SlideShare une entreprise Scribd logo
1  sur  19
Joe Dylewski
Health Care Management




                         © 2012 Health Care Management
 HIPAA, HITECH, and The Business Associate
 Relationships with Healthcare Entities and
  Medical Practices
 Next Steps
 Summary and Q/A




                                         © 2012 Health Care Management
IT Service
         Providers


                       MSPs


              600K +



MSSPs


                              © 2012 Health Care Management
▪ Defining the “certain functions or activities”
 ▪ Disclosures
 ▪ Services
 ▪ Reasonable and Appropriate Safeguards




                                                   © 2012 Health Care Management
HIPAA

                               Title II

                            Administrative
                            Simplification



          Electronic Data
            Interchange
                            Security Rule    Privacy Rule
         (Transaction and
             Code Sets)



Administrative                 Physical              Technical
  Safeguards                  Safeguards             Safeguards
45 CFR 164.308              45 CFR 164.310         45 CFR 164.312




                                                             © 2012 Health Care Management
What is HITECH?
   HITECH - The Health Information Technology for
    Economic Recovery and Reinvestment Act of 2009
     Meaningful Use
     Education
     HIPAA Enforcement




                                            © 2012 Health Care Management
What changed relative to HIPAA?
  Physician Attestation for Meaningful Use
  Improved Enforcement
  HIPAA ignorance no longer tolerated
  Business Associates now have the same HIPAA
  responsibilities as the Covered Entities they
  service



                                              © 2012 Health Care Management
Key Statistics
                                                                            Total        No BA                  BA
     Category                                                            Breaches      Involved           Involved
     Percent of Total                                                          100%        79%              21%
                                                                                                       12,103,99
     Total Individuals Affected                                       21,021,132      8,917,133                9
     Percent of Total                                                          100%        42%                       58%
     Average Individuals per Breach                                        43,076       23,101            118,667




Source :U.S. Department of Health and Human Services HIPAA Breach
Notifications – September 2009 to May 2012                                                    © 2012 Health Care 2011 ATMP Solutions
                                                                                                               © Management
Increasing Degree of HIPAA Compliance Effort




                                                               “By exercising
“Due to Willful       “Due to Willful         “Due to
                                                                 reasonable
 Neglect if the        Neglect if the      Reasonable
                                                              diligence would
violation is not        violation is      Cause and not
                                                                  not have
  corrected”            corrected”        Willful Neglect”
                                                                   known”


                   Decreasing Degree of HIPAA Compliance Risk




                                                                  © 2012 Health Care Management
Increasing Degree of HIPAA Compliance Effort by Covered Entity and
                            Business Associate



                               Business        Business
                                                               Business
No Business     Business       Associate      Associate is
                                                               Associate
 Associate     Associate          has            taking
                                                                proof of
Contract in    Contract in    Conducted        necessary
                                                                 HIPAA
   place         Place           Risk           steps to
                                                              Compliance
                              Assessment      compliance

        Decreasing Degree of HIPAA Compliance Risk to Covered Entity




                                                               © 2012 Health Care Management
   Is the Covered Entity responsible for their Business
    Associate’s HIPAA Compliance, or vice versa?
     No     
   Is the Covered Entity responsible for engaging in
    relationships with HIPAA Compliant Business
    Associates?
     Yes    
   If the Business Associate claims HIPAA Compliance,
    does this imply that the Covered Entity is HIPAA
    Compliant?
     No     
                                                 © 2012 Health Care 2011 ATMP Solutions
                                                                  © Management
Solution                         Institutional
                           Compliance                        Compliance




Electronic Medical   HIPAA Compliant EMR Hosted in   EMR Company HIPAA Compliance
Record               a HIPAA Compliant Facility      with respect to internal operating
                                                     policies




                                                                      © 2012 Health Care Management
EMR
                                                                      Health
                                                                       Health
                                                                   Information
                                                                    Information
                                                                    Exchange
                                                                     Exchange
                               Private Cloud / /                      (HIE)
                                                                       (HIE)
                                Private Cloud
                                Data Center
                                 Data Center

   DR Site




                                                                                              Insurance
                                                                                              Company
                     IT Services

