Health Information Management

Q: Are we in violation of HIPAA if we contract with the company that manages our clinical research database, which stores de-identified data, to host our electronic medical record?

HIPAA Weekly Advisor, April 7, 2008

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

A: No. You should consider the company a business associate.

This status requires it to implement appropriate privacy and security policies, procedures, and practices to meet minimum necessary standards.

Requiring the company to provide documentation that demonstrates the following is advisable:

  • That it will protect data
  • That only authorized members of its work force with a defined need will access data
  • That appropriate audit logs exist to track access to data is advisable.

      Requiring the company to provide documentation regarding its audit program to reasonably ensure that it periodically reviews audit logs also is recommended. Further, if you suspect inappropriate access to data, you must consider investigating the situation.

      Editor's note: Chris Apgar, president of Portland, OR-based Apgar & Associates, LLC, answered this question. This is not legal advice. Consult your attorney for legal matters.



    • Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

      Comments

      0 comments on “Q: Are we in violation of HIPAA if we contract with the company that manages our clinical research database, which stores de-identified data, to host our electronic medical record?

       

      • Briefings on APCs

        Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

      • Medical Records Briefing

        Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

      • Briefings on Coding Compliance Strategies

        Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

      • Briefings on HIPAA

        How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

      • APCs Weekly Monitor

        This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

      Most Popular

      Related Articles