What is HIPAA Privacy and Security?
The HIPAA Privacy Rule provides federal protections for Personal Health Information (PHI) held by covered entities and gives patients an array of rights with respect to that information. In addition, the Privacy Rule is balanced so that it permits the disclosure of PHI needed for patient care and other important purposes. The HIPAA Security Rule specifies a series of administrative, physical, and technical safeguards for covered entities to use to assure the confidentiality, integrity, and availability of electronic Protected Health Information (ePHI).
The HITECH Act, which is an addition to the overall HIPAA mandates, holds business associates responsible for being compliant with the HIPAA Privacy Rule and Security Rule. The HITECH Act also mandates the Business Associate’s responsibility for holding the covered entity to the Business Associate contract and the HIPAA Privacy Rule and Security Rule. If the Business Associate becomes aware of any non-compliance by the Covered Entity, the business associate must fix the breach, terminate the Business Associate contract, and/or report the non-compliance to the Department of Health and Human Services (HHS).
In order to fulfill HIPAA regulations, Business Associates have to comply with the HIPAA Privacy Rule and Security Rule effective Feb 17, 2012.
Cervisys is a Covered Entity under HIPAA, providing Business Associate services.
What are Business Associates and Covered Entities?
Covered Entities: Persons or organizations subject to the Privacy Rule. If you will be sending PHI (ePHI) to any outside entity for any services, like a billing service or clearinghouse, you are categorized as the Covered Entity. Cervisys is a Covered Entity under HIPAA, providing Business Associate services. Business Associate: Persons or organizations who will be receiving Protected Health Information (PHI or ePHI) from the Covered Entity to provide a service for the Covered Entity. This could be a billing service or clearinghouse, in which you send insurance claims to be further disbursed to multiple payers/health plans. Cervisys is a Covered Entity under HIPAA, providing Business Associate services.
- For any person, practice, or business that creates an account with Cervisys and sends PHI (ePHI) via our services, the account holder, or User, is the Covered Entity, and Cervisys is the Business Associate.
- When Cervisys sends the PHI (ePHI) to payers or third parties, Cervisys becomes the Covered Entity, and the payer or third party is the Business Associate or Trading Partner.
- User (Covered Entity) sends PHI (ePHI) to Cervisys (Business Associate)
- Cervisys (Covered Entity) sends PHI (ePHI) to payer/third party (Business Associate/Trading Partner)
What is a Business Associates Agreement?
What are the Obligations of Cervisys (Business Associates)?
The Business Associate Agreement (BAA) stipulates the requirements and limitations on how PHI (ePHI) is handled by Cervisys (Business Associate). Cervisys is a Covered Entity under HIPAA, providing Business Associate services. Limitations on Use and Disclosures
- The BAA specifically limits what Cervisys (Business Associate) can do with PHI (ePHI) that has been received or created for the User (Covered Entity). Strict limits are set so Cervisys is only able to use PHI (ePHI) to complete the agreed upon services for the User.
- Specific Uses and Disclosures that are permitted for Cervisys are listed in the BAA
Implement Safeguards to protect PHI (ePHI)
- Policies and Procedures determined by HIPAA
Reporting a Breach of PHI (ePHI) security
- Outlines the responsibilities of Cervisys (Business Associate) if there was any unauthorized discloser of PHI (ePHI)
- Required to inform the User (Covered Entity) of any breach of PHI (ePHI) within a reasonable timeframe, no more than 10 days from discovery, unless specifically indicated in BAA (II.e.ii)
- The notice needs to include what information was breached, and who it may have affected
- Cervisys (Business Associate) will assist in investigating and responding to the breach by providing the necessary information to the User (Covered Entity)
Availability of Information to Covered Entity
- The BAA outlines the type of information and the timeframe in which, if requested, Cervisys (Business Associate) must provide to the User (Covered Entity). This could include, but not limited to:
- Request to amend PHI
- Accounting of PHI
- Availability of Books and Records
- Record Retention
What are the Obligations of the User (Covered Entity)?
The User (Covered Entity) is responsible for conforming to all HIPAA regulations in their own practice/office/facility, as well as in their dealings with Cervisys (Business Associate). Cervisys is a Covered Entity under HIPAA, providing Business Associate services. Outlined in the BAA, there are multiple notifications the User (Covered Entity) must give Cervisys (Business Associate) if any of the following circumstances apply:
- One of the HIPAA Privacy Rule regulations is the Notice of Privacy Practices for PHI. If there are any restrictions or changes to that notice that would hinder Cervisys’ (Business Associate) ability to perform its services, the User (Covered Entity) must notify Cervisys.
- If there are any changes in who is authorized to access PHI (ePHI) in the User’s (Covered Entity) organization or practice, Cervisys (Business Associate) must be notified if the change would, in any way, affect the services provided.
- The User (Covered Entity) must notify Cervisys (Business Associate) of any new restrictions or changes they have agreed to for the use or disclosure of PHI (ePHI) that would hinder the Business Associate’s ability to provide services.
The HIPAA Privacy and Security Rules establish new regulations to protect patients’ privacy and improve the security surrounding that information. New obligations and responsibilities for Covered Entities and Business Associates help accomplish this. Cervisys strives continuously to ensure the utmost privacy and security for our users, in both the Covered Entity and Business Associate roles.
- Understanding Health Information Privacy
- The next HIPAA change: Business associates will have to comply directly
- 345 CFR 164.504(e)
- 445 CFR 164.308
- 545 CFR 164.310
- 645 CFR 164.312
- 745 CFR 164.316
- 845 CFR 164.520