HIPAA: Vet Your BA’s HIPAA Harmony Before Hiring

Subscribe or sign in to view the full article.

Note:  The following article synopsis was NOT provided by AAPC. It was created by Find-A-Code/innoviHealth.

Article Overview

This article discusses HIPAA compliance considerations for covered entities when evaluating business associates and related vendors. It covers general expectations around business associate agreements, privacy and security safeguards, risk analysis, vendor vetting, cybersecurity awareness, and incident preparedness. The guidance is intended for healthcare practices, compliance staff, and managers who handle protected health information and want to understand the kinds of questions and checks that may be relevant before onboarding a vendor.

Why This Topic Matters

A business associate’s noncompliance can create liability and privacy risk for the covered entity that shares patient information. Understanding the scope of HIPAA-related due diligence helps practices reduce exposure and better evaluate vendor readiness.

Article Sections

  1. Understanding business associate responsibility

    Introduces the relationship between covered entities and business associates and explains why vendor access to protected health information requires attention to compliance obligations.

  2. Going beyond satisfactory assurance

    Discusses general expectations for obtaining assurance that a vendor will safeguard protected health information and references related HIPAA privacy and security considerations.

  3. Questions to ask potential business associates

    Presents a set of broad interview topics a practice may use to evaluate a vendor’s compliance posture, training, security practices, and preparedness.

  4. Resource and guidance reference

    Points readers to official guidance resources for additional background on business associate compliance under HIPAA.

What You Will Learn

  • How business associates fit into HIPAA compliance oversight
  • What broad areas to review when evaluating a vendor’s safeguards
  • Why risk analysis and documentation matter in vendor due diligence
  • What general topics to cover when interviewing a potential business associate
  • Where to find official guidance on business associate compliance

Who Should Read This

  • Surgeons
  • Physician practices
  • Compliance officers
  • Practice managers
  • Healthcare administrators
  • Coding and billing staff with HIPAA responsibilities

Subscribe or sign in to view the full article.

Keep pace with evolving Medicare regulations — and onboard your team — with timely analysis of critical updates interpreted in an easy-to-follow, easy-to-apply format. Your subscription to TCI's Medicare Compliance & Reimbursement Alert will equip you to navigate code and guideline changes, CCI edits, and revisions to modifiers, payer policies, the fee schedule, OIG target areas, and more.

  • Current newsletters added each month
  • Fully searchable archives - over 4200 articles
  • ALL years/issues back to 2003 organized by year and issue
  • Codes mentioned in articles are linked to Code Information pages
  • Code Information pages link back to related articles

This feature is currently unavailable for online purchase. For more information, please call 801-770-4203 or Contact Us.

Related Articles

Articles are listed in order of calculated relevance.

demo
request yours today
subscribe
start today
newsletter
free subscription

Thank you for choosing Find-A-Code, please Sign In to remove ads.

Aimee- AI -powered coding assistant - Try it now for Free Would you like Aimee - AI
to help you with this?