SlideShare ist ein Scribd-Unternehmen logo
1 von 25
No More Excuses: HHS Releases
Tough Final HIPAA Privacy and
Security Rules
Brian R. Balow
Dickinson Wright PLLC
June 6, 2013
Overview
 Released January 17, 2013
 Effective March 26, 2013
 Covered entities and business associates have 180 days
beyond the effective date to come into compliance with
most of the Final Rule’s provisions (September 23, 2013)
Rules to be Discussed
 Privacy Rule
 Security Rule
 Breach Notification Rule
 Enforcement Rule
Some General Matters
 Patient Safety Organizations are now business
associates
 HIOs, E-Prescribing Gateways, and others that facilitate
ePHI transmission can be business associates (if
“access to PHI on routine basis” and not merely a
conduit)
 PHR vendors can be business associates if the PHR is
offered on behalf of a covered entity
Some General Matters
 Subcontractors to a covered entity can be business
associates “to the extent that they require access to
PHI.” Thus, covered entity must gain satisfactory
assurances of compliance required by the Rules from its
business associates, and business associates must
obtain same from subcontractors
 PHI “stored, whether intentionally or not, in photocopier,
facsimile, and other devices is subject to the Privacy and
Security Rules”
Copyright 2013 Michigan Health Information Network 5
Privacy Rule
 Uses and disclosures of patient information:
• Genetic information (health plans as defined in
HIPAA)
• Sale of PHI
• To health plan if services paid by patient
• Marketing activities
• Fundraising activities
• Deceased persons
• Immunization records to schools
Copyright 2013 Michigan Health Information Network 6
Privacy Rule
 Confirms a business associate’s direct liability for
specific provisions of the Privacy Rule
 Business associates not directly liable for other Privacy
Rule provisions (e.g., providing a NPP) unless
delegated to BA under a BAA
 BA may use PHI for “proper management and
administration of the BA and to provide data aggregation
services to a covered entity”
Privacy Rule
 A BA must enter into a BAA-style agreement with a
subcontractor prior to disclosing PHI
 Covered entities need no longer report uncured breach
by a BA of its obligations under a BAA
 A BA must attempt to cure a subcontractor’s breach of
“satisfactory assurance” type obligations (parallel to a
CE’s obligations vis-à-vis a BA)
Copyright 2013 Michigan Health Information Network 8
Privacy Rule
 Required changes to BAAs:
• BA must comply where applicable with Security Rule re
ePHI
• BA must report breaches of unsecured PHI to CE
• BA must flow down satisfactory assurance provisions to
subcontractors
• If Privacy Rule requirement delegated to BA, BA liable to
CE if BA breaches pertinent Privacy Rule requirement
(does not create direct BA liability, however)
Privacy Rule
 BAA Amendments
IF
• Existing BAA in place prior to January 25, 2013, and is
compliant with Privacy Rule as then in effect, and
• Existing BAA is not renewed or modified between March 26
and September 23, 2013,
THEN that BAA is deemed compliant until earlier of
• Date on which BAA is renewed or modified after September
23, 2013, or
• September 24, 2014
Copyright 2013 Michigan Health Information Network 10
Security Rule
 Security Rule’s administrative, physical, and technical safeguard
requirements, as well as the Rule’s policies and procedures and
documentation requirements, apply to business associates in the
same manner as they apply to covered entities, and BAs will be
civilly and criminally liable for violations
 It is the BA’s, and not the CE’s, obligation to obtain satisfactory
assurances from a subcontractor regarding protection of ePHI
 Allows that formerly required but duplicative BAA provisions are no
longer required (i.e., those required under each of the Privacy Rule
and the Security Rule)
Breach Notification Rule
 Unsecured PHI
• Secured PHI = Compliance with valid encryption processes for
data at rest consistent with NIST Special Publication 800-111,
Guide to Storage Encryption Technologies for End User Devices,
and with valid encryption processes for data in motion consistent
with NIST Special Publications 800-52, Guidelines for the
Selection and Use of Transport Layer Security (TLS)
Implementations; 800-77, Guide to IPsec VPNs; or 800-113,
