SlideShare a Scribd company logo
Taino Consultants Inc.
       Dr. Jose I. Delgado
www.TainoConsultants.com
        Tel 904-794-7830
 Title I Portability: guarantees health coverage
  when employees change jobs
 Title II Accountability: Also known as the

  Administrative Simplification establishes National
  Standards for the protection of health data
    ◦   Privacy
    ◦   Security
    ◦   Enforcement
    ◦   Electronic Transactions
   Covered Entity: refers to three specific groups that
    normally transmit health information electronically:
    ◦ health care providers
    ◦ health plans
    ◦ health care clearinghouses
   Business Associate: Person/agency who performs
    a function or activity for or on behalf of a covered
    entity that involves the use of patient information
Addresses a number of rules and incorporates them into
itself as the definitive requirements for compliance.
1.   Implemented changes to HIPAA that were mandated by the
     2009 Health Information Technology for Economic and
     Clinical Health Act (HITECH);
2.   Finalized the 2009 Enforcement and Breach Notification
     Interim Final Rules; and
3.   Modified HIPAA's Privacy Rule to strengthen the
     protections for genetic information required under the
     Genetic Information Nondiscrimination Act of 2008
     (GINA).
 Business Associate definition expanded to include
  any entity that creates, receives, maintains or
  transmits PHI on behalf of a Covered Entity or an
  organized health care arrangement.
 Broadened the definition of Business Associate to

  include any downstream subcontractors of
  Business Associates
 Liability and compliance rules expanded to include

  BA and its subcontractors
“All those entities that create, receive, maintain, or
  transmit PHI on behalf of a covered entity.”
  ◦ Data storage company that stores physical or electronic
    data;
  ◦ Software vendors
  ◦ Insurance sales agents and vendors
  ◦ Professionals (lawyers, consultants, lawyers)

  “It is what you do, not what you call yourself, that
  determines whether you are a Business Associate”
Civil Penalties
 Analyze whether you are now considered
  Business Associates;
 Assess whether your subcontractors/vendors are

  considered Business Associates;
 Conduct audits and gap analysis;

 Revise/Implement Policies and Procedures;

 Revise/Implement Agreements;

 Train employees.
 Posted in Federal Register: Jan 25, 2013
 Effective date: March 26,2013
 Compliance date: September 23, 2013
 Do not delay actions
 Enforcement date is Sep 2013

    ◦ Compliance steps may take over 6 months
   If in doubt consult an expert


Dr. Jose I. Delgado is the President and CEO of Taino Consultants Inc.,
consulting firm that focuses on healthcare business start-ups, compliance and
operations. Dr. Delgado can be contacted at
DrDelgado@TainoConsultants.com.

More Related Content

What's hot

Hipaa omnibus presentation webinar
Hipaa omnibus presentation webinarHipaa omnibus presentation webinar
Hipaa omnibus presentation webinar
HIPAA Continuity Plannaers
 
Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015
Patrick Doyle
 
Avoid the Audit Trap
Avoid the Audit TrapAvoid the Audit Trap
Avoid the Audit Trap
EAI Information Systems
 
Discussion2 week1
Discussion2 week1Discussion2 week1
Discussion2 week1
akei13sha
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
beleza1669
 
Cyberinsurance 111006
Cyberinsurance 111006Cyberinsurance 111006
Cyberinsurance 111006
JNicholson
 
Business associate policy and procedure 10
Business associate policy and procedure 10Business associate policy and procedure 10
Business associate policy and procedure 10
Tara Kresge
 
Don't Let Cybersecurity Trip You Up
Don't Let Cybersecurity Trip You UpDon't Let Cybersecurity Trip You Up
Don't Let Cybersecurity Trip You Up
EAI Information Systems
 
Confidentiality presentation(1)
Confidentiality presentation(1)Confidentiality presentation(1)
Confidentiality presentation(1)
Kimberlin1
 
HIPAA Omnibus Presentation
HIPAA Omnibus PresentationHIPAA Omnibus Presentation
HIPAA Omnibus Presentation
Compliancy Group
 
Pt hr confidentiality
Pt hr confidentialityPt hr confidentiality
Pt hr confidentiality
corbsan
 
You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Facts
resourceone
 
HIPAA Training Basics
HIPAA Training BasicsHIPAA Training Basics
HIPAA Training Basics
secky65
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliance
Prince George
 
