SlideShare a Scribd company logo
1 of 18
Download to read offline
PRESENTED BY
PAUL R. HALES, J.D.
HIPAA
BUSINESS ASSOCIATE
COMPLIANCE
EDUCATIONAL WEBINAR
1
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
2
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
What Are We Going to Cover?
HIPAA – Health Insurance Portability and Accountability Act
Alert – Important New Business Associate HIPAA Enforcement
HIPAA and Business Associates
Covered Entities & Business Associates
Entangled Responsibilities – Chain of Trust
Business Associate Agreements – Agency – Due Diligence
Business Associate Compliance
HIPAA Privacy, Breach Notification and Security Rules
Your Organization’s HIPAA Compliance Program
HIPAA Business Associate Compliance
Health Insurance Portability and Accountability Act of 1996
3
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
Definitions
Covered Entity
Health Care Provider – Health Plan – Health Care Clearinghouse
Business Associate
On behalf of a Covered Entity
• Creates, Receives, Maintains or Transmits Protected Health Information
(PHI) for a function or activity regulated by the HIPAA Rules
• Provides Services involving disclosure of PHI from a Covered Entity or
from another Business Associate
Subcontractor Business Associate
On behalf of a Business Associate
• Creates, Receives, Maintains or Transmits PHI for function or activity
regulated by the HIPAA Rules
4
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
June 28, 2023
OCR Press Release – iHealth Solutions BA Investigation
iHealth Solutions Resolution Agreement and Corrective Action Plan
July 5, 2023 Blog – Lessons – OCR & iHealth Solutions
Risk Analysis and HIPAA Training
February 27, 2023 HHS Announcement
HHS Announces New Divisions Within the Office for Civil Rights to
Better Address Growing Need of Enforcement in Recent Years
5
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
OCR statement about iHealth Solutions & Business Associates
“HIPAA business associates must protect the privacy and security of the
health information they are entrusted with by HIPAA covered entities,”
said OCR Director Melanie Fontes Rainer.
iHealth Solutions Corrective Action Plan (CAP)
• Risk Analysis and Risk Management
• HIPAA Policies and Procedures including management of identified Risks
• Privacy Rule
• Security Rule
• Breach Notification Rule
• Workforce Training – Privacy, Security & Breach Notification Policies &
Procedures
• Owner or Officer Attestation verifying compliance with CAP
6
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
1996 HIPAA – Privacy & Security subtitle applies only to Covered Entities
2003 Privacy Rule – Makeshift Fix – Before disclosing PHI a Covered
Entity must contract with BA requiring BA to safeguard PHI
2005 Security Rule – also requires CE contract with BA to safeguard ePHI
2009 HITECH Act – Congress amends and strengthens HIPAA statute
Breach Notification Rule – New
2013
Emphasis on Enforcement – BAs now directly liable
Modifications including direct BA compliance finalized to
Privacy – Security - Breach Notification - Enforcement Rules
Brief Background – HIPAA Rules & Business Associates
How and When Business Associates became liable for HIPAA Compliance
7
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
Brief Background – HIPAA Rules & Business Associates
2013 Security and Privacy Rule Modifications
HIPAA Security Rule
A Covered Entity or Business Associate must identify the Security Official to
develop and implement policies and procedures required by the Security Rule
for the Covered Entity or Business Associate
45 CFR § 164.308(a)(2)
HIPAA Privacy Rule
A Covered Entity must designate a Privacy Official to develop and implement
the policies and procedures to comply with the Privacy and Breach
Notification Rules
45 CFR 164.530(a)(1)(i)
45 CFR 164.530(i)(1)
8
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
Brief Background – HIPAA Rules & Business Associates
2013 Security and Privacy Rule Modifications
Note:
A Covered Entity must:
• identify a Security Official to develop and implement its Security Rule
Policies and Procedures and
• designate a Privacy Official to develop and implement its Privacy and Breach
Notification Rule Policies and Procedures.
However,
Business Associates have no specially named official to develop and
implement their Privacy and Breach Notification Rule Policies and Procedures.
Confusion – Omissions – Violations
9
