SlideShare a Scribd company logo
1 of 23
Pillsbury Winthrop Shaw Pittman LLP
Cybersecurity in the Health Care Sector:
HIPAA Responsibilities from a Legal
and Compliance Perspective
July 23, 2013
Gerry Hinkley, Pillsbury
Allen Briskin, Pillsbury
Overview
 Business associate obligations since the Omnibus Rule
 Developing an approach to HIPAA compliance – lessons from the
OCR Pilot Audits
1 |
Business associate obligations
Under Omnibus Final Rule
 Omnibus Rule conforms HIPAA regulations to HITECH Act changes
 Before HITECH, BAs regulated through business associate
contracts or agreements ("BACs")
 After HITECH, BAs and subcontractors are regulated directly
under HIPAA
 Must comply with Security Rule (rule is flexible to
accommodate small BAs)
 Must comply with some of Privacy Rule and provisions of BAC
2 |
Business associates – expanded regulation
 Expanded definition of “business associate”
• “Business associate” means one who, on behalf of a covered
entity, creates, receives, maintains or transmits PHI
 "Business associate" now also means "subcontractor of business
associate“ who creates, receives, maintains or transmits PHI on
behalf of a business associate
 Status as BA based upon role and responsibilities, not upon who
are the parties to the contract
3 |
Subcontractors of business associates
 Implications for subcontractor relationships
 Contract between the covered entity's BA and that BA's
subcontractor must satisfy the BAC requirements
 Subcontractor of subcontractor is also a BA, and so on
 As a result, HIPAA/HITECH obligations that apply to BAs also
directly apply to subcontractors
4 |
Clarification of “who is a business associate”
 Rule clarifies definition of "business associate” -- included:
 Patient Safety Organizations
 Health information exchange organizations, e-prescribing
gateways, covered entities' personal health record vendors (not all
PHRs)
 Data transmission providers that require access to PHI on a
routine basis
 Not included – those who just provide transmission services, like
digital couriers or “mere conduits”
 However, those who store PHI, even if they don’t intend to actually
view it, are BAs (NB: cloud model EHRs)
5 |
Business associates’ use of protected health
information
 Uses of PHI
 BAs may use or disclose PHI only as permitted by BAC or
required by law
 BAs may not use or disclose PHI in manner that would violate
Privacy Rule
 Subcontractors subject to limits in initial CE-BA agreement – must
pass along in subcontracts
 BAs not making a permitted use or disclosure if not following
minimum necessary rules
 BA does not comply if it knows of subcontractor's material
noncompliance and does not take reasonable steps to cure the
breach or, if such steps fail, to terminate the relationship
6 |
Consequences for business associates
 Secretary authorized to receive and investigate complaints against
BAs (including subcontractors), and to take action regarding
complaints and noncompliance
 BAs (incl. subs) required to maintain records and submit compliance
reports to Secretary, cooperate in complaint investigations and
compliance reviews, give Secretary access to information
 BAs (incl. subs) forbidden to intimidate, discriminate against, etc.
those who make complaints, cooperate with regulators or oppose
unlawful actions
 BAs (incl. subcontractors) subject to civil money penalties for HIPAA
violations
 BA/subs remain liable under contract (BAC) to CE/BA
7 |
Business associate contracts – transition provisions
 Generally, compliance required 180 days Rule’s effective date
(3/26/13), which is 9/23/13
 Additional time allowed to enter into conforming business associate
agreements (Limited Deemed Compliance Date)
 If BACs comply with pre-Omnibus rule, parties have 1 additional
year to bring their BACs into compliance with Omnibus Rule
(9/22/14)
 If BACs do not comply with pre-Omnibus rule (or no BAA exists),
must enter into BACs that comply with Omnibus Rule by 9/23/13
 Regardless of compliance deadlines, compliance with Omnibus
Rule required when existing BACs renew or are modified
8 |
Business associate contracts – transition provisions
 BACs not otherwise modified or renewed prior to 9/22/14 must be
brought into compliance by that date
9 |
Business associate contracts – new & changed
provisions
 Definitions of “business associate” & “subcontractor”
 Business associate’s compliance with applicable provisions of the
Security Rule
 Carrying out CE’s responsibilities in compliance with HIPAA
