SlideShare a Scribd company logo
Joe Dylewski
Health Care Management




                         © 2012 Health Care Management
 HIPAA, HITECH, and The Business Associate
 Relationships with Healthcare Entities and
  Medical Practices
 Next Steps
 Summary and Q/A




                                         © 2012 Health Care Management
IT Service
         Providers


                       MSPs


              600K +



MSSPs


                              © 2012 Health Care Management
▪ Defining the “certain functions or activities”
 ▪ Disclosures
 ▪ Services
 ▪ Reasonable and Appropriate Safeguards




                                                   © 2012 Health Care Management
HIPAA

                               Title II

                            Administrative
                            Simplification



          Electronic Data
            Interchange
                            Security Rule    Privacy Rule
         (Transaction and
             Code Sets)



Administrative                 Physical              Technical
  Safeguards                  Safeguards             Safeguards
45 CFR 164.308              45 CFR 164.310         45 CFR 164.312




                                                             © 2012 Health Care Management
What is HITECH?
   HITECH - The Health Information Technology for
    Economic Recovery and Reinvestment Act of 2009
     Meaningful Use
     Education
     HIPAA Enforcement




                                            © 2012 Health Care Management
What changed relative to HIPAA?
  Physician Attestation for Meaningful Use
  Improved Enforcement
  HIPAA ignorance no longer tolerated
  Business Associates now have the same HIPAA
  responsibilities as the Covered Entities they
  service



                                              © 2012 Health Care Management
Key Statistics
                                                                            Total        No BA                  BA
     Category                                                            Breaches      Involved           Involved
     Percent of Total                                                          100%        79%              21%
                                                                                                       12,103,99
     Total Individuals Affected                                       21,021,132      8,917,133                9
     Percent of Total                                                          100%        42%                       58%
     Average Individuals per Breach                                        43,076       23,101            118,667




Source :U.S. Department of Health and Human Services HIPAA Breach
Notifications – September 2009 to May 2012                                                    © 2012 Health Care 2011 ATMP Solutions
                                                                                                               © Management
Increasing Degree of HIPAA Compliance Effort




                                                               “By exercising
“Due to Willful       “Due to Willful         “Due to
                                                                 reasonable
 Neglect if the        Neglect if the      Reasonable
                                                              diligence would
violation is not        violation is      Cause and not
                                                                  not have
  corrected”            corrected”        Willful Neglect”
                                                                   known”


                   Decreasing Degree of HIPAA Compliance Risk




                                                                  © 2012 Health Care Management
Increasing Degree of HIPAA Compliance Effort by Covered Entity and
                            Business Associate



                               Business        Business
                                                               Business
No Business     Business       Associate      Associate is
                                                               Associate
 Associate     Associate          has            taking
                                                                proof of
Contract in    Contract in    Conducted        necessary
                                                                 HIPAA
   place         Place           Risk           steps to
                                                              Compliance
                              Assessment      compliance

        Decreasing Degree of HIPAA Compliance Risk to Covered Entity




                                                               © 2012 Health Care Management
   Is the Covered Entity responsible for their Business
    Associate’s HIPAA Compliance, or vice versa?
     No     
   Is the Covered Entity responsible for engaging in
    relationships with HIPAA Compliant Business
    Associates?
     Yes    
   If the Business Associate claims HIPAA Compliance,
    does this imply that the Covered Entity is HIPAA
    Compliant?
     No     
                                                 © 2012 Health Care 2011 ATMP Solutions
                                                                  © Management
Solution                         Institutional
                           Compliance                        Compliance




Electronic Medical   HIPAA Compliant EMR Hosted in   EMR Company HIPAA Compliance
Record               a HIPAA Compliant Facility      with respect to internal operating
                                                     policies




                                                                      © 2012 Health Care Management
EMR
                                                                      Health
                                                                       Health
                                                                   Information
                                                                    Information
                                                                    Exchange
                                                                     Exchange
                               Private Cloud / /                      (HIE)
                                                                       (HIE)
                                Private Cloud
                                Data Center
                                 Data Center

   DR Site




                                                                                              Insurance
                                                                                              Company
                     IT Services

                                                                                  Lab
                       Document Destruction
Physician Practice

                                                   Health System
                                                                                  © 2012 Health Care Management
EMR
                                                                      Health
                                                                       Health
                                                                   Information
                                                                    Information
                                                                    Exchange
                                                                     Exchange
                               Private Cloud / /                      (HIE)
                                                                       (HIE)
                                Private Cloud
                                Data Center
                                 Data Center

