Legal Issues in the EHR Acquisition RFP Process

Size: px
Start display at page:

Download "Legal Issues in the EHR Acquisition RFP Process"

Transcription

1 Legal Issues in the EHR Acquisition RFP Process Gerry Hinkley Co-Chair, Health Care Industry Team Pillsbury Winthrop Shaw Pittman LLP National EHR Acquisition, Implementation and Operations Summit October 3 6, 2010 San Francisco

2 Legal Issues To Be Covered Procurement Policy Managing conflicts of interest The Standard License, Hosting and Services Agreement Warranties and limitation of liability Termination Data breach liability Source code escrow Issues for pilots Issues for sublicensing Using the vendor to comply with Stark EHR donation requirements Antitrust issues for GPOs 2

3 Procurement Policy Elements Acknowledgements Procurement requirements imposed by grants, government regulations Required third party approvals Acquisition strategy and business plan Roles and responsibilities Competition requirements Vendor qualification criteria Document retention requirements Conflicts of interest 3

4 Managing Conflicts of Interest Employees, consultants, members of governing bodies, and subcontractors prevented from using their positions for purposes that are, or give the appearance of being, motivated by a desire for private gain for themselves or others, such as family and business Appropriate procedures for recusal, to prohibit affected personnel from involvement in any procurement in which they have an actual or potential conflict of interest Discipline, up to and including termination, of personnel who violate this prohibition 4

5 The Standard License, Hosting and Services Agreement In the RFP, include the form of agreement Responders must provide substitute provisions Establish a scale for grading requested changes to the agreement Elements of the agreement to be scored Transfer of risk of loss Ownership of data Business associate compliance Security audits Indemnification Insurance coverages Warranties and limitation of liability Termination and transition Data breach liability Source code escrow 5

6 Warranties and Limitation of Liability Documentation Warranty EHR software will perform as described in the documentation There can be a difference between what salespeople verbally promise and what is documented in the functional specifications RFP response should be designated as part of documentation Performance Warranty Software, as delivered, will perform to the functional specifications Key is to make certain that functionality is adequately covered by the specifications Include obligation of vendor to comply with state and federal laws and regs, e.g., HIPAA, HITECH, etc. Maintain CCHIT and meaningful use certification Infringement Warranty Assurance against risk that the vendor s software infringes on another vendor s proprietary software Customer s rights to it data need to be maintained Obligation to procure rights to use the software or comparable software must be absolute Not acceptable for vendor to terminate and refund payments 6

7 Warranties and Limitation of Liability - 2 If software does not function to specifications and the EHR system cannot be repaired by the vendor the customer may have the right to Obtain a refund from the vendor and get damages Have vendor pay for a replacement system Resort to self-help Require vendor to implement a detailed plan to remedy malfunctions The vendor will attempt to limit its liability for breach of warranty to amounts paid under the agreement Customer should quantify the total direct and indirect cost of replacing the system Specify that amount as liquidated damages for breach 7

8 Termination Vendor may only terminate for nonpayment Customer may terminate for vendor s material breach Transition on termination Customer ceases use of software Immediately, if vendor termination Phased, if customer termination Vendor provides electronic copy of patient data in a format transferable to another system Vendor continues to be obligated as a business associate of customer with respect to patient data that is retained by vendor Vendor must sequester patient data that is retained by vendor 8

9 Data Breach Liability Determine who the covered entity is and who is acting as a business associate of the covered entity The business associate may itself be a covered entity If the hospital is hosting or providing maintenance, it is the physician s business associate in that capacity Under HITECH, business associates are now directly liable under HIPAA Under proposed rules, business associates subcontractors who handle PHI are business associates themselves Responsibility for managing data breaches -- a covered entity may delegate responsibility for Identifying the existence of a potential breach Making the assessment whether a substantial risk of harm is presented so that a reportable breach has occurred Managing notifications Assisting with mitigation Consider partnering with an insurer and/or a data breach management vendor 9

10 Issues for Pilots Pilots are often used to De-bug installation and implementation Create physician champions for the technology Train hosting and maintenance personnel Pilot agreement Vendor s, sponsor s and pilot participants responsibilities during the pilot Pre-implementation Installation Training Feedback Championing deployment Pilot timeline Hardware and software to be installed and piloted Compensation to pilot participants Transition to production Pass-through provisions from vendor s license 10

11 Issues for Sub-licensing EHRs are often deployed via a master license to a sponsor Master licensee may be taking on unfamiliar hosting and maintenance responsibilities Sub-licensee may not have direct access to the master licensor/vendor Key sub-license agreement terms Impact of termination of master license Ownership of data Management of warranties Hosting and maintenance obligations Security breaches Pass-through warranties, limitations on liability 11

12 Source Code Escrows Protects against vendor s failure, discontinuation of supported application, acquisition by a competitor By agreement, a copy of the source code is kept by a trusted third party Mechanism for storing updates, upgrades and new releases Ensures that the customer will have future access to the source code to continue support through self-help Caveat: if software is antiquated, finding support may not be possible even if you have access to the source code 12

