
{"id":1762,"date":"2012-02-16T00:00:00","date_gmt":"2012-02-16T00:00:00","guid":{"rendered":"http:\/\/otava.test\/business-associates-must-be-hipaa-compliant-by-march-2012\/"},"modified":"2012-02-16T00:00:00","modified_gmt":"2012-02-16T00:00:00","slug":"business-associates-must-be-hipaa-compliant-by-march-2012","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/","title":{"rendered":"Business Associates Must Be HIPAA Compliant By March 2012"},"content":{"rendered":"<p>While the Department of Health and Human Services (HHS) shows that business associate-related HIPAA breaches were responsible for 62 percent of the total number of patient records breached (as seen in <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/business-associates-why-invest-in-a-hipaa-audit\/\">this blog post<\/a>), there has not been government legal action taken against business associates until recently.<\/p>\n<p>Minnesota\u2019s Attorney General is suing a business associate over an unencrypted data breach incident that occurred last year when a laptop containing 23,500 patient records was stolen from the business associate\u2019s car. Accretive Health is a licensed debt collector that also provides a patient analysis service for hospitals.<\/p>\n<p>Part of the reason why they were targeted may be linked to further complexity of the case \u2013 not only did Accretive Health suffer from a data breach, but the lawsuit claims they were also accessing and using patient data without the knowledge or consent of patients. One of their services provided the probability of a patient\u2019s hospital admittance and their calculated potential financial worth to the patient\u2019s healthcare provider, all based on perceived risk factors from their personal health information, according to the <a href=\"https:\/\/www.ag.state.mn.us\/PDF\/Consumer\/AccretiveHealth20120119.pdf\">claim<\/a> (PDF).<\/p>\n<p>Another major <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/hipaa-compliant-hosting\/resources\/what-is-a-hipaa-violation\">HIPAA violation<\/a> case involving a business associate was the Department of Defense\u2019s military healthcare program, in which nearly the <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/military-healthcare-contractor%E2%80%99s-hipaa-breach-followed-by-4-9-billion-lawsuit\/\">exact same incident<\/a> occurred \u2013 a contractor employee left an unencrypted laptop in their car and it was stolen. About 4.9 million patients were affected. A lawsuit was filed by a few of the affected patients, and in the claim, they indicated the need for all contractor employees to be properly trained in how to handle personal health information (PHI).<\/p>\n<p><strong>Modifications to HIPAA Applicability<\/strong><\/p>\n<p>Are business associates lax on HIPAA compliance because the law has no teeth? That\u2019ll change very soon \u2013 according to HealthCareInfoSecurity.com, <strong>March 2012<\/strong> is the target date to release a final version of the HIPAA modifications and breach notification rule (also known as the Omnibus rule, meaning <em>for all<\/em> in Latin). And in the proposed version of HIPAA modifications, business associates will be required to comply with the HIPAA standards, as seen in the change to the <strong><a href=\"https:\/\/www.hipaasurvivalguide.com\/hipaa-regulations\/164-104.php\">\u00a7164.104 Applicability<\/a> <\/strong>rule:<\/p>\n<blockquote><p>When a health care clearinghouse creates or receives protected health information as a business associate of another covered entity, or other than as a business associate of a covered entity, the clearinghouse must comply with <a href=\"https:\/\/www.hipaasurvivalguide.com\/hipaa-regulations\/164-105.php\">\u00a7164.105<\/a> relating to organizational requirements for covered entities, including the designation of health care components of a covered entity.<\/p><\/blockquote>\n<p><strong>Roadmap to Achieving Compliance<\/strong><\/p>\n<p>How can a business associate avoid a potential HIPAA violation, subsequent lawsuits and fines? Try the following:<\/p>\n<ul>\n<li><strong>Conduct and document an initial risk assessment\/analysis<\/strong> in order to check where your business is at when it comes to implementing HIPAA security safeguards, and where you need to fill in the gaps. This list of the <em><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/nine-elements-of-a-hipaa-risk-analysis\/\">Nine Components of a HIPAA Risk Analysis<\/a><\/em> provides a good high-level overview of what you need to include in your document.<\/li>\n<li><strong>Research and understand the HIPAA standards<\/strong>, and your role in handling PHI. As a <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">HIPAA compliant hosting<\/a> provider, Online Tech never accesses PHI or data on clients\u2019 servers, we only provide the secure infrastructure necessary to protect sensitive information in a fully compliant environment.<\/li>\n<li><strong>Draft a business associate agreement (BAA)<\/strong> that clearly defines your role and obligation in handling a client\u2019s sensitive data. Include clauses about contract termination, data ownership and breach notification. <em><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/what%E2%80%99s-in-a-business-associate-agreement\/\">What\u2019s in a Business Associate Agreement?<\/a> <\/em>provides a summary of the primary provisions to include in your BAA.<\/li>\n<li><strong>Ideally, invest in an independent HIPAA audit<\/strong> of your business in order to have the assurance and verification that your policies, procedures and services are in compliance. If you need guidance on which IT components can help you achieve compliance, read our <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/hipaa-compliant-hosting\/hipaa-faq#What services from Online Tech help make me compliant?\">HIPAA FAQ<\/a>.<\/li>\n<li><strong>Train all of your employees in HIPAA compliant policies and procedures<\/strong> as they affect the day-to-day operations of your company and according to the level of security needed by position \u2013 an employee that transports sensitive data will need more specific guidelines to stay compliant and prevent a data breach. Document proof of employee training and awareness.