SlideShare une entreprise Scribd logo
1  sur  1
The New Trend in Healthcare IT



Business Associate Initial Assessment Questionnaire
Goal: This initial business associate assessment questionnaire has been designed to support
the requirements of the Department of Health and Human Services (HHS), Office for the Civil
Rights (OCR) and other applicable data privacy laws and regulations. Upon completion of this
assessment questionnaire, a detail assessment questionnaire will be shared, if required, with
the business associate based on the response. It is not to be considered a binding contractual
document, but only a discovery mechanism to assist in fact-finding between the covered entity
and business associate.

Scope: Under the HIPAA Privacy and Security Rules health care organizations are required to
perform active risk prevention and safeguarding of patient information that are very important to
patient privacy. Health care organizations often use the services of a variety of contractors and
businesses. The HITECH act allows covered entities to disclose the minimum necessary for
protected health information (PHI) to these “business associates”. This should only be
allowed if the covered entities obtain satisfactory documented assurances that the business
associate will use the PHI information only for the required designated business purposes for
which it was engaged in contract by the covered entity. The business associate must
safeguard any and all subsequent information from misuse, abuse or unauthorized
disclosures. The business associate is required to render due diligence to help protect the
covered entity in complying with the covered entity’s duties under the HIPAA Privacy Rule within
the scope of their normal business processes, operations and services to the covered entity.


1. Security policy
Do you have formal and documented security policies, standards, plans and procedures?


A set of rules and procedures regulating the use of PHI, including its processing, storage,
distribution, and presentation. The set of laws, rules, and practices that regulate how an
organization manages, protects, and distributes PHI information.

COMMENTS BY BA:




2. Change control
Does your organization have a change control procedure to support your security policy?


Changes to the system, network, applications, databases, other system components, and
physical/environmental changes should be monitored and controlled. Changes should be
Your source for healthcare IT security and compliance                                       www.ehr20.com
Education * Consulting Services * Toolkit                                                     802-448-2255
                                                                                           info@ehr20.com

Contenu connexe

Plus de data brackets

Raleigh Orthopedic RA and CAP April 2016
Raleigh Orthopedic RA and CAP April 2016Raleigh Orthopedic RA and CAP April 2016
Raleigh Orthopedic RA and CAP April 2016data brackets
 
HIPAA Violation Fines: North memorial Hospistal Settlement
 HIPAA Violation Fines: North memorial Hospistal Settlement  HIPAA Violation Fines: North memorial Hospistal Settlement
HIPAA Violation Fines: North memorial Hospistal Settlement data brackets
 
Prepayment Audit Suggested Documentation
Prepayment Audit Suggested DocumentationPrepayment Audit Suggested Documentation
Prepayment Audit Suggested Documentationdata brackets
 
Lincare HIPAA remediated decision by administrative judge
Lincare HIPAA remediated decision by administrative judgeLincare HIPAA remediated decision by administrative judge
Lincare HIPAA remediated decision by administrative judgedata brackets
 
Lincare HIPAA Notice of Proposed Determination remediated
Lincare HIPAA Notice of Proposed Determination remediatedLincare HIPAA Notice of Proposed Determination remediated
Lincare HIPAA Notice of Proposed Determination remediateddata brackets
 
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...data brackets
 
Office of Inspector General Study on OCR's HIPAA audit program
Office of Inspector General Study on OCR's HIPAA audit programOffice of Inspector General Study on OCR's HIPAA audit program
Office of Inspector General Study on OCR's HIPAA audit programdata brackets
 
Cancer Care Group HIPAA Settlement Agreement
Cancer Care Group HIPAA Settlement AgreementCancer Care Group HIPAA Settlement Agreement
Cancer Care Group HIPAA Settlement Agreementdata brackets
 
Parkview HIPAA Settlement - Resolution Agreement
Parkview HIPAA Settlement - Resolution AgreementParkview HIPAA Settlement - Resolution Agreement
Parkview HIPAA Settlement - Resolution Agreementdata brackets
 
HIPAA Settlement New York Presbyterian and Columbia Universtiy
HIPAA Settlement New York Presbyterian and Columbia UniverstiyHIPAA Settlement New York Presbyterian and Columbia Universtiy
HIPAA Settlement New York Presbyterian and Columbia Universtiydata brackets
 
Skagit county- HIPAA violation settlement agreement with HHS
Skagit county- HIPAA violation settlement agreement with HHSSkagit county- HIPAA violation settlement agreement with HHS
Skagit county- HIPAA violation settlement agreement with HHSdata brackets
 
EHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample documentEHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample documentdata brackets
 
Adult & Pediatric Dermatology, Corrective Action Plan
Adult & Pediatric Dermatology, Corrective Action PlanAdult & Pediatric Dermatology, Corrective Action Plan
Adult & Pediatric Dermatology, Corrective Action Plandata brackets
 
OCR HHS HIPAA HITECH Audit Advisory Template
OCR HHS HIPAA HITECH Audit Advisory TemplateOCR HHS HIPAA HITECH Audit Advisory Template
OCR HHS HIPAA HITECH Audit Advisory Templatedata brackets
 
HIPAA HITECH Compliance Assurance Template
HIPAA HITECH Compliance Assurance TemplateHIPAA HITECH Compliance Assurance Template
HIPAA HITECH Compliance Assurance Templatedata brackets
 
HONI HIPAA Breach Resolution Agreement
HONI HIPAA Breach Resolution AgreementHONI HIPAA Breach Resolution Agreement
HONI HIPAA Breach Resolution Agreementdata brackets
 

Plus de data brackets (20)