13 How To Address the EHR Donation Exception Sunset Recipients of DHS referrals can pay up to 85% of the cost of software and certain related services to referrals sources Hospital subsidies cannot continue past December 31, 2013 Options to deal with the sunset if you are designing a program now Transition maintenance and support to physicians Terminate maintenance and support If your program does not address the sunset, work with the vendor and physicians now to effectuate a transition or termination Consider application of the community-wide health information system exception 13

14 Using the Vendor to Comply with Stark EHR Donation Requirements Physicians must pay at least 15% of the cost of software Hospitals do not want to be creditors of members of their medical staff Physicians may not take seriously an obligation to pay the hospital Vendors are used to being creditors of their customers Create mechanisms to be administered by vendors for Determining physician s share if costs are variable Security deposits (to avoid lapses in service) Billing of physician s share Collection of physician s share Documenting payment 14

15 Antitrust Issues for GPOs GPO goals Better prices for members Improve quality, reliability, and service for members purchasing activities Improve products and services Steps to avoid antitrust enforcement Market power (35-40% of market is safety zone) Avoid potential for price-fixing collusion among purchasers if goods purchased are substantial part of overhead (> 20% of revenues) Limit member information that is gathered and shared to avoid collusive overflow Emphasize pro-competitive benefits of GPOs in helping members to reduce costs, maintain or expand offerings and charge lower prices Develop antitrust guidelines and training for GPO participants 15

16 The purpose of this presentation is to inform and comment upon recent developments in health law. It is not intended, nor should it be used, as a substitute for specific legal advice legal counsel may only be given in response to inquiries regarding particular situations. 16

17 CONTACT INFORMATION Gerry Hinkley Pillsbury Winthrop Shaw Pittman LLP 50 Fremont Street San Francisco, CA Direct: (415)

Negotiating Standard Terms and Conditions/Best Price Arrangements with EHR Vendors

Negotiating Standard Terms and Conditions/Best Price Arrangements with EHR Vendors Negotiating Standard Terms and Conditions/Best Price Arrangements with EHR Vendors Gerry Hinkley Co-Chair, Health Care Industry Team Pillsbury Winthrop Shaw Pittman LLP National REC and HIE Summit West

More information

CURRENT AND FUTURE MEDICAL HOME LEGAL ISSUES

CURRENT AND FUTURE MEDICAL HOME LEGAL ISSUES CURRENT AND FUTURE MEDICAL HOME LEGAL ISSUES Presented by: Gerry Hinkley Co-Chair, Health Care Industry Team Pillsbury Winthrop Shaw Pittman gerry.hinkley@pillsburylaw.com Pillsbury Winthrop Shaw Pittman

More information

Gerry Hinkley Co-Chair, Health Care Industry Team Pillsbury Winthrop Shaw Pittman LLP

Gerry Hinkley Co-Chair, Health Care Industry Team Pillsbury Winthrop Shaw Pittman LLP How Regional Extension Centers (RECs), Beacon Programs, Community College Consortia and Health Insurance Exchanges Work and Why Privacy and Security are Important Gerry Hinkley Co-Chair, Health Care Industry

More information

HIT System Procurement Issues and Pitfalls Session 2.03

HIT System Procurement Issues and Pitfalls Session 2.03 HIT System Procurement Issues and Pitfalls Session 2.03 Presented by: Gerry Hinkley Davis Wright Tremaine LLP and Joseph M. DeLuca IT Optimizers Session Goals Provide you with A best practices approach

More information

HIT/EHR Vendor Contracting Checklist

HIT/EHR Vendor Contracting Checklist HIT/EHR Vendor Contracting Checklist Dear Members: You are likely coming to the end of an intense process of vetting one or more electronic health record (EHR) products and related vendor proposals. As

More information

Negotiating EHR Acquisition Contracts

Negotiating EHR Acquisition Contracts Negotiating EHR Acquisition Contracts Key Strategies, Terms and Conditions Louisa Barash, Esq. & Jane Eckels, Esq. The Art and Skill of Negotiations Painful Contract Negotiations Take too long Are too

More information

Cybersecurity in the Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective

Cybersecurity in the Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective Cybersecurity in the Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective July 23, 2013 Gerry Hinkley, Pillsbury Allen Briskin, Pillsbury Pillsbury Winthrop Shaw Pittman LLP

More information

Rebecca Williams, RN, JD Partner Co-chair Health Information Technology/HIPAA Practice Davis Wright Tremaine LLP beckywilliams@dwt.

Rebecca Williams, RN, JD Partner Co-chair Health Information Technology/HIPAA Practice Davis Wright Tremaine LLP beckywilliams@dwt. National EHR Acquisition, Implementation and Operations Summit Rebecca Williams, RN, JD Partner Co-chair Health Information Technology/HIPAA Practice Davis Wright Tremaine LLP beckywilliams@dwt.com Window

More information

Health Care Data Breach Discovery Strategies for Immediate Response

Health Care Data Breach Discovery Strategies for Immediate Response Health Care Data Breach Discovery Strategies for Immediate Response March 27, 2014 Pillsbury Winthrop Shaw Pittman LLP Faculty Gerry Hinkley Partner Pillsbury Winthrop Shaw Pittman LLP Sarah Flanagan Partner