Guide to SSL VPNs, or others which are Federal Information
Processing Standards (FIPS) 140-2 validated
Copyright 2013 Michigan Health Information Network 12
Breach Notification Rule, Cont’d
“Breach”
1. Impermissible use or disclosure of PHI is presumed to be a
breach unless CE or BA can demonstrate “low probability” that
PHI was “compromised” (move away from “risk of harm”
standard)
2. CE or BA must conduct a risk assessment to determine if PHI
was compromised
Breach Notification Rule, Cont’d
Risk Assessment:
1. Nature and extent of PHI involved (including identifiers/likelihood
of re-identification)
2. Consider the recipient (e.g., already under HIPAA obligation?)
3. Was PHI actually acquired or viewed
4. Extent to which risk has been mitigated
Breach Notification Rule, Cont’d
Notification to Individuals
 “Discovery”: When CE knew or by exercising reasonable
diligence would have been known to any person other than
the person committing the breach, who is a workforce
member or agent of CE
 Timeliness: w/o unreasonable delay, not more than 60 days
post-discovery (law enforcement delay exception remains)
 Content:
• What happened, when, and when discovered
• Description of compromised PHI
• Steps individuals should take to mitigate effects
• Steps CE is taking, plus contact information
Breach Notification Rule, Cont’d
Notification to Media:
 Unsecured PHI
 500+ affected individuals of any one State
 Within 60 days of discovery, max
 “Prominent media outlet” (depends on the market)
 Press release on a CE website does not meet this
requirement
Breach Notification Rule, Cont’d
 Notification to Secretary:
 500+ affected individuals (anywhere): “immediate” (meaning
at time individual notices are sent)
 Less than 500, maintain log and report on HHS website
annually, within 60 days of end of year
 Notification by a Business Associate:
 BA’s knowledge of breach is imputed to CE if the BA is an
agent of the CE (meaning CE’s clock starts ticking when BA
“discovers”
 Otherwise, CE’s clock begins upon notice from BA
Enforcement Rule
 Four civil money penalty tiers based on culpability:
Enforcement Rule, Cont’d
 “Reasonable cause” (second tier) defined as “an act or omission in
which a covered entity or business associate knew, or by exercising
reasonable diligence would have known, that the act or omission
violated an administrative simplification provision, but in which the
covered entity or business associate did not act with willful neglect.”
 Covered entities and business associates are now liable as
principals for the acts of business associates (for CEs) or
subcontractors (for BAs) acting as agents under Federal common
law principles
Copyright 2013 Michigan Health Information Network 19
Enforcement Rule, Cont’d
 Bases for Penalty Determinations:
1. Nature and extent of violation
2. Nature and extent of harm
3. History of prior compliance
4. Financial condition of the CE or BA
5. Other matters “as justice requires”
To-Do List: All
1.Print pp. 491 – 562 of the Final Rule
and put them in a binder
2.Read them in conjunction with
existing HIPAA regulations (which
should likewise be in a binder)
To Do List: Covered Entities
1. Update privacy policies (uses and disclosures of PHI)
2. Update compliance plan consistent with Breach Notification Rule changes
3. Examine BA relationships in light of agency liability issues
4. BAA review and revision (including amendments to existing BAAs)
5. Update notice of privacy practices and patient authorization form
6. (Seriously) consider encryption of ePHI if not already done
7. Conduct training
8. Use OCR resources
To Do List: Business Associates
1. Determine if you are a “business associate” (and if not be prepared
to defend your case)
2. Evaluate your current operations for compliance with applicable
Privacy Rule, Security Rule, and Breach Notification provisions
3. Ensure you have appropriate subcontracts in place and with proper
content
4. Conduct training
5. Use OCR resources
Disclaimer
This presentation is informational only. It does not constitute legal or
professional advice.
You are encouraged to consult with an attorney if you have specific
questions relating to any of the topics covered in this presentation
Contact Information
Brian R. Balow
248-433-7536
bbalow@dickinsonwright.com
Thank you

