SlideShare a Scribd company logo
1 of 11
Download to read offline
WHAT EVERY PHYSICIAN
NEEDS TO KNOW
ABOUT CLOUD STORAGE
1 GROWING TREND
CLOUD-BASED STORAGE IS A GROWING TREND IN
HEALTH CARE.
•	 Health care providers are using cloud storage for data collection,
aggregation, analytics, and decision making.
•	 By 2020, 80 percent of health care data will pass through “the cloud” at
some point in its lifetime. 1
1. http://www.fiercehealthit.com/story/2015-healthcare-predictions-growth-analytics-mobile-security-risks/2014-11-21
2 BUSINESS
ASSOCIATE
•	 According to the HIPAA Omnibus rule, cloud storage providers are business
associates and must comply with privacy and security rules.
A VENDOR DOES NOT HAVE TO VIEW PATIENT DATA
TO BE CONSIDERED A BUSINESS ASSOCIATE.
3 BUSINESS ASSOCIATE
AGREEMENT (BAA)
BAA’S MAIN PURPOSE:
•	 To legally document and acknowledge the relationship between the
covered entity and the cloud storage provider, while also setting rules and
expectations for each party.
•	 The cloud storage provider must understand that they are required to take
certain steps to appropriately safeguard the privacy and security of the
data it stores.
ASK YOUR CYBER LIABILITY INSURANCE
PROVIDER ABOUT WHAT TO INCLUDE IN A BAA.
4 HIPAA
COMPLIANCE
JUST BECAUSE CLOUD STORAGE VENDORS
CLAIM THEY ARE “CERTIFIED HIPAA COMPLIANT”
DOES NOT MEAN THEY ACTUALLY ARE.
•	 Proper vetting must take place on any vendor you are considering.
•	 Some third parties will assess HIPAA compliance among cloud storage
providers, but such HIPAA certification is not recognized by HHS or any other
government body.
-- A cloud provider’s (or a third party reviewer’s) definition of HIPAA
compliance may not equate to the HHS definition of compliance.
5 HIPAA
COMPLIANCE
YOU MIGHT WANT TO ASK
1.	About obtaining documentation of a quality third party assessment of vendor’s
HIPAA compliance.
2.	How often does the cloud provider conduct a risk analysis and will they provide
information from their most recent risk analysis?
3.	What specific security controls do they have in place? (For example, what form
of encryption is used and on what information? Who has access to the keys?)
6 HIPAA
COMPLIANCE
•	 According to the HIPAA Omnibus rule, covered entities share the
responsibility when a business associate has a security breach, meaning
both are responsible for sending proper notifications if a security breach
occurs.
•	 Two separate risk assessments must occur – one must be conducted by
the cloud provider and one must be conducted by the covered entity.
7 DATA STORAGE
POLICY
QUESTIONS TO ASK
•	 How will the vendor back up the data? How will the data be restored?
•	 Will the vendor’s staff ever read or look at the data? If so, in what situations?
•	 Under what circumstances would the vendor turn data over to law
enforcement, with or without a warrant?
•	 What happens if you surpass your storage limits?
•	 Does the vendor have a plan for returning your data if the vendor were to sell,
go out of business, or your contract is terminated?
8 CONCLUSION
•	 When choosing a cloud storage provider, be cautious about claims of
HIPAA compliance.
•	 Appropriately vet the vendor and sign an appropriate BAA to ensure
patient privacy and security.
•	 Choose a provider that understands the requirements of the HIPAA
Omnibus rule.
9 SOURCES
•	 Cloud Security Toolkit, Navigating HIPAA While Moving to the Cloud by
Adam H. Greene, JD, MPH
http://www.himss.org/ResourceLibrary/genResourceDetailPDF.
aspx?ItemNumber=28307
•	 Top 10 Things to Consider About Omnibus for Cloud Storage
http://www.ironmountain.com/~/media/Files/Iron%20Mountain/
Knowledge%20Center/Reference%20Library/Best%20Practices/
Top_10_Things_to_Consider_About_Omnibus_for_Cloud_Storage.
pdf?dmc=1&ts=20150810T1230482174
10
ABOUT TMLT:
With more than 17,500 physicians in its care, Texas Medical Liability Trust (TMLT)
provides malpractice insurance and related products to physicians. Our purpose is to
make a positive impact on the quality of health care for patients by educating, protecting,
and defending physicians. www.tmlt.org
Find us on:
PROTECTION FOR
A NEW ERA OF
MEDICINE