<\/li>\n<li><strong>Appoint a Risk Management and Security Officer <\/strong>position in your company to implement, manage and oversee compliance and ensure everyone is following the documented policies and procedures, preferably someone with a strong technical background.<\/li>\n<\/ul>\n<p>Or are you a covered entity that needs assurance their business associates are handling PHI in a HIPAA compliant manner? Read our E-Tip on the top <em><a href=\"https:\/\/otavawebsite.wpengine.com\/reference\/five-questions-to-ask-your-hipaa-hosting-provider\/\">Five Questions to Ask Your HIPAA Hosting Provider<\/a><\/em>.<\/p>\n<p>References:<br \/>\n<a href=\"https:\/\/www.healthcareinfosecurity.com\/articles.php?art_id=4508\">March Target for HIPAA Modifications<\/a><br \/>\n<a href=\"https:\/\/www.ag.state.mn.us\/PDF\/Consumer\/AccretiveHealth20120119.pdf\">State of Minnesota vs. Accretive Health, Inc. (PDF)<\/a><br \/>\n<a href=\"https:\/\/www.startribune.com\/local\/137678533.html\">Minnesota Sues Consulting Firm Over Lost Health Data<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>While the Department of Health and Human Services (HHS) shows that business associate-related HIPAA breaches were responsible for 62 percent of the total number of patient records breached (as seen in this blog post), there has not been government legal action taken against business associates until recently. Minnesota\u2019s Attorney General is suing a business associate over an unencrypted data breach incident that occurred last year when a laptop containing 23,500 patient records was stolen from the business associate\u2019s car. Accretive Health is a licensed debt collector that also provides a patient analysis service for hospitals. Part of the reason why they were targeted may be linked to further complexity of the case \u2013 not only did Accretive Health suffer from a data breach, but the lawsuit claims they were also accessing and using patient data without the knowledge or consent of patients. One of their services provided the probability of a patient\u2019s hospital admittance and their calculated potential financial worth to the patient\u2019s healthcare provider, all based on perceived risk factors from their personal health information, according to the claim (PDF). Another major HIPAA violation case involving a business associate was the Department of Defense\u2019s military healthcare program, in which&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-1762","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>Business Associates Must Be HIPAA Compliant By March 2012 | OTAVA<\/title>\n<meta name=\"description\" content=\"Business associates must be HIPAA compliat by March 2012. Here&#039;s the reason why and what your organization needs to know to be ready.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"Business Associates Must Be HIPAA Compliant By March 2012\" \/>\n<meta property=\"og:description\" content=\"Business associates must be HIPAA compliat by March 2012. Here&#039;s the reason why and what your organization needs to know to be ready.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2012-02-16T00:00:00+00:00\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"Business Associates Must Be HIPAA Compliant By March 2012\",\"datePublished\":\"2012-02-16T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\"},\"wordCount\":769,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\",\"url\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\",\"name\":\"Business Associates Must Be HIPAA Compliant By March 2012 | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"datePublished\":\"2012-02-16T00:00:00+00:00\",\"description\":\"Business associates must be HIPAA compliat by March 2012. Here's the reason why and what your organization needs to know to be ready.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"Business Associates Must Be HIPAA Compliant By March 2012\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"Business Associates Must Be HIPAA Compliant By March 2012 | OTAVA","description":"Business associates must be HIPAA compliat by March 2012. Here's the reason why and what your organization needs to know to be ready.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/","og_locale":"en_US","og_type":"article","og_title":"Business Associates Must Be HIPAA Compliant By March 2012","og_description":"Business associates must be HIPAA compliat by March 2012. Here's the reason why and what your organization needs to know to be ready.","og_url":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/","og_site_name":"OTAVA","article_published_time":"2012-02-16T00:00:00+00:00","author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"Business Associates Must Be HIPAA Compliant By March 2012","datePublished":"2012-02-16T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/"},"wordCount":769,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/","url":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/","name":"Business Associates Must Be HIPAA Compliant By March 2012 | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"datePublished":"2012-02-16T00:00:00+00:00","description":"Business associates must be HIPAA compliat by March 2012. Here's the reason why and what your organization needs to know to be ready.","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/business-associates-must-be-hipaa-compliant-by-march-2012\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"Business Associates Must Be HIPAA Compliant By March 2012"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/1762","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=1762"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/1762\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=1762"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=1762"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=1762"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=1762"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}