 BACs with subcontractors; obligations to seek cure of sub’s breach or
terminate
 Assurances that subcontractor will appropriately safeguard PHI
 Assurances that subcontractor will comply with BA’s obligations to CE
10 |
Approach to HIPAA compliance – lessons learned
from the OCR pilot audits
 Background on the pilot audits
 OCR’s findings
 Adopting the Pilot Audit approach to internal HIPAA compliance
 Focus on the hot buttons
 Organize your documentation
 Utilize internal audit procedures to test compliance
 How to prepare for an eventual audit
11 |
What were the OCR pilot audits?
 OCR completed audits of 115 entities, including 61 providers, 47
Health Plans and 7clearinghouses
 OCR had 979 audit findings and observations, including 293
Privacy, 592 Security and 94 Breach Notification
 The Pilot Audits focused on:
 The seven fundamental practices of the Privacy Rule
 The administrative, physical and technical safeguards of the Security Rule
 The requirements of the Breach Notification Rule
12 |
Audit findings
 HIPAA is not an organizational priority: lack of application of sufficient
resources, incomplete implementation and sometimes complete
disregard for HIPAA (30% didn’t know they had HIPAA obligations)
 Failure to conduct regular risk assessments (70%)
 Minimum necessary not understood
 Security issues predominate over privacy issues
 User access – authentication and limitations
 Attention to encryption – either encrypt or explain why not
 Media management – reuse and destruction
13 |
Adopt the pilot audit protocol for internal compliance
 Provide for a comprehensive assessment of policies, practices,
systems, operations, infrastructure
 Determine whether routine operations implement policies that comply
with legal requirements
 Targeted areas of high risk and frequent noncompliance
 Identify and correct critical weaknesses of compliance efforts
14 |
Hot buttons
 Current risk assessment (last three years)
 Response and reporting
 Awareness and training
 Access control – user activity monitoring
 Information access management
 Workstation security
 Business Associate contracts
 Minimum necessary
 Contingency planning
 De-identification
15 |
Documentation to study
 Organizational chart
 Policies and procedures, and specifically
 Uses and disclosures
 Breach notification
 Complaints and sanctions
 Incident response plans
 Technical controls and information
 Policies for physical safeguards
16 |
Documentation - 2
 Notice of privacy practices
 Network diagrams
 Training documentation
 Audit logs and other system generated information
17 |
Presenting material to internal audit in an organized
manner
 Determine how best to present the documentation in an organized
and responsive manner to tell the story about how your organization is
committed to comply with the Privacy and Security Rules
 Trace the lifecycle of PHI at your organization
 Know where high risk PHI exists
 Is data encrypted and if not, how is it protected
18 |
Preparedness – assume you will be audited
at some point
 Have a communication plan ready and engage senior leadership
 Prepare by performing self-assessments using the OCR Audit
Protocols
 Conduct mock interviews of staff to prepare them for the Audit
 If compliance issues exist, focus on the biggest issues and /or those
easier to fix
 Consider providing non-routine communications to serve as a refresher
of key principles for all staff
19 |
Given what we know – a practical approach to
getting ready
 Create a regulatory binder that contains the OCR and HHS guidance
for the Audit and what/where/how list to access the required documents
within your organization
 The Audit Protocol found at http://ocrnotifications.hhs.gov/hipaa.html
 List of contacts within your organization to assist in document retrieval for
all aspects of the Audit, namely, privacy, security and breach notification
 Recent risk assessment
 Policies and procedures related to the Privacy and Security Rules
 Notice of privacy practices
 Monitoring/audit log reports
20 |
21
The purpose of this presentation is to inform and
comment upon legal and regulatory developments in
the health care industry. It is not intended, nor should
it be used, as a substitute for specific legal advice
inasmuch as legal counsel may only be given in
response to inquiries regarding particular situations.
22 |
Contacts
Gerry Hinkley
Pillsbury Winthrop Shaw Pittman LLP
415.983.1135
gerry.hinkley@pillsburylaw.com
Allen Briskin
Pillsbury Winthrop Shaw Pittman LLP
415.983.1134
allen.briskin@pillsburylaw.com