More Related Content

What's hot

Health insurance portability and accountability act (hipaa)
Health insurance portability and accountability act (hipaa)Health insurance portability and accountability act (hipaa)
Health insurance portability and accountability act (hipaa)ZyLAB
 
Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...
Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...
Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...TrustArc
 
Get your Enterprise Ready for GDPR
Get your Enterprise Ready for GDPRGet your Enterprise Ready for GDPR
Get your Enterprise Ready for GDPRAbhishek Sood
 
Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
Security Regulations & Guidelines:  Is Your Business on the Path to Compliance? Security Regulations & Guidelines:  Is Your Business on the Path to Compliance?
Security Regulations & Guidelines: Is Your Business on the Path to Compliance? Blancco
 
Respond to the following in a minimum of 175 words security req
Respond to the following in a minimum of 175 words security reqRespond to the following in a minimum of 175 words security req
Respond to the following in a minimum of 175 words security reqSHIVA101531
 
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantCloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantBlancco
 
HIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHostway|HOSTING
 
Data Privacy Readiness Test
Data Privacy Readiness TestData Privacy Readiness Test
Data Privacy Readiness TestDruva
 
Be Confident in Your Research with LexisNexis
Be Confident in Your Research with LexisNexisBe Confident in Your Research with LexisNexis
Be Confident in Your Research with LexisNexisLexisNexis
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Jean-Michel Franco
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...TrustArc
 
Web Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance CertificationWeb Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance CertificationWeb Werks Data Centers
 
Cross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataCross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataUlf Mattsson
 
What I found in my data: True data security stories
What I found in my data: True data security storiesWhat I found in my data: True data security stories
What I found in my data: True data security storiesDataGravity
 
Make a case for Data Classification in your organization
Make a case for Data Classification in your organizationMake a case for Data Classification in your organization
Make a case for Data Classification in your organizationWatchful Software
 
OnRamp Customer Case Study - analyticsMD
OnRamp Customer Case Study - analyticsMDOnRamp Customer Case Study - analyticsMD
OnRamp Customer Case Study - analyticsMDJoshua Berman
 
The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...CureMD
 
GDPR Checklist Infographic
GDPR Checklist InfographicGDPR Checklist Infographic
GDPR Checklist InfographicConnexica
 
TrustArc Webinar: Challenges & Risks Of Data Graveyards
TrustArc Webinar: Challenges & Risks Of Data GraveyardsTrustArc Webinar: Challenges & Risks Of Data Graveyards
TrustArc Webinar: Challenges & Risks Of Data GraveyardsTrustArc
 

What's hot (20)

Health insurance portability and accountability act (hipaa)
Health insurance portability and accountability act (hipaa)Health insurance portability and accountability act (hipaa)
Health insurance portability and accountability act (hipaa)
 
Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...
Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...
Managing Multiple Compliance Priorities - GDPR, CCPA, HIPAA, APEC, ISO 27001,...
 
Get your Enterprise Ready for GDPR
Get your Enterprise Ready for GDPRGet your Enterprise Ready for GDPR
Get your Enterprise Ready for GDPR
 
Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
Security Regulations & Guidelines:  Is Your Business on the Path to Compliance? Security Regulations & Guidelines:  Is Your Business on the Path to Compliance?
Security Regulations & Guidelines: Is Your Business on the Path to Compliance?
 
Respond to the following in a minimum of 175 words security req
Respond to the following in a minimum of 175 words security reqRespond to the following in a minimum of 175 words security req
Respond to the following in a minimum of 175 words security req
 
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay CompliantCloud Storage: How to Fight Off Data Security Threats & Stay Compliant
Cloud Storage: How to Fight Off Data Security Threats & Stay Compliant
 
HIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare CloudHIPAA Compliance: Simple Steps to the Healthcare Cloud
HIPAA Compliance: Simple Steps to the Healthcare Cloud
 
Data Privacy Readiness Test
Data Privacy Readiness TestData Privacy Readiness Test
Data Privacy Readiness Test
 
Be Confident in Your Research with LexisNexis
Be Confident in Your Research with LexisNexisBe Confident in Your Research with LexisNexis
Be Confident in Your Research with LexisNexis
 
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
Enacting the Data Subjects Access Rights for GDPR with Data Services and Data...
 
