HIPAA now requires business-associate agreements

In 2009, through the enactment of the Health Information Technology for Clinical and Economic Health (HITECH) Act, the U.S. Department of Health and Human Services (HHS) sought to improve the national health care system by enabling patients and providers to access health information in any location, at any time. HITECH requires increased protections for the electronic exchange of personal, private health information to eliminate unwanted disclosure or accessibility to sensitive health information. In July, HHS, proposed a new federal health care information privacy rule that will amend the Health Insurance Portability and Accountability Act of 1996 (HIPAA) by expanding patients’ rights and implementing more stringent regulations to protect against unwanted use of patients’ health information by third parties who handle individuals’ identifiable health information.
Although HIPAA has in the past only applied to “covered entities” (hospitals, health care providers, pharmacies and health insurance plans), the July amendment to HIPAA requires that third parties which enter into agreements with covered entities contracting to serve as a provider for electronic health information systems or otherwise, must enter into business-associate agreements with the covered entity. Business associates are required to implement privacy and security policies and procedures in the same manner as covered entities. Further, business associates will need to conduct risk analysis and risk management in order to be considered effective under the regulations and will have to implement appropriate technology to comply with HIPAA.
Third-party business associates are also required to report breaches of patients’ unsecured, protected health information if the breach may cause financial, reputational or other harm to the patient. HITECH and the regulations require covered entities and business associates to develop and document policies and procedures for notification of individuals, train work force members on the policies and procedures and implement sanctions for a failure to comply with the policies and procedures. Covered entities and business associates should maintain documentation regarding notifications issued, the risk assessment performed and the analysis made to determine that an exception applied to substantiate that notification was not required. Covered entities are required to annually notify OCR of all breaches involving less than 500 individuals.
The increased attention paid to the privacy and security of health information has migrated toward a trend of increased protection of personal information such as name, date of birth and website activity. As a result, Rick Boucher, a Virginia Democrat and House Energy and Commerce Communications Subcommittee chairman, and Florida Rep. Cliff Sterns recently proposed a privacy bill requiring “notice to and consent of an individual prior to the collection and disclosure of certain personal information relating to that individual.” The purpose of the Boucher Privacy Act is to provide greater protections for consumers in the widespread use of the Internet to store and share information.
Concurrently, Rep. Bobby Rush, an Illinois Democrat, this summer presented the Best Practices Act “to foster transparency about the commercial use of personal information, provide consumers with meaningful choice about the collection, use and disclosure of such information and for other purposes.”
The Boucher and Rush bills mirror some provisions of HIPAA, which solidifies the intent of legislators to implement laws and regulations that increase privacy protections of personal information.
Any business that accesses health information for a covered entity must now implement policies and procedures that comply with HIPAA and HITECH. Further, any business that collects, holds, uses, accesses or discloses personal information of consumers, particularly electronically, should review their privacy policies and practices, their security measures and any risks associated with a breach of the information. Finally, if your company has a website and you are using consumer information collected from your website, it is important to review your privacy policies and practice and assess the risk. •


Linn Foster Freedman is a partner in Nixon Peabody’s Providence office. She chairs the firms HIPPA Compliance Group and is a member of the firms E-Discovery & Information Law Group.

Seifert Systems Invests in Energy Efficiency to Strengthen Operations

For manufacturers, energy is more than just another operating expense. It plays a critical role…

Learn More

No posts to display