
This is quite interesting and potentially may raise more questions than answers. Let’s consider a couple of scenarios first:
- Business provides healthcare insurance as a self-insured company. This basically means that instead of buying a plan for its employees thru a broker or exchange the business has implemented a risk management plan where they become responsible for the financial risk for providing health care benefits to its employees.
- Business/school has a nurse or similar healthcare professional on site who handles minor on site accidents.
- Business conducts on site-drug testing.
- Business offers on site physicals to its employees.
- How many of the above businesses are considered Covered Entities under the Health Insurance Portability Act (HIPAA) and therefore must comply with this law?
- How many of the above businesses have Patient Health Information (PHI) in their possession?
- Will having access to PHI makes a business a Covered Entity?
- In case of a breach, will the actions required be the same for all of them?
- Provider. Health care professional or entity, regardless of size, which electronically transmits health information in connection with certain transactions such as claims, eligibility inquiries and other electronic transactions, is a covered entity.
- Health Plan. Individual and group plans that provide or pay the cost of medical care are covered entities.
- Health Care Clearinghouse. Entities that process information from another entity and changes the same into a format that the receiving entity can process.
- Business Associate. Person or entity that is not an employee of Covered Entity but that the same receives access to PHI from the Covered to perform a function or activity in behalf if such Covered Entity.
- Keep health information separated from regular personnel records;
- Encrypt all electronic information;
- Keep antivirus and firewalls up to date;
- Consider the implementation of a Security Management Plan;
- Consider cyber liability and legal liability products.
About Dr. Jose Delgado
Dr. Jose I. Delgado is the founder and CEO of Taino Consultants, a veteran-owned, 8(a) graduate healthcare IT consulting firm based in St. Augustine, Florida. With over 30 years of experience in healthcare compliance and government contracting, Dr. Delgado has helped organizations navigate HIPAA, MACRA/MIPS, and federal IT security requirements.
Need help with healthcare compliance?
Taino Consultants provides HIPAA compliance consulting, MACRA/MIPS compliance support, and healthcare IT modernization services for government and private healthcare organizations.
Schedule a consultation
