Covered entities don’t have the option to hide behind BAA if a Health and Human Services (HHS) auditor comes knocking.
This article was also featured in HITECH Answers.
During the last few months of auditing various HIPAA environments, I’ve seen three distinct groups of covered entities that have responded to new HIPAA Omnibus requirements regarding business associates.
Want to take a guess which group you should be in?
Covered entities don’t have the option to hide behind BAA if a Health and Human Services (HHS) auditor comes knocking. This tactic may have worked before September 2013, but the HHS specifically stated in new HIPAA documentation that covered entities are required to take dual-responsibility for patient data protection, and signing a new agreement just isn’t enough anymore. The HHS calls this new business associate responsibility obtaining satisfactory assurances.
See also: What to Expect With Upcoming HHS Audits
Though government documentation does little to explain the phrase, ‘satisfactory assurances’ essentially means covered entities must personally take measures to check BA patient data handling processes and review BA security measures. To meet this requirement, some covered entities require proof of a completed risk analysis or personally request the implementation of a standard risk management plan. Others track all business associates with a compliance-monitoring tool.
The logic behind the new rule is quite sound when you think about it. The new rule prevents business associates from signing contracts without actually implementing HIPAA practices.
See also: SecurityMetrics HIPAA Guide
Would you give a teenager who failed the driving test the keys to your car if they promised they’d be careful? The HHS wouldn’t.
You have been assigned the part of the responsible parent, and if you willfully neglect that responsibility, the HHS may come after you to the tune of $50,000 minimum per violation.
Don't get me wrong, I’m not trying to downplay the importance of business associate agreements. After all, they are still required as per HIPAA rules. Just remember patient data is so important that you may need to consider dropping business associates that choose to ignore compliance best practices. With recent class-action lawsuits seeking $1,000 per compromised individual, it’s worth it to be choosey.
Here’s the moral of the story. The new HIPAA Omnibus rule isn’t just about signing a new BAA. Every covered entity with business associates (virtually all of you) is required to obtain assurances that their business associates treat patient data the way the HHS wants them to, and the way you want them to. Whether you choose to personally audit each BA, or require documented data security procedures, take the initiative to secure the future of your organization and safety of patient data.