More Related Content

What's hot

Managing HIPAA Business Associate Relationships - April 24, 2018
Managing HIPAA Business Associate Relationships  -  April 24, 2018  Managing HIPAA Business Associate Relationships  -  April 24, 2018
Managing HIPAA Business Associate Relationships - April 24, 2018 Dan Wellisch
 
HealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTHealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTKimberly Simon MBA
 
You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Factsresourceone
 
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapProf- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapHernan Huwyler, MBA CPA
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliancePrince George
 
Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...
Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...
Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...Ethisphere
 
Cyberinsurance 111006
Cyberinsurance 111006Cyberinsurance 111006
Cyberinsurance 111006JNicholson
 
Assessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceAssessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceHostway|HOSTING
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongLorianne Sainsbury-Wong
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations OnRamp
 
theprinciplesmaturitymodel
theprinciplesmaturitymodeltheprinciplesmaturitymodel
theprinciplesmaturitymodelDavid Vickers
 
Hipaa changes 2018 and how to comply
Hipaa changes 2018 and how to complyHipaa changes 2018 and how to comply
Hipaa changes 2018 and how to complySangeetha Parandhaman
 
Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines Aegify Inc.
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantCarbonite
 
SAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project CharterSAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project CharterDavid Sweigert
 

What's hot (20)

Managing HIPAA Business Associate Relationships - April 24, 2018
Managing HIPAA Business Associate Relationships  -  April 24, 2018  Managing HIPAA Business Associate Relationships  -  April 24, 2018
Managing HIPAA Business Associate Relationships - April 24, 2018
 
2010 New Guidelines Hipaa Checklist V1
2010 New Guidelines Hipaa Checklist V12010 New Guidelines Hipaa Checklist V1
2010 New Guidelines Hipaa Checklist V1
 
HealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUSTHealthCare Compliance - HIPAA & HITRUST
HealthCare Compliance - HIPAA & HITRUST
 
You and HIPAA - Get the Facts
You and HIPAA - Get the FactsYou and HIPAA - Get the Facts
You and HIPAA - Get the Facts
 
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 RoadmapProf- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
Prof- Hernan Huwyler, MBA CPA ISO 37002 Roadmap
 
A brief introduction to hipaa compliance
A brief introduction to hipaa complianceA brief introduction to hipaa compliance
A brief introduction to hipaa compliance
 
HM480 Ab103318 ch11
HM480 Ab103318 ch11HM480 Ab103318 ch11
HM480 Ab103318 ch11
 
Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...
Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...
Whistleblower Best Practices: What Do Compliance and Business Leaders Need to...
 
Cyberinsurance 111006
Cyberinsurance 111006Cyberinsurance 111006
Cyberinsurance 111006
 
Assessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA ComplianceAssessing Your Hosting Environment for HIPAA Compliance
Assessing Your Hosting Environment for HIPAA Compliance
 
HM480 Ab103318 ch20
HM480 Ab103318 ch20HM480 Ab103318 ch20
HM480 Ab103318 ch20
 
HIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-WongHIPAA Access Medical Records by Sainsbury-Wong
HIPAA Access Medical Records by Sainsbury-Wong
 
HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations HIPAA eBOOK: Avoid Common HIPAA Violations
HIPAA eBOOK: Avoid Common HIPAA Violations
 
theprinciplesmaturitymodel
theprinciplesmaturitymodeltheprinciplesmaturitymodel
theprinciplesmaturitymodel
 
HM480 Ab103318 ch10
HM480 Ab103318 ch10HM480 Ab103318 ch10
HM480 Ab103318 ch10
 
Hipaa changes 2018 and how to comply
Hipaa changes 2018 and how to complyHipaa changes 2018 and how to comply
Hipaa changes 2018 and how to comply
 
Hipaa basics
Hipaa basicsHipaa basics
Hipaa basics
 
Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines Importance of Following HITECH Compliance Guidelines
Importance of Following HITECH Compliance Guidelines
 
Keeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-CompliantKeeping Your Business HIPAA-Compliant
Keeping Your Business HIPAA-Compliant
 
SAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project CharterSAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
SAMPLE HIPAA Security Rule Corrective Action Plan Project Charter
 

Similar to Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective

Brian Balow HIPAA Final Rule
Brian Balow HIPAA Final RuleBrian Balow HIPAA Final Rule
Brian Balow HIPAA Final Rulemihinpr
 
Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...NJVC, LLC
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTControlCase
 
BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...
BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...
BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...Amatun Noor
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...IISPEastMids
 
HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013Quarles & Brady
 
Who Is A HIPAA Business Associate ?
Who Is A  HIPAA  Business  Associate ?Who Is A  HIPAA  Business  Associate ?
Who Is A HIPAA Business Associate ?Dan Wellisch
 
An Introduction To Compliance Program
An Introduction To Compliance ProgramAn Introduction To Compliance Program
An Introduction To Compliance Programlinhcuong
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskTrustArc
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Kimberly Simon MBA
 
PanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus CompendiumPanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus CompendiumOmar Vázquez
 
Watkins Meegan: Compliance with FAR Ethics Requirements
Watkins Meegan: Compliance with FAR Ethics RequirementsWatkins Meegan: Compliance with FAR Ethics Requirements
Watkins Meegan: Compliance with FAR Ethics RequirementsAndrea Contres Moore, MBA
 
Achieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification SuccessAchieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification SuccessShyamMishra72
 
HIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and DangersHIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and DangersConference Panel
 
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...Skoda Minotti
 
What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sIatric Systems
 
Staying ahead of the curve social media compliance 10-7-2010 - final
Staying ahead of the curve   social media compliance 10-7-2010 - finalStaying ahead of the curve   social media compliance 10-7-2010 - final
Staying ahead of the curve social media compliance 10-7-2010 - finalDeborah Well
 
How HIM Supports the Seven Elements of an Effective Compliance Program
How HIM Supports the Seven Elements of an Effective Compliance ProgramHow HIM Supports the Seven Elements of an Effective Compliance Program
How HIM Supports the Seven Elements of an Effective Compliance ProgramPYA, P.C.
 

Similar to Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective (20)

Brian Balow HIPAA Final Rule
Brian Balow HIPAA Final RuleBrian Balow HIPAA Final Rule
Brian Balow HIPAA Final Rule
 
Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...Training Your Business Associate Workforce: Understanding Obligations and Ri...
Training Your Business Associate Workforce: Understanding Obligations and Ri...
 
Healthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUSTHealthcare Compliance: HIPAA and HITRUST
Healthcare Compliance: HIPAA and HITRUST
 
BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...
BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...
BSCI (Business Social Compliance Initiative) Code of Conduct & it’s practical...
 
BSCI Guideline
BSCI GuidelineBSCI Guideline
BSCI Guideline
 
General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...General Data Protection Regulation: what do you need to do to get prepared? -...
General Data Protection Regulation: what do you need to do to get prepared? -...
 
HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013HIPAA Rules and Action Steps for Compliance April 2013
HIPAA Rules and Action Steps for Compliance April 2013
 
Who Is A HIPAA Business Associate ?
Who Is A  HIPAA  Business  Associate ?Who Is A  HIPAA  Business  Associate ?
Who Is A HIPAA Business Associate ?
 
An Introduction To Compliance Program
An Introduction To Compliance ProgramAn Introduction To Compliance Program
An Introduction To Compliance Program
 
How to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy RiskHow to Manage Vendors and Third Parties to Minimize Privacy Risk
How to Manage Vendors and Third Parties to Minimize Privacy Risk
 
Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017Health care compliance webinar may 10 2017
Health care compliance webinar may 10 2017
 
HIPAA Security 2019
HIPAA Security 2019HIPAA Security 2019
HIPAA Security 2019
 
PanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus CompendiumPanoMed HIPAA Omnibus Compendium
PanoMed HIPAA Omnibus Compendium
 