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
Brief Background – HIPAA Rules & Business Associates
2013 Security and Privacy Rule Modifications
2013 OCR Guidance – 78 FR 5598, Jan. 25, 2013
Business Associates are directly liable under the HIPAA Rules for a failure
to provide breach notification to the covered entity
Breach Notification Rule
Breach means the acquisition, access, use, or disclosure of protected health
information in a manner not permitted under the Privacy Rule which
compromises the security or privacy of the protected health information.
45 CFR 164.402 “Breach”
Security Rule
Covered entities and business associates must … protect against any
reasonably anticipated uses or disclosures of electronic protected health
information that are not permitted or required under the Privacy Rule.
45 CFR 164.306(a)(3)
10
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
PHI Covered Entity
11
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
Business Associate
Subcontractor Business Associate 1
Business Associates – Covered Entities – PHI Chain of Trust
PHI Chain of Trust
Subcontractor Business Associate 2
Subcontractor Business Associate 3
Business Associate Agreement required at each link of Chain
HIPAA Business Associate Compliance
A CE and a BA
A BA and a Sub-BA
A Sub-BA and a Sub-BA
CE
BA
Sub-BA1
Sub-BA 2
Sub-BA 3
CEs are not required to have
BAAs with Sub-BAs
Business Associates – Covered Entities – PHI Chain of Trust
PHI Chain of Trust
Business Associate Agreements are required between:
12
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
Business Associates – Covered Entities – Due Diligence
Enforcement Rule
Willful Neglect means conscious, intentional failure or reckless indifference to
the obligation to comply with the administrative simplification provision violated.
Enforcement Rule: 45 CFR 160.401 “Willful neglect”
The Secretary will investigate any complaint filed under this section when a
preliminary review of the facts indicates a possible violation due to willful
neglect.
Enforcement Rule: 45 CFR 160.306(c)(1)
The Secretary will conduct a compliance review to determine whether a covered
entity or business associate is complying with the applicable administrative
simplification provisions when a preliminary review of the facts indicates a
possible violation due to willful neglect.
Enforcement Rule: 45 CFR 160.308(a)
13
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
Business Associate HIPAA Compliance
Business Associates – Covered Entities – Due Diligence
Due Diligence
Business Associates
and
Subcontractor Business Associates
Important and Essential
“HIPAA Compliant”
14
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
Business Associate Privacy Rule Compliance
• A Business Associate may not use or disclose protected health
information in a manner that would violate the requirements of the
Privacy Rule, if done by a covered entity
• A Business Associate may use or disclose protected health information
only as permitted or required by its business associate contract or as
required by law
45 CFR 164.502(a)(3)
• A Business Associate is required to disclose protected health information
to HHS to investigate or determine the Business Associate's compliance
with the Privacy Rule
45 CFR 164.502(a)(4)(i)
15
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
Responsibility for Your Organization’s HIPAA Compliance Program
Senior Management is Responsible
• Delegate Authority to Compliance Officials
HIPAA Compliance Official
Explain – Teach – Laterally & Up
Your Audience
Senior Management
Compliance Colleagues
• Avoid Blame – Stick to Facts
• Present Opportunity
• Build Consensus
16
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
HIPAA Business Associate Compliance
HIPAA Business Associate Compliance
17
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
In conclusion we have covered
HIPAA – Health Insurance Portability and Accountability Act
Alert – Important New Business Associate HIPAA Enforcement
HIPAA and Business Associates
Covered Entities & Business Associates
Entangled Responsibilities – Chain of Trust
Business Associate Agreements – Agency – Due Diligence
Business Associate Compliance
HIPAA Privacy, Breach Notification and Security Rules
Your Organization’s HIPAA Compliance Program
HIPAA Business Associate Compliance
Thank You
Paul Hales, J. D.
18
www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
Register Now

