decisionhealth Newsletters, Part B News - 2022 Issue 7 (July)
After Meta pixel HIPAA gaffe, check your online business associate agreements
Subscribe or sign in to view the full article.
Article Overview
This article reviews a reported privacy incident involving health system websites, third-party tracking technology, and the possible exposure of patient information. It explains why the issue matters for covered entities, vendors, and compliance teams, with emphasis on business associate agreements, vendor due diligence, and related privacy obligations under HIPAA and other laws. The piece is aimed at health care administrators, compliance professionals, and legal or revenue-cycle teams responsible for vendor contracts and online patient-facing services.
Why This Topic Matters
Health care organizations increasingly rely on online scheduling and patient intake tools, which can create privacy and contractual risk if third-party services handle patient information in unexpected ways. Understanding the article helps compliance and legal teams review vendor relationships, strengthen agreements, and reduce exposure to privacy investigations or breach-related claims.
Article Sections
-
Experts surprised
This section summarizes reactions from health care and legal experts to the reported use of website tracking technology on public-facing appointment pages. It also frames the compliance and privacy concerns that the report raised.
-
‘Bare bones’ BAA not enough
This section discusses business associate agreement considerations for appointment-related vendors and broader vendor oversight expectations. It addresses how covered entities think about privacy protections, responsibilities, and contract review.
-
Be cautious of all agreements
This section focuses on reviewing vendor agreements more broadly and monitoring how patient information may flow to other parties. It emphasizes due diligence, data handling concerns, and the need to align vendor practices with organizational expectations.
-
2 more things to watch
This section highlights additional privacy considerations beyond HIPAA and encourages ongoing communication with vendors. It points to other legal frameworks and practical steps for clarifying how online services operate.
What You Will Learn
- How website tracking on patient-facing pages can create privacy concerns for health care organizations
- What to consider when reviewing business associate agreements for online vendors
- Why vendor due diligence matters for patient-facing appointment and intake tools
- What broader privacy and state-law issues may arise alongside HIPAA compliance
- How covered entities can approach conversations with vendors about data handling practices
Who Should Read This
- Health care compliance professionals
- Healthcare attorneys
- Practice administrators
- Hospital privacy officers
- Revenue cycle and operations teams
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com