Watkins Meegan: Compliance with FAR Ethics Requirements
Watkins Meegan: Compliance with FAR Ethics RequirementsWatkins Meegan: Compliance with FAR Ethics Requirements
Watkins Meegan: Compliance with FAR Ethics Requirements
 
Achieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification SuccessAchieving HIPAA Compliance: The Roadmap to Certification Success
Achieving HIPAA Compliance: The Roadmap to Certification Success
 
HIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and DangersHIPAA Business Associate Compliance and Dangers
HIPAA Business Associate Compliance and Dangers
 
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
HIPAA Compliance: What Medical Practices and Their Business Associates Need t...
 
What Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​sWhat Covered Entities Need to Know about OCR HIPAA Audit​s
What Covered Entities Need to Know about OCR HIPAA Audit​s
 
Staying ahead of the curve social media compliance 10-7-2010 - final
Staying ahead of the curve   social media compliance 10-7-2010 - finalStaying ahead of the curve   social media compliance 10-7-2010 - final
Staying ahead of the curve social media compliance 10-7-2010 - final
 
How HIM Supports the Seven Elements of an Effective Compliance Program
How HIM Supports the Seven Elements of an Effective Compliance ProgramHow HIM Supports the Seven Elements of an Effective Compliance Program
How HIM Supports the Seven Elements of an Effective Compliance Program
 

Recently uploaded

Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426jennyeacort
 
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...chandars293
 
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...narwatsonia7
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...tanya dube
 
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...aartirawatdelhi
 
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...perfect solution
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...Arohi Goyal
 
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeCall Girls Delhi
 
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableDipal Arora
 
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
Russian Call Girls Service Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...
Russian Call Girls Service  Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...Russian Call Girls Service  Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...
Russian Call Girls Service Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...parulsinha
 
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service AvailableDipal Arora
 
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort ServicePremium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Servicevidya singh
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋TANUJA PANDEY
 
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Dipal Arora
 
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Ishani Gupta
 

Recently uploaded (20)

Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
 
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Haridwar Just Call 8250077686 Top Class Call Girl Service Available
 
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Kochi Just Call 8250077686 Top Class Call Girl Service Available
 
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...Top Rated  Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
Top Rated Hyderabad Call Girls Erragadda ⟟ 9332606886 ⟟ Call Me For Genuine ...
 
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...Top Rated Bangalore Call Girls Mg Road ⟟   9332606886 ⟟ Call Me For Genuine S...
Top Rated Bangalore Call Girls Mg Road ⟟ 9332606886 ⟟ Call Me For Genuine S...
 
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
Premium Bangalore Call Girls Jigani Dail 6378878445 Escort Service For Hot Ma...
 
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Tirupati Just Call 8250077686 Top Class Call Girl Service Available
 
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
Night 7k to 12k Navi Mumbai Call Girl Photo 👉 BOOK NOW 9833363713 👈 ♀️ night ...
 
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Ludhiana Just Call 9907093804 Top Class Call Girl Service Available
 
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
College Call Girls in Haridwar 9667172968 Short 4000 Night 10000 Best call gi...
 
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
All Time Service Available Call Girls Marine Drive 📳 9820252231 For 18+ VIP C...
 
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any TimeTop Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
Top Quality Call Girl Service Kalyanpur 6378878445 Available Call Girls Any Time
 
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service AvailableCall Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
Call Girls Gwalior Just Call 8617370543 Top Class Call Girl Service Available
 
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Nagpur Just Call 9907093804 Top Class Call Girl Service Available
 
Russian Call Girls Service Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...
Russian Call Girls Service  Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...Russian Call Girls Service  Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...
Russian Call Girls Service Jaipur {8445551418} ❤️PALLAVI VIP Jaipur Call Gir...
 
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Aurangabad Just Call 8250077686 Top Class Call Girl Service Available
 
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort ServicePremium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
Premium Call Girls Cottonpet Whatsapp 7001035870 Independent Escort Service
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
 
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
 
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
Mumbai ] (Call Girls) in Mumbai 10k @ I'm VIP Independent Escorts Girls 98333...
 