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
Demonstrating Compliance & the Role of Certification Under the GDPR [Webinar ...
 
Web Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance CertificationWeb Werks Data Center Achieves HIPAA Compliance Certification
Web Werks Data Center Achieves HIPAA Compliance Certification
 
Cross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive dataCross border - off-shoring and outsourcing privacy sensitive data
Cross border - off-shoring and outsourcing privacy sensitive data
 
What I found in my data: True data security stories
What I found in my data: True data security storiesWhat I found in my data: True data security stories
What I found in my data: True data security stories
 
Security&Governance
Security&GovernanceSecurity&Governance
Security&Governance
 
Make a case for Data Classification in your organization
Make a case for Data Classification in your organizationMake a case for Data Classification in your organization
Make a case for Data Classification in your organization
 
OnRamp Customer Case Study - analyticsMD
OnRamp Customer Case Study - analyticsMDOnRamp Customer Case Study - analyticsMD
OnRamp Customer Case Study - analyticsMD
 
The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...The real reason why physicians must comply with HIPAA. What the government do...
The real reason why physicians must comply with HIPAA. What the government do...
 
GDPR Checklist Infographic
GDPR Checklist InfographicGDPR Checklist Infographic
GDPR Checklist Infographic
 
TrustArc Webinar: Challenges & Risks Of Data Graveyards
TrustArc Webinar: Challenges & Risks Of Data GraveyardsTrustArc Webinar: Challenges & Risks Of Data Graveyards
TrustArc Webinar: Challenges & Risks Of Data Graveyards
 

Viewers also liked

Nutrients
NutrientsNutrients
NutrientsM K
 
Michael Mabrouk CV 1 (2)
Michael Mabrouk CV 1 (2)Michael Mabrouk CV 1 (2)
Michael Mabrouk CV 1 (2)michael mabrouk
 
Kepengurusan Kampung Kautsar
Kepengurusan Kampung KautsarKepengurusan Kampung Kautsar
Kepengurusan Kampung KautsarAhmad Syarifudin
 
Cultivating a Culture of Innovative Creators: iBooks & the CCSS
Cultivating a Culture of Innovative Creators: iBooks & the CCSSCultivating a Culture of Innovative Creators: iBooks & the CCSS
Cultivating a Culture of Innovative Creators: iBooks & the CCSSracheldiep
 
Things to Consider Before Buying Cyber Liability Insurance
Things to Consider Before Buying Cyber Liability InsuranceThings to Consider Before Buying Cyber Liability Insurance
Things to Consider Before Buying Cyber Liability InsuranceTexas Medical Liability Trust
 
What Every Physician Needs to Know: Employment Practices Liability
What Every Physician Needs to Know: Employment Practices LiabilityWhat Every Physician Needs to Know: Employment Practices Liability
What Every Physician Needs to Know: Employment Practices LiabilityTexas Medical Liability Trust
 
What Every Physician Needs to Know About Their Malpractice Insurance Policy
What Every Physician Needs to Know About Their Malpractice Insurance PolicyWhat Every Physician Needs to Know About Their Malpractice Insurance Policy
What Every Physician Needs to Know About Their Malpractice Insurance PolicyTexas Medical Liability Trust
 
KETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPA
KETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPAKETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPA
KETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPAamrinarosada7x
 
Terminating the Physician-Patient Relationship, Part 2
Terminating the Physician-Patient Relationship, Part 2Terminating the Physician-Patient Relationship, Part 2
Terminating the Physician-Patient Relationship, Part 2Texas Medical Liability Trust
 

Viewers also liked (20)

Nutrients
NutrientsNutrients
Nutrients
 
Michael Mabrouk CV 1 (2)
Michael Mabrouk CV 1 (2)Michael Mabrouk CV 1 (2)
Michael Mabrouk CV 1 (2)
 
Kepengurusan Kampung Kautsar
Kepengurusan Kampung KautsarKepengurusan Kampung Kautsar
Kepengurusan Kampung Kautsar
 
Resume - Gazala
Resume - GazalaResume - Gazala
Resume - Gazala
 
Cultivating a Culture of Innovative Creators: iBooks & the CCSS
Cultivating a Culture of Innovative Creators: iBooks & the CCSSCultivating a Culture of Innovative Creators: iBooks & the CCSS
Cultivating a Culture of Innovative Creators: iBooks & the CCSS
 
