Recording and written materials of
AIS's Webinar on April 7, 2010 |
| How to Amend HIPAA Business Associate Agreements to Comply With the HITECH Act |
|
The new HITECH Act required hospitals, providers, health plans and other HIPAA covered entities (CEs) to meet a February 2010 deadline for revising their business associate (BA) agreements. Developing and maintaining effective BA relationships should be a top compliance priority for CEs, since privacy and security breaches often take place at the BA level and can be just as damaging to a covered entity’s reputation. With a lack of guidance by HHS's Office for Civil Rights and lots of tricky questions to resolve, covered entities need a quick crash course in what their options are for designing and implementing these amendments. |
Sponsored
by Atlantic Information Services, Inc., publisher of Report on Patient Privacy and Report on Medicare Compliance |
While the HITECH Act did not come right out and say “business associate agreements must be revised,” it does stipulate that certain provisions “shall be incorporated into the business associate agreement between the business associate and the covered entity.” Among them: business associate agreements must be amended to reflect the new mandate that BAs must comply with the Security Rule, should be amended to provide the covered entity with adequate notice in the event of a security breach, and should incorporate new privacy obligations imposed on CEs by the HITECH Act.
But with no OCR guidance issued yet, there are many unanswered questions that covered entities must address. Among them:
- Which security rule provisions do BAs need to comply with?
- How much time should CEs give BAs to notify them of a security breach, since the CE itself must go public with certain breaches in 60 days?
- How do these issues change for a CE if a BA is an “agent” instead of a “contractor”?
- What definition of “breach” should CEs give to their BAs? Should it include the “harm” standard or should CEs reserve this determination for themselves?
Veteran HIPAA attorney Reece Hirsch, a partner with Morgan, Lewis & Bockius LLP in San Francisco, answers these and many other questions ... and outlines specific steps your organization should consider for amending your business associate agreements.
- What are the new HITECH Act requirements that are driving amendments to business associate agreements?
- What timing issues should covered entities be aware of, in terms of the February compliance deadline and the current absence of OCR guidance on HITECH Act implementation of business associate agreement amendments?
- What should be a covered entity’s objectives related to their business associates’ compliance with breach notification and the security rule?
- What specific contract language should CEs consider for meeting these two sets of objectives?
- What strategies should CEs consider to effectively manage the onerous and difficult task of amending scores (if not hundreds) of BA agreements?
- To what extent have the HIPAA liabilities of covered entities been lessened with these new obligations for business associates?
Attendees of the meeting said ...
“I was very, very pleased with today’s audioconference. I thought that: (a) the printed materials were quite helpful; (b) the speaker was knowledgeable, informative and responsive; and, (c) the Q/A session was excellent. I cannot remember the last time that I’ve found an audioconference like this to be so good (and I’m usually a really harsh critic of these types of events). So kudos to you, Mr. Hirsch, and to AIS!”
-John R. Hamilton III
Vice President of Compliance Services
Gentiva Health Services
”Well done. The materials are informative and thorough. Attorney Hirsch was very clear and provided thoughtful analysis and practical solutions.”
-Lynda Godkin, Esq.
Senior Vice President & General Counsel
Women’s Health USA, Inc
|
Speaker
REECE HIRSCH, a partner in the San Francisco office of the law firm of Morgan, Lewis & Bockius LLP, is one of the nation's leading health care privacy and security attorneys. Mr. Hirsch counsels hospitals, health plans, insurance companies, pharmaceutical companies, physician organizations and health care technology companies with respect to a wide range of privacy and security compliance issues. Mr. Hirsch was named one of Nightingale's "Outstanding Healthcare Information Technology Attorneys" for 2009. He has written and lectured extensively on HIPAA privacy and security, security breach notification issues, and state and federal privacy and security laws. Mr. Hirsch is a contributing author to AIS's HIPAA Compliance Center at www.AISHIPAA.com.
Moderator: Liana Heitin, Editor, Report on Patient Privacy and Assistant Editor, Report on Medicare Compliance
Designed
Especially For
Compliance officers, privacy officers, data security and IT managers, internal auditors, legal counsel and business managers with:
- Hospitals and health systems
- Medical group practices and providers
- Health plans and insurance companies
- Health care clearinghouses
- Billing companies
- Ancillary provider groups
- Pharmaceutical companies
- E-health companies
... and other HIPAA covered entities and business associates, which now have new obligations under the recently enacted law.
Shipping
Information
Please note that the On-Demand recordings will be available within 2-3 days of the conference and the CDs will be available within 2 weeks.
CDs (and accompanying written materials) are shipped via UPS. Please give us your
street address when you order (UPS does not deliver to PO boxes).
You should receive your order within 5-7 business days.* Shipping
cost is $5.
The On-Demand Recording will be delivered as a link within a PDF file of the accompanying written materials. Shipping will NOT be charged for this item.
If you order the On-Demand Recording before the conference date (by itself or in combination with the live Webinar), you will be sent an e-mail with the PDF file attached once the recording is available.*
After the On-Demand Recording is available*, if you order on this Web site through our secure shopping cart, a link will appear directing you to download the PDF file. This link will be accessible only for 24 hours, so be sure to save the file to your computer. If you order through our customer service department (by phone, mail, fax or e-mail), you will be sent an e-mail with the PDF file attached.
Rush
Orders: Please call us at 800-521-4323 to place a rush order.* We
will overnight your order for an additional charge of $30, or you
can give us your FedEx or UPS account number and we will charge
the shipping to your account. Rush orders placed after 3:00pm
EST will not be shipped out until the next business day.
*The On-Demand recordings will be available within 2-3 days of the conference and the CDs will be available within 2 weeks.
Written
Materials
Listeners will
also receive practical written materials to supplement information
covered by the Webinar speakers.
For further information
call 800-521-4323 or e-mail customerserv@aispub.com