Implementation Business Associates and Breach Notification



Similar documents
OCR UPDATE Breach Notification Rule & Business Associates (BA)

Business Associates, HITECH & the Omnibus HIPAA Final Rule

OCR Reports on the Enforcement. Learning Objectives 4/1/2013. HIPAA Compliance/Enforcement (As of December 31, 2012) HCCA Compliance Institute

OCR Reports on the Enforcement. Learning Objectives

This presentation focuses on the Healthcare Breach Notification Rule. First published in 2009, the final breach notification rule was finalized in

HIPAA Omnibus Rule Overview. Presented by: Crystal Stanton MicroMD Marketing Communication Specialist

HIPAA Omnibus Rule Practice Impact. Kristen Heffernan MicroMD Director of Prod Mgt and Marketing

FIVE EASY STEPS FOR HANDLING NEW HIPAA REQUIREMENTS & MANAGING YOUR ELECTRONIC COMMUNICATIONS

Business Associate Considerations for the HIE Under the Omnibus Final Rule

UNDERSTANDING THE HIPAA/HITECH BREACH NOTIFICATION RULE 2/25/14

Business Associates and Breach Reporting Under HITECH and the Omnibus Final HIPAA Rule

White Paper THE HIPAA FINAL OMNIBUS RULE: NEW CHANGES IMPACTING BUSINESS ASSOCIATES

HIPAA OMNIBUS RULE: EXPANDED COMPLIANCE REQUIREMENTS

Protecting Patient Information in an Electronic Environment- New HIPAA Requirements

Community First Health Plans Breach Notification for Unsecured PHI

HHS Issues New HITECH/HIPAA Rule: Implications for Hospice Providers

OCR s Anatomy: HIPAA Breaches, Investigations, and Enforcement

Everett School Employee Benefit Trust. Reportable Breach Notification Policy HIPAA HITECH Rules and Washington State Law

Am I a Business Associate? Do I want to be a Business Associate? What are my obligations?

You Probably Don t Even Know

Key HIPAA HITECH Changes. Gina Kastel, Partner, Health and Life Sciences

Breach Notification Policy

HIPAA Privacy and Security Rules: A Refresher. Marilyn Freeman, RHIA California Area HIPAA Coordinator California Area HIM Consultant

POLICY AND PROCEDURE MANUAL

HIPAA and HITECH Compliance Under the New HIPAA Final Rule. HIPAA Final Omnibus Rule ( Final Rule )

Updated HIPAA Regulations What Optometrists Need to Know Now. HIPAA Overview

HHS Finalizes HIPAA Privacy and Data Security Rules, Including Stricter Rules for Breaches of Unsecured PHI

Surviving a HIPAA violation One Agency s Experience Presented by: Roger Shindell. Topics Covered Part One. Topics Covered Part Two.

HIPAA 101. March 18, 2015 Webinar

New HIPAA Breach Notification Rule: Know Your Responsibilities. Loudoun Medical Group Spring 2010

Trust 9/10/2015. Why Does Privacy and Security Matter? Who Must Comply with HIPAA Rules? HIPAA Breaches, Security Risk Analysis, and Audits

Information Privacy and Security Program. Title: EC.PS.01.02

The Challenges of Applying HIPAA to the Cloud. Adam Greene, Partner Davis Wright Tremaine LLP

Am I a Business Associate?

New HIPAA regulations require action. Are you in compliance?

6/17/2013 PRESENTED BY: Updates on HIPAA, Data, IT and Security Technology. June 25, 2013

HIPAA in an Omnibus World. Presented by

Violation Become a Privacy Breach? Agenda

Chris Bennington, Esq., INCompliance Consulting Shannon DeBra, Esq., Bricker & Eckler LLP Victoria Norton, R.N., J.D., M.B.A.

Creating Stable Security & Compliance Relationships

HIPAA Update Focus on Breach Prevention

Why Lawyers? Why Now?

HIPAA Update. Presented by: Melissa M. Zambri. June 25, 2014

Lessons Learned from HIPAA Audits

Name of Other Party: Address of Other Party: Effective Date: Reference Number as applicable:

ADMINISTRATIVE REGULATION EFFECTIVE DATE: 1/1/2016

Breaches. Complying with the HIPAA Omnibus Final Rule. Important Definitions. Protected Health Information Includes HIPAA PRIVACY 3/2/2014

STANDARD ADMINISTRATIVE PROCEDURE

Breach Notification Decision Process 1/1/2014

Business Associate Management Methodology

12/19/2014. HIPAA More Important Than You Realize. Administrative Simplification Privacy Rule Security Rule

HIPAA initially went into effect April 14, HIPAA is a set of rules that is to be followed by doctors, hospitals and other health care providers.