   DR Site




                                                                                              Insurance
                                                                                              Company
                     IT Services

                                                                                  Lab
                       Document Destruction
Physician Practice

                                                   Health System
                                                                                  © 2012 Health Care Management
EMR
                                                                      Health
                                                                       Health
                                                                   Information
                                                                    Information
                                                                    Exchange
                                                                     Exchange
                               Private Cloud / /                      (HIE)
                                                                       (HIE)
                                Private Cloud
                                Data Center
                                 Data Center

   DR Site




                                                                                              Insurance
                                                                                              Company
                     IT Services

                                                                                  Lab
                       Document Destruction
Physician Practice

                                                   Health System
                                                                                  © 2012 Health Care Management
Privacy /
           Security




         Compliance

Policy                 Proof




                          © 2012 Health Care Management
 United States Department of Health and Human
  Services
   Office of Civil Rights
 Individual state’s Office of The Attorney General




                                              © 2012 Health Care Management
 Treat HIPAA compliance with the same
  degree of diligence and urgency as
  Accounting, Taxes, and the IRS
 Start with a simple checklist of areas that
  need to be addressed
   A.K.A. - Risk Assessment




                                          © 2012 Health Care Management
Questions and Answers

jdylewski@healthcaremgt.net
        616.977.2679




                          © 2012 Health Care Management

More Related Content

Viewers also liked

Group 5
Group 5Group 5
Group 5
taralaneville
 
What is music and its objectives?
What is music and its objectives?What is music and its objectives?
What is music and its objectives?
PRECY REGALADO
 
Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10
Huynh Tinh
 
RDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China PresentationRDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China Presentation
raydoyle133
 
TaraLaneMAT
TaraLaneMATTaraLaneMAT
TaraLaneMAT
taralaneville
 
Pphg waled ayad
Pphg waled ayadPphg waled ayad
Pphg waled ayad
Waled Ayad
 
Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10
Huynh Tinh
 
Winter weather
Winter weatherWinter weather
Winter weather
taralaneville
 
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)โสภณ ศุภวิริยากร
 
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Manos Nikiforakis
 
La competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELELa competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELE
Luis Enrique Elias Ruiz
 
สรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อมสรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อมโสภณ ศุภวิริยากร
 
Kualiti kepimpinan
Kualiti kepimpinanKualiti kepimpinan
Kualiti kepimpinan
Khairi Alattas
 
Mapeh what is music and its objectives
Mapeh what is music and its objectivesMapeh what is music and its objectives
Mapeh what is music and its objectives
PRECY REGALADO
 

Viewers also liked (15)

Group 5
Group 5Group 5
Group 5
 
PhotoEditor
PhotoEditorPhotoEditor
PhotoEditor
 
What is music and its objectives?
What is music and its objectives?What is music and its objectives?
What is music and its objectives?
 
Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10
 
RDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China PresentationRDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China Presentation
 
TaraLaneMAT
TaraLaneMATTaraLaneMAT
TaraLaneMAT
 
Pphg waled ayad
Pphg waled ayadPphg waled ayad
Pphg waled ayad
 
Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10
 
Winter weather
Winter weatherWinter weather
Winter weather
 
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
 
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
 
La competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELELa competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELE
 
สรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อมสรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อม
 
Kualiti kepimpinan
Kualiti kepimpinanKualiti kepimpinan
Kualiti kepimpinan
 
Mapeh what is music and its objectives
Mapeh what is music and its objectivesMapeh what is music and its objectives
Mapeh what is music and its objectives
 

Similar to Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities

Interconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years LaterInterconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years Later
privacypros
 
Hipaa omnibus presentation webinar
Hipaa omnibus presentation webinarHipaa omnibus presentation webinar
Hipaa omnibus presentation webinar
HIPAA Continuity Plannaers
 
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based WellnessA Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
Tanya Gonzalez
 
RajivKumarPrivacy
RajivKumarPrivacyRajivKumarPrivacy
RajivKumarPrivacy
Whitney Bowman-Zatzkin
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdf
SeasiaInfotech2
 
Q11 protect privacy
Q11   protect privacyQ11   protect privacy
Q11 protect privacy
TEDMED
 
HIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy WebinarHIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy Webinar
Compliancy Group
 