                                                                                  Lab
                       Document Destruction
Physician Practice

                                                   Health System
                                                                                  © 2012 Health Care Management
EMR
                                                                      Health
                                                                       Health
                                                                   Information
                                                                    Information
                                                                    Exchange
                                                                     Exchange
                               Private Cloud / /                      (HIE)
                                                                       (HIE)
                                Private Cloud
                                Data Center
                                 Data Center

   DR Site




                                                                                              Insurance
                                                                                              Company
                     IT Services

                                                                                  Lab
                       Document Destruction
Physician Practice

                                                   Health System
                                                                                  © 2012 Health Care Management
EMR
                                                                      Health
                                                                       Health
                                                                   Information
                                                                    Information
                                                                    Exchange
                                                                     Exchange
                               Private Cloud / /                      (HIE)
                                                                       (HIE)
                                Private Cloud
                                Data Center
                                 Data Center

   DR Site




                                                                                              Insurance
                                                                                              Company
                     IT Services

                                                                                  Lab
                       Document Destruction
Physician Practice

                                                   Health System
                                                                                  © 2012 Health Care Management
Privacy /
           Security




         Compliance

Policy                 Proof




                          © 2012 Health Care Management
 United States Department of Health and Human
  Services
   Office of Civil Rights
 Individual state’s Office of The Attorney General




                                              © 2012 Health Care Management
 Treat HIPAA compliance with the same
  degree of diligence and urgency as
  Accounting, Taxes, and the IRS
 Start with a simple checklist of areas that
  need to be addressed
   A.K.A. - Risk Assessment




                                          © 2012 Health Care Management
Questions and Answers

jdylewski@healthcaremgt.net
        616.977.2679




                          © 2012 Health Care Management

Contenu connexe

En vedette

What is music and its objectives?
What is music and its objectives?What is music and its objectives?
What is music and its objectives?PRECY REGALADO
 
Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10Huynh Tinh
 
RDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China PresentationRDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China Presentationraydoyle133
 
Pphg waled ayad
Pphg waled ayadPphg waled ayad
Pphg waled ayadWaled Ayad
 
Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10Huynh Tinh
 
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)โสภณ ศุภวิริยากร
 
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)Manos Nikiforakis
 
La competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELELa competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELELuis Enrique Elias Ruiz
 
สรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อมสรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อมโสภณ ศุภวิริยากร
 
Mapeh what is music and its objectives
Mapeh what is music and its objectivesMapeh what is music and its objectives
Mapeh what is music and its objectivesPRECY REGALADO
 

En vedette (15)

Group 5
Group 5Group 5
Group 5
 
PhotoEditor
PhotoEditorPhotoEditor
PhotoEditor
 
What is music and its objectives?
What is music and its objectives?What is music and its objectives?
What is music and its objectives?
 
Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10Yahoo! Messenger Images On BlackBerry 10
Yahoo! Messenger Images On BlackBerry 10
 
RDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China PresentationRDC Sourcing Made Easy from China Presentation
RDC Sourcing Made Easy from China Presentation
 
TaraLaneMAT
TaraLaneMATTaraLaneMAT
TaraLaneMAT
 
Pphg waled ayad
Pphg waled ayadPphg waled ayad
Pphg waled ayad
 
Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10Yahoo! messenger images on black berry 10
Yahoo! messenger images on black berry 10
 
Winter weather
Winter weatherWinter weather
Winter weather
 
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
อบรมค่ายศิลปะ คุณธรรม และสิ่งแวดล้อม(Power point)
 
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
Παρουσίαση του νέου εξεταστικού συστήματος (v.3)
 
La competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELELa competencia digital: las TIC en la clase de ELE
La competencia digital: las TIC en la clase de ELE
 
สรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อมสรุปรายงานโครงการอบรมผ้ามัดย้อม
สรุปรายงานโครงการอบรมผ้ามัดย้อม
 
Kualiti kepimpinan
Kualiti kepimpinanKualiti kepimpinan
Kualiti kepimpinan
 
Mapeh what is music and its objectives
Mapeh what is music and its objectivesMapeh what is music and its objectives
Mapeh what is music and its objectives
 