More Related Content

Similar to HIPAA Business Associate Compliance and Dangers

HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013RightScale
 
HIPAA Business Associate Responsibilities – What They Are?
HIPAA Business Associate Responsibilities – What They Are?HIPAA Business Associate Responsibilities – What They Are?
HIPAA Business Associate Responsibilities – What They Are?Conference Panel
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations OnRamp
 
HIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business AssociatesHIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business AssociatesBridge Front
 
Is your billing partner hipaa compliant
Is your billing partner hipaa compliantIs your billing partner hipaa compliant
Is your billing partner hipaa compliantjennyvergeese
 
Protecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital LandscapesProtecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital LandscapesConference Panel
 
Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...NJVC, LLC
 
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDHIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDCompliancy Group
 
HIPAA Compliance Requirements for Business Associates
HIPAA Compliance Requirements for Business AssociatesHIPAA Compliance Requirements for Business Associates
HIPAA Compliance Requirements for Business AssociatesGlobalCompliancePanel
 
Explaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxExplaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxVistaInfosec
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Traininghimalya sharma
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Traininghimalya sharma
 
hipaa compliance requirements for business associates
hipaa compliance requirements for business associateshipaa compliance requirements for business associates
hipaa compliance requirements for business associatesGlobalCompliancePanel
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceTrueVault
 
2014 updated editable hipaa hitech policy and procedures
2014 updated editable hipaa hitech policy and procedures2014 updated editable hipaa hitech policy and procedures
2014 updated editable hipaa hitech policy and proceduresCharles McNeil
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfSeasiaInfotech2
 
Privacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxPrivacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxMohammadBashir26
 

Similar to HIPAA Business Associate Compliance and Dangers (20)

HNI U: HIPAA Essentials
HNI U: HIPAA EssentialsHNI U: HIPAA Essentials
HNI U: HIPAA Essentials
 
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
 
HIPAA Business Associate Responsibilities – What They Are?
HIPAA Business Associate Responsibilities – What They Are?HIPAA Business Associate Responsibilities – What They Are?
HIPAA Business Associate Responsibilities – What They Are?
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations
 
HIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business AssociatesHIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business Associates
 
Is your billing partner hipaa compliant
Is your billing partner hipaa compliantIs your billing partner hipaa compliant
Is your billing partner hipaa compliant
 
Protecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital LandscapesProtecting Patient Privacy: Navigating HIPAA in Digital Landscapes
Protecting Patient Privacy: Navigating HIPAA in Digital Landscapes
 
Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...
 
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINEDHIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
HIPAA MYTHS: HOW MUCH DO YOU KNOW? COMMON MYTHS DEBUNKED & EXPLAINED
 
HIPAA Compliance Requirements for Business Associates
HIPAA Compliance Requirements for Business AssociatesHIPAA Compliance Requirements for Business Associates
HIPAA Compliance Requirements for Business Associates
 
Explaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxExplaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docx
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Training
 
HIPAA | HIPAA Training
HIPAA | HIPAA TrainingHIPAA | HIPAA Training
HIPAA | HIPAA Training
 
hipaa compliance requirements for business associates
hipaa compliance requirements for business associateshipaa compliance requirements for business associates
hipaa compliance requirements for business associates
 
Application Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA ComplianceApplication Developers Guide to HIPAA Compliance
Application Developers Guide to HIPAA Compliance
 
2014 updated editable hipaa hitech policy and procedures
2014 updated editable hipaa hitech policy and procedures2014 updated editable hipaa hitech policy and procedures
2014 updated editable hipaa hitech policy and procedures
 
HIPAA Security 2019
HIPAA Security 2019HIPAA Security 2019
HIPAA Security 2019
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdf
 
Privacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxPrivacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptx
 

More from Conference Panel

Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...Conference Panel
 
The 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical ProvidersThe 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical ProvidersConference Panel
 
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...Conference Panel
 
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024Conference Panel
 
Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024Conference Panel
 
Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024Conference Panel
 
Demystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 UpdatesDemystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 UpdatesConference Panel
 
Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024Conference Panel
 
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondBreaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondConference Panel
 
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...Conference Panel
 
Provider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program GuideProvider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program GuideConference Panel
 
What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024Conference Panel
 
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...Conference Panel
 
Demystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection CriteriaDemystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection CriteriaConference Panel
 
Medicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS PerspectiveMedicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS PerspectiveConference Panel
 
Part B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention MandatesConference Panel
 
Part A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention MandatesConference Panel
 
Key Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness RegulationsKey Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness RegulationsConference Panel
 
2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to KnowConference Panel
 
Prepare for October 2023: ICD-10 Coding Changes Ahead
Prepare for October 2023: ICD-10 Coding Changes AheadPrepare for October 2023: ICD-10 Coding Changes Ahead
Prepare for October 2023: ICD-10 Coding Changes AheadConference Panel
 

More from Conference Panel (20)

Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
Grievances and Complaints 2024 Compliance with the CMS CoPs, Joint Commission...
 