DOL Fiduciary Rule Infographic
DOL Fiduciary Rule InfographicDOL Fiduciary Rule Infographic
DOL Fiduciary Rule Infographic
EAI Information Systems
 
Confidentiality week 1 discussion 2 mha690 healthcare capstone
Confidentiality  week 1 discussion 2 mha690 healthcare capstoneConfidentiality  week 1 discussion 2 mha690 healthcare capstone
Confidentiality week 1 discussion 2 mha690 healthcare capstone
RachelMargrave5
 
GDPR vs ISO27001 en
GDPR vs ISO27001 enGDPR vs ISO27001 en
GDPR vs ISO27001 en
Walter Vannini
 
Patient Confidentiality
Patient ConfidentialityPatient Confidentiality
Patient Confidentiality
Mike1fla
 
Confidentiality: Effective Training for Healthcare Employees
Confidentiality: Effective Training for Healthcare EmployeesConfidentiality: Effective Training for Healthcare Employees
Confidentiality: Effective Training for Healthcare Employees
jacquelinecwinston
 
Confidentiality and you
Confidentiality and youConfidentiality and you
Confidentiality and you
yola121
 

What's hot (20)

Hipaa omnibus presentation webinar
Hipaa omnibus presentation webinarHipaa omnibus presentation webinar
Hipaa omnibus presentation webinar
 
Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015Training innovations information governance slideshare 2015
Training innovations information governance slideshare 2015
 
Avoid the Audit Trap
Avoid the Audit TrapAvoid the Audit Trap
Avoid the Audit Trap
 
Discussion2 week1
Discussion2 week1Discussion2 week1
Discussion2 week1
 
Mha 690 week one discussion ii
Mha 690 week one discussion iiMha 690 week one discussion ii
Mha 690 week one discussion ii
 
Cyberinsurance 111006
Cyberinsurance 111006Cyberinsurance 111006
Cyberinsurance 111006
 
Business associate policy and procedure 10
Business associate policy and procedure 10Business associate policy and procedure 10
Business associate policy and procedure 10
 
Don't Let Cybersecurity Trip You Up
Don't Let Cybersecurity Trip You UpDon't Let Cybersecurity Trip You Up
Don't Let Cybersecurity Trip You Up
 
Confidentiality presentation(1)
Confidentiality presentation(1)Confidentiality presentation(1)
Confidentiality presentation(1)
 
HIPAA Omnibus Presentation
HIPAA Omnibus PresentationHIPAA Omnibus Presentation
HIPAA Omnibus Presentation
 
Pt hr confidentiality
Pt hr confidentialityPt hr confidentiality
Pt hr confidentiality
 
You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Facts
 
HIPAA Training Basics
HIPAA Training BasicsHIPAA Training Basics
HIPAA Training Basics
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliance
 
DOL Fiduciary Rule Infographic
DOL Fiduciary Rule InfographicDOL Fiduciary Rule Infographic
DOL Fiduciary Rule Infographic
 
Confidentiality week 1 discussion 2 mha690 healthcare capstone
Confidentiality  week 1 discussion 2 mha690 healthcare capstoneConfidentiality  week 1 discussion 2 mha690 healthcare capstone
Confidentiality week 1 discussion 2 mha690 healthcare capstone
 
GDPR vs ISO27001 en
GDPR vs ISO27001 enGDPR vs ISO27001 en
GDPR vs ISO27001 en
 
Patient Confidentiality
Patient ConfidentialityPatient Confidentiality
Patient Confidentiality
 
Confidentiality: Effective Training for Healthcare Employees
Confidentiality: Effective Training for Healthcare EmployeesConfidentiality: Effective Training for Healthcare Employees
Confidentiality: Effective Training for Healthcare Employees
 
Confidentiality and you
Confidentiality and youConfidentiality and you
Confidentiality and you
 

Similar to HIPAA Omnibus Rule for Business Associates

Hippa training v2
Hippa training v2Hippa training v2
Hippa training v2
Suzanne Guggenheim
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentation
Provider Resources Group
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
wardell henley
 
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxCHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
christinemaritza
 
PanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus CompendiumPanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus Compendium
Omar Vázquez
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
Jose Ivan Delgado, Ph.D.
 