Cybersecurity in Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective

  • 1. Pillsbury Winthrop Shaw Pittman LLP Cybersecurity in the Health Care Sector: HIPAA Responsibilities from a Legal and Compliance Perspective July 23, 2013 Gerry Hinkley, Pillsbury Allen Briskin, Pillsbury
  • 2. Overview  Business associate obligations since the Omnibus Rule  Developing an approach to HIPAA compliance – lessons from the OCR Pilot Audits 1 |
  • 3. Business associate obligations Under Omnibus Final Rule  Omnibus Rule conforms HIPAA regulations to HITECH Act changes  Before HITECH, BAs regulated through business associate contracts or agreements ("BACs")  After HITECH, BAs and subcontractors are regulated directly under HIPAA  Must comply with Security Rule (rule is flexible to accommodate small BAs)  Must comply with some of Privacy Rule and provisions of BAC 2 |
  • 4. Business associates – expanded regulation  Expanded definition of “business associate” • “Business associate” means one who, on behalf of a covered entity, creates, receives, maintains or transmits PHI  "Business associate" now also means "subcontractor of business associate“ who creates, receives, maintains or transmits PHI on behalf of a business associate  Status as BA based upon role and responsibilities, not upon who are the parties to the contract 3 |
  • 5. Subcontractors of business associates  Implications for subcontractor relationships  Contract between the covered entity's BA and that BA's subcontractor must satisfy the BAC requirements  Subcontractor of subcontractor is also a BA, and so on  As a result, HIPAA/HITECH obligations that apply to BAs also directly apply to subcontractors 4 |
  • 6. Clarification of “who is a business associate”  Rule clarifies definition of "business associate” -- included:  Patient Safety Organizations  Health information exchange organizations, e-prescribing gateways, covered entities' personal health record vendors (not all PHRs)  Data transmission providers that require access to PHI on a routine basis  Not included – those who just provide transmission services, like digital couriers or “mere conduits”  However, those who store PHI, even if they don’t intend to actually view it, are BAs (NB: cloud model EHRs) 5 |
  • 7. Business associates’ use of protected health information  Uses of PHI  BAs may use or disclose PHI only as permitted by BAC or required by law  BAs may not use or disclose PHI in manner that would violate Privacy Rule  Subcontractors subject to limits in initial CE-BA agreement – must pass along in subcontracts  BAs not making a permitted use or disclosure if not following minimum necessary rules  BA does not comply if it knows of subcontractor's material noncompliance and does not take reasonable steps to cure the breach or, if such steps fail, to terminate the relationship 6 |
  • 8. Consequences for business associates  Secretary authorized to receive and investigate complaints against BAs (including subcontractors), and to take action regarding complaints and noncompliance  BAs (incl. subs) required to maintain records and submit compliance reports to Secretary, cooperate in complaint investigations and compliance reviews, give Secretary access to information  BAs (incl. subs) forbidden to intimidate, discriminate against, etc. those who make complaints, cooperate with regulators or oppose unlawful actions  BAs (incl. subcontractors) subject to civil money penalties for HIPAA violations  BA/subs remain liable under contract (BAC) to CE/BA 7 |
  • 9. Business associate contracts – transition provisions  Generally, compliance required 180 days Rule’s effective date (3/26/13), which is 9/23/13  Additional time allowed to enter into conforming business associate agreements (Limited Deemed Compliance Date)  If BACs comply with pre-Omnibus rule, parties have 1 additional year to bring their BACs into compliance with Omnibus Rule (9/22/14)  If BACs do not comply with pre-Omnibus rule (or no BAA exists), must enter into BACs that comply with Omnibus Rule by 9/23/13  Regardless of compliance deadlines, compliance with Omnibus Rule required when existing BACs renew or are modified 8 |
  • 10. Business associate contracts – transition provisions  BACs not otherwise modified or renewed prior to 9/22/14 must be brought into compliance by that date 9 |
  • 11. Business associate contracts – new & changed provisions  Definitions of “business associate” & “subcontractor”  Business associate’s compliance with applicable provisions of the Security Rule  Carrying out CE’s responsibilities in compliance with HIPAA  BACs with subcontractors; obligations to seek cure of sub’s breach or terminate  Assurances that subcontractor will appropriately safeguard PHI  Assurances that subcontractor will comply with BA’s obligations to CE 10 |
