HIPAA and Business Associates - New Responsibilities and Obligations

Speaker

Instructor: Jim Sheldon-Dean
Product ID: 702610

Location
  • Duration: 90 Min
HIPAA regulations pertaining to the relationships of business entities that share PHI are now being enforced. HIPAA Business Associates are covered directly under the Privacy Rule’s use and disclosure limitations, the Security Rule’s safeguard provisions, and the Breach Notification Rule’s notification requirements. HIPAA Business Associates are responsible for their own compliance with the regulations, and may be held directly liable for any violations of the regulations. Whether your organization is a Business Associate or a Covered Entity that hires HIPAA Business Associates, you have significant obligations in compliance that you overlook at your peril.
RECORDED TRAINING
Last Recorded Date: Oct-2019

 

$249.00
1 Person Unlimited viewing for 6 month info Recorded Link and Ref. material will be available in My CO Section
(For multiple locations contact Customer Care)

$349.00
Downloadable file is for usage in one location only. info Downloadable link along with the materials will be emailed within 2 business days
(For multiple locations contact Customer Care)

 

 

Customer Care

Fax: +1-650-362-2367

Email: [email protected]

Read Frequently Asked Questions

 

Why Should You Attend:

This presentation will help entities working with healthcare information on behalf of others understand the obligations under HIPAA and see what needs to be done to ensure data are properly protected and penalties for noncompliance are avoided. In this modern environment of electronic systems, potential security threats, and big penalties in the millions of dollars for non-compliance, it is essential to understand your obligations and act accordingly under HIPAA.

Areas Covered in the Webinar:

  • The regulations will be reviewed and their effects on usual practices for Business Associates and their relationships with covered entities will be discussed.
  • We will describe the kinds of entities that qualify as Business Associates and why it is important to carefully consider the designation before using it.
  • We will examine other types of HIPAA entities, such as Hybrid entities, Affiliated Covered Entities, and Organized Health Care Arrangements, how they relate to Business Associates, and when Business Associate Agreements may be required among the various entities.
  • We will review the new HHS guide to guide to the direct enforcement liabilities of Business Associates under the HIPAA regulations.
  • We will explain what a Business Associate needs to do under the regulations, provide a policy framework for information security, and show what policies need to be in place.
  • We will describe the required and recommended elements of a Business Associate Agreement, including identifying the template language provided by the US Department of Health and Human Services and its role in the process. We will explore the questions that should be posed to HIPAA Business Associates to ensure they have considered good privacy and security compliance practices in their businesses.
  • The new enforcement penalty structure and the latest plans for audits by HHS OCR will be described and a plan for being prepared for audits and enforcement actions will be discussed.

Who Will Benefit:

This webinar will provide valuable assistance to all personnel in:

Medical offices, practice groups, hospitals, academic medical centers, insurers, business associates (shredding, data storage, systems vendors, billing services, etc.). The titles are:

  • Compliance director
  • CEO
  • CFO
  • Privacy Officer
  • Security Officer
  • Information Systems Manager
  • HIPAA Officer
  • Chief Information Officer
  • Health Information Manager
  • Healthcare Counsel/lawyer
  • Office Manager
  • Contracts Manager
Instructor Profile:
Jim Sheldon-Dean

Jim Sheldon-Dean
Principal and Director of Compliance Services, Lewis Creek Systems, LLC

Jim Sheldon-Dean is the founder and director of compliance services at Lewis Creek Systems, LLC, a Vermont-based consulting firm founded in 1982, providing information privacy and security regulatory compliance services to a wide variety of health care entities. He is a frequent speaker regarding HIPAA, including speaking engagements at numerous regional and national healthcare association conferences and conventions and the annual NIST/OCR HIPAA Security Conference.

Sheldon-Dean has more than 16 years of experience specializing in HIPAA compliance, more than 34 years of experience in policy analysis and implementation, business process analysis, information systems and software development, and eight years of experience doing hands-on medical work as a Vermont certified volunteer emergency medical technician.

Sheldon-Dean received his B.S. degree, summa cum laude, from the University of Vermont and his master’s degree from the Massachusetts Institute of Technology.

Topic Background:

A provider of services to a healthcare entity may be considered a HIPAA Business Associate if they create, receive, maintain, or transmit HIPAA Protected Health Information (PHI) on behalf of those entities, whether or not the required agreements are in place, and is subject to the obligations imposed on such business partners by the HIPAA regulations. Certain activities can place a firm in a business associate relationship, and once that’s the case, there are compliance obligations that can lead to significant penalties if ignored.

The definition of a HIPAA Business Associate casts a wide net of healthcare business activities, including any business that creates, receives, maintains, or transmits any Protected Health Information on behalf of a HIPAA Covered Entity or Business Associate, and even sub-contractors of Business Associates are also treated as business associates, greatly expanding the pool of entities under regulation to some that may not even be aware they have become HIPAA Business Associates.

Based on recent enforcement actions, it is now more important than ever to carefully consider whether a BA designation is appropriate or not – Business Associate Agreements are not to be entered into lightly. The requirements have a direct impact on what needs to be put into the business associate agreements you establish. And, in order to satisfy their clients’ requirements for adequate assurances of good practices, Business Associates may be asked to provide not just a simple contract, but also third-party reviews and assessments of HIPAA compliance.

HHS recently issued a guidance document to explain how Business Associates may be liable for compliance enforcement under HIPAA, giving a ten-item list of ways an entity could become liable under the regulations. Some of the specifications are far from trivial, such as complying with the Security Rule, but the organization of items relevant to Business Associates is a helpful guide.

Business Associate Agreements are now more important than ever, because breaches by Business Associates are becoming more common and carry tremendous expenses for the affected covered entities. Audit and penalty liabilities confirm the need to make sure covered entities and Business Associates are in compliance before HHS OCR knocks on the door.

Follow us :

 

 

Refund Policy

Our refund policy is governed by individual products and services refund policy mentioned against each of offerings. However in absence of specific refund policy of an offering below refund policy will be effective.
Registrants may cancel up to two working days prior to the course start date and will receive a letter of credit to be used towards a future course up to one year from date of issuance. ComplianceOnline would process/provide refund if the Live Webinar has been cancelled. The attendee could choose between the recorded version of the webinar or refund for any cancelled webinar. Refunds will not be given to participants who do not show up for the webinar. On-Demand Recordings can be requested in exchange. Webinar may be cancelled due to lack of enrolment or unavoidable factors. Registrants will be notified 24hours in advance if a cancellation occurs. Substitutions can happen any time. On-Demand Recording purchases will not be refunded as it is available for immediate streaming. However if you are not able to view the webinar or you have any concern about the content of the webinar please contact us at below email or by call mentioning your feedback for resolution of the matter. We respect feedback/opinions of our customers which enables us to improve our products and services. To contact us please email [email protected] call +1-888-717-2436 (Toll Free).

 

 

+1-888-717-2436

6201 America Center Drive Suite 240, San Jose, CA 95002, USA

Follow Us

facebook twitter linkedin youtube

 

Copyright © 2023 ComplianceOnline.com MetricStream
Our Policies: Terms of use | Privacy

PAYMENT METHOD: 100% Secure Transaction

payment method