Mha 690 presentation hippa
Mha 690 presentation hippaMha 690 presentation hippa
Mha 690 presentation hippa
belle0508
 
HiPAA info
HiPAA infoHiPAA info
HiPAA info
Rob Jones
 
What is HIPAA Compliance?
What is HIPAA Compliance?What is HIPAA Compliance?
What is HIPAA Compliance?
Power Admin LLC
 
HIPAA and FDCPA Compliance for Process Servers
HIPAA and FDCPA Compliance for Process ServersHIPAA and FDCPA Compliance for Process Servers
HIPAA and FDCPA Compliance for Process Servers
Lawgical
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
Carbonite
 
Does your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdfDoes your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdf
Shelly Megan
 
HIPAA , REGULATORY AFFAIRS , M.PHARM ...
HIPAA , REGULATORY AFFAIRS , M.PHARM ...HIPAA , REGULATORY AFFAIRS , M.PHARM ...
HIPAA , REGULATORY AFFAIRS , M.PHARM ...
susmitaghosh93
 
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docxChapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
cravennichole326
 
It industry regulations
It industry regulationsIt industry regulations
It industry regulations
Nicholas Davis
 
It Industry Regulations
It Industry RegulationsIt Industry Regulations
It Industry Regulations
Nicholas Davis
 
Privacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxPrivacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptx
MohammadBashir26
 
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdfData Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
CIOWomenMagazine
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
vrgill22
 

Similar to HIPAA Omnibus Rule for Business Associates (20)

Hippa training v2
Hippa training v2Hippa training v2
Hippa training v2
 
how to really implement hipaa presentation
how to really implement hipaa presentationhow to really implement hipaa presentation
how to really implement hipaa presentation
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
 
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxCHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
 
PanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus CompendiumPanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus Compendium
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
Mha 690 presentation hippa
Mha 690 presentation hippaMha 690 presentation hippa
Mha 690 presentation hippa
 
HiPAA info
HiPAA infoHiPAA info
HiPAA info
 
What is HIPAA Compliance?
What is HIPAA Compliance?What is HIPAA Compliance?
What is HIPAA Compliance?
 
HIPAA and FDCPA Compliance for Process Servers
HIPAA and FDCPA Compliance for Process ServersHIPAA and FDCPA Compliance for Process Servers
HIPAA and FDCPA Compliance for Process Servers
 
HIPAA Privacy & Security
HIPAA Privacy & SecurityHIPAA Privacy & Security
HIPAA Privacy & Security
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
Does your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdfDoes your Mobile App require HIPAA Compliance.pdf
Does your Mobile App require HIPAA Compliance.pdf
 
HIPAA , REGULATORY AFFAIRS , M.PHARM ...
HIPAA , REGULATORY AFFAIRS , M.PHARM ...HIPAA , REGULATORY AFFAIRS , M.PHARM ...
HIPAA , REGULATORY AFFAIRS , M.PHARM ...
 
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docxChapter 10 Privacy and Security of Health RecordsLearnin.docx
Chapter 10 Privacy and Security of Health RecordsLearnin.docx
 
It industry regulations
It industry regulationsIt industry regulations
It industry regulations
 
It Industry Regulations
It Industry RegulationsIt Industry Regulations
It Industry Regulations
 
Privacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptxPrivacy-Security-Training-Session-Template-4.6.21.pptx
Privacy-Security-Training-Session-Template-4.6.21.pptx
 
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdfData Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
Data Privacy Compliance Navigating the Evolving Regulatory Landscape.pdf
 
Week 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy trainingWeek 1 discussion 2 hipaa and privacy training
Week 1 discussion 2 hipaa and privacy training
 

More from Jose Ivan Delgado, Ph.D.

Guide to Online Tracking Technologies.pptx
Guide to Online Tracking Technologies.pptxGuide to Online Tracking Technologies.pptx
Guide to Online Tracking Technologies.pptx
Jose Ivan Delgado, Ph.D.
 
HIPAA Security 2019
HIPAA Security 2019HIPAA Security 2019
HIPAA Security 2019
Jose Ivan Delgado, Ph.D.
 
Macra 101
Macra 101Macra 101
Macra 2017
Macra 2017Macra 2017
Healthcare unplug oct
Healthcare unplug octHealthcare unplug oct
Healthcare unplug oct
Jose Ivan Delgado, Ph.D.
 
