healthcare Services
 
Maintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docxMaintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docxjessiehampson
 
Maintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docxMaintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docxcroysierkathey
 
The Role of Fixed Asset Appraisals in Healthcare Valuations
The Role of Fixed Asset Appraisals in Healthcare Valuations The Role of Fixed Asset Appraisals in Healthcare Valuations
The Role of Fixed Asset Appraisals in Healthcare Valuations PYA, P.C.
 

Similar to Business associate policy and procedure 10 (20)

hitech act
hitech acthitech act
hitech act
 
How to Get Medical Pre-approval or Prior Authorization Effectively
How to Get Medical Pre-approval or Prior Authorization EffectivelyHow to Get Medical Pre-approval or Prior Authorization Effectively
How to Get Medical Pre-approval or Prior Authorization Effectively
 
web-MINImag
web-MINImagweb-MINImag
web-MINImag
 
TPACommittee30Apr09
TPACommittee30Apr09TPACommittee30Apr09
TPACommittee30Apr09
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUST
 
Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207
Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207
Electronic Health Records Protecting Assets With A Solid Security Plan Wp101207
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
Mastering Pharmacy Medical Billing + Claims Submission
Mastering Pharmacy Medical Billing + Claims SubmissionMastering Pharmacy Medical Billing + Claims Submission
Mastering Pharmacy Medical Billing + Claims Submission
 
Critical Role of Insurance Verification Process in Orthopedic Practices
Critical Role of Insurance Verification Process in Orthopedic PracticesCritical Role of Insurance Verification Process in Orthopedic Practices
Critical Role of Insurance Verification Process in Orthopedic Practices
 
Cblt power point
Cblt power pointCblt power point
Cblt power point
 
Align your compliance efforts with the 2014 oig strategy
Align your compliance efforts with the 2014 oig strategyAlign your compliance efforts with the 2014 oig strategy
Align your compliance efforts with the 2014 oig strategy
 
Massachusetts Marketing Code of Conduct
Massachusetts Marketing Code of Conduct Massachusetts Marketing Code of Conduct
Massachusetts Marketing Code of Conduct
 
Life Science Codes of Conduct
Life Science Codes of ConductLife Science Codes of Conduct
Life Science Codes of Conduct
 
Physician Credentialing- Worth Getting Right to Get Paid.pptx
Physician Credentialing- Worth Getting Right to Get Paid.pptxPhysician Credentialing- Worth Getting Right to Get Paid.pptx
Physician Credentialing- Worth Getting Right to Get Paid.pptx
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
HealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUSTHealthCare Compliance - HIPAA and HITRUST
HealthCare Compliance - HIPAA and HITRUST
 
Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...
Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...
Unlocking the Essentials Healthcare Provider and Medical Billing Credentialin...
 
Maintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docxMaintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docx
 
Maintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docxMaintaining a Legally Sound Health Record Paper and Elect.docx
Maintaining a Legally Sound Health Record Paper and Elect.docx
 
The Role of Fixed Asset Appraisals in Healthcare Valuations
The Role of Fixed Asset Appraisals in Healthcare Valuations The Role of Fixed Asset Appraisals in Healthcare Valuations
The Role of Fixed Asset Appraisals in Healthcare Valuations
 

Business associate policy and procedure 10

  • 1. Ophthalmic Associates of Fort Washington Business Associate Policy and Procedure Reference: Administrative safeguards standards section 164.308(b)(1)—Business Associate Contract and other Arrangements Issued: 01/01/2014 Effective Date: 01/01/2014 Policy Number: 10 Approved by: Tara Kresge _____________________________________________________________________________ _ Policy Ophthalmic Associates of Fort Washington will establish Business Associate Agreements to ensure that organizations that 1) create, maintain, receive, or transmit electronic protected health information (ePHI) for Ophthalmic Associates of Fort Washington or 2) provide legal, actuarial, consulting, data aggregation, management, administrative, accreditation, or financial services for Ophthalmic Associates of Fort Washington will appropriately safeguard this information. Ophthalmic Associates of Fort Washington will update the Business Associate Agreements implemented in accordance with the Privacy Rule to incorporate the requirements of the Security Rule. Procedures Written Contract or Other Arrangement The security officer will determine all organizations that are considered business associates. Agreements with all business associates will be documented via a written contract. All business associates will be required to implement “reasonable and appropriate” safeguards to protect ePHI and to notify the practice if they become aware of a “security incident.” Business associates will also be required to enter into similar agreements with subcontractors to whom they delegate a function, activity, or service they have agreed to perform for Ophthalmic Associates of Fort Washington that involves the creation, receipt, maintenance, or transmission of protected health information. Examples of business associates include: • Billing companies • Software vendors • Transcription services • Medical record storage companies • Answering services • Accountants • Consultants • Health information organizations
  • 2. • ePrescribing gateways • Personal health record companies © Pennsylvania Medical Society, 2013. Reproduction and use of this example policy by physician practices that purchase the HIPAA Security Toolkit is permitted, but it should be customized for your use. Any other use, duplication, or distribution of this example policy by any other party requires the prior written approval of PAMED.