Showing posts with label BAA. Show all posts
Showing posts with label BAA. Show all posts

Thursday, July 28, 2016

Preparing for Phase 2 of HIPAA Audits

Phase 2 HIPAA audits are here. It’s no longer a matter of when.
The question is: Are you ready?
 HCSI
On March 21, 2016, the HHS Office for Civil Rights (OCR) launched the second phase of audits for compliance with HIPAA privacy, security and breach notification rules. And in his July 18, article, Second phase of HIPAA audits shifts into high gear, HDM’s Managing Editor Greg Slabodkin informed us that according to OCR, letters were delivered via email to “167 health plans, healthcare providers and clearinghouses” on July 11. Unlike the pilot audits that focused only on covered entities, Phase 2 targets both covered entities and their business associates.
While most of the Phase 2 audits will be desk audits, some onsite audits will be conducted. Phase 2 audits will focus on areas with high occurrences of noncompliance in Phase 1, particularly issues raised during data breach investigations. These include risk analysis and management, notice of privacy practices, timeliness of breach notification, reasonable safeguards, facility access control, and workforce training on policies and procedures.

To prepare for Phase 2 audits, covered entities and business associates should review their HIPAA privacy, security and breach notification policies and confirm that the following requirements are in place and current:

Comprehensive documented risk assessment. Promptly address any deficiencies and complete all action items. Build on the assessment outcomes to create a strong risk assessment management program. Conduct a follow-up security risk analysis periodically to identify, address and document deficiencies that may occur.

Written HIPAA policies and procedures. These should reflect privacy and security standards along with any risks or vulnerabilities identified during the assessment process.

Incident response plan for responding to breach of protected health information (PHI). Implement breach notification policies and procedures that are aligned with requirements under the HIPAA breach notification standards. Conduct practice rounds to prepare staff for a real event should it occur. 

Current Notice of Privacy Practices. Provide printed copies of the most recent notice to patients and also make the notice available on the organization’s website. 

Safeguards to protect all forms of PHI. This applies to paper, electronic and verbal PHI, including mobile devices and storage media. For employees who have personal devices, implement a BYOD policy aligned with HIPAA standards. Keep an up-to-date inventory of all systems and mobile devices.

Workforce training program. Conduct and document training for new employees. Conduct and document ongoing training for all workforce members.


Business associate agreements. Organizations must maintain a current inventory of all business associates. Agreements should be updated and implemented in compliance with current HIPAA requirements.

PHI transmission policy. Verify that all PHI is encrypted, or document a risk analysis to support the decision not to use encryption technology. 

Even if your organization is not selected for a Phase 2 audit, implementing judicious measures now will support future audits and improve HIPAA compliance. 

It doesn’t just end with an audit occurring within the four walls of a healthcare organization. With more healthcare professionals working from home, there is growing concern about the possibility of “at-home” audits - if not now, these may happen in the near future. We’re operating in a virtual world - building a remote workforce, and many HIM departments are sending people home - coders, transcriptionists, even management staff. 

Suppose OCR conducts an onsite audit at your facility and finds that some employees work from home. You must be prepared for the inevitable questions. How are you protecting information offsite? What measures are you taking to make sure PHI is secure? What policies and procedures are in place to address specific issues of at-home worksites? If you’re preparing for OCR audits - or any audits - these are increasingly important points to consider.

Business associates should also be taking a proactive approach in case auditors want to know how workers at home are being audited. Options might include Skype, Facetime or Hangouts. Here are some basic questions to ask employees when evaluating at-home privacy and security risks: 
  • Where are you located in your personal residence? 
  • Is your workspace private? 
  • Are passcodes properly concealed, not posted in the workspace? 
  • Do you use a virtual privacy network (VPN)? 
  • Do you have the capability to print information? 
  • Do you have appropriate shredding capability? 
  • Is your computer set to shut down (encryption mode) in your absence? 
These questions are just the beginning of the conversation. It is critical to communicate clear expectations to employees who work at home - along with consequences if they fail to maintain privacy and security according to your policies and procedures.

A company’s work-from-home policy defines the telecommuting work arrangement, including comprehensive privacy and security practices. The telecommuting employee must sign an agreement to ensure the protection of proprietary information and PHI, and to maintain the same level of confidentiality that exists on the company premises. If issues arise, there are several options depending on the severity of noncompliance - corrective action, education and training, increased audits, return to in-house, or termination of employment.

Although current OCR requirements do not specifically require at-home audits, the regulations clearly state that all reasonable precautions must be taken to ensure that all information is secure and privacy is maintained.