Healthcare unplug
Healthcare unplugHealthcare unplug
Healthcare unplug
Jose Ivan Delgado, Ph.D.
 
Meaningful use 2016
Meaningful use 2016Meaningful use 2016
Meaningful use 2016
Jose Ivan Delgado, Ph.D.
 
Icd 10 general presentation
Icd 10 general presentationIcd 10 general presentation
Icd 10 general presentation
Jose Ivan Delgado, Ph.D.
 
Icd 10 codes
Icd 10 codesIcd 10 codes
Colors only god could create
Colors only god could createColors only god could create
Colors only god could create
Jose Ivan Delgado, Ph.D.
 
Meaningful Use Basics for Healthcare Professionals and Organizations
Meaningful Use Basics for Healthcare Professionals and OrganizationsMeaningful Use Basics for Healthcare Professionals and Organizations
Meaningful Use Basics for Healthcare Professionals and Organizations
Jose Ivan Delgado, Ph.D.
 
Meaningful use 2015
Meaningful use 2015Meaningful use 2015
Meaningful use 2015
Jose Ivan Delgado, Ph.D.
 
Healhcare Billing Comparison
Healhcare Billing ComparisonHealhcare Billing Comparison
Healhcare Billing Comparison
Jose Ivan Delgado, Ph.D.
 
Services, Compliance and Innovation
Services, Compliance and InnovationServices, Compliance and Innovation
Services, Compliance and Innovation
Jose Ivan Delgado, Ph.D.
 
HIPAA security risk assessments
HIPAA security risk assessmentsHIPAA security risk assessments
HIPAA security risk assessments
Jose Ivan Delgado, Ph.D.
 
Healthcare Compliance Software
Healthcare Compliance SoftwareHealthcare Compliance Software
Healthcare Compliance Software
Jose Ivan Delgado, Ph.D.
 
Physician quality reporting system (pqrs)
Physician quality reporting system (pqrs)Physician quality reporting system (pqrs)
Physician quality reporting system (pqrs)
Jose Ivan Delgado, Ph.D.
 
Healthcare update 2
Healthcare update 2Healthcare update 2
Healthcare update 2
Jose Ivan Delgado, Ph.D.
 
Healthcare Business: Present and Future Challenges
Healthcare Business: Present and Future ChallengesHealthcare Business: Present and Future Challenges
Healthcare Business: Present and Future Challenges
Jose Ivan Delgado, Ph.D.
 
From paper to digital
From paper to digitalFrom paper to digital
From paper to digital
Jose Ivan Delgado, Ph.D.
 

More from Jose Ivan Delgado, Ph.D. (20)

Guide to Online Tracking Technologies.pptx
Guide to Online Tracking Technologies.pptxGuide to Online Tracking Technologies.pptx
Guide to Online Tracking Technologies.pptx
 
HIPAA Security 2019
HIPAA Security 2019HIPAA Security 2019
HIPAA Security 2019
 
Macra 101
Macra 101Macra 101
Macra 101
 
Macra 2017
Macra 2017Macra 2017
Macra 2017
 
Healthcare unplug oct
Healthcare unplug octHealthcare unplug oct
Healthcare unplug oct
 
Healthcare unplug
Healthcare unplugHealthcare unplug
Healthcare unplug
 
Meaningful use 2016
Meaningful use 2016Meaningful use 2016
Meaningful use 2016
 
Icd 10 general presentation
Icd 10 general presentationIcd 10 general presentation
Icd 10 general presentation
 
Icd 10 codes
Icd 10 codesIcd 10 codes
Icd 10 codes
 
Colors only god could create
Colors only god could createColors only god could create
Colors only god could create
 
Meaningful Use Basics for Healthcare Professionals and Organizations
Meaningful Use Basics for Healthcare Professionals and OrganizationsMeaningful Use Basics for Healthcare Professionals and Organizations
Meaningful Use Basics for Healthcare Professionals and Organizations
 
Meaningful use 2015
Meaningful use 2015Meaningful use 2015
Meaningful use 2015
 
Healhcare Billing Comparison
Healhcare Billing ComparisonHealhcare Billing Comparison
Healhcare Billing Comparison
 
Services, Compliance and Innovation
Services, Compliance and InnovationServices, Compliance and Innovation
Services, Compliance and Innovation
 