Lean Enterprise Initiative
Lean Enterprise InitiativeLean Enterprise Initiative
Lean Enterprise Initiative
WillowTree Advisors
 
Hipaa audits and enforcement
Hipaa audits and enforcementHipaa audits and enforcement
Hipaa audits and enforcement
supportc2go
 
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Discovery District
 
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Compliance Trainings
 
Hipaa random audit
Hipaa random auditHipaa random audit
Hipaa random audit
supportc2go
 
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
Shelly Megan
 
Salesforce ecollab himss2 copy
Salesforce ecollab himss2 copySalesforce ecollab himss2 copy
Salesforce ecollab himss2 copy
Collaborative Health Consortium
 
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdfUnderstanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
OmniMD Healthcare
 
A Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act LandscapeA Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act Landscape
Denny Weinberg
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
Carbonite
 
Healthcare Without Walls
Healthcare Without WallsHealthcare Without Walls
Healthcare Without Walls
Health Informatics New Zealand
 
Medscheme mauritius health outsourcing
Medscheme mauritius health outsourcingMedscheme mauritius health outsourcing
Medscheme mauritius health outsourcing
medschemeinternational
 
Medscheme health outsourcing ppt
Medscheme health outsourcing pptMedscheme health outsourcing ppt
Medscheme health outsourcing ppt
Medscheme
 

Similar to Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities (20)

Interconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years LaterInterconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years Later
 
Hipaa omnibus presentation webinar
Hipaa omnibus presentation webinarHipaa omnibus presentation webinar
Hipaa omnibus presentation webinar
 
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based WellnessA Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
 
RajivKumarPrivacy
RajivKumarPrivacyRajivKumarPrivacy
RajivKumarPrivacy
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdf
 
Q11 protect privacy
Q11   protect privacyQ11   protect privacy
Q11 protect privacy
 
HIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy WebinarHIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy Webinar
 
Lean Enterprise Initiative
Lean Enterprise InitiativeLean Enterprise Initiative
Lean Enterprise Initiative
 
Hipaa audits and enforcement
Hipaa audits and enforcementHipaa audits and enforcement
Hipaa audits and enforcement
 
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
 
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
 
Hipaa random audit
Hipaa random auditHipaa random audit
Hipaa random audit
 
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
 
Salesforce ecollab himss2 copy
Salesforce ecollab himss2 copySalesforce ecollab himss2 copy
Salesforce ecollab himss2 copy
 
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdfUnderstanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
 
A Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act LandscapeA Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act Landscape
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
Healthcare Without Walls
Healthcare Without WallsHealthcare Without Walls
Healthcare Without Walls
 
Medscheme mauritius health outsourcing
Medscheme mauritius health outsourcingMedscheme mauritius health outsourcing
Medscheme mauritius health outsourcing
 
Medscheme health outsourcing ppt
Medscheme health outsourcing pptMedscheme health outsourcing ppt
Medscheme health outsourcing ppt
 

Recently uploaded

Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
LuanWise
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
my Pandit
 
Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
Corey Perlman, Social Media Speaker and Consultant
 
How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
MJ Global
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
Adnet Communications
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
my Pandit
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
Chandresh Chudasama
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
sssourabhsharma
 
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
Stephen Cashman
 
Easily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYCEasily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYC
Any kyc Account
 
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & InnovationInnovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Operational Excellence Consulting
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
techboxsqauremedia
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
Norma Mushkat Gaffin
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
taqyea
 
Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024
Top Forex Brokers Review
 
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
Aleksey Savkin
 
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdfThe 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
thesiliconleaders
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
➒➌➎➏➑➐➋➑➐➐Dpboss Matka Guessing Satta Matka Kalyan Chart Indian Matka
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
Aggregage
 

Recently uploaded (20)

Building Your Employer Brand with Social Media
Building Your Employer Brand with Social MediaBuilding Your Employer Brand with Social Media
Building Your Employer Brand with Social Media
 
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your TasteZodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
Zodiac Signs and Food Preferences_ What Your Sign Says About Your Taste
 
Authentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto RicoAuthentically Social by Corey Perlman - EO Puerto Rico
Authentically Social by Corey Perlman - EO Puerto Rico
 
How MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdfHow MJ Global Leads the Packaging Industry.pdf
How MJ Global Leads the Packaging Industry.pdf
 
Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024Lundin Gold Corporate Presentation - June 2024
Lundin Gold Corporate Presentation - June 2024
 
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel ChartSatta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
Satta Matka Dpboss Matka Guessing Kalyan Chart Indian Matka Kalyan panel Chart
 
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
Taurus Zodiac Sign: Unveiling the Traits, Dates, and Horoscope Insights of th...
 