More information

Building a Culture of Health Care Privacy Compliance

Building a Culture of Health Care Privacy Compliance Building a Culture of Health Care Privacy Compliance September 10, 2014 Presented by: Gerry Hinkley, Partner, Pillsbury Greg Radinsky, VP & Chief Corporate Compliance, North Shore - LIJ Wendy Maneval,

More information

Legal Issues in Electronic Health Records Acquisition, Implementation and Monitoring

Legal Issues in Electronic Health Records Acquisition, Implementation and Monitoring Legal Issues in Electronic Health Records Acquisition, Implementation and Monitoring Thomas E. Jeffry, Jr., Esq. Partner Los Angeles, CA 90017-2566 213-633-4265 tomjeffry@dwt.com Rebecca L. Williams, RN,

More information

Business Associate Considerations for the HIE Under the Omnibus Final Rule

Business Associate Considerations for the HIE Under the Omnibus Final Rule Business Associate Considerations for the HIE Under the Omnibus Final Rule Joseph R. McClure, Esq. Counsel Siemens Medical Solutions USA, Inc. WEDI Privacy & Security Work Group Co-Chair Agenda Who is

More information

2012 Winston & Strawn LLP

2012 Winston & Strawn LLP 2012 Winston & Strawn LLP Top 5 Negotiation Points for Software, SaaS, and Outsourcing Agreements Brought to you by Winston & Strawn s Advertising, Marketing, and Entertainment Law Group 2012 Winston &

More information

A s a covered entity or business associate, you have

A s a covered entity or business associate, you have Health IT Law & Industry Report VOL. 7, NO. 19 MAY 11, 2015 Reproduced with permission from Health IT Law & Industry Report, 07 HITR, 5/11/15. Copyright 2015 by The Bureau of National Affairs, Inc. (800-372-1033)

More information

Society of Corporate Compliance and Ethics

Society of Corporate Compliance and Ethics Society of Corporate Compliance and Ethics 8 th Annual Conference for Effective Compliance Systems in Higher Education We Are Special!! The Special Need for Contract Management for the Health Sciences

More information

PointCentral Subscription Agreement v.9.2

PointCentral Subscription Agreement v.9.2 PointCentral Subscription Agreement v.9.2 READ THIS SUBSCRIPTION AGREEMENT ( AGREEMENT ) CAREFULLY BEFORE INSTALLING THIS SOFTWARE. THIS AGREEMENT, BETWEEN CALYX TECHNOLOGY, INC., DBA CALYX SOFTWARE (

More information

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq.

The HITECH Act: Implications to HIPAA Covered Entities and Business Associates. Linn F. Freedman, Esq. The HITECH Act: Implications to HIPAA Covered Entities and Business Associates Linn F. Freedman, Esq. Introduction and Overview On February 17, 2009, President Obama signed P.L. 111-05, the American Recovery

More information

XANGATI END USER SOFTWARE LICENSE TERMS AND CONDITIONS

XANGATI END USER SOFTWARE LICENSE TERMS AND CONDITIONS XANGATI END USER SOFTWARE LICENSE TERMS AND CONDITIONS IMPORTANT: PLEASE READ BEFORE DOWNLOADING, INSTALLING OR USING THE XANGATI, INC. ("LICENSOR") SOFTWARE YOU HAVE LICENSED ("SOFTWARE"). BY EXECUTING

More information

PARTICIPATION AGREEMENT For ELECTRONIC HEALTH RECORD TECHNICAL ASSISTANCE

PARTICIPATION AGREEMENT For ELECTRONIC HEALTH RECORD TECHNICAL ASSISTANCE PARTICIPATION AGREEMENT For ELECTRONIC HEALTH RECORD TECHNICAL ASSISTANCE THIS AGREEMENT, effective, 2011, is between ( Provider Organization ), on behalf of itself and its participating providers ( Providers

More information

IMPORTANT ISSUES TO CONSIDER WHEN NEGOTIATING SOFTWARE LICENSES AND AGREEMENTS

IMPORTANT ISSUES TO CONSIDER WHEN NEGOTIATING SOFTWARE LICENSES AND AGREEMENTS NEW YORK UNIVERSITY A private university in the public service Office of General Counsel Elmer Holmes Bobst Library 70 Washington Square South New York, New York 10012-1091 Phone: 212 998 2240 Fax: 212

More information

QUESTIONS TO ASK IN THE DEVELOPMENT OF A SOFTWARE LICENSE

QUESTIONS TO ASK IN THE DEVELOPMENT OF A SOFTWARE LICENSE Alan R. Singleton, Esq. singleton@singletonlawfirm.com 2001 South First Street, Suite 209, Champaign, IL 61820 phone 217-352-3900 fax 217-352-4900 QUESTIONS TO ASK IN THE DEVELOPMENT OF A SOFTWARE LICENSE

More information

Preparing for and Responding to an OCR HIPAA Audit

Preparing for and Responding to an OCR HIPAA Audit Preparing for and Responding to Carole Klove Carole.Klove@ucsfmedctr.or g Gerry Hinkley gerry.hinkley@pillsburylaw.com SIXTH NATIONAL HIPAA SUMMIT WEST October 10-12, 2012 Overview Background What to expect

More information

340B Omnibus Guidance Would Significantly Narrow the Pool of Eligible Patients

340B Omnibus Guidance Would Significantly Narrow the Pool of Eligible Patients White Paper August 31, 2015 340B Omnibus Guidance Would Significantly Narrow the Pool of Eligible Patients By Kristi V. Kung This client alert also was published as a bylined article on Law360 on September

More information

This License Agreement applies to the Real Vision Software

This License Agreement applies to the Real Vision Software P.O. Box 12958 Alexandria, LA 71315 REAL VISION SOFTWARE INC. LICENSE AGREEMENT COVER This License Agreement, by and between Real Vision Software, Inc., a Louisiana Corporation, hereinafter referred to

More information

Business Associates, HITECH & the Omnibus HIPAA Final Rule

Business Associates, HITECH & the Omnibus HIPAA Final Rule Business Associates, HITECH & the Omnibus HIPAA Final Rule HIPAA Omnibus Final Rule Changes Business Associates Marissa Gordon-Nguyen, JD, MPH Health Information Privacy Specialist Office for Civil Rights/HHS

More information

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1 A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1 Policy and Procedure Templates Reflects modifications published in the Federal Register

More information

PocketSuite Terms of Service. Last modified: November 2015

PocketSuite Terms of Service. Last modified: November 2015 PocketSuite Terms of Service Last modified: November 2015 These Terms of Service (these Terms ) constitute the agreement (this Agreement ) between PocketSuite, Inc. (the Company ) and the User (as defined

More information

what your business needs to do about the new HIPAA rules

what your business needs to do about the new HIPAA rules what your business needs to do about the new HIPAA rules Whether you are an employer that provides health insurance for your employees, a business in the growing health care industry, or a hospital or

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT (this Agreement ) is made effective as of the day of 2014 (the Effective Date ), by and between Sarasota County Public Hospital District,

More information

Kaiser Permanente Affiliate Link Provider Web Site Application

Kaiser Permanente Affiliate Link Provider Web Site Application Kaiser Foundation Health Plan of Colorado Kaiser Permanente Affiliate Link Provider Web Site Application FOR PROVIDERS CONTRACTED WITH KAISER IN THE COLORADO REGION ONLY Page 1 of 7 Kaiser Permanente Affiliate

More information

Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate

Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate Privacy, Data Security & Information Use September 16, 2010 Data Breach Notification Burden Grows With First State Insurance Commissioner Mandate by John L. Nicholson and Meighan E. O'Reardon Effective

More information

HYBRID SOLUTIONS INDEPENDENT SOFTWARE VENDOR AGREEMENT

HYBRID SOLUTIONS INDEPENDENT SOFTWARE VENDOR AGREEMENT HYBRID SOLUTIONS INDEPENDENT SOFTWARE VENDOR AGREEMENT THE VERTEXFX TRADER API (THE SOFTWARE ) AND THE ACCOMPANYING DOCUMENTATION (THE RELATED MATERIALS ) (COLLECTIVELY, THE PRODUCT ) ARE PROTECTED BY

More information

Adopting Electronic Medical Records: What Do the New Federal Incentives Mean to Your Individual Physician Practice?

Adopting Electronic Medical Records: What Do the New Federal Incentives Mean to Your Individual Physician Practice? Adopting Electronic Medical Records: What Do the New Federal Incentives Mean to Your Individual Physician Practice? U John M. Neclerio, Esq.,* Kathleen Cheney, Esq., C. Mitchell Goldman, Esq., and Lisa

More information

The Art of the Deal: Negotiating a Winning EHR Contract

The Art of the Deal: Negotiating a Winning EHR Contract The Art of the Deal: Negotiating a Winning EHR Contract Rural Hospital Information Technology Conference October 20, 2010 Austin, Texas Diana J.P. McKenzie Partner and Chair, Information Technology & Outsourcing

More information

What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act

What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act by Lane W. Staines and Cheri D. Green On February 17, 2009, The American Recovery and Reinvestment Act

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT is made and entered into as of the day of, 2013 ( Effective Date ), by and between [Physician Practice] on behalf of itself and each of its

More information

Adding Cloud Solutions to Customer Contracts Robert J. Scott

Adding Cloud Solutions to Customer Contracts Robert J. Scott Adding Cloud Solutions to Customer Contracts Robert J. Scott MSP vs. Cloud Who owns the hardware? Where does the data reside? Dedicated vs. Multi tenant? Who contracts with 3 rd parties? How are services

More information

ZIMPERIUM, INC. END USER LICENSE TERMS

ZIMPERIUM, INC. END USER LICENSE TERMS ZIMPERIUM, INC. END USER LICENSE TERMS THIS DOCUMENT IS A LEGAL CONTRACT. PLEASE READ IT CAREFULLY. These End User License Terms ( Terms ) govern your access to and use of the zanti and zips client- side

More information

15 questions to ask before signing an electronic medical record or electronic health record agreement

15 questions to ask before signing an electronic medical record or electronic health record agreement 15 questions to ask before signing an electronic medical record or electronic health record agreement Many definitions exist for electronic medical record (EMR) and electronic health record (EHR). Although

More information

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308)

Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) HIPAA Business Associate Agreement Sample Notice Disclaimer: Template Business Associate Agreement (45 C.F.R. 164.308) The information provided in this document does not constitute, and is no substitute

More information

Commercial Software Licensing

Commercial Software Licensing Commercial Software Licensing CHAPTER 6: Prepared by DoD ESI January 2013 Chapter Overview Government contracts must comply with FAR and DFARS. They include terms and conditions (Ts & Cs) from GSA, BPAs,

More information

AN ACT CONCERNING ELECTRONIC HEALTH RECORDS AND HEALTH INFORMATION EXCHANGE.

