Category: HIPAA
HIPAA is the US law governing the privacy and security of protected health information. It applies to covered entities — health plans, clearinghouses and most healthcare providers — and, since the HITECH Act, directly to their business associates.
Two rules do most of the work and are routinely confused. The Privacy Rule governs how PHI in any form may be used and disclosed, and establishes patient rights. The Security Rule applies only to electronic PHI and requires administrative, physical and technical safeguards, anchored on a documented security risk analysis.
The risk analysis is the requirement most often found missing in enforcement actions. It is not a questionnaire; it is a documented assessment of where ePHI lives, what threatens it, how likely and how damaging a compromise would be, and what you are doing about it. Its absence is treated as a compliance failure in its own right.
Business Associate Agreements are the other recurring gap. Every vendor that creates, receives, maintains or transmits PHI on your behalf needs one, with the provisions HHS requires it to contain.
The guides below cover the compliance checklist rule by rule, how to conduct a risk assessment, what a BAA must contain, the policy set you need, and how the Security and Privacy Rules differ.