Preliminary exercise
Preliminary exercisePreliminary exercise
Preliminary exercise
 
Things to Consider Before Buying Cyber Liability Insurance
Things to Consider Before Buying Cyber Liability InsuranceThings to Consider Before Buying Cyber Liability Insurance
Things to Consider Before Buying Cyber Liability Insurance
 
Failure to insist on EMS transport
Failure to insist on EMS transportFailure to insist on EMS transport
Failure to insist on EMS transport
 
The Medical Malpractice Claims Process
The Medical Malpractice Claims ProcessThe Medical Malpractice Claims Process
The Medical Malpractice Claims Process
 
What Every Physician Needs to Know: Employment Practices Liability
What Every Physician Needs to Know: Employment Practices LiabilityWhat Every Physician Needs to Know: Employment Practices Liability
What Every Physician Needs to Know: Employment Practices Liability
 
Top 5 Physician Websites
Top 5 Physician WebsitesTop 5 Physician Websites
Top 5 Physician Websites
 
Communicating With Patients in the Digital Age
Communicating With Patients in the Digital AgeCommunicating With Patients in the Digital Age
Communicating With Patients in the Digital Age
 
What Every Physician Needs to Know About Their Malpractice Insurance Policy
What Every Physician Needs to Know About Their Malpractice Insurance PolicyWhat Every Physician Needs to Know About Their Malpractice Insurance Policy
What Every Physician Needs to Know About Their Malpractice Insurance Policy
 
farah new cv
farah new cvfarah new cv
farah new cv
 
EHR Best Practices
EHR Best PracticesEHR Best Practices
EHR Best Practices
 
KETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPA
KETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPAKETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPA
KETETAPAN KESEIMBANGAN - KIMIA KELAS XI IPA
 
Overprescribing pain medication
Overprescribing pain medicationOverprescribing pain medication
Overprescribing pain medication
 
A model for enquiry based learning in the classroom
A model for enquiry based learning in the classroom A model for enquiry based learning in the classroom
A model for enquiry based learning in the classroom
 
Tort Reform 2015
Tort Reform 2015Tort Reform 2015
Tort Reform 2015
 
Terminating the Physician-Patient Relationship, Part 2
Terminating the Physician-Patient Relationship, Part 2Terminating the Physician-Patient Relationship, Part 2
Terminating the Physician-Patient Relationship, Part 2
 

Similar to What Every Physician Needs to Know About Cloud Storage

Keeping Control: Data Security and Vendor Management
Keeping Control: Data Security and Vendor ManagementKeeping Control: Data Security and Vendor Management
Keeping Control: Data Security and Vendor ManagementPaige Rasid
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations OnRamp
 
Cloud compliance test
Cloud compliance testCloud compliance test
Cloud compliance testPrancer Io
 
Ensuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdf
Ensuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdfEnsuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdf
Ensuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdfPostDICOM
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskTrustArc
 
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013RightScale
 
BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...
BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...
BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...Kurt Hagerman
 
The Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTThe Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTCompliancy Group
 
365 infographic-compliance
365 infographic-compliance365 infographic-compliance
365 infographic-compliance365 Data Centers
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTControlCase
 
10 questions to ask your cloud provider
10 questions to ask your cloud provider10 questions to ask your cloud provider
10 questions to ask your cloud providerHighQ
 
HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...
HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...
HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...Ajeet Singh
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudCheryl Goldberg
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudCheryl Goldberg
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantCarbonite
 
Hortonworks help customers building a HIPAA compliant Data Lake
Hortonworks help customers building a HIPAA compliant Data Lake Hortonworks help customers building a HIPAA compliant Data Lake
Hortonworks help customers building a HIPAA compliant Data Lake Vitor Lundberg
 
The importance of hipaa compliance and training
The importance of hipaa compliance and trainingThe importance of hipaa compliance and training
The importance of hipaa compliance and trainingLaDavia Day, MHA, BS
 
HIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and GuidelinesHIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and GuidelinesConference Panel
 
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Compliancy Group
 
HIPAA Conduit Exception: The Facts
HIPAA Conduit Exception: The FactsHIPAA Conduit Exception: The Facts
HIPAA Conduit Exception: The FactsScrypt, Inc.
 