AN ACT CONCERNING ELECTRONIC HEALTH RECORDS AND HEALTH INFORMATION EXCHANGE. OLR Bill Analysis ssb 812 AN ACT CONCERNING ELECTRONIC HEALTH RECORDS AND HEALTH INFORMATION EXCHANGE. SUMMARY: This bill establishes a statewide health information exchange to, among other things, allow

More information

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Compliance Tip Sheet National Hospice and Palliative Care Organization www.nhpco.org/regulatory HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers Hospice Provider Compliance To Do List

More information

How To Deal With Cloud Computing

How To Deal With Cloud Computing A LEGAL GUIDE TO CLOUD COMPUTING INTRODUCTION Many companies are considering implementation of cloud computing services to decrease IT costs while providing the flexibility to scale usage on demand. The

More information

Contracting Guidelines with EHR Vendors

Contracting Guidelines with EHR Vendors Contracting Guidelines with EHR Vendors In general, if a contract is presented to your group from a software company, it will be written from the perspective of the software company. You can request language

More information

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist. www.riskwatch.com HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist www.riskwatch.com Introduction Last year, the federal government published its long awaited final regulations implementing the Health

More information

STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM

STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM STATE OF NEVADA DEPARTMENT OF HEALTH AND HUMAN SERVICES BUSINESS ASSOCIATE ADDENDUM BETWEEN The Division of Health Care Financing and Policy Herein after referred to as the Covered Entity and (Enter Business

More information

University Healthcare Physicians Compliance and Privacy Policy

University Healthcare Physicians Compliance and Privacy Policy Page 1 of 11 POLICY University Healthcare Physicians (UHP) will enter into business associate agreements in compliance with the provisions of the Health Insurance Portability and Accountability Act of

More information

www.shipmangoodwin.com Shipman & Goodwin LLP 2015. All rights reserved. @SGHealthLaw HARTFORD STAMFORD GREENWICH WASHINGTON, DC

www.shipmangoodwin.com Shipman & Goodwin LLP 2015. All rights reserved. @SGHealthLaw HARTFORD STAMFORD GREENWICH WASHINGTON, DC HIPAA Compliance and Non-Business Associate Vendors: Strategies and Best Practices July 14, 2015 William J. Roberts, Esq. Shipman & Goodwin LLP 2015. All rights reserved. HARTFORD STAMFORD GREENWICH WASHINGTON,

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement ( Agreement ) by and between (hereinafter known as Covered Entity ) and Office Ally, LLC. (hereinafter known as Business Associate ), and

More information

Data Breach, Electronic Health Records and Healthcare Reform

Data Breach, Electronic Health Records and Healthcare Reform Data Breach, Electronic Health Records and Healthcare Reform (This presentation is for informational purposes only and it is not intended, and should not be relied upon, as legal advice.) Overview of HIPAA

More information

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015 Katherine M. Layman Cozen O Connor 1900 Market Street Philadelphia, PA 19103 (215) 665-2746

More information

HIPAA NOTICE OF PRIVACY PRACTICES

HIPAA NOTICE OF PRIVACY PRACTICES HIPAA NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW YOUR MEDICAL INFORMATION MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS INFORMATION. PLEASE REVIEW IT CAREFULLY. This HIPAA Notice

More information

GENERAL TERMS. 1.1 Hardware refers to the computer equipment, including components, options and spare parts.

GENERAL TERMS. 1.1 Hardware refers to the computer equipment, including components, options and spare parts. YOU AGREE THAT BY PLACING AN ORDER THROUGH AN ORDERING DOCUMENT THAT INCORPORATES THESE GENERAL TERMS (THE ORDERING DOCUMENT ) YOU AGREE TO FOLLOW AND BE BOUND BY THE TERMS AND CONDITIONS OF THE ORDERING

More information

GUIDANCE FOR MANAGING THIRD-PARTY RISK

GUIDANCE FOR MANAGING THIRD-PARTY RISK GUIDANCE FOR MANAGING THIRD-PARTY RISK Introduction An institution s board of directors and senior management are ultimately responsible for managing activities conducted through third-party relationships,

More information

ROLE OF CONTRACT MANAGEMENT IN A HEALTHCARE COMPLIANCE PROGRAM DESIGN

ROLE OF CONTRACT MANAGEMENT IN A HEALTHCARE COMPLIANCE PROGRAM DESIGN ROLE OF CONTRACT MANAGEMENT IN A HEALTHCARE COMPLIANCE PROGRAM DESIGN John Riley Vice President of Sales MediTract, Inc. Session Overview Overview of Compliance Regulations affecting Contract Management

