Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
To help you understand the HIPAA terminology, we will go through some basic definitions. HIPAA stands for Health Insurance Portability and Accountability Act of 1996. HITECH stands for Health Information Technology for Economic and Clinical Health Act of 2009. The goal of HITECH is to promote the adoption and meaningful use of health information technology and significantly expands the HIPAA privacy rule and security standards and adds new requirements concerning privacy and security of PHI. PHI is Protected Health Information, and it deals with a patient’s personal information. ePHI is electronic Protected Health Information such as personal health information stored and transmitted electronically. Examples are faxes, emails, data backup and cloud providers, patient portals, removable media, and secure texting. All of this data should be encrypted at rest and in transit wherever that is reasonable and appropriate. However, reasonable and appropriate is not a matter of opinion; it means what a careful organization your size, with your resources and risks, would reasonably do to protect the information. If encryption is not reasonable and appropriate for the covered entity or business associate, the reason must be documented and an equivalent safeguard used instead. A Business Associate is anybody that supports the healthcare industry and performs functions or activities in support of a covered entity. Per the HITECH regulation, business associates are now legally required to be compliant with the HITECH rule. They are also financially liable for data breaches caused by their organization or employees. Business Associates are now required to have a risk assessment, just like a covered entity, including training and books of evidence. A Risk Assessment is a set of government-mandated questions to help you identify your gaps in risk not only to your business but also to a covered entity. We must also have a risk report with a roadmap to resolution. There are 3 sections of questions: Administrative, Technical, and Physical, which include standard, required, and addressable questions. The standard questions measure a covered entity to ensure the confidentiality, integrity, and availability of ePHI while in the custody of covered entities and business associates. Covered entities and business associates must comply with the applicable Standards provided in the Security Rule with respect to all ePHI. Required means that it must be implemented by the covered entity or business associate. Addressable was developed to provide covered entities additional flexibility with respect to compliance with the security standards. However, “addressable” does not mean “optional.” You must determine the level of risk to PHI and address it to ensure it is reasonable and appropriate security measures are applied. A Book of Evidence is the customized book of policies and procedures you are required to create and explains how you handle PHI and ePHI. This includes data breach notifications, disaster recovery policies, and privacy and patient policies. Privacy Policy explains how a covered entity and business associate handle all PHI. As a covered entity, you are required to provide your patients with a copy of your privacy policy upon request. Business Associates must be able to provide their privacy policy to their internal employees, external companies, which we call downstream suppliers, and for government audits.
In this lesson, we will go through some essential HIPAA definitions and core terms to help you better understand the law, including encryption standards, business associate liabilities, and risk assessment structures.
All ePHI should be encrypted at rest and in transit wherever reasonable and appropriate. "Reasonable and appropriate" is not a matter of opinion; it refers to what a careful organization of your size, resources, and risk level would do to protect data. If encryption is not feasible, the reason must be documented and an equivalent safeguard implemented instead.
A Business Associate is any individual or entity that supports the healthcare industry and performs functions on behalf of a covered entity. Under HITECH regulations, business associates must comply directly with HITECH rules and assume financial liability for data breaches caused by their organization or employees.
Business associates are required to maintain:
A Risk Assessment consists of government-mandated questions to identify potential security gaps and risk levels. It requires a corresponding risk report featuring a clear roadmap to resolution. Questionnaires cover three main domains (Administrative, Technical, and Physical) and utilize three implementation levels:
Pro Tip #1: A Book of Evidence is your customized set of written policies and procedures explaining how your organization manages PHI and ePHI, including data breach notification protocols, disaster recovery, and privacy policies.
Pro Tip #2: Covered entities must provide patients with a copy of their Privacy Policy upon request. Business associates must make their privacy policies available to internal employees, downstream suppliers, and government auditors.