Similaire à Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities

Interconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years LaterInterconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years Laterprivacypros
 
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based WellnessA Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based WellnessTanya Gonzalez
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfSeasiaInfotech2
 
Q11 protect privacy
Q11   protect privacyQ11   protect privacy
Q11 protect privacyTEDMED
 
HIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy WebinarHIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy WebinarCompliancy Group
 
Hipaa audits and enforcement
Hipaa audits and enforcementHipaa audits and enforcement
Hipaa audits and enforcementsupportc2go
 
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...MaRS Discovery District
 
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...Compliance Trainings
 
Hipaa random audit
Hipaa random auditHipaa random audit
Hipaa random auditsupportc2go
 
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!Shelly Megan
 
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdfUnderstanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdfOmniMD Healthcare
 
A Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act LandscapeA Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act LandscapeDenny Weinberg
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantCarbonite
 
Medscheme mauritius health outsourcing
Medscheme mauritius health outsourcingMedscheme mauritius health outsourcing
Medscheme mauritius health outsourcingmedschemeinternational
 
Medscheme health outsourcing ppt
Medscheme health outsourcing pptMedscheme health outsourcing ppt
Medscheme health outsourcing pptMedscheme
 

Similaire à Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities (20)

Interconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years LaterInterconnected Health 2012 Hitech 3 Years Later
Interconnected Health 2012 Hitech 3 Years Later
 
Hipaa omnibus presentation webinar
Hipaa omnibus presentation webinarHipaa omnibus presentation webinar
Hipaa omnibus presentation webinar
 
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based WellnessA Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
A Road Map: Moving From Participation Based Wellness to Outcomes Based Wellness
 
RajivKumarPrivacy
RajivKumarPrivacyRajivKumarPrivacy
RajivKumarPrivacy
 
An Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdfAn Overview of HIPAA Laws and Regulations.pdf
An Overview of HIPAA Laws and Regulations.pdf
 
Q11 protect privacy
Q11   protect privacyQ11   protect privacy
Q11 protect privacy
 
HIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy WebinarHIPAA HITECH Express Security Privacy Webinar
HIPAA HITECH Express Security Privacy Webinar
 
Lean Enterprise Initiative
Lean Enterprise InitiativeLean Enterprise Initiative
Lean Enterprise Initiative
 
Hipaa audits and enforcement
Hipaa audits and enforcementHipaa audits and enforcement
Hipaa audits and enforcement
 
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
MaRS Market Insights - Consumer Digital Health: Market Opportunities and New ...
 
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...Hipaa privacy and security 2014 update, including the latest trends in omnibu...
Hipaa privacy and security 2014 update, including the latest trends in omnibu...
 
Hipaa random audit
Hipaa random auditHipaa random audit
Hipaa random audit
 
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
The Importance of HIPAA Compliance in ensuring the Privacy and Security of PHI!
 
Salesforce ecollab himss2 copy
Salesforce ecollab himss2 copySalesforce ecollab himss2 copy
Salesforce ecollab himss2 copy
 
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdfUnderstanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
Understanding the Importance of HIPAA Compliance in Medical Billing Software.pdf
 
A Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act LandscapeA Complex Post Affordable Care Act Landscape
A Complex Post Affordable Care Act Landscape
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
Healthcare Without Walls
Healthcare Without WallsHealthcare Without Walls
Healthcare Without Walls
 
Medscheme mauritius health outsourcing
Medscheme mauritius health outsourcingMedscheme mauritius health outsourcing
Medscheme mauritius health outsourcing
 
Medscheme health outsourcing ppt
Medscheme health outsourcing pptMedscheme health outsourcing ppt
Medscheme health outsourcing ppt
 

Dernier

Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with CultureSeta Wicaksana
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756dollysharma2066
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxAndy Lambert
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...lizamodels9
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...lizamodels9
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLkapoorjyoti4444
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Sheetaleventcompany
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communicationskarancommunications
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Dipal Arora
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Serviceritikaroy0888
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...Aggregage
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Neil Kimberley
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1kcpayne
 

Dernier (20)

Organizational Transformation Lead with Culture
Organizational Transformation Lead with CultureOrganizational Transformation Lead with Culture
Organizational Transformation Lead with Culture
 
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
FULL ENJOY Call Girls In Mahipalpur Delhi Contact Us 8377877756
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
Monthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptxMonthly Social Media Update April 2024 pptx.pptx
Monthly Social Media Update April 2024 pptx.pptx
 
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
Russian Call Girls In Gurgaon ❤️8448577510 ⊹Best Escorts Service In 24/7 Delh...
 