Weitere ähnliche Inhalte

Was ist angesagt?

HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?Redspin, Inc.
 
Hipaa in the era of ehr mo dept hss
Hipaa in the era of ehr  mo dept hssHipaa in the era of ehr  mo dept hss
Hipaa in the era of ehr mo dept hsslearfield
 
Assessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceAssessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceHostway|HOSTING
 
Redspin Webinar Business Associate Risk
Redspin Webinar Business Associate RiskRedspin Webinar Business Associate Risk
Redspin Webinar Business Associate RiskRedspin, Inc.
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookElizabeth Dimit
 
Establishing CCPA Compliance in Legacy PeopleSoft Systems
Establishing CCPA Compliance in Legacy PeopleSoft SystemsEstablishing CCPA Compliance in Legacy PeopleSoft Systems
Establishing CCPA Compliance in Legacy PeopleSoft SystemsAppsian
 
HIPAA Omnibus Presentation
HIPAA Omnibus PresentationHIPAA Omnibus Presentation
HIPAA Omnibus PresentationCompliancy Group
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rssupportc2go
 
Hipaa audits and enforcement
Hipaa audits and enforcementHipaa audits and enforcement
Hipaa audits and enforcementsupportc2go
 
Lawyers: What You Don't Know About HIPAA Could Hurt You
Lawyers: What You Don't Know About HIPAA Could Hurt YouLawyers: What You Don't Know About HIPAA Could Hurt You
Lawyers: What You Don't Know About HIPAA Could Hurt YouOregon Law Practice Management
 
The Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & SecurityThe Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & SecurityPolsinelli PC
 
MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE Milk663
 
ALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the HorizonALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the HorizonPatton Boggs LLP
 
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...Compliancy Group
 
Texas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New ChangesTexas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New ChangesJim Brashear
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceJim Anfield
 

Was ist angesagt? (20)

HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?
 
Hipaa in the era of ehr mo dept hss
Hipaa in the era of ehr  mo dept hssHipaa in the era of ehr  mo dept hss
Hipaa in the era of ehr mo dept hss
 
Assessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceAssessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA Compliance
 
Redspin Webinar Business Associate Risk
Redspin Webinar Business Associate RiskRedspin Webinar Business Associate Risk
Redspin Webinar Business Associate Risk
 
HIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule PlaybookHIPAA Final Omnibus Rule Playbook
HIPAA Final Omnibus Rule Playbook
 
Establishing CCPA Compliance in Legacy PeopleSoft Systems
Establishing CCPA Compliance in Legacy PeopleSoft SystemsEstablishing CCPA Compliance in Legacy PeopleSoft Systems
Establishing CCPA Compliance in Legacy PeopleSoft Systems
 
HIPAA Omnibus Presentation
HIPAA Omnibus PresentationHIPAA Omnibus Presentation
HIPAA Omnibus Presentation
 
Hi paa and eh rs
Hi paa and eh rsHi paa and eh rs
Hi paa and eh rs
 
Hipaa for business associates simple
Hipaa for business associates   simpleHipaa for business associates   simple
Hipaa for business associates simple
 
Hipaa audits and enforcement
Hipaa audits and enforcementHipaa audits and enforcement
Hipaa audits and enforcement
 
KMA Insights Webinar July 2009 -- Compliance with MA Privacy Law
KMA Insights Webinar July 2009 -- Compliance with MA Privacy LawKMA Insights Webinar July 2009 -- Compliance with MA Privacy Law
KMA Insights Webinar July 2009 -- Compliance with MA Privacy Law
 
Lawyers: What You Don't Know About HIPAA Could Hurt You
Lawyers: What You Don't Know About HIPAA Could Hurt YouLawyers: What You Don't Know About HIPAA Could Hurt You
Lawyers: What You Don't Know About HIPAA Could Hurt You
 
HIPAA Basic Healthcare Guide
HIPAA Basic Healthcare GuideHIPAA Basic Healthcare Guide
HIPAA Basic Healthcare Guide
 
The Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & SecurityThe Intersection of OCR Enforcement and Health Care Data Privacy & Security
The Intersection of OCR Enforcement and Health Care Data Privacy & Security
 
MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE MEDICAL ANSWERING SERVICE
MEDICAL ANSWERING SERVICE
 
ALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the HorizonALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
ALERT: Health Care Cybersecurity Reform and Regulations on the Horizon
 
HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...HIPAA compliance for Business Associates- The value of compliance, how to acq...
HIPAA compliance for Business Associates- The value of compliance, how to acq...
 