The 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical ProvidersThe 2024 Prior Authorization Process For Medical Providers
The 2024 Prior Authorization Process For Medical Providers
 
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
HIPAA Guidelines and Electronic Communication: What Healthcare Professionals ...
 
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
Nursing Standards in Hospital Accreditation: CMS Guidelines 2024
 
Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024Implementing CMS Hospital QAPI Guidelines for 2024
Implementing CMS Hospital QAPI Guidelines for 2024
 
Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024Exploring the Revised Medicare 855 Enrollment Form for 2024
Exploring the Revised Medicare 855 Enrollment Form for 2024
 
Demystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 UpdatesDemystifying Shared Care and "Incident To" Billing: 2024 Updates
Demystifying Shared Care and "Incident To" Billing: 2024 Updates
 
Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024Understanding CPT Code Revisions in 2024
Understanding CPT Code Revisions in 2024
 
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and BeyondBreaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
Breaking Down the Latest HIPAA Modifications: What's New in 2024 and Beyond
 
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
Decoding the Latest Changes in the 2024 Medicare Physician Fee Schedule (MPFS...
 
Provider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program GuideProvider Enrollment Excellence: A Strategic Program Guide
Provider Enrollment Excellence: A Strategic Program Guide
 
What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024What Physicians Need to Know: CMS Final Rules 2024
What Physicians Need to Know: CMS Final Rules 2024
 
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
A Deep Dive into 2023: Hospital CoPs and Best Practices for History and Physi...
 
Demystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection CriteriaDemystifying the 2024 OIG Audit Selection Criteria
Demystifying the 2024 OIG Audit Selection Criteria
 
Medicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS PerspectiveMedicare Preventive Care: A CMS Perspective
Medicare Preventive Care: A CMS Perspective
 
Part B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part B Unpacking the 2023 CMS Hospital Infection Prevention Mandates
 
Part A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention MandatesPart A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
Part A Unpacking the 2023 CMS Hospital Infection Prevention Mandates
 
Key Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness RegulationsKey Elements of CMS Emergency Preparedness Regulations
Key Elements of CMS Emergency Preparedness Regulations
 
2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know2023 Proposed HIPAA Amendments: What You Need to Know
2023 Proposed HIPAA Amendments: What You Need to Know
 
Prepare for October 2023: ICD-10 Coding Changes Ahead
Prepare for October 2023: ICD-10 Coding Changes AheadPrepare for October 2023: ICD-10 Coding Changes Ahead
Prepare for October 2023: ICD-10 Coding Changes Ahead
 

Recently uploaded

Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in LucknowRussian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknowgragteena
 
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...delhimodelshub1
 
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsiindian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana TulsiHigh Profile Call Girls Chandigarh Aarushi
 
Call Girl Raipur 9873940964 Book Hot And Sexy Girls
Call Girl Raipur 9873940964 Book Hot And Sexy GirlsCall Girl Raipur 9873940964 Book Hot And Sexy Girls
Call Girl Raipur 9873940964 Book Hot And Sexy Girlsddev2574
 
Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...Niamh verma
 
Leading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsLeading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsHelenBevan4
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...Vip call girls In Chandigarh
 
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591adityaroy0215
 
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012Call Girls Service Gurgaon
 
Call Girls Kukatpally 7001305949 all area service COD available Any Time
Call Girls Kukatpally 7001305949 all area service COD available Any TimeCall Girls Kukatpally 7001305949 all area service COD available Any Time
Call Girls Kukatpally 7001305949 all area service COD available Any Timedelhimodelshub1
 
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...High Profile Call Girls Chandigarh Aarushi
 
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...Call Girls Service Chandigarh Ayushi
 
hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...
hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...
hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...delhimodelshub1
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171Call Girls Service Gurgaon
 
Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...
Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...
Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...Call Girls Noida
 
Call Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any TimeCall Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any Timedelhimodelshub1
 
Dehradun Call Girls Service 7017441440 Real Russian Girls Looking Models
Dehradun Call Girls Service 7017441440 Real Russian Girls Looking ModelsDehradun Call Girls Service 7017441440 Real Russian Girls Looking Models
Dehradun Call Girls Service 7017441440 Real Russian Girls Looking Modelsindiancallgirl4rent
 

Recently uploaded (20)

Call Girl Guwahati Aashi 👉 7001305949 👈 🔝 Independent Escort Service Guwahati
Call Girl Guwahati Aashi 👉 7001305949 👈 🔝 Independent Escort Service GuwahatiCall Girl Guwahati Aashi 👉 7001305949 👈 🔝 Independent Escort Service Guwahati
Call Girl Guwahati Aashi 👉 7001305949 👈 🔝 Independent Escort Service Guwahati
 
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in LucknowRussian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
Russian Escorts Aishbagh Road * 9548273370 Naughty Call Girls Service in Lucknow
 
Model Call Girl in Subhash Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Subhash Nagar Delhi reach out to us at 🔝9953056974🔝Model Call Girl in Subhash Nagar Delhi reach out to us at 🔝9953056974🔝
Model Call Girl in Subhash Nagar Delhi reach out to us at 🔝9953056974🔝
 
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
Russian Call Girls Hyderabad Indira 9907093804 Independent Escort Service Hyd...
 
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsiindian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
indian Call Girl Panchkula ❤️🍑 9907093804 Low Rate Call Girls Ludhiana Tulsi
 
Call Girl Raipur 9873940964 Book Hot And Sexy Girls
Call Girl Raipur 9873940964 Book Hot And Sexy GirlsCall Girl Raipur 9873940964 Book Hot And Sexy Girls
Call Girl Raipur 9873940964 Book Hot And Sexy Girls
 
Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...
Call Girls Service Chandigarh Gori WhatsApp ❤9115573837 VIP Call Girls Chandi...
 
Leading transformational change: inner and outer skills
Leading transformational change: inner and outer skillsLeading transformational change: inner and outer skills
Leading transformational change: inner and outer skills
 
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...No Advance 9053900678 Chandigarh  Call Girls , Indian Call Girls  For Full Ni...
No Advance 9053900678 Chandigarh Call Girls , Indian Call Girls For Full Ni...
 
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
VIP Call Girl Sector 25 Gurgaon Just Call Me 9899900591
 
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
VIP Call Girls Sector 67 Gurgaon Just Call Me 9711199012
 
Call Girls Kukatpally 7001305949 all area service COD available Any Time
Call Girls Kukatpally 7001305949 all area service COD available Any TimeCall Girls Kukatpally 7001305949 all area service COD available Any Time
Call Girls Kukatpally 7001305949 all area service COD available Any Time
 
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
Russian Call Girls in Chandigarh Ojaswi ❤️🍑 9907093804 👄🫦 Independent Escort ...
 
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...Jalandhar  Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
Jalandhar Female Call Girls Contact Number 9053900678 💚Jalandhar Female Call...
 
Call Girls in Lucknow Esha 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
Call Girls in Lucknow Esha 🔝 8923113531  🔝 🎶 Independent Escort Service LucknowCall Girls in Lucknow Esha 🔝 8923113531  🔝 🎶 Independent Escort Service Lucknow
Call Girls in Lucknow Esha 🔝 8923113531 🔝 🎶 Independent Escort Service Lucknow
 
hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...
hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...
hyderabad call girl.pdfRussian Call Girls in Hyderabad Amrita 9907093804 Inde...
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
 
Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...
Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...
Vip sexy Call Girls Service In Sector 137,9999965857 Young Female Escorts Ser...
 
