How to Manage the HIPAA Business Associate Process

How to Manage the HIPAA Business Associate Process

If you are a healthcare organization that has vendors providing services as a HIPAA Business Associate, managing this process can be confusing. A “business associate” is a person or entity that performs certain functions or activities that involve the use or disclosure of protected health information on behalf of, or provides services to, a covered entity healthcare provider.

Having a systematic process to handle these business relationships to ensure a healthcare organization’s protected health information is being properly accessed and protected by the business associate is critical.

Organizations must know how to identify business associates. Business associate functions and activities include the use of tracking technologies, claims processing or administration; data analysis, processing or administration; utilization review; quality assurance; billing; benefit management; and practice management. Business associate services are legal; actuarial; accounting; consulting; data aggregation; management; administrative; accreditation; and financial.

Webinar Objectives

  • How to determine if a vendor is a HIPAA Business Associate.
  • How to assess a vendor in determining compliance with HIPAA requirements.
  • Understanding the Business Associate Agreement (BAA) process and making sure all government mandated requirements are in place.
  • I like this vendor, but…..
  • Focus on tracking technologies and third-party vendors.
  • What if a Business Associate causes a breach of your organization’s data.
  • Review case examples of HIPAA breaches.
  • What are the penalties and fines for non-compliance and how to avoid them?
  • Q&A

Webinar Highlights

  • Learn from an expert who has served as a HIPAA Compliance Officer in a large organization.
  • Learn how to manage the Business Associate process.
  • Learn how to develop and use a Vendor Security Questionnaire.
  • Learn how to audit your Business Associates.

Who Should Attend

  • Compliance Officer
  • HIPAA Privacy Officer
  • HIPAA Security Officer
  • Medical/Dental Office Managers
  • Practice Managers
  • Information Systems Manager
  • Chief Information Officer
  • General Counsel/lawyer
  • Practice Management Consultants
  • Any Business Associates that access protected health information

 

HIPAA Business Associate Compliance and Dangers

HIPAA Business Associate Compliance and Dangers

This webinar is for HIPAA Covered Entities (CEs) and Business Associates (BAs). Criminals increasingly focus cyber-attacks on BAs because one hit can give them access to PHI of all the BA’s customers. Growth of serious BA PHI breaches affecting tens of millions of patients put the spotlight on BA HIPAA compliance, attracting HHS Office for Civil Rights investigations and aggressive private class action lawsuits filed within days of a breach targeting BAs and their CE customers. CEs that did nothing wrong can still be held liable to pay the same civil money penalty as their BA for the BA’s HIPAA violation under the Federal Common Law of Agency which is included in the HIPAA Enforcement Rule.
Simple steps, often overlooked but easy to follow, enable CEs and BAs to protect against costs and damage to their reputations caused by violations of HIPAA Rules that apply to BAs. The chain of HIPAA compliance starts with a CE. It extends to a BA that provides a CE with services involving PHI. And the chain of compliance continues on down to any subcontractors of a BA that perform services involving PHI. BA subcontractors are defined by HIPAA as BAs and are fully liable for compliance.

  • CEs must obtain “satisfactory assurances” from each BA, documented in writing, that the BA complies with HIPAA before disclosing PHI to the BA or allowing the BA to create, receive, maintain or transmit PHI on their behalf.
  • BAs must obtain “satisfactory assurances” from each Subcontractor BA, documented in writing, that the Subcontractor BA complies with HIPAA before permitting the Subcontractor BA to perform services involving PHI.

This webinar explains the interconnected HIPAA compliance responsibilities and liabilities of CEs and BAs. HIPAA Rules that apply to both are easy to follow, step-by-step, when you know the steps.