More information

Key HIPAA HITECH Changes. Gina Kastel, Partner, Health and Life Sciences

Key HIPAA HITECH Changes. Gina Kastel, Partner, Health and Life Sciences Key HIPAA HITECH Changes Gina Kastel, Partner, Health and Life Sciences Agenda Business Associates Restrictions on Disclosures Access to PHI Notice of Privacy Practices Fundraising 2 Business Associates

More information

Business Associates: HITECH Changes You Need to Know

Business Associates: HITECH Changes You Need to Know Business Associates: HITECH Changes You Need to Know Rebecca L. Williams, RN, JD Partner Co-chair of HIT/HIPAA Practice Davis Wright Tremaine LLP beckywilliams@dwt.com 1 Who Is a Business Associate? A

More information

OFFSHORE OUTSOURCING IN HEALTH CARE: PRIVACY AND SECURITY CONCERNS

OFFSHORE OUTSOURCING IN HEALTH CARE: PRIVACY AND SECURITY CONCERNS OFFSHORE OUTSOURCING IN HEALTH CARE: PRIVACY AND SECURITY CONCERNS CONCURRENT SESSION IV September 9, 2005 Gregg D. Reisman, Esq. Peter B. Mancino, Esq. On behalf of Garfunkel, Wild & Travis, P.C. 1 WHAT

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT THIS BUSINESS ASSOCIATE AGREEMENT (the AGREEMENT ) is entered into this (the "Effective Date"), between Delta Dental of Tennessee ( Covered Entity ) and ( Business Associate

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT 1. The terms and conditions of this document entitled Business Associate Agreement ( Business Associate Agreement ), shall be attached to and incorporated by reference in the

More information

REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES PLEASE REVIEW IT CAREFULLY.

REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES PLEASE REVIEW IT CAREFULLY. REPRODUCTIVE ASSOCIATES OF DELAWARE (RAD) NOTICE OF PRIVACY PRACTICES THIS NOTICE DESCRIBES HOW PROTECTED HEALTH INFORMATION (PHI) ABOUT YOU MAY BE USED AND DISCLOSED AND HOW YOU CAN GET ACCESS TO THIS

More information

Minimizing Risk in Technology Agreements

Minimizing Risk in Technology Agreements Minimizing Risk in Technology Agreements Joel Lehrer Partner, IP Transactions and Strategies February 25, 2015 2015 Types of Agreements and Key Considerations Software License Agreements Scope of granted

More information

END USER LICENSE AGREEMENT ( EULA )

END USER LICENSE AGREEMENT ( EULA ) END USER LICENSE AGREEMENT ( EULA ) PLEASE READ CAREFULLY THIS EULA IS A LEGAL AGREEMENT BETWEEN YOU, EITHER AS AN INDIVIDUAL, COMPANY OR OTHER LEGAL ENTITY (IN ANY CAPACITY REFERRED TO HEREIN AS END USER,

More information

BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM RECITALS

BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM RECITALS BUSINESS ASSOCIATE PRIVACY AND SECURITY ADDENDUM This Business Associate Addendum ( Addendum ), effective, 20 ( Effective Date ), is entered into by and between University of Southern California, ( University

More information

EHR Donation: Compliance with Stark Law and the Anti-Kickback Statute

EHR Donation: Compliance with Stark Law and the Anti-Kickback Statute EHR Donation: Compliance with Stark Law and the Anti-Kickback Statute Digital Medical Office of the Future: Driving Toward Meaningful Use Las Vegas, NV September 9, 2010 Lawrence W. Vernaglia, J.D., M.P.H.

More information

Risk Management of Outsourced Technology Services. November 28, 2000

Risk Management of Outsourced Technology Services. November 28, 2000 Risk Management of Outsourced Technology Services November 28, 2000 Purpose and Background This statement focuses on the risk management process of identifying, measuring, monitoring, and controlling the

More information

HSS Specific Terms HSS SOFTWARE LICENSE AGREEMENT

HSS Specific Terms HSS SOFTWARE LICENSE AGREEMENT HSS Specific Terms HSS SOFTWARE LICENSE AGREEMENT 1. LICENSE 2. TERMINATION Subject to the terms and conditions of this HSS Software License Agreement (the Agreement ), HSS hereby grants to Client (herein

More information

MASTER SERVICES AGREEMENT

MASTER SERVICES AGREEMENT MASTER SERVICES AGREEMENT This Master Services Agreement ( Agreement ) is between 3seventy Inc. ( 3seventy ), whose principal place of business is 2224 Walsh Tarlton Lane, Suite 220, Austin, TX, 78746,

More information

Select Internet. Standard Terms and Conditions relating to the supply of online backup services by Select Internet

Select Internet. Standard Terms and Conditions relating to the supply of online backup services by Select Internet Select Internet Standard Terms and Conditions relating to the supply of online backup services by Select Internet Select Internet, PO Box 317 Kidlington, Oxford. OX5 3WZ www.selectinternet.co.uk Page 1

More information

Regulatory Update with a Touch of HIPAA

Regulatory Update with a Touch of HIPAA Regulatory Update with a Touch of HIPAA Cloud Communications Alliance Quarterly Meeting Miami, January 2015 Glenn S. Richards, Partner Pillsbury Winthrop Shaw Pittman LLP Phone: 202.663.8215 glenn.richards@pillsburylaw.com

