HIPAA compliance is ever evolving and may seem complicated. The Health Insurance Portability and Accountability Act (HIPAA) of 1996 is broken into three primary rules; Privacy 45 CFR 164. 500, Security 45 CFR 164.302 and Breach Notification 45 CFR 164.400.
The Privacy Rule established protection for protected health information whether in paper or electronic format. The rule defines patient rights that provide some control over their own health information and establishes standards regarding access, use and disclosure.
While the Security Rule established requirements for electronic protected health information. In general, the rule outlines administrative, technical and physical safeguards that must be addressed by covered entities and business associates.
Last, but certainly not least, the Breach Notification rule established detailed standards requiring covered entities to report breaches to impacted patients.
In 2009, the HITECH Act was signed and required Business Associates to implement the security rule safeguards. Additionally, it required covered entities and business associates to notify individuals of a breach. Then, in 2013, the Omnibus Rule modified the standard for a reportable breach to make breaches presumptively reported. The rule also extended requirement to Business Associates requiring them to have a privacy and security program in place and assigned direct liability for criminal and civil penalties for uses or disclosures that violate the privacy rule.
No wonder, HIPAA seems complicated…it is!
We have experienced consults that have spent time in the trenches and offer a broad array of consulting services for healthcare organizations and business associates to meet all aspects of HIPAA compliance.
Here are some of the key components of our HIPAA Compliance Services: