Business associate misusing PHI
Compliance Monitor, September 22, 2006
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Q: What should we do if a business associate (BA) misuses our PHI?
A: If you know the BA has violated its contract, you must take reasonable steps to mitigate the breach or end the violation. If such steps are unsuccessful, you must terminate the contract. If you cannot terminate the contract, you must report the problem to HHS.
The HHS commentary notes that "knowing" that a BA has violated its contract means you have substantial and credible evidence of a violation. HHS also notes that although this standard relieves you of the need to actively monitor BAs, you must nonetheless investigate complaints or other evidence of violations by a BA.
For more information see Section 164.504(e) Business Associate Contracts and Section 164.530(f) Mitigation of the privacy rule.
Editor's note: Attorneys from Bricker & Eckler, LLP, answered this question. This is not legal advice. Consult with your attorney for legal matters. This question and answer originally ran in HIPAA Weekly Advisor.
Want to receive articles like this one in your inbox? Subscribe to Compliance Monitor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Identify potential Medicaid RAC target areas
- HIPAA Q&A: Level of encryption needed for email
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- What does case-mix index mean to you?
- OB services: Coding inside and outside of the package
- QA:Coding multiple initial infusions
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- CMS has reformulated payments for some bilateral procedures
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- What does case-mix index mean to you?
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- Do not code 57288 with 52000
- Searched