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
Call Girls In DLf Gurgaon ➥99902@11544 ( Best price)100% Genuine Escort In 24...
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRLBAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
BAGALUR CALL GIRL IN 98274*61493 ❤CALL GIRLS IN ESCORT SERVICE❤CALL GIRL
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Pharma Works Profile of Karan Communications
Pharma Works Profile of Karan CommunicationsPharma Works Profile of Karan Communications
Pharma Works Profile of Karan Communications
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Falcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in indiaFalcon Invoice Discounting platform in india
Falcon Invoice Discounting platform in india
 
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
Call Girls Navi Mumbai Just Call 9907093804 Top Class Call Girl Service Avail...
 
Call Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine ServiceCall Girls In Panjim North Goa 9971646499 Genuine Service
Call Girls In Panjim North Goa 9971646499 Genuine Service
 
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
The Path to Product Excellence: Avoiding Common Pitfalls and Enhancing Commun...
 
Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023Mondelez State of Snacking and Future Trends 2023
Mondelez State of Snacking and Future Trends 2023
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 

Business Associate HIPAA Compliance Impact on the Business Associate and Covered Entities

  • 1. Joe Dylewski Health Care Management © 2012 Health Care Management
  • 2.  HIPAA, HITECH, and The Business Associate  Relationships with Healthcare Entities and Medical Practices  Next Steps  Summary and Q/A © 2012 Health Care Management
  • 3. IT Service Providers MSPs 600K + MSSPs © 2012 Health Care Management
  • 4. ▪ Defining the “certain functions or activities” ▪ Disclosures ▪ Services ▪ Reasonable and Appropriate Safeguards © 2012 Health Care Management
  • 5. HIPAA Title II Administrative Simplification Electronic Data Interchange Security Rule Privacy Rule (Transaction and Code Sets) Administrative Physical Technical Safeguards Safeguards Safeguards 45 CFR 164.308 45 CFR 164.310 45 CFR 164.312 © 2012 Health Care Management
  • 6. What is HITECH?  HITECH - The Health Information Technology for Economic Recovery and Reinvestment Act of 2009  Meaningful Use  Education  HIPAA Enforcement © 2012 Health Care Management
  • 7. What changed relative to HIPAA?  Physician Attestation for Meaningful Use  Improved Enforcement  HIPAA ignorance no longer tolerated  Business Associates now have the same HIPAA responsibilities as the Covered Entities they service © 2012 Health Care Management
  • 8. Key Statistics Total No BA BA Category Breaches Involved Involved Percent of Total 100% 79% 21% 12,103,99 Total Individuals Affected 21,021,132 8,917,133 9 Percent of Total 100% 42% 58% Average Individuals per Breach 43,076 23,101 118,667 Source :U.S. Department of Health and Human Services HIPAA Breach Notifications – September 2009 to May 2012 © 2012 Health Care 2011 ATMP Solutions © Management
  • 9. Increasing Degree of HIPAA Compliance Effort “By exercising “Due to Willful “Due to Willful “Due to reasonable Neglect if the Neglect if the Reasonable diligence would violation is not violation is Cause and not not have corrected” corrected” Willful Neglect” known” Decreasing Degree of HIPAA Compliance Risk © 2012 Health Care Management
  • 10. Increasing Degree of HIPAA Compliance Effort by Covered Entity and Business Associate Business Business Business No Business Business Associate Associate is Associate Associate Associate has taking proof of Contract in Contract in Conducted necessary HIPAA place Place Risk steps to Compliance Assessment compliance Decreasing Degree of HIPAA Compliance Risk to Covered Entity © 2012 Health Care Management
  • 11. Is the Covered Entity responsible for their Business Associate’s HIPAA Compliance, or vice versa?  No   Is the Covered Entity responsible for engaging in relationships with HIPAA Compliant Business Associates?  Yes   If the Business Associate claims HIPAA Compliance, does this imply that the Covered Entity is HIPAA Compliant?  No  © 2012 Health Care 2011 ATMP Solutions © Management
  • 12. Solution Institutional Compliance Compliance Electronic Medical HIPAA Compliant EMR Hosted in EMR Company HIPAA Compliance Record a HIPAA Compliant Facility with respect to internal operating policies © 2012 Health Care Management
  • 13. EMR Health Health Information Information Exchange Exchange Private Cloud / / (HIE) (HIE) Private Cloud Data Center Data Center DR Site Insurance Company IT Services Lab Document Destruction Physician Practice Health System © 2012 Health Care Management
  • 14. EMR Health Health Information Information Exchange Exchange Private Cloud / / (HIE) (HIE) Private Cloud Data Center Data Center DR Site Insurance Company IT Services Lab Document Destruction Physician Practice Health System © 2012 Health Care Management
  • 15. EMR Health Health Information Information Exchange Exchange Private Cloud / / (HIE) (HIE) Private Cloud Data Center Data Center DR Site Insurance Company IT Services Lab Document Destruction Physician Practice Health System © 2012 Health Care Management
  • 16. Privacy / Security Compliance Policy Proof © 2012 Health Care Management
  • 17.  United States Department of Health and Human Services  Office of Civil Rights  Individual state’s Office of The Attorney General © 2012 Health Care Management
  • 18.  Treat HIPAA compliance with the same degree of diligence and urgency as Accounting, Taxes, and the IRS  Start with a simple checklist of areas that need to be addressed  A.K.A. - Risk Assessment © 2012 Health Care Management
  • 19. Questions and Answers jdylewski@healthcaremgt.net 616.977.2679 © 2012 Health Care Management