HIPAA security risk assessments
HIPAA security risk assessmentsHIPAA security risk assessments
HIPAA security risk assessments
 
Healthcare Compliance Software
Healthcare Compliance SoftwareHealthcare Compliance Software
Healthcare Compliance Software
 
Physician quality reporting system (pqrs)
Physician quality reporting system (pqrs)Physician quality reporting system (pqrs)
Physician quality reporting system (pqrs)
 
Healthcare update 2
Healthcare update 2Healthcare update 2
Healthcare update 2
 
Healthcare Business: Present and Future Challenges
Healthcare Business: Present and Future ChallengesHealthcare Business: Present and Future Challenges
Healthcare Business: Present and Future Challenges
 
From paper to digital
From paper to digitalFrom paper to digital
From paper to digital
 

Recently uploaded

Aortic Association CBL Pilot April 19 – 20 Bern
Aortic Association CBL Pilot April 19 – 20 BernAortic Association CBL Pilot April 19 – 20 Bern
Aortic Association CBL Pilot April 19 – 20 Bern
suvadeepdas911
 
Novas diretrizes da OMS para os cuidados perinatais de mais qualidade
Novas diretrizes da OMS para os cuidados perinatais de mais qualidadeNovas diretrizes da OMS para os cuidados perinatais de mais qualidade
Novas diretrizes da OMS para os cuidados perinatais de mais qualidade
Prof. Marcus Renato de Carvalho
 
CHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdf
CHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdfCHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdf
CHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdf
rishi2789
 
Netter's Atlas of Human Anatomy 7.ed.pdf
Netter's Atlas of Human Anatomy 7.ed.pdfNetter's Atlas of Human Anatomy 7.ed.pdf
Netter's Atlas of Human Anatomy 7.ed.pdf
BrissaOrtiz3
 
How STIs Influence the Development of Pelvic Inflammatory Disease.pptx
How STIs Influence the Development of Pelvic Inflammatory Disease.pptxHow STIs Influence the Development of Pelvic Inflammatory Disease.pptx
How STIs Influence the Development of Pelvic Inflammatory Disease.pptx
FFragrant
 
THERAPEUTIC ANTISENSE MOLECULES .pptx
THERAPEUTIC ANTISENSE MOLECULES    .pptxTHERAPEUTIC ANTISENSE MOLECULES    .pptx
THERAPEUTIC ANTISENSE MOLECULES .pptx
70KRISHPATEL
 
OCT Training Course for clinical practice Part 1
OCT Training Course for clinical practice Part 1OCT Training Course for clinical practice Part 1
OCT Training Course for clinical practice Part 1
KafrELShiekh University
 
Top 10 Best Ayurvedic Kidney Stone Syrups in India
Top 10 Best Ayurvedic Kidney Stone Syrups in IndiaTop 10 Best Ayurvedic Kidney Stone Syrups in India
Top 10 Best Ayurvedic Kidney Stone Syrups in India
Swastik Ayurveda
 
Role of Mukta Pishti in the Management of Hyperthyroidism
Role of Mukta Pishti in the Management of HyperthyroidismRole of Mukta Pishti in the Management of Hyperthyroidism
Role of Mukta Pishti in the Management of Hyperthyroidism
Dr. Jyothirmai Paindla
 
A Classical Text Review on Basavarajeeyam
A Classical Text Review on BasavarajeeyamA Classical Text Review on Basavarajeeyam
A Classical Text Review on Basavarajeeyam
Dr. Jyothirmai Paindla
 
CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1
CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1
CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1
rishi2789
 
Top Effective Soaps for Fungal Skin Infections in India
Top Effective Soaps for Fungal Skin Infections in IndiaTop Effective Soaps for Fungal Skin Infections in India
Top Effective Soaps for Fungal Skin Infections in India
SwisschemDerma
 
The Electrocardiogram - Physiologic Principles
The Electrocardiogram - Physiologic PrinciplesThe Electrocardiogram - Physiologic Principles
The Electrocardiogram - Physiologic Principles
MedicoseAcademics
 
Cell Therapy Expansion and Challenges in Autoimmune Disease
Cell Therapy Expansion and Challenges in Autoimmune DiseaseCell Therapy Expansion and Challenges in Autoimmune Disease
Cell Therapy Expansion and Challenges in Autoimmune Disease
Health Advances
 