Similar to What Every Physician Needs to Know About Cloud Storage (20)

Keeping Control: Data Security and Vendor Management
Keeping Control: Data Security and Vendor ManagementKeeping Control: Data Security and Vendor Management
Keeping Control: Data Security and Vendor Management
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations
 
Cloud compliance test
Cloud compliance testCloud compliance test
Cloud compliance test
 
Ensuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdf
Ensuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdfEnsuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdf
Ensuring HIPAA Compliance in the Cloud A Guide for Healthcare Organizations.pdf
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
HIPAA in the Public Cloud: The Rules Have Been Set - RightScale Compute 2013
 
BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...
BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...
BECOME A SMARTER CLOUD CONSUMER - Ripping through the Rhetoric to Find Your C...
 
The Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOTThe Most Wonderful Time of the Year for Health-IT...NOT
The Most Wonderful Time of the Year for Health-IT...NOT
 
365 infographic-compliance
365 infographic-compliance365 infographic-compliance
365 infographic-compliance
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUST
 
10 questions to ask your cloud provider
10 questions to ask your cloud provider10 questions to ask your cloud provider
10 questions to ask your cloud provider
 
HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...
HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...
HIPAA Compliant Salesforce Health Cloud – Why Healthcare Organizations Must C...
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
 
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_CloudPerspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
Perspecsys_Best_Practices_Guide_for_Protecting_Healthcare_Data_in_the_Cloud
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
Hortonworks help customers building a HIPAA compliant Data Lake
Hortonworks help customers building a HIPAA compliant Data Lake Hortonworks help customers building a HIPAA compliant Data Lake
Hortonworks help customers building a HIPAA compliant Data Lake
 
The importance of hipaa compliance and training
The importance of hipaa compliance and trainingThe importance of hipaa compliance and training
The importance of hipaa compliance and training
 
HIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and GuidelinesHIPAA and Patient Access of Information - New Rules and Guidelines
HIPAA and Patient Access of Information - New Rules and Guidelines
 
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...Business Associates: How to become HIPAA compliant, increase revenue, and gai...
Business Associates: How to become HIPAA compliant, increase revenue, and gai...
 
HIPAA Conduit Exception: The Facts
HIPAA Conduit Exception: The FactsHIPAA Conduit Exception: The Facts
HIPAA Conduit Exception: The Facts
 

More from Texas Medical Liability Trust

More from Texas Medical Liability Trust (20)

TMB pain management rules
TMB pain management rulesTMB pain management rules
TMB pain management rules
 
Telemedicine: Managing your risks
Telemedicine: Managing your risksTelemedicine: Managing your risks
Telemedicine: Managing your risks
 
Cultural Competency
Cultural CompetencyCultural Competency
Cultural Competency
 
COVID-19 Re-opening Your Practice
COVID-19 Re-opening Your PracticeCOVID-19 Re-opening Your Practice
COVID-19 Re-opening Your Practice
 
Texas COVID-19 regulatory changes
Texas COVID-19 regulatory changesTexas COVID-19 regulatory changes
Texas COVID-19 regulatory changes
 
Strategies to Improve Patient Follow Up
Strategies to Improve Patient Follow UpStrategies to Improve Patient Follow Up
Strategies to Improve Patient Follow Up
 
Telemedicine and Telehealth
Telemedicine and TelehealthTelemedicine and Telehealth
Telemedicine and Telehealth
 
Medical Malpractice Claim Trends
Medical Malpractice Claim TrendsMedical Malpractice Claim Trends
Medical Malpractice Claim Trends
 
10 Things That Compromise Patient Data
10 Things That Compromise Patient Data10 Things That Compromise Patient Data
10 Things That Compromise Patient Data
 
Human Trafficking, Part 2
Human Trafficking, Part 2Human Trafficking, Part 2
Human Trafficking, Part 2
 
Human Trafficking, Part 1
Human Trafficking, Part 1Human Trafficking, Part 1
Human Trafficking, Part 1
 
Risk Management Trends
Risk Management TrendsRisk Management Trends
Risk Management Trends
 
Ransomware attacks
Ransomware attacksRansomware attacks
Ransomware attacks
 
Addressing transgender health care disparities
Addressing transgender health care disparitiesAddressing transgender health care disparities
Addressing transgender health care disparities
 