HIPAA Rules that apply to CEs in dealing with BAs and that BAs must follow are discussed and explained including:

  • Serious Business Associate HIPAA Violations
    Brief review of current OCR BA Enforcement and Class Action lawsuits based on BA HIPAA violations
  • Explanation of how HIPAA Rules apply to BAs
    • Security, Privacy and Breach Notification Rules
  • Business Associate Agreements and the key Agency Issue – Don’t make your BA or Subcontractor BA your legal agent by mistake like many do
  • CE Due Diligence for BAs and BA Due Diligence for Subcontractor BAs
  • Who’s in Charge? – Responsibility & Authority – Responsibility of Senior Management and Owners – Delegation of Authority for development and implementation of a BA HIPAA compliance program

Why You Should Attend This Webinar

CEs can find themselves fully liable for HIPAA violations committed by BAs and BAs for violations committed by Subcontractors under the little known Federal Common Law of Agency. However, risks associated with BA HIPAA compliance can be managed calmly and confidently by following the HIPAA Rules that are easy to follow, step-by-step.
CEs should attend to see what to look for in Due Diligence, how to obtain HIPAA required satisfactory assurances that a BA is complying with HIPAA and avoid liability by inadvertently making a BA their agent.
BAs should attend this webinar to see exactly what they must do to comply with HIPAA Rules – Security, Privacy and Breach Notification Rules. And what to look for in Due Diligence and how to obtain HIPAA required satisfactory assurances that a Subcontractor BA is complying with HIPAA while avoiding liability by inadvertently making a Subcontractor BA their agent

Who Should Attend This Webinar

Covered Entities of all types who disclose PHI to BAs and allow BAs to create, receive, maintain and transmit PHI on their behalf
Business Associates of all types including for example:

  • Billing and Coding companies
  • Practice Management Companies
  • IT Vendors
  • Data Storage firms (electronic and paper)
  • Secure and unsecure providers of PHI email and text message services
  • Vendors of patient satisfaction surveys
  • PHI record retrieval and release of information vendors
  • Law and Accounting Firms
  • Health Plan Third Party Administrators
  • CE Owner – CEO – COO Compliance Manager
  • Board of Directors – for profit and non-profit CEs
  • Healthcare Practice Manager
  • Administrator, Long Term Care Facility
  • BA Owner – CEO – COO
  • Security and Privacy Officers
  • Compliance, Information Security and Risk Management Directors
  • Business Manager
  • Attorney – General Counsel, Associate General Counsel, Inside Compliance Attorney, Outside Health Law Attorney

Venue: Recorded Webinar

Enrollment option

Related Events

Excel: Practical Pivot Tables for Fast and Flexible Reporting
Compliance Webinars
Live Webinar

Excel: Practical Pivot Tables for Fast and Flexible Reporting

Pivot Tables are one of Excel’s most powerful and misunderstood tools but once you know how to use them, they can transform how you analyse and report on data. In just a few clicks, you can summarise thousands of rows into meaningful, dynamic reports - no formulas required. This session will show you how to quickly create and customise Pivot Tables to reveal trends, answer questions, and support better decision-making. You’ll also discover how to turn your Pivot Table into a visual dashboard using built-in charting tools, slicers, and layout options. If you've ever looked at a Pivot Table and thought, “I should really learn that”, this is your moment. Why you should attend Manually building summaries and reports from Excel data is time-consuming and error-prone. Pivot Tables eliminate the guesswork, automate the process, and give you instant insights. This session is perfect if you want to save time, reduce complexity, and finally get confident with one of Excel’s most powerful (but underused) features. Topics covered How to structure your source data for best results Creating Pivot Tables in just a few clicks Summarising data with totals, counts, and percentages Formatting your Pivot Table for clarity and impact Sorting and filtering with built-in tools and slicers Visualising data using Pivot Charts Understanding and using (or avoiding) GETPIVOTDATA Who should attend This session is for anyone who wants to level up their Excel skills and gain confidence with Pivot Tables. It’s ideal for professionals in admin, finance, HR, operations, or anyone who builds regular reports. You should be comfortable with basic Excel tasks like entering data, using copy/paste, and applying simple formatting. The training is delivered using Excel for Windows (Microsoft 365), but most techniques also apply to earlier versions and Excel for Mac.