Tests for analysis of different pharmaceutical.pptx
Tests for analysis of different pharmaceutical.pptxTests for analysis of different pharmaceutical.pptx
Tests for analysis of different pharmaceutical.pptx
taiba qazi
 
Ear and its clinical correlations By Dr. Rabia Inam Gandapore.pptx
Ear and its clinical correlations By Dr. Rabia Inam Gandapore.pptxEar and its clinical correlations By Dr. Rabia Inam Gandapore.pptx
Ear and its clinical correlations By Dr. Rabia Inam Gandapore.pptx
Dr. Rabia Inam Gandapore
 
Dehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in Dehradun
Dehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in DehradunDehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in Dehradun
Dehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in Dehradun
chandankumarsmartiso
 
Integrating Ayurveda into Parkinson’s Management: A Holistic Approach
Integrating Ayurveda into Parkinson’s Management: A Holistic ApproachIntegrating Ayurveda into Parkinson’s Management: A Holistic Approach
Integrating Ayurveda into Parkinson’s Management: A Holistic Approach
Ayurveda ForAll
 
Identification and nursing management of congenital malformations .pptx
Identification and nursing management of congenital malformations .pptxIdentification and nursing management of congenital malformations .pptx
Identification and nursing management of congenital malformations .pptx
MGM SCHOOL/COLLEGE OF NURSING
 
REGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptx
REGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptxREGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptx
REGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptx
LaniyaNasrink
 

Recently uploaded (20)

Aortic Association CBL Pilot April 19 – 20 Bern
Aortic Association CBL Pilot April 19 – 20 BernAortic Association CBL Pilot April 19 – 20 Bern
Aortic Association CBL Pilot April 19 – 20 Bern
 
Novas diretrizes da OMS para os cuidados perinatais de mais qualidade
Novas diretrizes da OMS para os cuidados perinatais de mais qualidadeNovas diretrizes da OMS para os cuidados perinatais de mais qualidade
Novas diretrizes da OMS para os cuidados perinatais de mais qualidade
 
CHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdf
CHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdfCHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdf
CHEMOTHERAPY_RDP_CHAPTER 1_ANTI TB DRUGS.pdf
 
Netter's Atlas of Human Anatomy 7.ed.pdf
Netter's Atlas of Human Anatomy 7.ed.pdfNetter's Atlas of Human Anatomy 7.ed.pdf
Netter's Atlas of Human Anatomy 7.ed.pdf
 
How STIs Influence the Development of Pelvic Inflammatory Disease.pptx
How STIs Influence the Development of Pelvic Inflammatory Disease.pptxHow STIs Influence the Development of Pelvic Inflammatory Disease.pptx
How STIs Influence the Development of Pelvic Inflammatory Disease.pptx
 
THERAPEUTIC ANTISENSE MOLECULES .pptx
THERAPEUTIC ANTISENSE MOLECULES    .pptxTHERAPEUTIC ANTISENSE MOLECULES    .pptx
THERAPEUTIC ANTISENSE MOLECULES .pptx
 
OCT Training Course for clinical practice Part 1
OCT Training Course for clinical practice Part 1OCT Training Course for clinical practice Part 1
OCT Training Course for clinical practice Part 1
 
Top 10 Best Ayurvedic Kidney Stone Syrups in India
Top 10 Best Ayurvedic Kidney Stone Syrups in IndiaTop 10 Best Ayurvedic Kidney Stone Syrups in India
Top 10 Best Ayurvedic Kidney Stone Syrups in India
 
Role of Mukta Pishti in the Management of Hyperthyroidism
Role of Mukta Pishti in the Management of HyperthyroidismRole of Mukta Pishti in the Management of Hyperthyroidism
Role of Mukta Pishti in the Management of Hyperthyroidism
 
A Classical Text Review on Basavarajeeyam
A Classical Text Review on BasavarajeeyamA Classical Text Review on Basavarajeeyam
A Classical Text Review on Basavarajeeyam
 
CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1
CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1
CHEMOTHERAPY_RDP_CHAPTER 2 _LEPROSY.pdf1
 
Top Effective Soaps for Fungal Skin Infections in India
Top Effective Soaps for Fungal Skin Infections in IndiaTop Effective Soaps for Fungal Skin Infections in India
Top Effective Soaps for Fungal Skin Infections in India
 
