Showing posts with label Business Associate Agreement. Show all posts
Showing posts with label Business Associate Agreement. Show all posts

Thursday, June 15, 2017

Hold Your Business Associates Feet To The Fire

Documented HIPAA compliance training is NOT an option for your Business Associates!

With the focus of the Office for Civil Rights (OCR) so squarely on the Business Associates of Covered Entities, it is more important than ever to hold your Business Associates feet to the fire when it comes to providing proof of their HIPAA training.

It is strongly recommended that Covered Entities require {45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)} all of their Business Associates to provide them with documented proof of their HIPAA compliance training. This documentation could come in the form of individual employee training certificates or (if the Business Associate does not have training certifications) a signed addendum along with your Business Associate Agreement (BAA) attesting to the fact that the Business Associate's HIPAA training program was completed and will continue to be on an annual basis to maintain a standard for ongoing compliance training and awareness of evolving standards.

Far too often, I have talked with Covered Entities who's Business Associates verbally claimed that all of their employees were HIPAA trained, but could not provided documented proof. Simply saying, "Yah sure, we do HIPAA training..." is not enough proof for OCR. It is vital that Covered Entities are able to provide documentation of their Business Associates claim that they have completed their HIPAA training. If a Covered Entity is working with a Business Associate who either does not have documented proof of their HIPAA training program or refuses to supply the Covered Entity with such documentation, then that Covered Entity has two options:
  1. Recommend a BA HIPAA Compliance Training Program to their Business Associate;
  2. Begin exploring the option of no longer doing business with that particular Business Associate
Remember a BAA is a binding legal Contract and should be treated accordingly. Having Business Associates provide documented proof of a HIPAA training program will greatly assist in helping to limit additional liabilities for a Covered Entity and their patients.


To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Friday, May 27, 2016

Identifying Business Associates

Covered Entities & Business Associates
 HCSI
With business associates and business associate agreements (BAAs) coming under increased scrutiny in the latest round of HIPAA audits, some covered entities are wondering how to identify which vendors are considered business associates, and therefore require a BAA, and which vendors are not.
According to the Privacy Rule, a business associate is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information (PHI) on behalf of, or provides services to, a covered entity (CE).
Business associate functions and activities include the following:
        Claims processing or administration;
        Data analysis;
        Processing or administration;
        Utilization review;
        Quality assurance;
        Billing;
        Benefit management;
        Practice management; and
        Repricing;
Additionally, any entity that provides any of the following services involving the disclosure of PHI by a CE, is a business associate:
        Legal;
        Actuarial;
        Accounting;
        Consulting;
        Data aggregation;
        Management;
        Administrative;
        Accreditation; or
        Financial.
In addition, the Omnibus Rule includes a new definition of a business associate. A business associate is also defined as an individual or organization that creates, receives, maintains, or transmits PHI on behalf of a CE. In addition, four new categories were added to the definition:
        Health Information Exchanges;
        E-prescribing gateways;
        Data transmission services; and
        Entities that offer a personal health record to individuals on behalf of a CE.
The following is a list of sample business associates a CE may have. A BAA would need to be initiated for all of these vendors. Examples include
        IT companies that support health care providers;
        Electronic Health Record (EHR) system providers;
        Data centers, online backup companies, cloud service providers, even if they do not access data;
        Shredding companies;
        Insurance agents;
        A CPA firm whose accounting services to a health care provider involve access to PHI;
        An attorney whose legal services to a health plan or provider involve access to PHI;
        Any person or entity providing services to a business associate that requires access to PHI; and
        Data centers, online backup companies, cloud service providers, providing services to a business associate, even if they do not access data.
The Privacy rule also outlines situations where it is not necessary to enter into a BAA. Some examples of when a BAA is not required are the following:
        When a health care provider discloses PHI to a health plan for payment purposes, or when the health care provider simply accepts a discounted rate to participate in the health plan’s network.
        With persons or organizations (e.g., janitorial service or electrician) whose functions or services do not involve the use or disclosure of PHI, and where any access to PHI by such persons would be incidental, if at all.
        Among CEs who participate in an organized health care arrangement (OHCA) to make disclosures that relate to the joint health care activities of the OHCA.
        Where a group health plan purchases insurance from a health insurance issuer or HMO.
        Where one CE purchases a health plan product or other insurance, for example, reinsurance, from an insurer.
        With a person or organization that acts merely as a conduit for PHI, for example, the US Postal Service, certain private couriers, and their electronic equivalents.
        To disclose PHI to a researcher for research purposes, either with patient authorization, pursuant to a waiver, or as a limited data set.
        When a financial institution processes consumer-conducted financial transactions by debit, credit, or other payment card, clears checks, initiates or processes electronic funds transfers, or conducts any other activity that directly facilitates or affects the transfer of funds for payment for health care or health plan premiums.
Also included are the following exceptions to the business associate standard. In these situations, a CE is not required to have a BAA or other written agreement in place before PHI may be disclosed to the person or entity.
        Disclosures by a covered entity to a health care provider for treatment of the individual;
        Disclosures to a health plan sponsor, such as an employer, by a group health plan, or by the health insurance issuer or HMO that provides the health insurance benefits or coverage for the group health plan, provided that the group health plan’s documents have been amended to limit the disclosures or one of the exceptions at 45 CFR 164.504(f) have been met;
        The collection and sharing of PHI by a health plan that is a public benefits program, such as Medicare, and an agency other than the agency administering the health plan, such as the Social Security Administration, that collects PHI to determine eligibility or enrollment, or determines eligibility or enrollment, for the government program, where the joint activities are authorized by law; and