Texas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New ChangesTexas Privacy Laws - Tough New Changes
Texas Privacy Laws - Tough New Changes
 
The Startup Path to HIPAA Compliance
The Startup Path to HIPAA ComplianceThe Startup Path to HIPAA Compliance
The Startup Path to HIPAA Compliance
 
Healthcare Data Security Update
Healthcare Data Security UpdateHealthcare Data Security Update
Healthcare Data Security Update
 

Andere mochten auch

MiHIN Cyber-Security Panel Agenda
MiHIN Cyber-Security Panel AgendaMiHIN Cyber-Security Panel Agenda
MiHIN Cyber-Security Panel Agendamihinpr
 
Panel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie WaggonerPanel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie Waggonermihinpr
 
Doug Dietzman National HIE Landscape
Doug Dietzman National HIE LandscapeDoug Dietzman National HIE Landscape
Doug Dietzman National HIE Landscapemihinpr
 
Michigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia EdwardsMichigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia Edwardsmihinpr
 
HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012mihinpr
 
GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012mihinpr
 
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14mihinpr
 
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet KingPanel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet Kingmihinpr
 
Health IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich HodgeHealth IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich Hodgemihinpr
 
Dr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIEDr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIEmihinpr
 
A Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra SripadaA Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra Sripadamihinpr
 
MiHIN 101 Overview v4 04-08-15
MiHIN 101 Overview v4 04-08-15MiHIN 101 Overview v4 04-08-15
MiHIN 101 Overview v4 04-08-15mihinpr
 
MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15
MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15
MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15mihinpr
 
Connecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka KeynoteConnecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka Keynotemihinpr
 
MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15
MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15
MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15mihinpr
 
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy WalkerA Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walkermihinpr
 

Andere mochten auch (16)

MiHIN Cyber-Security Panel Agenda
MiHIN Cyber-Security Panel AgendaMiHIN Cyber-Security Panel Agenda
MiHIN Cyber-Security Panel Agenda
 
Panel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie WaggonerPanel Cyber Security and Privacy without Carrie Waggoner
Panel Cyber Security and Privacy without Carrie Waggoner
 
Doug Dietzman National HIE Landscape
Doug Dietzman National HIE LandscapeDoug Dietzman National HIE Landscape
Doug Dietzman National HIE Landscape
 
Michigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia EdwardsMichigan HIE Model- Cynthia Edwards
Michigan HIE Model- Cynthia Edwards
 
HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012HIE Day- JCMR Overview June 2012
HIE Day- JCMR Overview June 2012
 
GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012GLHIE Presentation June 19 2012
GLHIE Presentation June 19 2012
 
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
MiHIN Direct Webinar for EHR Intelligence v10 11 12-14
 
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet KingPanel: Achieving Interoperability Dr. John Loonsk & Janet King
Panel: Achieving Interoperability Dr. John Loonsk & Janet King
 
Health IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich HodgeHealth IT and Public Policy Issues Dr. Rich Hodge
Health IT and Public Policy Issues Dr. Rich Hodge
 
Dr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIEDr. Charles Friedman Transcending HIE
Dr. Charles Friedman Transcending HIE
 
A Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra SripadaA Vision for Creating a Connected State Subra Sripada
A Vision for Creating a Connected State Subra Sripada
 
MiHIN 101 Overview v4 04-08-15
MiHIN 101 Overview v4 04-08-15MiHIN 101 Overview v4 04-08-15
MiHIN 101 Overview v4 04-08-15
 
MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15
MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15
MiHIN Health Provider Directory Demo Slides with CQMRR v43 02 18-15
 
Connecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka KeynoteConnecting Patients, Providers and Payers John Halamka Keynote
Connecting Patients, Providers and Payers John Halamka Keynote
 
MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15
MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15
MiHIN Statewide Consumer Directory Overview - Direct Workgroup v4 03-09-15
 
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy WalkerA Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
A Consistent Nationwide Data Matching Strategy Donna Roach & Nancy Walker
 

Ähnlich wie Brian Balow HIPAA Final Rule

Business Associate Assessment, Agreement and Requirements
Business Associate Assessment, Agreement and RequirementsBusiness Associate Assessment, Agreement and Requirements
Business Associate Assessment, Agreement and Requirementsdata brackets
 
HIPAA Security Rule application to Business Associates heats up
HIPAA Security Rule application to Business Associates heats upHIPAA Security Rule application to Business Associates heats up
HIPAA Security Rule application to Business Associates heats upDavid Sweigert
 
Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Samantha Haas
 
HIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business AssociatesHIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business AssociatesBridge Front
 
Hhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklistHhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklistTodd LaRue
 
Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...
Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...
Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...Tracie Thompson
 
Explaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxExplaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxVistaInfosec
 
2013 06-21 HIPPA omnibus rule
2013 06-21 HIPPA omnibus rule2013 06-21 HIPPA omnibus rule
2013 06-21 HIPPA omnibus ruleDusaElraha
 
HIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and DangersHIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and DangersConference Panel
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantCarbonite
 