More information

PWNIE EXPRESS TERMS AND CONDITIONS AND END USER LICENSE AGREEMENT PWN PULSE SOFTWARE AND SENSOR HARDWARE AS A SERVICE

PWNIE EXPRESS TERMS AND CONDITIONS AND END USER LICENSE AGREEMENT PWN PULSE SOFTWARE AND SENSOR HARDWARE AS A SERVICE PWNIE EXPRESS TERMS AND CONDITIONS AND END USER LICENSE AGREEMENT PWN PULSE SOFTWARE AND SENSOR HARDWARE AS A SERVICE Pwnie Express and the end user customer or licensee (the Licensee ) agree that the

More information

Addressing Employee Health and Wellness:

Addressing Employee Health and Wellness: 2015 CLE Marathons Addressing Employee Health and Wellness: Employer Options for On-Site Care January 13, 2015 Pillsbury Winthrop Shaw Pittman LLP Overview What do workplace clinics look like in 2015?

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT Express Scripts, Inc. and one or more of its subsidiaries ( ESI ), and Sponsor or one of its affiliates ( Sponsor ), are parties to an agreement ( PBM Agreement ) whereby ESI

More information

New Privacy Laws Impacting the Health Care Work Place

New Privacy Laws Impacting the Health Care Work Place New Privacy Laws Impacting the Health Care Work Place Presented by Thomas E. Jeffry, Jr., Esq. Arent Fox LLP Washington, DC New York, NY Los Angeles, CA November 12 & 19, 2009 Overview 1. Overview of California

More information

Business Associates under HITECH: A Chain of Trust

Business Associates under HITECH: A Chain of Trust FAQ on InfoSafe Shredding Services: Frequently Asked Questions on InfoSafe Shredding Information And Video on One Time Cleanouts: Cleanouts and Purges Business Associates under HITECH: A Chain of Trust

More information

Revised 10/13 SUBSCRIBER AGREEMENT. Introduction

Revised 10/13 SUBSCRIBER AGREEMENT. Introduction SUBSCRIBER AGREEMENT Introduction This Agreement (the "Agreement") sets forth the terms and conditions under which Consolidated Companies, Inc., together with any affiliate and/or distribution partner

More information

CCH INCORPORATED, A WOLTERSKLUWER COMPANY ACCESS AGREEMENT FOR THE

CCH INCORPORATED, A WOLTERSKLUWER COMPANY ACCESS AGREEMENT FOR THE CCH INCORPORATED, A WOLTERSKLUWER COMPANY ACCESS AGREEMENT FOR THE Accounting Research Manager INFORMATION DATABASE PROVIDED THROUGH Mayer Hoffman McCann P.C. ("AGREEMENT" OR "ACCESS AGREEMENT") IN THIS

More information

Heritage Credit Union Mobile Deposit User Agreement Effective: April, 2016

Heritage Credit Union Mobile Deposit User Agreement Effective: April, 2016 Heritage Credit Union Mobile Deposit User Agreement Effective: April, 2016 This Agreement contains the terms and conditions for use of Heritage Credit Union s (HCU) Mobile Deposit service ( Mobile Deposit

More information

Contracting Guidelines with EHR Vendors

Contracting Guidelines with EHR Vendors Doctors Office Quality - Information Technology (DOQ-IT) Project Contracting Guidelines with EHR Vendors In general, if a contract is presented to your group from a software company, it will be written

More information

Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks

Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks Presenting a live 90-minute webinar with interactive Q&A Negotiating EHR Agreements: Complying with HIPAA, Stark and AKS, Overcoming Privacy and Security Risks Acquiring an EHR and Meeting Incentive Program

More information

Business Associate Agreement (BAA) Guidance

Business Associate Agreement (BAA) Guidance Business Associate Agreement (BAA) Guidance Introduction The purpose of this document is to provide guidance for creating or updating business associate agreements between your Practice ( Covered Entity

More information

ENHANCED HOST CONTROLLER INTERFACE SPECIFICATION FOR UNIVERSAL SERIAL BUS (USB) 2.0 - ADOPTERS AGREEMENT

ENHANCED HOST CONTROLLER INTERFACE SPECIFICATION FOR UNIVERSAL SERIAL BUS (USB) 2.0 - ADOPTERS AGREEMENT ENHANCED HOST CONTROLLER INTERFACE SPECIFICATION FOR UNIVERSAL SERIAL BUS (USB) 2.0 - ADOPTERS AGREEMENT This Enhanced Host Controller Interface Specification for Universal Serial Bus (USB) 2.0 - Adopters

More information

AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION BETWEEN WAKE FOREST UNIVERSITY BAPTIST MEDICAL CENTER AND

AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION BETWEEN WAKE FOREST UNIVERSITY BAPTIST MEDICAL CENTER AND AGREEMENT FOR ACCESS TO PROTECTED HEALTH INFORMATION BETWEEN WAKE FOREST UNIVERSITY BAPTIST MEDICAL CENTER AND THIS AGREEMENT for Access to Protected Health Information ( PHI ) ( Agreement ) is entered

More information

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - Business Associates 10230

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - Business Associates 10230 IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - Business Associates 10230 POLICY INFORMATION Major Functional Area (MFA): MFA X - Office of General Counsel & Compliance Policy Title:

