tci Medicare Compliance & Reimbursement - 2019 Issue 9
HIPAA: Know the 5 Different Contracts That Concern Privacy and Security
Subscribe or sign in to view the full article.
Article Overview
This article explains common HIPAA contract types and why they matter for privacy, security, and compliance planning. It is aimed at covered entities, business associates, and healthcare compliance professionals who manage vendor relationships, data sharing, research-related arrangements, and annual contract review processes. The discussion also highlights the role of risk assessment, documentation, and cybersecurity considerations in maintaining compliant agreements.
Why This Topic Matters
HIPAA compliance depends not only on policies and training, but also on having the right agreements in place with vendors and partners. Understanding the broad categories of contracts covered here helps organizations evaluate their relationships, protect information appropriately, and keep arrangements aligned with privacy and security obligations.
Article Sections
-
Know These 5 Major Contracts
An overview of the agreement types discussed in the article and the general circumstances in which they arise. The section focuses on HIPAA relationship categories, privacy and security concerns, and the role of covered entities and partners.
-
Business Associate Agreement
General discussion of agreements involving outside parties that handle protected health information on behalf of covered entities. The section also addresses subcontractor relationships and compliance oversight.
-
Data Use Agreement
General discussion of agreements connected to limited data sets and research or public health uses. The section covers the broader relationship between privacy rule requirements and permitted data sharing.
-
Organized Health Care Arrangement
General discussion of arrangements that support coordination among separate covered entities. The section covers shared care settings, operational integration, and related compliance considerations.
-
Confidentiality Agreement
General discussion of agreements used with personnel or service providers who are not business associates. The section explains the role of confidentiality protections for workers who may encounter sensitive information.
-
Here’s Why You Should Review Your Contracts Annually
Guidance on periodically reassessing business relationships and related agreements as part of HIPAA risk management. The section emphasizes contract maintenance, updates, and cybersecurity-related review considerations.
What You Will Learn
- How HIPAA-related contract categories are organized at a high level
- When different kinds of agreements may be relevant to vendor and partner relationships
- Why annual review of agreements is part of compliance planning
- How privacy, security, and cybersecurity concerns fit into contract oversight
- Which organizations and roles are commonly involved in these arrangements
Who Should Read This
- Healthcare compliance professionals
- Covered entities
- Business associates
- Practice managers
- Health information management staff
- Healthcare attorneys
Subscribe or sign in to view the full article.
Thank you for choosing Find-A-Code, please Sign In to remove ads.


Quick, Current, Complete - www.findacode.com