What s New with HIPAA? Policy and Enforcement Update

HHS announces sweeping changes to the HIPAA Privacy and Security Rules in the final HIPAA Omnibus Rule

HIPAA Compliance The Time is Now Changes on the Horizon: The Final Regulations on Privacy and Security. May 7, 2013

Page 1. NAOP HIPAA and Privacy Risks 3/11/2014. Privacy means being able to have control over how your information is collected, used, or shared;

NCHICA HITECH Act Breach Notification Risk Assessment Tool. Prepared by the NCHICA Privacy, Security & Legal Officials Workgroup

HIPAA/HITECH and Texas Privacy Laws Comparison Tool Updated 2013

HIPAA Privacy Breach Notification Regulations

Art Gross President & CEO HIPAA Secure Now! How to Prepare for the 2015 HIPAA Audits and Avoid Data Breaches

It s a New Regulatory Landscape: Do You Know Where Your Business Associates are and What They are Doing?

Enforcement of Health Information Privacy & Security Standards Federal Enforcement Through Recent Cases and Tools to Measure Regulatory Compliance

HIPAA Privacy & Breach Notification Training for System Administration Business Associates

SaaS. Business Associate Agreement

HIPAA BREACH NOTIFICATION REQUIREMENTS. Heman A. Marshall, III July 25, 2014

Overview of the HIPAA Security Rule

THE HIPAA TANGO CHOREOGRAPHING PRIVACY AND SECURITY UNDER THE FINAL RULE

Legislative & Regulatory Information

The HIPAA Omnibus Final Rule

FEDERAL AND STATE BREACH NOTIFICATION LAWS FOR CALIFORNIA

Ethics, Privilege, and Practical Issues in Cloud Computing, Privacy, and Data Protection: HIPAA February 13, 2015

Understanding HIPAA Privacy and Security Helping Your Practice Select a HIPAA- Compliant IT Provider A White Paper by CMIT Solutions

Sample Business Associate Agreement Provisions

Presented by Jack Kolk President ACR 2 Solutions, Inc.

What do you need to know?

UPDATES FOR MEDICAL PRACTICES: RED FLAGS AND IDENTITY THEFT AND HIPAA PRIVACY CHANGES (FROM HITECH)

HIPAA Omnibus & HITECH Rules: Key Provisions and a Simple Checklist.

HIPAA AND MEDICAID COMPLIANCE POLICIES AND PROCEDURES

COMPLIANCE ALERT 10-12

HIPAA Compliance Guide

Privacy & Security. Risk Management Strategies for Healthcare Data. Ohio Hospital Association Centennial Annual Meeting.

HIPAA Compliance: Are you prepared for the new regulatory changes?

HIPAA BUSINESS ASSOCIATE AGREEMENT

HIPAA Health & Medical Billing Requirements and Risk Management

What Health Care Entities Need to Know about HIPAA and the American Recovery and Reinvestment Act

Philip L. Gordon, Esq. Littler Mendelson, P.C.

Dissecting New HIPAA Rules and What Compliance Means For You

Lawyers as HIPAA Business Associates

Accounting for Disclosure Requirements Summary of Changes Included in the Proposed Rule 76 Federal Register May 31, 2011

IDAHO STATE UNIVERSITY POLICIES AND PROCEDURES (ISUPP) HIPAA Privacy - Data Breach Notification Policy 10240

Greenway Marketplace. Hear from GSG Compliance & White Plume November 14, 2013

HIPAA PRIVACY AND SECURITY RULES BUSINESS ASSOCIATE AGREEMENT BETWEEN. Stewart C. Miller & Co., Inc. (Business Associate) AND

HEALTH INSURANCE PORTABILITY AND ACCOUNTABILITY ACT (HIPAA) TERMS AND CONDITIONS FOR BUSINESS ASSOCIATES

Heather L. Hughes, J.D. HIPAA Privacy Officer U.S. Legal Support, Inc.

Breaches, Business Associates and Texting, Oh My! A HIPAA HITECH Update. Overview

HIPAA Compliance Guide

The ReHabilitation Center Buffalo Street. Olean. NY

Welcome to ChiroCare s Fourth Annual Fall Business Summit. October 3, 2013

Are You Still HIPAA Compliant? Staying Protected in the Wake of the Omnibus Final Rule Click to edit Master title style.

A How-To Guide for Updating HIPAA Policies & Procedures to Align with ARRA Health Care Provider Edition Version 1

Transcription:

Implementation Business Associates and Breach Notification Tony Brooks, CISA, CRISC, Tony.Brooks@horne-llp.com Clay J. Countryman, Esq., Clay.Countryman@bswllp.com Stephen M. Angelette, Esq., Stephen.Angelette@bswllp.com

Breach Notification Duty to notify, risk assessments, and corrective action Business Associate Agreements Monitoring of Business Associates and Subcontractors Focus of Presentation: Implementation

HIPAA Omnibus Final Rule: Important Dates Published in Federal Register January 25, 2013 Effective Date March 26, 2013 Compliance Date September 23, 2013 Conform Business Associate Agreements September 22, 2014

OCR: Largest Breaches in 2012 Hacking network server - 780,000 individuals affected Backup tapes stored at hospital cannot be found and are presumed lost - 315,000 affected Unencrypted emails sent to employee s unsecured email address - 228,435 affected Theft of laptop from employee s vehicle - 116,506 Unauthorized access to e-phi stored in database - 105,646 Hacking database stored on network server 70,000 affected

Breach Notification: Implementation OCR: We expect risk assessments to be thorough, completed in good faith, and for the conclusions reached to be reasonable. A risk assessment is required for both impermissible uses and disclosures Uses or disclosures that impermissibly involve more than the minimum necessary may constitute a breach.