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxCHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxchristinemaritza
 
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAConfidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAParsons Behle & Latimer
 
Who Is A HIPAA Business Associate ?
Who Is A  HIPAA  Business  Associate ?Who Is A  HIPAA  Business  Associate ?
Who Is A HIPAA Business Associate ?Dan Wellisch
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Kimberly Simon MBA
 
HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013Quarles & Brady
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations OnRamp
 

Ähnlich wie Brian Balow HIPAA Final Rule (20)

Business Associate Assessment, Agreement and Requirements
Business Associate Assessment, Agreement and RequirementsBusiness Associate Assessment, Agreement and Requirements
Business Associate Assessment, Agreement and Requirements
 
HIPAA Security Rule application to Business Associates heats up
HIPAA Security Rule application to Business Associates heats upHIPAA Security Rule application to Business Associates heats up
HIPAA Security Rule application to Business Associates heats up
 
Hipaa omnibus
Hipaa omnibusHipaa omnibus
Hipaa omnibus
 
Hipaa privacy and security 03192014
Hipaa privacy and security 03192014Hipaa privacy and security 03192014
Hipaa privacy and security 03192014
 
HIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business AssociatesHIPAA Omnibus Rule: Critical Changes for Business Associates
HIPAA Omnibus Rule: Critical Changes for Business Associates
 
Hhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklistHhs issues hipaa cyber attack response checklist
Hhs issues hipaa cyber attack response checklist
 
Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...
Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...
Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and ...
 
HIPAA vs GDPR The How, What, and Why ?
HIPAA vs GDPR The How, What, and Why ? HIPAA vs GDPR The How, What, and Why ?
HIPAA vs GDPR The How, What, and Why ?
 
Explaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docxExplaining the HIPAA Privacy[.docx
Explaining the HIPAA Privacy[.docx
 
HIPAA for Dummies
HIPAA for DummiesHIPAA for Dummies
HIPAA for Dummies
 
2013 06-21 HIPPA omnibus rule
2013 06-21 HIPPA omnibus rule2013 06-21 HIPPA omnibus rule
2013 06-21 HIPPA omnibus rule
 
HIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and DangersHIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and Dangers
 
HiPAA info
HiPAA infoHiPAA info
HiPAA info
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docxCHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
CHAPTER3 Maintaining ComplianceMANY LAWS AND REGULATIONS.docx
 
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAAConfidentiality Issues Arising Under the ADA, FMLA, HIPAA
Confidentiality Issues Arising Under the ADA, FMLA, HIPAA
 
Who Is A HIPAA Business Associate ?
Who Is A  HIPAA  Business  Associate ?Who Is A  HIPAA  Business  Associate ?
Who Is A HIPAA Business Associate ?
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations
 

Mehr von mihinpr

MiHIN ADT ONC Presentation v10 02-02-15
MiHIN ADT ONC Presentation v10 02-02-15MiHIN ADT ONC Presentation v10 02-02-15
MiHIN ADT ONC Presentation v10 02-02-15mihinpr
 
MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14
MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14
MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14mihinpr
 
Panel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE LandscapePanel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE Landscapemihinpr
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITmihinpr
 
Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)mihinpr
 
State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)mihinpr
 
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & NationwideJennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & Nationwidemihinpr
 
Carrie Waggoner Cyber Security Panel
Carrie Waggoner Cyber Security PanelCarrie Waggoner Cyber Security Panel
Carrie Waggoner Cyber Security Panelmihinpr
 
Andrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyondAndrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyondmihinpr
 
MiHIN Brief Overview
MiHIN Brief OverviewMiHIN Brief Overview
MiHIN Brief Overviewmihinpr
 
MIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEMIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEmihinpr
 
SEMHIE Overview for MIHIN Sub-State HIE Panel
SEMHIE Overview for MIHIN Sub-State HIE PanelSEMHIE Overview for MIHIN Sub-State HIE Panel
SEMHIE Overview for MIHIN Sub-State HIE Panelmihinpr
 

Mehr von mihinpr (12)

MiHIN ADT ONC Presentation v10 02-02-15
MiHIN ADT ONC Presentation v10 02-02-15MiHIN ADT ONC Presentation v10 02-02-15
MiHIN ADT ONC Presentation v10 02-02-15
 
MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14
MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14
MiHIN Overview - Health Information Exchange Meet and Greet v7 10 22-14
 
Panel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE LandscapePanel: Understanding Michigan's HIE Landscape
Panel: Understanding Michigan's HIE Landscape
 
