decisionhealth Newsletters, Part B News - 2016 Issue 7 (July)
Write, revisit BAA policies that protect you when associates mess up HIPAA
Subscribe or sign in to view the full article.
Article Overview
This article covers HIPAA business associate agreements (BAAs), recent enforcement activity involving a business associate, and practical policy considerations for organizations that work with vendors handling protected health information. It is aimed at compliance staff, privacy officers, healthcare administrators, and legal teams that oversee vendor contracts and HIPAA risk management. The discussion focuses on who should have BAAs, what makes an agreement more protective, and how organizations can audit or revisit their current BAA processes.
Why This Topic Matters
BAAs are a key administrative safeguard for HIPAA compliance and vendor oversight. Understanding how they are handled can help organizations reduce breach exposure, improve contract management, and better evaluate responsibility when a vendor incident occurs.
Article Sections
-
Recent OCR enforcement and business associate responsibility
Summarizes a recent federal enforcement action and its relevance to business associate accountability under HIPAA.
-
Who gets BAAs?
Discusses which vendor relationships generally warrant a business associate agreement and when a different type of arrangement may be sufficient.
-
Is your BAA good enough?
Addresses contract management considerations for existing agreements, including how organizations may think about added protections and potential remedies.
-
3 questions to ask about your BAA policy
Outlines review points for organizations assessing how they track, maintain, and update their BAA program.
What You Will Learn
- How BAAs fit into HIPAA vendor oversight
- What recent enforcement activity suggests about business associate responsibility
- What to consider when reviewing existing vendor agreements
- How organizations can evaluate BAA tracking, audits, and renewal practices
- Why current vendor access and agreement status should be monitored closely
Who Should Read This
- Healthcare compliance professionals
- Privacy officers
- Healthcare administrators
- Legal counsel
- Revenue cycle and vendor management staff
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com