Care of the LGBTQI + Patient and their Families:   Policies, Procedures, & Practices
Compliance Webinars
Live Webinar

Care of the LGBTQI + Patient and their Families: Policies, Procedures, & Practices

Whether your employer is a clinic, a hospital, home health, or long term care; whether you are an MD, RN, an occupational therapist, a receptionist, or in the C-Suite, approximately 5% - 10% of your patients may be gay, lesbian, or bisexual. Additional patients may be transgender, intersex, or questioning their gender identity or sexual orientation. The healthcare needs of GLBT patients may appear to be the same as other patients’, but institutionalized heterosexism in healthcare is a real barrier to quality care. Healthcare providers acknowledge they are serving more GLBT patients, and that they want to provide quality GLBT care, but aren’t sure how to best create and implement the policies, procedures, and practices to ensure best patient outcomes. GLBT patients face a multitude of barriers to equitable care such as: refusals of care, delayed or substandard care, mistreatment, inequitable policies and practices, end-of-life issues, and limits on visitation. The challenges begin from the beginning of the health professionals’ relationship with their GLBT patient—starting from asking them to identify if they are male or female, married or single, on their intake form. Objectives To list relevant laws, regulations and standards required for health equity and patient-centered care of GLBT patients To identify key policy, procedure and practice issues related to GLBT patients and their families to incorporate into already existing policies, procedures and practices To discuss opportunities to collect GLBT – relevant data and information during the healthcare encounter To identify or revise strategic community outreach efforts to the GLBT population To name a variety of resources Who should Attend? HR Management Nurses Other Health Professionals  

Effective Decision Making: A Critical Skill for Managers
Compliance Webinars
Live Webinar

Effective Decision Making: A Critical Skill for Managers

Everyone makes decisions, but of course some decisions are more important and complex than others. Whether it is a decision about what to wear to work to deciding on a merger, the decision making process is generally the same. Most decision making by management is convoluted with much fuzziness and backtracking. Research suggests that managers put little thought into the decision making process such as—analysis of the risk, what values are poignant, the alternatives evaluated, quantitative and qualitative data, identifying the stakeholders, bias, and the impact of the decision on the system, to name a few. Decision making is the basic foundation of the process of management. Yet most management training and development tactics ignore this essential skill. Learning Objectives To examine the “act of choice” To analyze roadblocks to effective decision making To discuss 10 decision making/problem solving tools To list the various models of decision making Analyze how managers make decisions Who should Attend? HR Management Any Employee

Engaging Your Team in Critical Thinking
Compliance Webinars
Live Webinar

Engaging Your Team in Critical Thinking

It is our nature to think—we all do it, obviously. However, a good share of our thinking is biased, distorted, or incomplete. Critical thinking is an essential skill for both managers and employees. Few of us are effective critical thinkers though research suggests that leaders believe they think quite well. Critical thinking ensures we pose the right questions, view others’ viewpoints with merit, and challenge assumptions in strategic thinking, decision making and problem solving. Non-critical thinkers shoot down ideas before they are understood, or take action based on faulty assumptions resulting in a business disaster. Teams, as well as individuals, must learn to think critically which requires a work atmosphere that is conducive to challenging others’ perspectives. Critical thinking enables teams to develop positive insights and ideas that lead to effective action. It focuses on reframing and rethinking issues so that the right problems are addressed, and requires challenging conventional wisdom. Using the process of critical thinking leads to reasoned conclusions, better decisions, fewer mistakes, and improves collaboration among team members. Learning Objectives Define critical thinking List characteristics of critical thinkers Examine the critical thinking process Explore the elements of reasoning Discuss critical thinking techniques Identify organizational, team, and individual critical thinking barriers Who should Attend? HR Management Any Employee