Top Banner
Joe Dylewski Health Care Management © 2012 Health Care Management
19

Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities

May 11, 2015

Download

Business

Welcome message from author
This document is posted to help you gain knowledge. Please leave a comment to let me know what you think about it! Share it to your friends and learn new things together.
Transcript
Page 1: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Joe DylewskiHealth Care Management

© 2012 Health Care Management

Page 2: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

HIPAA, HITECH, and The Business Associate

Relationships with Healthcare Entities and Medical Practices

Next StepsSummary and Q/A

© 2012 Health Care Management

Page 3: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

MSPs

MSSPs

IT Service Providers

600K +

© 2012 Health Care Management

Page 4: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

▪ Defining the “certain functions or activities”

▪ Disclosures▪ Services▪ Reasonable and Appropriate Safeguards

© 2012 Health Care Management

Page 5: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

HIPAA

Title II

Administrative Simplification

Electronic Data

Interchange (Transaction

and Code Sets)

Privacy RuleSecurity

Rule

Administrative Safeguards

45 CFR 164.308

Physical Safeguards

45 CFR 164.310

Technical Safeguards

45 CFR 164.312

© 2012 Health Care Management

Page 6: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

What is HITECH? HITECH - The Health Information

Technology for Economic Recovery and Reinvestment Act of 2009 Meaningful Use Education HIPAA Enforcement

© 2012 Health Care Management

Page 7: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

What changed relative to HIPAA? Physician Attestation for Meaningful Use Improved Enforcement HIPAA ignorance no longer tolerated Business Associates now have the same

HIPAA responsibilities as the Covered Entities they service

© 2012 Health Care Management

Page 8: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Key Statistics

CategoryTotal

BreachesNo BA

InvolvedBA

Involved

Percent of Total 100% 79% 21%

Total Individuals Affected 21,021,132 8,917,133 12,103,99

9

Percent of Total 100% 42% 58%

Average Individuals per Breach 43,076 23,101 118,667

Source :U.S. Department of Health and Human Services HIPAA Breach Notifications – September 2009 to May 2012 © 2011 ATMP Solutions© 2012 Health Care Management

Page 9: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

“By exercising reasonable diligence would not

have known”

“Due to Willful

Neglect if the violation

is not corrected”

“Due to Willful

Neglect if the violation is corrected”

“Due to Reasonable Cause and not Willful Neglect”

Increasing Degree of HIPAA Compliance Effort

Decreasing Degree of HIPAA Compliance Risk

© 2012 Health Care Management

Page 10: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Business Associate is taking

necessary steps to

compliance

No Business Associate Contract in place

Business Associate Contract in Place

Business Associate

has Conducte

d Risk Assessme

nt

Increasing Degree of HIPAA Compliance Effort by Covered Entity and Business Associate

Decreasing Degree of HIPAA Compliance Risk to Covered Entity

Business Associate proof of HIPAA

Compliance

© 2012 Health Care Management

Page 11: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Is the Covered Entity responsible for their Business Associate’s HIPAA Compliance, or vice versa? No

Is the Covered Entity responsible for engaging in relationships with HIPAA Compliant Business Associates? Yes

If the Business Associate claims HIPAA Compliance, does this imply that the Covered Entity is HIPAA Compliant? No

© 2011 ATMP Solutions© 2012 Health Care Management

Page 12: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Solution Complian

ce

Institutional

Compliance

Electronic Medical Record

HIPAA Compliant EMR Hosted in a HIPAA Compliant Facility

EMR Company HIPAA Compliance with respect to internal operating policies

© 2012 Health Care Management

Page 13: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Private Cloud / Data Center

Private Cloud / Data Center

Health Information Exchange

(HIE)

Health Information Exchange

(HIE)

EMR

Physician Practice

IT Services

Document Destruction

Insurance Company

Health System

Lab

DR Site

© 2012 Health Care Management

Page 14: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Private Cloud / Data Center

Private Cloud / Data Center

Health Information Exchange

(HIE)

Health Information Exchange

(HIE)

EMR

Physician Practice

IT Services

Document Destruction

Insurance Company

Health System

Lab

DR Site

© 2012 Health Care Management

Page 15: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Private Cloud / Data Center

Private Cloud / Data Center

Health Information Exchange

(HIE)

Health Information Exchange

(HIE)

EMR

Physician Practice

IT Services

Document Destruction

Insurance Company

Health System

Lab

DR Site

© 2012 Health Care Management

Page 16: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Compliance

Privacy / Security

Policy Proof

© 2012 Health Care Management

Page 17: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

United States Department of Health and Human Services Office of Civil Rights

Individual state’s Office of The Attorney General

© 2012 Health Care Management

Page 18: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Treat HIPAA compliance with the same degree of diligence and urgency as Accounting, Taxes, and the IRS

Start with a simple checklist of areas that need to be addressed A.K.A. - Risk Assessment

© 2012 Health Care Management

Page 19: Business Associate HIPAA Compliance   Impact on the Business Associate and Covered Entities

Questions and Answers

[email protected]

© 2012 Health Care Management