The best way to mitigate regulation issues is to have a solid HIPAA program in place and be well prepared to demonstrate best practices that proactively identify and address risks to PHI.

HIM must work closely with IT and other departments - risk management, C-suite, compliance, training and HR - to properly prepare for audits. HIM directors and their staff understand the content and use of PHI, where it is most likely to be at risk, and how to protect it. As experts in HIPAA and information governance practices, HIM professionals and Compliance Support Partners can lead organizations through a successful audit.

Also See: OCR's Top 7 Areas of Focus During Phase Two Audits



To subscribe to this blog, enter your email address:

Delivered by FeedBurner

Friday, May 27, 2016

Identifying Business Associates

Covered Entities & Business Associates
 HCSI
With business associates and business associate agreements (BAAs) coming under increased scrutiny in the latest round of HIPAA audits, some covered entities are wondering how to identify which vendors are considered business associates, and therefore require a BAA, and which vendors are not.
According to the Privacy Rule, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) on behalf of, or provides services to, a covered entity (CE).
Business associate functions and activities include the following:
        Claims processing or administration;
        Data analysis;
        Processing or administration;
        Utilization review;
        Quality assurance;
        Billing;
        Benefit management;
        Practice management; and
        Repricing;
Additionally, any entity that provides any of the following services involving the disclosure of PHI by a CE, is a business associate:
        Legal;
        Actuarial;
        Accounting;
        Consulting;
        Data aggregation;
        Management;
        Administrative;
        Accreditation; or
        Financial.
In addition, the Omnibus Rule includes a new definition of a business associate. A business associate is also defined as an individual or organization that creates, receives, maintains, or transmits PHI on behalf of a CE. In addition, four new categories were added to the definition:
        Health Information Exchanges;
        E-prescribing gateways;
        Data transmission services; and
        Entities that offer a personal health record to individuals on behalf of a CE.
The following is a list of sample business associates a CE may have. A BAA would need to be initiated for all of these vendors. Examples include
        IT companies that support health care providers;
        Electronic Health Record (EHR) system providers;
        Data centers, online backup companies, cloud service providers, even if they do not access data;
        Shredding companies;
        Insurance agents;
        A CPA firm whose accounting services to a health care provider involve access to PHI;
        An attorney whose legal services to a health plan or provider involve access to PHI;
        Any person or entity providing services to a business associate that requires access to PHI; and
        Data centers, online backup companies, cloud service providers, providing services to a business associate, even if they do not access data.
The Privacy rule also outlines situations where it is not necessary to enter into a BAA. Some examples of when a BAA is not required are the following:
        When a health care provider discloses PHI to a health plan for payment purposes, or when the health care provider simply accepts a discounted rate to participate in the health plan’s network.
        With persons or organizations (e.g., janitorial service or electrician) whose functions or services do not involve the use or disclosure of PHI, and where any access to PHI by such persons would be incidental, if at all.
        Among CEs who participate in an organized health care arrangement (OHCA) to make disclosures that relate to the joint health care activities of the OHCA.
        Where a group health plan purchases insurance from a health insurance issuer or HMO.
        Where one CE purchases a health plan product or other insurance, for example, reinsurance, from an insurer.
        With a person or organization that acts merely as a conduit for PHI, for example, the US Postal Service, certain private couriers, and their electronic equivalents.
        To disclose PHI to a researcher for research purposes, either with patient authorization, pursuant to a waiver, or as a limited data set.
        When a financial institution processes consumer-conducted financial transactions by debit, credit, or other payment card, clears checks, initiates or processes electronic funds transfers, or conducts any other activity that directly facilitates or affects the transfer of funds for payment for health care or health plan premiums.
Also included are the following exceptions to the business associate standard. In these situations, a CE is not required to have a BAA or other written agreement in place before PHI may be disclosed to the person or entity.
        Disclosures by a covered entity to a health care provider for treatment of the individual;
        Disclosures to a health plan sponsor, such as an employer, by a group health plan, or by the health insurance issuer or HMO that provides the health insurance benefits or coverage for the group health plan, provided that the group health plan’s documents have been amended to limit the disclosures or one of the exceptions at 45 CFR 164.504(f) have been met;
        The collection and sharing of PHI by a health plan that is a public benefits program, such as Medicare, and an agency other than the agency administering the health plan, such as the Social Security Administration, that collects PHI to determine eligibility or enrollment, or determines eligibility or enrollment, for the government program, where the joint activities are authorized by law; and

        Patient safety organizations.
Source(s): http://www.hcsiinc.com, http://www.hhs.gov

To subscribe to this blog, enter your email address:


Delivered by FeedBurner