Call Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any TimeCall Girls Secunderabad 7001305949 all area service COD available Any Time
Call Girls Secunderabad 7001305949 all area service COD available Any Time
 
Dehradun Call Girls Service 7017441440 Real Russian Girls Looking Models
Dehradun Call Girls Service 7017441440 Real Russian Girls Looking ModelsDehradun Call Girls Service 7017441440 Real Russian Girls Looking Models
Dehradun Call Girls Service 7017441440 Real Russian Girls Looking Models
 

HIPAA Business Associate Compliance and Dangers

  • 1. PRESENTED BY PAUL R. HALES, J.D. HIPAA BUSINESS ASSOCIATE COMPLIANCE EDUCATIONAL WEBINAR 1 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 2. HIPAA Business Associate Compliance 2 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC What Are We Going to Cover? HIPAA – Health Insurance Portability and Accountability Act Alert – Important New Business Associate HIPAA Enforcement HIPAA and Business Associates Covered Entities & Business Associates Entangled Responsibilities – Chain of Trust Business Associate Agreements – Agency – Due Diligence Business Associate Compliance HIPAA Privacy, Breach Notification and Security Rules Your Organization’s HIPAA Compliance Program
  • 3. HIPAA Business Associate Compliance Health Insurance Portability and Accountability Act of 1996 3 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 4. HIPAA Business Associate Compliance Definitions Covered Entity Health Care Provider – Health Plan – Health Care Clearinghouse Business Associate On behalf of a Covered Entity • Creates, Receives, Maintains or Transmits Protected Health Information (PHI) for a function or activity regulated by the HIPAA Rules • Provides Services involving disclosure of PHI from a Covered Entity or from another Business Associate Subcontractor Business Associate On behalf of a Business Associate • Creates, Receives, Maintains or Transmits PHI for function or activity regulated by the HIPAA Rules 4 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 5. HIPAA Business Associate Compliance June 28, 2023 OCR Press Release – iHealth Solutions BA Investigation iHealth Solutions Resolution Agreement and Corrective Action Plan July 5, 2023 Blog – Lessons – OCR & iHealth Solutions Risk Analysis and HIPAA Training February 27, 2023 HHS Announcement HHS Announces New Divisions Within the Office for Civil Rights to Better Address Growing Need of Enforcement in Recent Years 5 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 6. HIPAA Business Associate Compliance OCR statement about iHealth Solutions & Business Associates “HIPAA business associates must protect the privacy and security of the health information they are entrusted with by HIPAA covered entities,” said OCR Director Melanie Fontes Rainer. iHealth Solutions Corrective Action Plan (CAP) • Risk Analysis and Risk Management • HIPAA Policies and Procedures including management of identified Risks • Privacy Rule • Security Rule • Breach Notification Rule • Workforce Training – Privacy, Security & Breach Notification Policies & Procedures • Owner or Officer Attestation verifying compliance with CAP 6 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 7. HIPAA Business Associate Compliance 1996 HIPAA – Privacy & Security subtitle applies only to Covered Entities 2003 Privacy Rule – Makeshift Fix – Before disclosing PHI a Covered Entity must contract with BA requiring BA to safeguard PHI 2005 Security Rule – also requires CE contract with BA to safeguard ePHI 2009 HITECH Act – Congress amends and strengthens HIPAA statute Breach Notification Rule – New 2013 Emphasis on Enforcement – BAs now directly liable Modifications including direct BA compliance finalized to Privacy – Security - Breach Notification - Enforcement Rules Brief Background – HIPAA Rules & Business Associates How and When Business Associates became liable for HIPAA Compliance 7 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 8. HIPAA Business Associate Compliance Brief Background – HIPAA Rules & Business Associates 2013 Security and Privacy Rule Modifications HIPAA Security Rule A Covered Entity or Business Associate must identify the Security Official to develop and implement policies and procedures required by the Security Rule for the Covered Entity or Business Associate 45 CFR § 164.308(a)(2) HIPAA Privacy Rule A Covered Entity must designate a Privacy Official to develop and implement the policies and procedures to comply with the Privacy and Breach Notification Rules 45 CFR 164.530(a)(1)(i) 45 CFR 164.530(i)(1) 8 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 9. HIPAA Business Associate Compliance Brief Background – HIPAA Rules & Business Associates 2013 Security and Privacy Rule Modifications Note: A Covered Entity must: • identify a Security Official to develop and implement its Security Rule Policies and Procedures and • designate a Privacy Official to develop