Structural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for BuildingsStructural Design Process: Step-by-Step Guide for Buildings
Structural Design Process: Step-by-Step Guide for Buildings
 
Digital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on SustainabilityDigital Marketing with a Focus on Sustainability
Digital Marketing with a Focus on Sustainability
 
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
The Heart of Leadership_ How Emotional Intelligence Drives Business Success B...
 
Easily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYCEasily Verify Compliance and Security with Binance KYC
Easily Verify Compliance and Security with Binance KYC
 
Innovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & InnovationInnovation Management Frameworks: Your Guide to Creativity & Innovation
Innovation Management Frameworks: Your Guide to Creativity & Innovation
 
Creative Web Design Company in Singapore
Creative Web Design Company in SingaporeCreative Web Design Company in Singapore
Creative Web Design Company in Singapore
 
Mastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnapMastering B2B Payments Webinar from BlueSnap
Mastering B2B Payments Webinar from BlueSnap
 
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
一比一原版新西兰奥塔哥大学毕业证(otago毕业证)如何办理
 
Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024Best Forex Brokers Comparison in INDIA 2024
Best Forex Brokers Comparison in INDIA 2024
 
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
How to Implement a Strategy: Transform Your Strategy with BSC Designer's Comp...
 
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdfThe 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
The 10 Most Influential Leaders Guiding Corporate Evolution, 2024.pdf
 
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta MatkaDpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
Dpboss Matka Guessing Satta Matta Matka Kalyan Chart Satta Matka
 
Understanding User Needs and Satisfying Them
Understanding User Needs and Satisfying ThemUnderstanding User Needs and Satisfying Them
Understanding User Needs and Satisfying Them
 

Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities

  • 1. Joe Dylewski Health Care Management © 2012 Health Care Management
  • 2.  HIPAA, HITECH, and The Business Associate  Relationships with Healthcare Entities and Medical Practices  Next Steps  Summary and Q/A © 2012 Health Care Management
  • 3. IT Service Providers MSPs 600K + MSSPs © 2012 Health Care Management
  • 4. ▪ Defining the “certain functions or activities” ▪ Disclosures ▪ Services ▪ Reasonable and Appropriate Safeguards © 2012 Health Care Management
  • 5. HIPAA Title II Administrative Simplification Electronic Data Interchange Security Rule Privacy Rule (Transaction and Code Sets) Administrative Physical Technical Safeguards Safeguards Safeguards 45 CFR 164.308 45 CFR 164.310 45 CFR 164.312 © 2012 Health Care Management
  • 6. What is HITECH?  HITECH - The Health Information Technology for Economic Recovery and Reinvestment Act of 2009  Meaningful Use  Education  HIPAA Enforcement © 2012 Health Care Management
  • 7. What changed relative to HIPAA?  Physician Attestation for Meaningful Use  Improved Enforcement  HIPAA ignorance no longer tolerated  Business Associates now have the same HIPAA responsibilities as the Covered Entities they service © 2012 Health Care Management
  • 8. Key Statistics Total No BA BA Category Breaches Involved Involved Percent of Total 100% 79% 21% 12,103,99 Total Individuals Affected 21,021,132 8,917,133 9 Percent of Total 100% 42% 58% Average Individuals per Breach 43,076 23,101 118,667 Source :U.S. Department of Health and Human Services HIPAA Breach Notifications – September 2009 to May 2012 © 2012 Health Care 2011 ATMP Solutions © Management
  • 9. Increasing Degree of HIPAA Compliance Effort “By exercising “Due to Willful “Due to Willful “Due to reasonable Neglect if the Neglect if the Reasonable diligence would violation is not violation is Cause and not not have corrected” corrected” Willful Neglect” known” Decreasing Degree of HIPAA Compliance Risk © 2012 Health Care Management
  • 10. Increasing Degree of HIPAA Compliance Effort by Covered Entity and Business Associate Business Business Business No Business Business Associate Associate is Associate Associate Associate has taking proof of Contract in Contract in Conducted necessary HIPAA place Place Risk steps to Compliance Assessment compliance Decreasing Degree of HIPAA Compliance Risk to Covered Entity © 2012 Health Care Management
  • 11. Is the Covered Entity responsible for their Business Associate’s HIPAA Compliance, or vice versa?  No   Is the Covered Entity responsible for engaging in relationships with HIPAA Compliant Business Associates?  Yes   If the Business Associate claims HIPAA Compliance, does this imply that the Covered Entity is HIPAA Compliant?  No  © 2012 Health Care 2011 ATMP Solutions © Management
  • 12. Solution Institutional Compliance Compliance Electronic Medical HIPAA Compliant EMR Hosted in EMR Company HIPAA Compliance Record a HIPAA Compliant Facility with respect to internal operating policies © 2012 Health Care Management
  • 13. EMR Health Health Information Information Exchange Exchange Private Cloud / / (HIE) (HIE) Private Cloud Data Center Data Center DR Site Insurance Company IT Services Lab Document Destruction Physician Practice Health System © 2012 Health Care Management
  • 14. EMR Health Health Information Information Exchange Exchange Private Cloud / / (HIE) (HIE) Private Cloud Data Center Data Center DR Site Insurance Company IT Services Lab Document Destruction Physician Practice Health System © 2012 Health Care Management
  • 15. EMR Health Health Information Information Exchange Exchange Private Cloud / / (HIE) (HIE) Private Cloud Data Center Data Center DR Site Insurance Company IT Services Lab Document Destruction Physician Practice Health System © 2012 Health Care Management
  • 16. Privacy / Security Compliance Policy Proof © 2012 Health Care Management
  • 17.  United States Department of Health and Human Services  Office of Civil Rights  Individual state’s Office of The Attorney General © 2012 Health Care Management
  • 18.  Treat HIPAA compliance with the same degree of diligence and urgency as Accounting, Taxes, and the IRS  Start with a simple checklist of areas that need to be addressed  A.K.A. - Risk Assessment © 2012 Health Care Management
  • 19. Questions and Answers jdylewski@healthcaremgt.net 616.977.2679 © 2012 Health Care Management

