HIPAA Privacy Flashcards
Safeguards and protections for PHI from a people standpoint
3 classes for BA interaction, and standard for HIPAA privacy
- clients BA contracts
- partners BA contracts
- staff Administrative Safeguards
BA contract
<ul>
<li>required between entities which share PHI</li>
<li>written assurance that a BA will safeguard PHI</li>
<li>defines BA obligations</li>
<li>defines purpose & uses for PHI</li>
<li>either separate contract or addendum to an existing service agreement</li>
</ul>
BA contract provisions
<ul>
<li>intended purpose</li>
<li>not to violate BA contract</li>
<li>safeguard PHI</li>
<li>report unauthorized disclosures to attestee</li>
<li>ensure subcontractors & agents safeguard</li>
<li>if maintainer of original PHI, to support individuals to access, amend, receive accounting of disclosures</li>
<li>internal records available to Department of Health and Human Services</li>
<li>return or destroy PHI upon termination of contract, if feasible</li>
</ul>
HIPAA privacy
<ul>
<li>Compliance officer responsible for implementing+overseeing organizational compliance</li>
<li>for those with access to PHI, Employee training every 2 years or when regulations change</li>
<li>Formal Documents and Controls to protect PHI</li>
</ul>