General Surgery Coding Alert - 2012 Issue 45
Privacy: Storing PHI Offsite? Refer to This Checklist to Stay Compliant
Subscribe or sign in to view the full article.
Article Overview
This article explains practical compliance considerations for healthcare practices that store protected health information in cloud or online systems. It focuses on vendor evaluation, data protection, breach response, business associate agreements, oversight, policy updates, and self-auditing in the context of HIPAA and related privacy and security responsibilities. The piece is aimed at practices and compliance staff assessing whether a storage vendor and internal safeguards are appropriate for PHI.
Why This Topic Matters
Moving PHI to offsite storage changes a practice’s privacy and security risk profile and can trigger specific contractual, operational, and oversight obligations. This article helps readers understand the broad compliance areas they should review before and after adopting cloud storage.
Article Sections
-
Evaluate the Vendor
Introduces vendor-selection considerations for organizations handling regulated health information and cloud-based storage services.
-
Check Out the Data Protection
Covers general storage-security topics such as encryption and separation of client data within a vendor environment.
-
Ensure Proper Breach Protocols
Discusses breach monitoring, response planning, and how responsibilities may be divided between the practice and the vendor.
-
Develop a BAA
Addresses business associate contracting, required compliance language, and vendor assurances tied to privacy and security obligations.
-
Monitor Compliance
Describes ongoing oversight expectations and the broader compliance relationship between covered entities and business associates.
-
Update Your Policies & Procedures
Focuses on internal policy and procedure updates needed to reflect online storage activities and related safeguards.
-
Audit Yourself
Reviews self-audit, risk assessment, access-control, and documentation topics related to cloud-based PHI storage.
What You Will Learn
- How cloud storage introduces privacy and security considerations for PHI
- What areas to review when selecting an offsite storage vendor
- Why written agreements and internal oversight matter for compliance
- How policies, procedures, and self-audits support HIPAA-related readiness
Who Should Read This
- Medical practices
- Part B providers
- Privacy officers
- Security officers
- Compliance staff
- Healthcare administrators
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com