More information

HIPAA: Protecting Your. Ericka L. Adler. Practice and Your Patients

HIPAA: Protecting Your. Ericka L. Adler. Practice and Your Patients HIPAA: Protecting Your Ericka L. Adler Practice and Your Patients Rachel V. Rose Fallout from the Omnibus Rule Compliance strategies for medical practices 1. Know / manage your business associates and

More information

Infor Sys Ve. Top 10 Warning Signs of Problem Vendors

Infor Sys Ve. Top 10 Warning Signs of Problem Vendors Infor Sys Ve Top 10 Warning Signs of Problem Vendors 16 mation tems ndors By Susan M. Kornfield Complex information systems, once predominantly the realm of the sophisticated, high-tech company, are now

More information

Licensor: Deveo Oy Customer: [address line 2] LICENSE NUMBER:

Licensor: Deveo Oy Customer: [address line 2] LICENSE NUMBER: 1/8 DEVEO SOFTWARE LICENSE AGREEMENT COVER PAGE LICENSE CERTIFICATE AND LICENSE NUMBER Licensor: Deveo Oy Customer: [address line 1] [address line 2] Product Deveo on-premises Software version License

More information

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA BUSINESS ASSOCIATE AGREEMENT HIPAA BUSINESS ASSOCIATE AGREEMENT This HIPAA Business Associate Agreement ("BA AGREEMENT") supplements and is made a part of any and all agreements entered into by and between The Regents of the University

More information

AHLA. Y. Advising Providers in Adopting or Substituting a Health IT System. Charles C. Dunham Bond Schoeneck & King PLLC Albany, NY

AHLA. Y. Advising Providers in Adopting or Substituting a Health IT System. Charles C. Dunham Bond Schoeneck & King PLLC Albany, NY AHLA Y. Advising Providers in Adopting or Substituting a Health IT System Charles C. Dunham Bond Schoeneck & King PLLC Albany, NY Health Care Transactions April 10-11, 2014 Advising Providers in Adopting

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT This Business Associate Agreement (Hereinafter "Agreement") dated as of, 2013, is made by and between (Hereinafter Covered Entity ) and (Hereinafter Business Associate ). ARTICLE

More information

Use & Disclosure of Protected Health Information by Business Associates

Use & Disclosure of Protected Health Information by Business Associates Applicability: Policy Title: Policy Number: Use & Disclosure of Protected Health Information by Business Associates PP-12 Superseded Policy(ies) or Entity Policy: N/A Date Established: January 31, 2003

More information

The HIPAA Audit Program

The HIPAA Audit Program The HIPAA Audit Program Anna C. Watterson Davis Wright Tremaine LLP The U.S. Department of Health and Human Services (HHS) was given authority, and a mandate, to conduct periodic audits of HIPAA 1 compliance

More information

DISCLAIMER. HIPPAA Notice of Privacy. HIPAA Notice of Privacy Practices Printable PDF. Effective November 1, 2015

DISCLAIMER. HIPPAA Notice of Privacy. HIPAA Notice of Privacy Practices Printable PDF. Effective November 1, 2015 DISCLAIMER Direct Medical Imaging LLC (DMI) dba Pembina High Field MRI provides scanning and services, including an interpretation of the scan by a board certified radiologist. DMI cannot and does not

More information

Central Florida Health Information Technology Initiative. UCF College of Medicine Regional Extension Center

Central Florida Health Information Technology Initiative. UCF College of Medicine Regional Extension Center Central Florida Health Information Technology Initiative UCF College of Medicine Regional Extension Center Provider Technical Assistance Agreement for Grant Eligible Providers The Central Florida Health

More information

BUSINESS ASSOCIATE AGREEMENT

BUSINESS ASSOCIATE AGREEMENT BUSINESS ASSOCIATE AGREEMENT The parties to this ( Agreement ) are, a _New York_ corporation ( Business Associate ) and ( Client ) you, as a user of our on-line health record system (the "System"). BY

More information

Business Associate Liability Under HIPAA/HITECH

Business Associate Liability Under HIPAA/HITECH Business Associate Liability Under HIPAA/HITECH Joseph R. McClure, JD, CHP Siemens Healthcare WEDI Security & Privacy SNIP Co-Chair Reece Hirsch, CIPP, Partner Morgan Lewis & Bockius LLP ` Fifth National

More information

Mobile Check Deposit (MCD) User Agreement ( Agreement )

Mobile Check Deposit (MCD) User Agreement ( Agreement ) Mobile Check Deposit (MCD) User Agreement ( Agreement ) This Agreement contains the terms and conditions for the use of Mobile Check Deposit and/or other MCD services that Western Sun Federal Credit Union

More information

Why Lawyers? Why Now?

Why Lawyers? Why Now? TODAY S PRESENTERS Why Lawyers? Why Now? New HIPAA regulations go into effect September 23, 2013 Expands HIPAA safeguarding and breach liabilities for business associates (BAs) Lawyer is considered a business

More information

Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates

Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates Legal Update February 11, 2013 Long-Expected Omnibus HIPAA Rule Implements Significant Privacy and Security Regulations for Entities and Business Associates On January 17, 2013, the Department of Health

More information