Keeping Your Email Secure
Keeping Your Email SecureKeeping Your Email Secure
Keeping Your Email Secure
 
Case Closed: HIPAA and patient privacy
Case Closed: HIPAA and patient privacyCase Closed: HIPAA and patient privacy
Case Closed: HIPAA and patient privacy
 
Googling Your Patients
Googling Your PatientsGoogling Your Patients
Googling Your Patients
 
CDC Guidelines for Prescribing Opioids
CDC Guidelines for Prescribing OpioidsCDC Guidelines for Prescribing Opioids
CDC Guidelines for Prescribing Opioids
 
Top 10 Risk Management Recommendations
Top 10 Risk Management RecommendationsTop 10 Risk Management Recommendations
Top 10 Risk Management Recommendations
 
Combating Physician Stress and Burnout
Combating Physician Stress and BurnoutCombating Physician Stress and Burnout
Combating Physician Stress and Burnout
 

Recently uploaded

(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...indiancallgirl4rent
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...Gfnyt.com
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591adityaroy0215
 
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetbhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Chandigarh Escorts, 😋9988299661 😋50% off at Escort Service in Chandigarh
Chandigarh Escorts, 😋9988299661 😋50% off at Escort Service in ChandigarhChandigarh Escorts, 😋9988299661 😋50% off at Escort Service in Chandigarh
Chandigarh Escorts, 😋9988299661 😋50% off at Escort Service in ChandigarhSheetaleventcompany
 
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetraisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Memriyagarg453
 
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171Call Girls Service Gurgaon
 
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetnagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Memriyagarg453
 
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMuzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetJalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Vipesco
 
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetCall Girls Service
 
Jaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
Jaipur Call Girls 9257276172 Call Girl in Jaipur RajasthanJaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
Jaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthanindiancallgirl4rent
 
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...Ahmedabad Call Girls
 
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In FaridabadCall Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabadgragmanisha42
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...russian goa call girl and escorts service
 

Recently uploaded (20)

(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
(Ajay) Call Girls in Dehradun- 8854095900 Escorts Service 50% Off with Cash O...
 
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF  ...
❤️♀️@ Jaipur Call Girls ❤️♀️@ Jaispreet Call Girl Services in Jaipur QRYPCF ...
 
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
VIP Call Girl Sector 88 Gurgaon Delhi Just Call Me 9899900591
 
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetbhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
bhubaneswar Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Chandigarh Escorts, 😋9988299661 😋50% off at Escort Service in Chandigarh
Chandigarh Escorts, 😋9988299661 😋50% off at Escort Service in ChandigarhChandigarh Escorts, 😋9988299661 😋50% off at Escort Service in Chandigarh
Chandigarh Escorts, 😋9988299661 😋50% off at Escort Service in Chandigarh
 
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetraisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
raisen Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near MeVIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
VIP Call Girls Noida Jhanvi 9711199171 Best VIP Call Girls Near Me
 
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Mangalore Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171VIP Call Girl Sector 32 Noida Just Book Me 9711199171
VIP Call Girl Sector 32 Noida Just Book Me 9711199171
 
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetnagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
nagpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near MeVIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
VIP Call Girls Noida Sia 9711199171 High Class Call Girl Near Me
 
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetMuzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Muzaffarpur Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real MeetJalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
Jalna Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510Krishnagiri call girls Tamil aunty 7877702510
Krishnagiri call girls Tamil aunty 7877702510
 
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meetooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
ooty Call Girls 👙 6297143586 👙 Genuine WhatsApp Number for Real Meet
 
Jaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
Jaipur Call Girls 9257276172 Call Girl in Jaipur RajasthanJaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
Jaipur Call Girls 9257276172 Call Girl in Jaipur Rajasthan
 
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
(Deeksha) 💓 9920725232 💓High Profile Call Girls Navi Mumbai You Can Get The S...
 
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In FaridabadCall Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
Call Girls Service Faridabad 📲 9999965857 ヅ10k NiGhT Call Girls In Faridabad
 
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Hyderabad Just Call 9907093804 Top Class Call Girl Service Available
 
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...Call Girls Service In Goa  💋 9316020077💋 Goa Call Girls  By Russian Call Girl...
Call Girls Service In Goa 💋 9316020077💋 Goa Call Girls By Russian Call Girl...
 