The Electrocardiogram - Physiologic Principles
The Electrocardiogram - Physiologic PrinciplesThe Electrocardiogram - Physiologic Principles
The Electrocardiogram - Physiologic Principles
 
Cell Therapy Expansion and Challenges in Autoimmune Disease
Cell Therapy Expansion and Challenges in Autoimmune DiseaseCell Therapy Expansion and Challenges in Autoimmune Disease
Cell Therapy Expansion and Challenges in Autoimmune Disease
 
Tests for analysis of different pharmaceutical.pptx
Tests for analysis of different pharmaceutical.pptxTests for analysis of different pharmaceutical.pptx
Tests for analysis of different pharmaceutical.pptx
 
Ear and its clinical correlations By Dr. Rabia Inam Gandapore.pptx
Ear and its clinical correlations By Dr. Rabia Inam Gandapore.pptxEar and its clinical correlations By Dr. Rabia Inam Gandapore.pptx
Ear and its clinical correlations By Dr. Rabia Inam Gandapore.pptx
 
Dehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in Dehradun
Dehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in DehradunDehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in Dehradun
Dehradun #ℂall #gIRLS Oyo Hotel 8107221448 #ℂall #gIRL in Dehradun
 
Integrating Ayurveda into Parkinson’s Management: A Holistic Approach
Integrating Ayurveda into Parkinson’s Management: A Holistic ApproachIntegrating Ayurveda into Parkinson’s Management: A Holistic Approach
Integrating Ayurveda into Parkinson’s Management: A Holistic Approach
 
Identification and nursing management of congenital malformations .pptx
Identification and nursing management of congenital malformations .pptxIdentification and nursing management of congenital malformations .pptx
Identification and nursing management of congenital malformations .pptx
 
REGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptx
REGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptxREGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptx
REGULATION FOR COMBINATION PRODUCTS AND MEDICAL DEVICES.pptx
 

HIPAA Omnibus Rule for Business Associates

  • 1. Taino Consultants Inc. Dr. Jose I. Delgado www.TainoConsultants.com Tel 904-794-7830
  • 2.
  • 3.  Title I Portability: guarantees health coverage when employees change jobs  Title II Accountability: Also known as the Administrative Simplification establishes National Standards for the protection of health data ◦ Privacy ◦ Security ◦ Enforcement ◦ Electronic Transactions
  • 4. Covered Entity: refers to three specific groups that normally transmit health information electronically: ◦ health care providers ◦ health plans ◦ health care clearinghouses  Business Associate: Person/agency who performs a function or activity for or on behalf of a covered entity that involves the use of patient information
  • 5. Addresses a number of rules and incorporates them into itself as the definitive requirements for compliance. 1. Implemented changes to HIPAA that were mandated by the 2009 Health Information Technology for Economic and Clinical Health Act (HITECH); 2. Finalized the 2009 Enforcement and Breach Notification Interim Final Rules; and 3. Modified HIPAA's Privacy Rule to strengthen the protections for genetic information required under the Genetic Information Nondiscrimination Act of 2008 (GINA).
  • 6.  Business Associate definition expanded to include any entity that creates, receives, maintains or transmits PHI on behalf of a Covered Entity or an organized health care arrangement.  Broadened the definition of Business Associate to include any downstream subcontractors of Business Associates  Liability and compliance rules expanded to include BA and its subcontractors
  • 7. “All those entities that create, receive, maintain, or transmit PHI on behalf of a covered entity.” ◦ Data storage company that stores physical or electronic data; ◦ Software vendors ◦ Insurance sales agents and vendors ◦ Professionals (lawyers, consultants, lawyers) “It is what you do, not what you call yourself, that determines whether you are a Business Associate”
  • 9.  Analyze whether you are now considered Business Associates;  Assess whether your subcontractors/vendors are considered Business Associates;  Conduct audits and gap analysis;  Revise/Implement Policies and Procedures;  Revise/Implement Agreements;  Train employees.
  • 10.  Posted in Federal Register: Jan 25, 2013  Effective date: March 26,2013  Compliance date: September 23, 2013
  • 11.  Do not delay actions  Enforcement date is Sep 2013 ◦ Compliance steps may take over 6 months  If in doubt consult an expert Dr. Jose I. Delgado is the President and CEO of Taino Consultants Inc., consulting firm that focuses on healthcare business start-ups, compliance and operations. Dr. Delgado can be contacted at DrDelgado@TainoConsultants.com.

