HIPAA Q&A: You’ve got questions. We’ve got answers!
HIM-HIPAA Insider, April 28, 2014
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Submit your HIPAA questions to Editor Jaclyn Fitzgerald at jfitzgerald@hcpro.com and we will work with our experts to provide you with the information you need.
Q: If a business associate (BA) commits a breach, should they notify OCR or should we?
A: Covered entities (CE) are responsible for reporting breaches to OCR. You can delegate the reporting, but it needs to be in writing. If your BA fails to report the breach, OCR will call you and not the BA because it's your regulatory responsibility.
Also, the Breach Notification Rule requires BAs to report all breaches of unsecure PHI to CEs. CEs are responsible for completing a four-factor risk assessment to determine what needs to be reported. That can be delegated, too, but it still remains CEs' regulatory obligation.
Editor’s note: Chris Apgar, CISSP, president of Apgar & Associates, LLC, in Portland, Ore., answered this question for HCPro’ s Briefings on HIPAA newsletter.
Want to receive articles like this one in your inbox? Subscribe to HIM-HIPAA Insider!
Related Products
Most Popular
- Articles
-
- Math can be tricky: TJC corrects ABHR storage requirement
- Air control equals infection control
- Don't forget the three checks in medication administration
- Note similarities and differences between HCPCS, CPT® codes
- Five ways to safeguard your patients' valuables
- The consequences of an incomplete medical record
- Q&A: Primary, principal, and secondary diagnoses
- OB services: Coding inside and outside of the package
- Skills of effective case managers
- Practice the six rights of medication administration
- E-mailed
-
- Air control equals infection control
- OSHA HazCom updates include labeling, SDS requirements
- Plan of Care Supports Documentation of Homebound Status
- Note similarities and differences between HCPCS, CPT® codes
- Note from the instructor: CMS clarifies billing guidelines on proper billing for drugs in a single-dose or single-use vial, including billing for discarded drugs
- Neurological checks for head injuries
- Modifiers and medical necessity
- Follow these tips to properly report bladder catheter codes
- Five ways to safeguard your patients' valuables
- Differentiate between types of wound debridement
- Searched