        Patient safety organizations.
Source(s): http://www.hcsiinc.com, http://www.hhs.gov

To subscribe to this blog, enter your email address:


Delivered by FeedBurner

Wednesday, July 8, 2015

10 Business Associate Agreement Requirements

10 HIPAA Requirements for Business Associate Agreements


HIPAA requires that covered entities (CEs) enter into contracts with their business associates (BAs) to ensure that BAs will appropriately safeguard protected health information (PHI).  The business associate contract also serves to clarify and limit the permissible uses and disclosures of PHI based on the relationship between the parties and the services being performed.

The Department of Health and Human Services (HHS) Office for Civil Rights in 2013 issued extensive guidance on handling BA agreements under the HIPAA privacy and security rules. This guidance has been condensed down to the following 10 requirements. Some requirements are commonly included in a business associate agreement, but others may not be.

1.      Determine when and how the business associate is allowed to use or disclose PHI.
2.      Require that the BA will not use or disclose PHI other than what has been permitted by the contract or required by law.
3.      Establish what safeguards will be put in place to prevent unauthorized PHI disclosure. This includes implementing HIPAA requirements surrounding electronic PHI.
4.      Require the BA to report to the CE any use or disclosure of PHI not covered by the contract, including incidents or breaches of unsecured PHI.
5.      Ensure the BA will disclose PHI as specified in the contract to satisfy a CE’s obligation with respect to individuals’ requests for copies of their PHI. PHI should be available for amendments as well.
6.      To the extent the BA is to carry out a CE’s obligation under HIPAA, require that the BA comply with the requirement relevant to the obligation.
7.      Ensure internal practices, books and records relating to the use and disclosure of PHI by the BA will be made available to HHS to determine the CE’s HIPAA compliance.
8.      Require that the BA return or destroy all PHI received from, or created or received by the BA on the CE’s behalf, upon termination of the contract.
9.      Require that BAs enter into agreements with their subcontractors that may have access to PHI.
10.  Allow the CE to terminate the contract if the BA violates a material term of the contract.

Other helpful tips include:

        Keep all agreements in a centralized location that can be accessed anytime;
        Know when agreements expire;
        Continually monitor BA compliance by issuing assessments; and
        Include BAs in your risk analyses.


(SourceMedia website)