Editor's Notes

  1. The Health Insurance Portability and Accountability Act of 1996 ( HIPAA ; Pub.L. 104-191 , 110  Stat.  1936, enacted August 21, 1996) was enacted by the United States Congress and signed by President Bill Clinton in 1996. It was sponsored by Sen. Nancy Kassebaum (R-Kan.). Title I of HIPAA protects health insurance coverage for workers and their families when they change or lose their jobs. Title II of HIPAA, known as the Administrative Simplification (AS) provisions, requires the establishment of national standards for electronic health care transactions and national identifiers for providers, health insurance plans, and employers
  2. The Health Insurance Portability and Accountability Act of 1996 (HIPAA), Public Law 104-191, included Administrative Simplification (AS) provisions (Title II) that required national standards for electronic health care transactions and code sets, unique health identifiers, and security. AS also covered the areas of Privacy, Security, Enforcement and Electronic Transactions. The Privacy Rule set national standards for the protection of individually identifiable health information while the security rule emphasized the protections of information in electronic format. The enforcement rule established the procedures and penalties in case of unauthorized releases.
  3. The term "covered entity" under the HIPAA Privacy Rule refers to three specific groups, including health plans, health care clearinghouses, and health care providers that transmit health information electronically.  Covered entities under the HIPAA Privacy Rule must comply with the Rule's requirements for safeguarding the privacy of protected health information.  Below is a more detailed list of those who fall under the covered entity category under HIPAA. Health Care Providers This includes all health care providers, regardless of practice size, provided that they transmit health information electronically.  The specific electronic transactions subject to this rule are those that are covered under the HIPAA Transactions Rule.  Providers subject to the Privacy rule include:       o Doctors,       o Clinics,       o Psychologists,       o Dentists,       o Chiropractors,       o Nursing Homes, and,       o Pharmacies. Health Plans Medical, Dental, and Vision Plans HMOs Medicare and Medicaid Medicare+Choice and Medicare Supplement Insurers Long-Term Care Insurers (excluding nursing home fixed-indemnity policies) Veterans Health Plans Company Health Plans Exceptions include:    o A group health plan with less than 50 participants that is  administered solely by the employer that established and maintains the plan is not a covered entity;    o Government-funded programs whose principal purpose is not providing or paying the cost of health care;     o Government-funded programs whose principal activity is directly providing health care or the making of grants to fund the direct provision of health care; and,    o Certain types of insurance entities such as those providing only workers' compensation, automobile insurance, and property and casualty insurance. Health Care Clearinghouses Entities that process nonstandard health information they receive from another entity into a standard (i.e., standard electronic format or data content), or vice versa.  This includes: o Billing Services, o Repricing Companies, o Community Health Management Information Systems, and, o Value-added networks and switches if these entities perform clearinghouse functions.
  4. Amendments to the Enforcement Rule: Increased Penalties and Fewer Defenses Even for covered entities that have long been subject directly to HIPAA regulations, the stakes will now be higher. The HITECH Act raised the maximum penalty for HIPAA violations to $50,000 per violation and $1.5 million for a group of identical violations. 31 These increased penalties will now apply to violations by covered entities and business associates alike. The revised Enforcement Rule limits the affirmative defenses available to an entity that violates HIPAA. A complete defense is available only if the violation was not due to willful neglect and was corrected within thirty days of when the entity knew, or by exercising “reasonable diligence” would have known, of the violation. This means that an entity’s reasonable lack of knowledge of a violation, alone, will no longer constitute a complete defense, which it had in the past. Moreover, an employee or business associate’s knowledge of a violation may be imputed to a covered entity. In addition, business associates will become directly liable for their breaches. HIPAA requires BAAs to provide that business associates must notify the covered entity upon discovery of any violation. The new rules also make business associates directly liable for the failure to provide such notice. A covered entity or business associate is non-compliant if it knows “of a pattern of activity or practice of [its business associate or subcontractor] that constituted a material breach or violation of the [BAA],” unless the superior either took “reasonable steps” to cure the breach or end the arrangement. 8 Even when a subordinate’s potentially violative activity is not known, the supervising authority may be liable for the violation if the subordinate was acting as the “agent” of the covered entity or business associate. 39