Notes de l'éditeur

  1.  
  2. Definition of “Business Associate” A “business associate” is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity. United States Department of Health and Human Services Office of Civil Rights - [ 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e)] If you would like a copy of the law, send me an email.
  3. Establish the permitted and required uses and disclosures of such information by the business associate The contract may permit the business associate to provide services relating to the health care operations of the covered entity Calls for the implementation of reasonable and appropriate administrative, physical, and technical safeguards to prevent use or disclosure of the information other than as provided for by its contract
  4. Appropriated funds to be provided as individual reimbursement to physicians who adopt and “meaningfully use” Electronic Medical Records Appropriated funds to educate the workforce in Health Information Technology Tightened guidelines and enforcement around HIPAA Add pictures (cement mixer) Add a picture of something that has changed – old style football versus new style football
  5. Physician Attestation for Meaningful Use Meaningful Use measure #15 calls for a HIPAA Risk Assessment and Remediation Improved Enforcement Maximum fines raised from $25, 000 to $1.5MM per calendar year for serious offenses Categories of violations HIPAA ignorance no longer tolerated Business Associates now have the same HIPAA responsibilities as the Covered Entities they service Implied accountability – whether a Business Associate Contract/Agreement is in place or not Breach Notifications include Business Associate and Covered Entity Why the focus on Business Associates?
  6. Drop the first line “total Breach”
  7. Animate by box – from left to right
  8. Animate by box
  9. Animate by questions
  10. Does EMR = Compliance? No Home Health Care / Hospice / Long Term Care Adherence to referring entity’s privacy and security policies HIPAA Compliance with respect to internal operating policies Document Destruction Documented Media Destruction Processes and Policies Document Destruction Company HIPAA Compliance with respect to internal operating policies
  11. Office of Civil Rights Currently developing list of HIPAA Compliance Audit Candidates KPMG has developed the audit process and will begin auditing activities in Fall 2011 Individual state’s Office of Attorney General On behalf of the public Currently completing training through OCR on HIPAA enforcement
  12. Graphic of a guy taking a step Industry calls this a “risk assessment”
  13. Need copies of the rule – send me a message? Seed questions: How much does this cost? Complete turnkey serivces start at $2,500 How long does this take? The risk assessment can be completed within 2 weeks. I understand that HIPAA is a lot of policies. How do I address dveloping all of the policies? We have policy templates and often assist clients in the development.