Editor's Notes

  1.  
  2. Definition of “Business Associate” A “business associate” is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity. United States Department of Health and Human Services Office of Civil Rights - [ 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)] If you would like a copy of the law, send me an email.
  3. Establish the permitted and required uses and disclosures of such information by the business associate The contract may permit the business associate to provide services relating to the health care operations of the covered entity Calls for the implementation of reasonable and appropriate administrative, physical, and technical safeguards to prevent use or disclosure of the information other than as provided for by its contract
  4. Appropriated funds to be provided as individual reimbursement to physicians who adopt and “meaningfully use” Electronic Medical Records Appropriated funds to educate the workforce in Health Information Technology Tightened guidelines and enforcement around HIPAA Add pictures (cement mixer) Add a picture of something that has changed – old style football versus new style football
  5. Physician Attestation for Meaningful Use Meaningful Use measure #15 calls for a HIPAA Risk Assessment and Remediation Improved Enforcement Maximum fines raised from $25, 000 to $1.5MM per calendar year for serious offenses Categories of violations HIPAA ignorance no longer tolerated Business Associates now have the same HIPAA responsibilities as the Covered Entities they service Implied accountability – whether a Business Associate Contract/Agreement is in place or not Breach Notifications include Business Associate and Covered Entity Why the focus on Business Associates?
  6. Drop the first line “total Breach”
  7. Animate by box – from left to right
  8. Animate by box
  9. Animate by questions
  10. Does EMR = Compliance? No Home Health Care / Hospice / Long Term Care Adherence to referring entity’s privacy and security policies HIPAA Compliance with respect to internal operating policies Document Destruction Documented Media Destruction Processes and Policies Document Destruction Company HIPAA Compliance with respect to internal operating policies
  11. Office of Civil Rights Currently developing list of HIPAA Compliance Audit Candidates KPMG has developed the audit process and will begin auditing activities in Fall 2011 Individual state’s Office of Attorney General On behalf of the public Currently completing training through OCR on HIPAA enforcement
  12. Graphic of a guy taking a step Industry calls this a “risk assessment”
  13. Need copies of the rule – send me a message? Seed questions: How much does this cost? Complete turnkey serivces start at $2,500 How long does this take? The risk assessment can be completed within 2 weeks. I understand that HIPAA is a lot of policies. How do I address dveloping all of the policies? We have policy templates and often assist clients in the development.