Raleigh Orthopedic RA and CAP April 2016
Raleigh Orthopedic RA and CAP April 2016Raleigh Orthopedic RA and CAP April 2016
Raleigh Orthopedic RA and CAP April 2016
 
HIPAA Violation Fines: North memorial Hospistal Settlement
 HIPAA Violation Fines: North memorial Hospistal Settlement  HIPAA Violation Fines: North memorial Hospistal Settlement
HIPAA Violation Fines: North memorial Hospistal Settlement
 
Prepayment Audit Suggested Documentation
Prepayment Audit Suggested DocumentationPrepayment Audit Suggested Documentation
Prepayment Audit Suggested Documentation
 
Lincare HIPAA remediated decision by administrative judge
Lincare HIPAA remediated decision by administrative judgeLincare HIPAA remediated decision by administrative judge
Lincare HIPAA remediated decision by administrative judge
 
Lincare HIPAA Notice of Proposed Determination remediated
Lincare HIPAA Notice of Proposed Determination remediatedLincare HIPAA Notice of Proposed Determination remediated
Lincare HIPAA Notice of Proposed Determination remediated
 
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...
Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule and ...
 
Office of Inspector General Study on OCR's HIPAA audit program
Office of Inspector General Study on OCR's HIPAA audit programOffice of Inspector General Study on OCR's HIPAA audit program
Office of Inspector General Study on OCR's HIPAA audit program
 
Cancer Care Group HIPAA Settlement Agreement
Cancer Care Group HIPAA Settlement AgreementCancer Care Group HIPAA Settlement Agreement
Cancer Care Group HIPAA Settlement Agreement
 
Parkview HIPAA Settlement - Resolution Agreement
Parkview HIPAA Settlement - Resolution AgreementParkview HIPAA Settlement - Resolution Agreement
Parkview HIPAA Settlement - Resolution Agreement
 
HIPAA Settlement New York Presbyterian and Columbia Universtiy
HIPAA Settlement New York Presbyterian and Columbia UniverstiyHIPAA Settlement New York Presbyterian and Columbia Universtiy
HIPAA Settlement New York Presbyterian and Columbia Universtiy
 
Qca agreement
Qca agreementQca agreement
Qca agreement
 
Concentra agreement
Concentra agreementConcentra agreement
Concentra agreement
 
Skagit county- HIPAA violation settlement agreement with HHS
Skagit county- HIPAA violation settlement agreement with HHSSkagit county- HIPAA violation settlement agreement with HHS
Skagit county- HIPAA violation settlement agreement with HHS
 
EHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample documentEHR meaningful use security risk assessment sample document
EHR meaningful use security risk assessment sample document
 
Adult & Pediatric Dermatology, Corrective Action Plan
Adult & Pediatric Dermatology, Corrective Action PlanAdult & Pediatric Dermatology, Corrective Action Plan
Adult & Pediatric Dermatology, Corrective Action Plan
 
Affinity agreement
Affinity agreementAffinity agreement
Affinity agreement
 
Shasta agreement
Shasta agreementShasta agreement
Shasta agreement
 
OCR HHS HIPAA HITECH Audit Advisory Template
OCR HHS HIPAA HITECH Audit Advisory TemplateOCR HHS HIPAA HITECH Audit Advisory Template
OCR HHS HIPAA HITECH Audit Advisory Template
 
HIPAA HITECH Compliance Assurance Template
HIPAA HITECH Compliance Assurance TemplateHIPAA HITECH Compliance Assurance Template
HIPAA HITECH Compliance Assurance Template
 
HONI HIPAA Breach Resolution Agreement
HONI HIPAA Breach Resolution AgreementHONI HIPAA Breach Resolution Agreement
HONI HIPAA Breach Resolution Agreement
 

Business Associate Assessment Questinnaire

  • 1. The New Trend in Healthcare IT Business Associate Initial Assessment Questionnaire Goal: This initial business associate assessment questionnaire has been designed to support the requirements of the Department of Health and Human Services (HHS), Office for the Civil Rights (OCR) and other applicable data privacy laws and regulations. Upon completion of this assessment questionnaire, a detail assessment questionnaire will be shared, if required, with the business associate based on the response. It is not to be considered a binding contractual document, but only a discovery mechanism to assist in fact-finding between the covered entity and business associate. Scope: Under the HIPAA Privacy and Security Rules health care organizations are required to perform active risk prevention and safeguarding of patient information that are very important to patient privacy. Health care organizations often use the services of a variety of contractors and businesses. The HITECH act allows covered entities to disclose the minimum necessary for protected health information (PHI) to these “business associates”. This should only be allowed if the covered entities obtain satisfactory documented assurances that the business associate will use the PHI information only for the required designated business purposes for which it was engaged in contract by the covered entity. The business associate must safeguard any and all subsequent information from misuse, abuse or unauthorized disclosures. The business associate is required to render due diligence to help protect the covered entity in complying with the covered entity’s duties under the HIPAA Privacy Rule within the scope of their normal business processes, operations and services to the covered entity. 1. Security policy Do you have formal and documented security policies, standards, plans and procedures? A set of rules and procedures regulating the use of PHI, including its processing, storage, distribution, and presentation. The set of laws, rules, and practices that regulate how an organization manages, protects, and distributes PHI information. COMMENTS BY BA: 2. Change control Does your organization have a change control procedure to support your security policy? Changes to the system, network, applications, databases, other system components, and physical/environmental changes should be monitored and controlled. Changes should be Your source for healthcare IT security and compliance www.ehr20.com Education * Consulting Services * Toolkit 802-448-2255 info@ehr20.com