Panel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HITPanel Interstate and Other State HIE HIT
Panel Interstate and Other State HIE HIT
 
Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)Panel: Transitions of Care and ADT (without Rachel Sherman)
Panel: Transitions of Care and ADT (without Rachel Sherman)
 
State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)State of Michigan HIE Update (without Tina Scott)
State of Michigan HIE Update (without Tina Scott)
 
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & NationwideJennifer Horowitz EHR Adoption in Michigan & Nationwide
Jennifer Horowitz EHR Adoption in Michigan & Nationwide
 
Carrie Waggoner Cyber Security Panel
Carrie Waggoner Cyber Security PanelCarrie Waggoner Cyber Security Panel
Carrie Waggoner Cyber Security Panel
 
Andrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyondAndrea walrath mu stage 2 and beyond
Andrea walrath mu stage 2 and beyond
 
MiHIN Brief Overview
MiHIN Brief OverviewMiHIN Brief Overview
MiHIN Brief Overview
 
MIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIEMIHIN HIE Presentation UPHIE
MIHIN HIE Presentation UPHIE
 
SEMHIE Overview for MIHIN Sub-State HIE Panel
SEMHIE Overview for MIHIN Sub-State HIE PanelSEMHIE Overview for MIHIN Sub-State HIE Panel
SEMHIE Overview for MIHIN Sub-State HIE Panel
 

Kürzlich hochgeladen

Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort ServiceCall Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Serviceparulsinha
 
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original PhotosBook Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photosnarwatsonia7
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original PhotosCall Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photosnarwatsonia7
 
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...narwatsonia7
 
97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAA97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAAjennyeacort
 
High Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service Jaipur
High Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service JaipurHigh Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service Jaipur
High Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service Jaipurparulsinha
 
Glomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptxGlomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptxDr.Nusrat Tariq
 
Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024Gabriel Guevara MD
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Availablenarwatsonia7
 
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safenarwatsonia7
 
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdfHemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdfMedicoseAcademics
 
Glomerular Filtration and determinants of glomerular filtration .pptx
Glomerular Filtration and  determinants of glomerular filtration .pptxGlomerular Filtration and  determinants of glomerular filtration .pptx
Glomerular Filtration and determinants of glomerular filtration .pptxDr.Nusrat Tariq
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...narwatsonia7
 
Book Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbers
Book Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbersBook Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbers
Book Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbersnarwatsonia7
 
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service MumbaiLow Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbaisonalikaur4
 
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️saminamagar
 

Kürzlich hochgeladen (20)

Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Hosur Just Call 7001305949 Top Class Call Girl Service Available
 
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in green park  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in green park DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort ServiceCall Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
Call Girls Service In Shyam Nagar Whatsapp 8445551418 Independent Escort Service
 
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original PhotosBook Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
Book Call Girls in Yelahanka - For 7001305949 Cheap & Best with original Photos
 
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Jp Nagar Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original PhotosCall Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
Call Girl Service Bidadi - For 7001305949 Cheap & Best with original Photos
 
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
Call Girls Whitefield Just Call 7001305949 Top Class Call Girl Service Available
 
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
Call Girls Frazer Town Just Call 7001305949 Top Class Call Girl Service Avail...
 
97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAA97111 47426 Call Girls In Delhi MUNIRKAA
97111 47426 Call Girls In Delhi MUNIRKAA
 
High Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service Jaipur
High Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service JaipurHigh Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service Jaipur
High Profile Call Girls Jaipur Vani 8445551418 Independent Escort Service Jaipur
 
Glomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptxGlomerular Filtration rate and its determinants.pptx
Glomerular Filtration rate and its determinants.pptx
 
Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024Asthma Review - GINA guidelines summary 2024
Asthma Review - GINA guidelines summary 2024
 
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service AvailableCall Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
Call Girls ITPL Just Call 7001305949 Top Class Call Girl Service Available
 
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% SafeBangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
Bangalore Call Girls Marathahalli 📞 9907093804 High Profile Service 100% Safe
 
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdfHemostasis Physiology and Clinical correlations by Dr Faiza.pdf
Hemostasis Physiology and Clinical correlations by Dr Faiza.pdf
 
Glomerular Filtration and determinants of glomerular filtration .pptx
Glomerular Filtration and  determinants of glomerular filtration .pptxGlomerular Filtration and  determinants of glomerular filtration .pptx
Glomerular Filtration and determinants of glomerular filtration .pptx
 
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
Call Girls Electronic City Just Call 7001305949 Top Class Call Girl Service A...
 
