The document discusses changes to HIPAA regulations and compliance requirements for emergency medical services organizations. Key points include:
- Major changes from HIPAA/HITECH include an expanded definition of business associates, new requirements for business associate agreements and breach notification, and increased civil penalties.
- Non-compliance can result in significant fines from audits by the Office for Civil Rights. Fines have been issued in the millions for violations like unencrypted devices being stolen.
- Third party assistance can help EMS organizations establish HIPAA compliance programs and avoid "willful neglect" violations that carry mandatory minimum fines. Regular risk analysis and security practices are important to maintain compliance.