General Surgery Coding Alert - 2019 Issue 8
HIPAA: Master 4 Contracts for Security and Privacy
Subscribe or sign in to view the full article.
Article Overview
This article covers four common HIPAA contract types and the organizational situations that call for each one. It is aimed at healthcare compliance, privacy, security, and operations professionals who need a broad understanding of how business relationships, data sharing, and risk management affect agreement selection and review. The discussion also touches on annual contract review, subcontractor considerations, and cybersecurity-related contract language.
Why This Topic Matters
Understanding which agreement belongs in a given relationship helps organizations support HIPAA compliance, manage PHI access, and align contracts with current privacy and security expectations.
Article Sections
-
Know These 4 Major Agreements
Introduces four agreement categories used in HIPAA-related business relationships and explains the general contexts in which they arise.
-
Business Associate Agreement
Covers the role of business associates, subcontractor relationships, and the need to align access to protected health information with contractual obligations.
-
Data Use Agreement
Discusses agreements used for limited data set sharing and research-related or public health-related data arrangements.
-
Organized Health Care Arrangement
Describes a coordinated care arrangement among covered entities and the compliance context in which it operates.
-
Confidentiality Agreement
Addresses workers and service providers who are not business associates and the purpose of confidentiality commitments in those relationships.
-
Here’s Why You Should Review Your Contracts Annually
Explains why ongoing contract review is part of HIPAA risk management and why organizations should reassess agreement terms over time.
What You Will Learn
- The main HIPAA agreement types discussed in the article
- How agreement needs can vary by business relationship and data-sharing context
- Why subcontractor and vendor arrangements matter for HIPAA compliance
- Why periodic contract review is part of risk management
- How cybersecurity considerations can affect agreement language
Who Should Read This
- HIPAA compliance professionals
- Healthcare privacy officers
- Healthcare security professionals
- Practice managers
- Revenue cycle and operations staff
- Medical office administrators
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com