Health Information Management

What are "affiliated covered entities"?

HIPAA Weekly Advisor, May 10, 2002

Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

Q: What are "affiliated covered entities"? Which group health plans are not required to designate a privacy contact person or office?

A: HIPAA allows legally separated covered entities to designate themselves as a single "affiliated covered entity," if all of the designated covered entities are under common ownership or control.

"Common control" exists if an entity has the power, directly or indirectly, to significantly influence or direct the actions or policies of another entity.

Common ownership exists if an entity or entities possess an ownership or equity interest of 5% or more in another entity.

Such organizations may use a single shared notice of information practices.

Q: Which group health plans are not required to designate a privacy contact person or office?

A: A group health plan that provides benefits solely through an issuer or health maintenance organization (HMO), and does not create, receive, or maintain individual protected health information other than regarding enrollment and disenrollment is exempt from the requirement of having a contact person or office.

The privacy rule requires each covered entity except these group health plans to designate a contact person or office who is responsible for receiving complaints about compliance with the regulations and provide further information about matters covered in the notice of privacy practices.

The contact person for complaints can but doesn't have to be the designated privacy official.

The covered entity should document the name and job description of the designated contact person.

Covered entities with multiple subsidiaries that meet the definition of covered entities have the flexibility to decide whether such subsidiaries are each separate covered entities or are together a single covered entity. If only one covered entity is designated, only one contact person is needed. There is nothing to prohibit the contact person for one covered entity from serving as the contact person for another covered entity.

Editor's note: Brought to you by attorneys Marty Baxter and Gretchen McBeath at Bricker and Eckler, LLP (http://www.bricker.com/hipaa) and The Quality Management Consulting Group, Ltd. (http://www.qmcg.com). E-mail: mbaxter@bricker.com or gmcbeath@bricker.com.



Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!

  • Briefings on APCs

    Worried about the complexities of the new rules under OPPS and APCs? Briefings on APCs helps you understand the new rules...

  • Medical Records Briefing

    Guiding Health Information Management professionals through the continuously changing field of medical records and toward a...

  • Briefings on Coding Compliance Strategies

    Submitting improper Medicare documentaion can lead to denial of fees, payback, fines, and increased diligence from payers...

  • Briefings on HIPAA

    How can you minimize the impact of HIPAA? Subscribe to Briefings on HIPAA, your health information management resource for...

  • APCs Weekly Monitor

    This HTML-based e-mail newsletter provides weekly tips and advice on the new ambulatory payment classifications regulations...

Most Popular

Related Articles