  • 12. Approach to HIPAA compliance – lessons learned from the OCR pilot audits  Background on the pilot audits  OCR’s findings  Adopting the Pilot Audit approach to internal HIPAA compliance  Focus on the hot buttons  Organize your documentation  Utilize internal audit procedures to test compliance  How to prepare for an eventual audit 11 |
  • 13. What were the OCR pilot audits?  OCR completed audits of 115 entities, including 61 providers, 47 Health Plans and 7clearinghouses  OCR had 979 audit findings and observations, including 293 Privacy, 592 Security and 94 Breach Notification  The Pilot Audits focused on:  The seven fundamental practices of the Privacy Rule  The administrative, physical and technical safeguards of the Security Rule  The requirements of the Breach Notification Rule 12 |
  • 14. Audit findings  HIPAA is not an organizational priority: lack of application of sufficient resources, incomplete implementation and sometimes complete disregard for HIPAA (30% didn’t know they had HIPAA obligations)  Failure to conduct regular risk assessments (70%)  Minimum necessary not understood  Security issues predominate over privacy issues  User access – authentication and limitations  Attention to encryption – either encrypt or explain why not  Media management – reuse and destruction 13 |
  • 15. Adopt the pilot audit protocol for internal compliance  Provide for a comprehensive assessment of policies, practices, systems, operations, infrastructure  Determine whether routine operations implement policies that comply with legal requirements  Targeted areas of high risk and frequent noncompliance  Identify and correct critical weaknesses of compliance efforts 14 |
  • 16. Hot buttons  Current risk assessment (last three years)  Response and reporting  Awareness and training  Access control – user activity monitoring  Information access management  Workstation security  Business Associate contracts  Minimum necessary  Contingency planning  De-identification 15 |
  • 17. Documentation to study  Organizational chart  Policies and procedures, and specifically  Uses and disclosures  Breach notification  Complaints and sanctions  Incident response plans  Technical controls and information  Policies for physical safeguards 16 |
  • 18. Documentation - 2  Notice of privacy practices  Network diagrams  Training documentation  Audit logs and other system generated information 17 |
  • 19. Presenting material to internal audit in an organized manner  Determine how best to present the documentation in an organized and responsive manner to tell the story about how your organization is committed to comply with the Privacy and Security Rules  Trace the lifecycle of PHI at your organization  Know where high risk PHI exists  Is data encrypted and if not, how is it protected 18 |
  • 20. Preparedness – assume you will be audited at some point  Have a communication plan ready and engage senior leadership  Prepare by performing self-assessments using the OCR Audit Protocols  Conduct mock interviews of staff to prepare them for the Audit  If compliance issues exist, focus on the biggest issues and /or those easier to fix  Consider providing non-routine communications to serve as a refresher of key principles for all staff 19 |
  • 21. Given what we know – a practical approach to getting ready  Create a regulatory binder that contains the OCR and HHS guidance for the Audit and what/where/how list to access the required documents within your organization  The Audit Protocol found at http://ocrnotifications.hhs.gov/hipaa.html  List of contacts within your organization to assist in document retrieval for all aspects of the Audit, namely, privacy, security and breach notification  Recent risk assessment  Policies and procedures related to the Privacy and Security Rules  Notice of privacy practices  Monitoring/audit log reports 20 |
  • 22. 21 The purpose of this presentation is to inform and comment upon legal and regulatory developments in the health care industry. It is not intended, nor should it be used, as a substitute for specific legal advice inasmuch as legal counsel may only be given in response to inquiries regarding particular situations.
  • 23. 22 | Contacts Gerry Hinkley Pillsbury Winthrop Shaw Pittman LLP 415.983.1135 gerry.hinkley@pillsburylaw.com Allen Briskin Pillsbury Winthrop Shaw Pittman LLP 415.983.1134 allen.briskin@pillsburylaw.com