and implement its Privacy and Breach Notification Rule Policies and Procedures. However, Business Associates have no specially named official to develop and implement their Privacy and Breach Notification Rule Policies and Procedures. Confusion – Omissions – Violations 9 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 10. HIPAA Business Associate Compliance Brief Background – HIPAA Rules & Business Associates 2013 Security and Privacy Rule Modifications 2013 OCR Guidance – 78 FR 5598, Jan. 25, 2013 Business Associates are directly liable under the HIPAA Rules for a failure to provide breach notification to the covered entity Breach Notification Rule Breach means the acquisition, access, use, or disclosure of protected health information in a manner not permitted under the Privacy Rule which compromises the security or privacy of the protected health information. 45 CFR 164.402 “Breach” Security Rule Covered entities and business associates must … protect against any reasonably anticipated uses or disclosures of electronic protected health information that are not permitted or required under the Privacy Rule. 45 CFR 164.306(a)(3) 10 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 11. HIPAA Business Associate Compliance PHI Covered Entity 11 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC Business Associate Subcontractor Business Associate 1 Business Associates – Covered Entities – PHI Chain of Trust PHI Chain of Trust Subcontractor Business Associate 2 Subcontractor Business Associate 3 Business Associate Agreement required at each link of Chain
  • 12. HIPAA Business Associate Compliance A CE and a BA A BA and a Sub-BA A Sub-BA and a Sub-BA CE BA Sub-BA1 Sub-BA 2 Sub-BA 3 CEs are not required to have BAAs with Sub-BAs Business Associates – Covered Entities – PHI Chain of Trust PHI Chain of Trust Business Associate Agreements are required between: 12 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 13. HIPAA Business Associate Compliance Business Associates – Covered Entities – Due Diligence Enforcement Rule Willful Neglect means conscious, intentional failure or reckless indifference to the obligation to comply with the administrative simplification provision violated. Enforcement Rule: 45 CFR 160.401 “Willful neglect” The Secretary will investigate any complaint filed under this section when a preliminary review of the facts indicates a possible violation due to willful neglect. Enforcement Rule: 45 CFR 160.306(c)(1) The Secretary will conduct a compliance review to determine whether a covered entity or business associate is complying with the applicable administrative simplification provisions when a preliminary review of the facts indicates a possible violation due to willful neglect. Enforcement Rule: 45 CFR 160.308(a) 13 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 14. Business Associate HIPAA Compliance Business Associates – Covered Entities – Due Diligence Due Diligence Business Associates and Subcontractor Business Associates Important and Essential “HIPAA Compliant” 14 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 15. HIPAA Business Associate Compliance Business Associate Privacy Rule Compliance • A Business Associate may not use or disclose protected health information in a manner that would violate the requirements of the Privacy Rule, if done by a covered entity • A Business Associate may use or disclose protected health information only as permitted or required by its business associate contract or as required by law 45 CFR 164.502(a)(3) • A Business Associate is required to disclose protected health information to HHS to investigate or determine the Business Associate's compliance with the Privacy Rule 45 CFR 164.502(a)(4)(i) 15 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC
  • 16. Responsibility for Your Organization’s HIPAA Compliance Program Senior Management is Responsible • Delegate Authority to Compliance Officials HIPAA Compliance Official Explain – Teach – Laterally & Up Your Audience Senior Management Compliance Colleagues • Avoid Blame – Stick to Facts • Present Opportunity • Build Consensus 16 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC HIPAA Business Associate Compliance
  • 17. HIPAA Business Associate Compliance 17 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC In conclusion we have covered HIPAA – Health Insurance Portability and Accountability Act Alert – Important New Business Associate HIPAA Enforcement HIPAA and Business Associates Covered Entities & Business Associates Entangled Responsibilities – Chain of Trust Business Associate Agreements – Agency – Due Diligence Business Associate Compliance HIPAA Privacy, Breach Notification and Security Rules Your Organization’s HIPAA Compliance Program
  • 18. HIPAA Business Associate Compliance Thank You Paul Hales, J. D. 18 www.thehipaaetool.com Protecting Patient Privacy is our Job® © 2023 ET&C Group LLC Register Now