Modification to the Breach Notification Rule: Notification to Individuals Important Clarifications include: A Covered Entity that is acting as a Business Associate should respond to a breach as a Business Associate. The obligation to disclose will rest with the Covered Entity whose PHI is compromised. Alternative Notice: Notice has not been given if a written notice is returned as undeliverable. CEs responding to a breach with more than 10 notifications returned as undeliverable may take some reasonable time to search for correct, current addresses, but must provide substitute notice as soon as reasonably possible and within the original 60-day time frame for notifications.

Breach Notification Rule: Notification to the Media HHS clarified several points regarding media notifications, including: Covered entities are not obligated to incur the cost of any media broadcast regarding the breach in question. Media outlets are not obligated to publicize each and every breach notice they receive (and a failure to publicize does not render the notice provided insufficient). CEs must deliver a press release directly to the media outlet being notified. Posting a general press release on a website is insufficient.

Breach Notification: Implementation Revise breach response policies/practices to expressly include at least the four risk assessment factors Thoroughly document risk assessment, especially an assessment finding a low probability that PHI was compromised Review vendor assessment practices and tools mindful of heightened risk that an unauthorized disclosure is a breach Do not forget that state breach notification laws often have different breach definitions and requirements Be mindful that 60 days is an outer limit Expect future OCR guidance on risk assessments

Breach Notification Burden of Proof If a risk assessment is not performed, the default is notification of the breach Burden of demonstrating low probability that PHI is compromised is on the CE/BA Decision not to notify must be documented in case of review

Breach Notification: Obligations CEs must notify individuals (although can delegate this to BAs) BAs must notify CEs Subcontractors must be obligated to notify their contracting partner so the information can go back up the chain

Breach Notification Examples of Likelihood of identification or re-identification: Risk Analysis Criteria A list of patient names not low probability Patient discharge data, patient not specified can patients be reidentified? Who is the unauthorized recipient: A HIPAA covered entity low probability, as long as you have evidence the risk has been mitigated An employer may be able to use personnel records to re-identify PHI actually acquired or viewed: Untampered with laptop low probability Information mailed to wrong person not low probability Has improper use been mitigated: Satisfactory assurances of destruction from a known person low probability

Business Associate Agreements The contract between a CE and BA must provide that the BA will: Comply with the HIPAA Privacy and Security Rule Report to the CE any security incident of which it becomes aware, including breaches of unsecured PHI as required by 164.410 Ensure that any subcontractors who create, receive, maintain, or transmit ephi on behalf the BA comply with the Rule

Business Associate Subcontractor Agreement BAs must enter into a proper downstream BAA with any subcontractors Same requirements as between the CE and BA Subcontractors are subject to limits in the initial CE/BA Agreement

BA Agreement Transition The Compliance Date for Business Associate Agreements to be compliant with the Final Rule is September 23, 2013. BUT, if CE and BA, prior to the January 25, 2013 (Publication date of Omnibus Rule), had a current BAA, the time period is extended to the earlier of: the renewal date of the BA Agreement, or September 22, 2014.

BA Agreement Transition Renewals If BAA drafted prior to January 25, 2013 is renewed or modified during the period between March 23, 2013 and September 23, 2013, it will not qualify for the full transition period and must be compliant by September 23, 2013 BUT, if a BAA is subject to automatic or evergreen renewal, it will qualify for the full transition period

Okay let s make this simple. Did you have a BAA before January 25? No. Have one by September 23.

Okay let s make this simple. Did you have a BAA before January 25? Yes. Is it up for non-automatic renewal between March 23 and September 23, 2013? Yes. Make it compliant by September 23, 2013.

Okay let s make this simple. Did you have a BAA before January 25? Yes. Is it up for non-automatic renewal between March 23 and September 23, 2013? No. Make it compliant by its renewal date or September 22, 2014 (whichever is sooner).

Okay let s make this simple. Do you have a BAA that is compliant with the regulations in the Omnibus Rule? Good job.

Questions? Tony Brooks, CISA, CRISC, Tony.Brooks@horne-llp.com Clay J. Countryman, Esq., Clay.Countryman@bswllp.com Stephen M. Angelette, Esq., Stephen.Angelette@bswllp.com