What Every Physician Needs to Know About Cloud Storage

  • 1. WHAT EVERY PHYSICIAN NEEDS TO KNOW ABOUT CLOUD STORAGE
  • 2. 1 GROWING TREND CLOUD-BASED STORAGE IS A GROWING TREND IN HEALTH CARE. • Health care providers are using cloud storage for data collection, aggregation, analytics, and decision making. • By 2020, 80 percent of health care data will pass through “the cloud” at some point in its lifetime. 1 1. http://www.fiercehealthit.com/story/2015-healthcare-predictions-growth-analytics-mobile-security-risks/2014-11-21
  • 3. 2 BUSINESS ASSOCIATE • According to the HIPAA Omnibus rule, cloud storage providers are business associates and must comply with privacy and security rules. A VENDOR DOES NOT HAVE TO VIEW PATIENT DATA TO BE CONSIDERED A BUSINESS ASSOCIATE.
  • 4. 3 BUSINESS ASSOCIATE AGREEMENT (BAA) BAA’S MAIN PURPOSE: • To legally document and acknowledge the relationship between the covered entity and the cloud storage provider, while also setting rules and expectations for each party. • The cloud storage provider must understand that they are required to take certain steps to appropriately safeguard the privacy and security of the data it stores. ASK YOUR CYBER LIABILITY INSURANCE PROVIDER ABOUT WHAT TO INCLUDE IN A BAA.
  • 5. 4 HIPAA COMPLIANCE JUST BECAUSE CLOUD STORAGE VENDORS CLAIM THEY ARE “CERTIFIED HIPAA COMPLIANT” DOES NOT MEAN THEY ACTUALLY ARE. • Proper vetting must take place on any vendor you are considering. • Some third parties will assess HIPAA compliance among cloud storage providers, but such HIPAA certification is not recognized by HHS or any other government body. -- A cloud provider’s (or a third party reviewer’s) definition of HIPAA compliance may not equate to the HHS definition of compliance.
  • 6. 5 HIPAA COMPLIANCE YOU MIGHT WANT TO ASK 1. About obtaining documentation of a quality third party assessment of vendor’s HIPAA compliance. 2. How often does the cloud provider conduct a risk analysis and will they provide information from their most recent risk analysis? 3. What specific security controls do they have in place? (For example, what form of encryption is used and on what information? Who has access to the keys?)
  • 7. 6 HIPAA COMPLIANCE • According to the HIPAA Omnibus rule, covered entities share the responsibility when a business associate has a security breach, meaning both are responsible for sending proper notifications if a security breach occurs. • Two separate risk assessments must occur – one must be conducted by the cloud provider and one must be conducted by the covered entity.
  • 8. 7 DATA STORAGE POLICY QUESTIONS TO ASK • How will the vendor back up the data? How will the data be restored? • Will the vendor’s staff ever read or look at the data? If so, in what situations? • Under what circumstances would the vendor turn data over to law enforcement, with or without a warrant? • What happens if you surpass your storage limits? • Does the vendor have a plan for returning your data if the vendor were to sell, go out of business, or your contract is terminated?
  • 9. 8 CONCLUSION • When choosing a cloud storage provider, be cautious about claims of HIPAA compliance. • Appropriately vet the vendor and sign an appropriate BAA to ensure patient privacy and security. • Choose a provider that understands the requirements of the HIPAA Omnibus rule.
  • 10. 9 SOURCES • Cloud Security Toolkit, Navigating HIPAA While Moving to the Cloud by Adam H. Greene, JD, MPH http://www.himss.org/ResourceLibrary/genResourceDetailPDF. aspx?ItemNumber=28307 • Top 10 Things to Consider About Omnibus for Cloud Storage http://www.ironmountain.com/~/media/Files/Iron%20Mountain/ Knowledge%20Center/Reference%20Library/Best%20Practices/ Top_10_Things_to_Consider_About_Omnibus_for_Cloud_Storage. pdf?dmc=1&ts=20150810T1230482174
  • 11. 10 ABOUT TMLT: With more than 17,500 physicians in its care, Texas Medical Liability Trust (TMLT) provides malpractice insurance and related products to physicians. Our purpose is to make a positive impact on the quality of health care for patients by educating, protecting, and defending physicians. www.tmlt.org Find us on: PROTECTION FOR A NEW ERA OF MEDICINE