Book Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbers
Book Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbersBook Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbers
Book Call Girls in Kasavanahalli - 7001305949 with real photos and phone numbers
 
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service MumbaiLow Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
Low Rate Call Girls Mumbai Suman 9910780858 Independent Escort Service Mumbai
 
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️call girls in munirka  DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
call girls in munirka DELHI 🔝 >༒9540349809 🔝 genuine Escort Service 🔝✔️✔️
 

Brian Balow HIPAA Final Rule

  • 1. No More Excuses: HHS Releases Tough Final HIPAA Privacy and Security Rules Brian R. Balow Dickinson Wright PLLC June 6, 2013
  • 2. Overview  Released January 17, 2013  Effective March 26, 2013  Covered entities and business associates have 180 days beyond the effective date to come into compliance with most of the Final Rule’s provisions (September 23, 2013)
  • 3. Rules to be Discussed  Privacy Rule  Security Rule  Breach Notification Rule  Enforcement Rule
  • 4. Some General Matters  Patient Safety Organizations are now business associates  HIOs, E-Prescribing Gateways, and others that facilitate ePHI transmission can be business associates (if “access to PHI on routine basis” and not merely a conduit)  PHR vendors can be business associates if the PHR is offered on behalf of a covered entity
  • 5. Some General Matters  Subcontractors to a covered entity can be business associates “to the extent that they require access to PHI.” Thus, covered entity must gain satisfactory assurances of compliance required by the Rules from its business associates, and business associates must obtain same from subcontractors  PHI “stored, whether intentionally or not, in photocopier, facsimile, and other devices is subject to the Privacy and Security Rules” Copyright 2013 Michigan Health Information Network 5
  • 6. Privacy Rule  Uses and disclosures of patient information: • Genetic information (health plans as defined in HIPAA) • Sale of PHI • To health plan if services paid by patient • Marketing activities • Fundraising activities • Deceased persons • Immunization records to schools Copyright 2013 Michigan Health Information Network 6
  • 7. Privacy Rule  Confirms a business associate’s direct liability for specific provisions of the Privacy Rule  Business associates not directly liable for other Privacy Rule provisions (e.g., providing a NPP) unless delegated to BA under a BAA  BA may use PHI for “proper management and administration of the BA and to provide data aggregation services to a covered entity”
  • 8. Privacy Rule  A BA must enter into a BAA-style agreement with a subcontractor prior to disclosing PHI  Covered entities need no longer report uncured breach by a BA of its obligations under a BAA  A BA must attempt to cure a subcontractor’s breach of “satisfactory assurance” type obligations (parallel to a CE’s obligations vis-à-vis a BA) Copyright 2013 Michigan Health Information Network 8
  • 9. Privacy Rule  Required changes to BAAs: • BA must comply where applicable with Security Rule re ePHI • BA must report breaches of unsecured PHI to CE • BA must flow down satisfactory assurance provisions to subcontractors • If Privacy Rule requirement delegated to BA, BA liable to CE if BA breaches pertinent Privacy Rule requirement (does not create direct BA liability, however)
  • 10. Privacy Rule  BAA Amendments IF • Existing BAA in place prior to January 25, 2013, and is compliant with Privacy Rule as then in effect, and • Existing BAA is not renewed or modified between March 26 and September 23, 2013, THEN that BAA is deemed compliant until earlier of • Date on which BAA is renewed or modified after September 23, 2013, or • September 24, 2014 Copyright 2013 Michigan Health Information Network 10
  • 11. Security Rule  Security Rule’s administrative, physical, and technical safeguard requirements, as well as the Rule’s policies and procedures and documentation requirements, apply to business associates in the same manner as they apply to covered entities, and BAs will be civilly and criminally liable for violations  It is the BA’s, and not the CE’s, obligation to obtain satisfactory assurances from a subcontractor regarding protection of ePHI  Allows that formerly required but duplicative BAA provisions are no longer required (i.e., those required under each of the Privacy Rule and the Security Rule)
  • 12. Breach Notification Rule  Unsecured PHI • Secured PHI = Compliance with valid encryption processes for data at rest consistent with NIST Special Publication 800-111, Guide to Storage Encryption Technologies for End User Devices, and with valid encryption processes for data in motion consistent with NIST Special Publications 800-52, Guidelines for the Selection and Use of Transport Layer Security (TLS) Implementations; 800-77, Guide to IPsec VPNs; or 800-113, Guide to SSL VPNs, or others which are Federal Information Processing Standards (FIPS) 140-2 validated Copyright 2013 Michigan Health Information Network 12
