Medicare Compliance & Reimbursement - 2021 Issue 7
HIPAA: Vet Your BA’s HIPAA Harmony Before Hiring
Subscribe or sign in to view the full article.
Article Overview
This article discusses HIPAA compliance considerations for covered entities when evaluating business associates and related vendors. It covers general expectations around business associate agreements, privacy and security safeguards, risk analysis, vendor vetting, cybersecurity awareness, and incident preparedness. The guidance is intended for healthcare practices, compliance staff, and managers who handle protected health information and want to understand the kinds of questions and checks that may be relevant before onboarding a vendor.
Why This Topic Matters
A business associate’s noncompliance can create liability and privacy risk for the covered entity that shares patient information. Understanding the scope of HIPAA-related due diligence helps practices reduce exposure and better evaluate vendor readiness.
Article Sections
-
Understanding business associate responsibility
Introduces the relationship between covered entities and business associates and explains why vendor access to protected health information requires attention to compliance obligations.
-
Going beyond satisfactory assurance
Discusses general expectations for obtaining assurance that a vendor will safeguard protected health information and references related HIPAA privacy and security considerations.
-
Questions to ask potential business associates
Presents a set of broad interview topics a practice may use to evaluate a vendor’s compliance posture, training, security practices, and preparedness.
-
Resource and guidance reference
Points readers to official guidance resources for additional background on business associate compliance under HIPAA.
What You Will Learn
- How business associates fit into HIPAA compliance oversight
- What broad areas to review when evaluating a vendor’s safeguards
- Why risk analysis and documentation matter in vendor due diligence
- What general topics to cover when interviewing a potential business associate
- Where to find official guidance on business associate compliance
Who Should Read This
- Surgeons
- Physician practices
- Compliance officers
- Practice managers
- Healthcare administrators
- Coding and billing staff with HIPAA responsibilities
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com