  • 13. Breach Notification Rule, Cont’d “Breach” 1. Impermissible use or disclosure of PHI is presumed to be a breach unless CE or BA can demonstrate “low probability” that PHI was “compromised” (move away from “risk of harm” standard) 2. CE or BA must conduct a risk assessment to determine if PHI was compromised
  • 14. Breach Notification Rule, Cont’d Risk Assessment: 1. Nature and extent of PHI involved (including identifiers/likelihood of re-identification) 2. Consider the recipient (e.g., already under HIPAA obligation?) 3. Was PHI actually acquired or viewed 4. Extent to which risk has been mitigated
  • 15. Breach Notification Rule, Cont’d Notification to Individuals  “Discovery”: When CE knew or by exercising reasonable diligence would have been known to any person other than the person committing the breach, who is a workforce member or agent of CE  Timeliness: w/o unreasonable delay, not more than 60 days post-discovery (law enforcement delay exception remains)  Content: • What happened, when, and when discovered • Description of compromised PHI • Steps individuals should take to mitigate effects • Steps CE is taking, plus contact information
  • 16. Breach Notification Rule, Cont’d Notification to Media:  Unsecured PHI  500+ affected individuals of any one State  Within 60 days of discovery, max  “Prominent media outlet” (depends on the market)  Press release on a CE website does not meet this requirement
  • 17. Breach Notification Rule, Cont’d  Notification to Secretary:  500+ affected individuals (anywhere): “immediate” (meaning at time individual notices are sent)  Less than 500, maintain log and report on HHS website annually, within 60 days of end of year  Notification by a Business Associate:  BA’s knowledge of breach is imputed to CE if the BA is an agent of the CE (meaning CE’s clock starts ticking when BA “discovers”  Otherwise, CE’s clock begins upon notice from BA
  • 18. Enforcement Rule  Four civil money penalty tiers based on culpability:
  • 19. Enforcement Rule, Cont’d  “Reasonable cause” (second tier) defined as “an act or omission in which a covered entity or business associate knew, or by exercising reasonable diligence would have known, that the act or omission violated an administrative simplification provision, but in which the covered entity or business associate did not act with willful neglect.”  Covered entities and business associates are now liable as principals for the acts of business associates (for CEs) or subcontractors (for BAs) acting as agents under Federal common law principles Copyright 2013 Michigan Health Information Network 19
  • 20. Enforcement Rule, Cont’d  Bases for Penalty Determinations: 1. Nature and extent of violation 2. Nature and extent of harm 3. History of prior compliance 4. Financial condition of the CE or BA 5. Other matters “as justice requires”
  • 21. To-Do List: All 1.Print pp. 491 – 562 of the Final Rule and put them in a binder 2.Read them in conjunction with existing HIPAA regulations (which should likewise be in a binder)
  • 22. To Do List: Covered Entities 1. Update privacy policies (uses and disclosures of PHI) 2. Update compliance plan consistent with Breach Notification Rule changes 3. Examine BA relationships in light of agency liability issues 4. BAA review and revision (including amendments to existing BAAs) 5. Update notice of privacy practices and patient authorization form 6. (Seriously) consider encryption of ePHI if not already done 7. Conduct training 8. Use OCR resources
  • 23. To Do List: Business Associates 1. Determine if you are a “business associate” (and if not be prepared to defend your case) 2. Evaluate your current operations for compliance with applicable Privacy Rule, Security Rule, and Breach Notification provisions 3. Ensure you have appropriate subcontracts in place and with proper content 4. Conduct training 5. Use OCR resources
  • 24. Disclaimer This presentation is informational only. It does not constitute legal or professional advice. You are encouraged to consult with an attorney if you have specific questions relating to any of the topics covered in this presentation
  • 25. Contact Information Brian R. Balow 248-433-7536 bbalow@dickinsonwright.com Thank you

Hinweis der Redaktion

  1. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  2. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  3. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  4. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  5. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  6. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  7. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  8. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  9. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  10. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  11. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  12. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  13. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  14. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  15. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  16. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  17. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  18. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted
  19. Copyright 2013 Michigan Health Information Network. All rights reserved. MiHIN Confidential--Proprietary--Restricted