
{"id":2231,"date":"2013-01-21T00:00:00","date_gmt":"2013-01-21T00:00:00","guid":{"rendered":"http:\/\/otava.test\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/"},"modified":"2013-01-21T00:00:00","modified_gmt":"2013-01-21T00:00:00","slug":"hipaa-omnibus-rule-narrows-the-hipaa-hosting-market","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/","title":{"rendered":"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market"},"content":{"rendered":"<p>The final HIPAA omnibus rule released late last week holds business associates (BAs) and subcontractors (the BA of a business associate) directly liable for compliance with the HIPAA rules, and sets a deadline for compliance with the new modifications. There\u2019s some cushion time though &#8211; the final rule isn\u2019t officially effective until March 26, and even after the date, covered entities and business associates of all sizes will have 180 days to be in compliance. According to HealthDataManagement.com, covered entities will have one year from the compliance date to modify business associate agreements to match the new requirements.<\/p>\n<p>This may not be enough time for BAs and subcontractors to achieve compliance with the modified rules, especially for those that were never initially in compliance. However, this works two-fold to 1) weed out quality <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">HIPAA hosting<\/a> providers that focus on the healthcare compliance market from the rest; 2) increase the ease of covered entities in securing patient data and maintaining patient privacy by limiting the hosting provider market.<\/p>\n<p>Compliance is time-consuming and expensive, but the service providers that are willing and able to make that commitment will fare well in the healthcare market, especially since covered entities and BAs are now legally liable for the acts of their subcontractors and therefore monetarily motivated to have a vested interest in the security practices of their hosting providers.<\/p>\n<p>The Medical Group Management Association (MGMA) issued their own comments on the modifications &#8211; they\u2019ve voiced concerns over the short time frames alloted to get up to speed, as reported by HealthDataManagement.com:<\/p>\n<blockquote>\n<p dir=\"ltr\">We are strongly supportive of comprehensive privacy and security standards aimed at avoiding unauthorized use or disclosure of patient health information. However, it is critical that the safeguards mandated by the government be practical, flexible and affordable for the broad spectrum of medical practices.<\/p>\n<p dir=\"ltr\">We are concerned about the ability of practices to implement the changes associated with this final rule, including the requirement to modify and reissue notices of privacy practices and modify business associate agreements&#8211;within the short time frames allotted. We will continue to monitor our member practices to ensure that administrative burdens imposed by the government do not hinder the necessary flow of health information for patient treatment, payment and healthcare operations purposes.<\/p>\n<\/blockquote>\n<p>Considering the definition of a BA has expanded to include patient safety organizations, health information organizations, e-prescribing gateways, providers of data transmission services for protected health information to a covered entity, etc., the rule comes as a serious wake-up call to providers that haven\u2019t done their due diligence in the security arena. A compromise has to be made between the degree of federally ordered \u2018administrative burdens\u2019 and the need to tighten up patient data security.<\/p>\n<p>So how do you start the arduous process of establishing a culture of security in your organization? Conducting a HIPAA risk analysis is the first step toward implementing the <a href=\"https:\/\/www.onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#Security%20Rule\">HIPAA Security Rule<\/a> safeguards. The first mandatory component of the nine outlined by the HHS is the scope of the analysis; meaning any potential risks and vulnerabilities to the privacy, availability and integrity of ePHI. For a full list of the risk analysis components, read <a href=\"https:\/\/otavawebsite.wpengine.com\/reference\/whats-in-a-hipaa-risk-analysis\/\">What\u2019s in a HIPAA Risk Analysis?<\/a><\/p>\n<p>Other best practices include:<\/p>\n<ul>\n<li dir=\"ltr\">Document data management, security, training and notification plans.<\/li>\n<li dir=\"ltr\">Use a password policy for access.<\/li>\n<li dir=\"ltr\">Encrypt PHI, whether it is in a database or in files on a server. Although not required by HIPAA, it is strongly suggested and considered best practice to do so while stored in the database, and especially during transmission. More encryption considerations:<\/li>\n<li dir=\"ltr\">Always use SSL for web-based access of any sensitive data.<\/li>\n<li dir=\"ltr\">Encryption techniques and mechanisms of sensitive information should be known to only a select few.<\/li>\n<li dir=\"ltr\">Content such as images or scans should be encrypted and contain no personally identifying information.<\/li>\n<li dir=\"ltr\">Don\u2019t use public FTP \u2013 use an alternative method to move files.<\/li>\n<li dir=\"ltr\">Only use VPN access for remote access.<\/li>\n<li dir=\"ltr\">Use login retry protection in your application.<\/li>\n<li dir=\"ltr\">Document a <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/data-protection\/disaster-recovery-as-a-service\">disaster recovery<\/a> plan.<\/li>\n<li dir=\"ltr\">Save money and time by hosting with a company that already has a BAA in place \u2013 that way your auditor can review the document instead of conducting another audit on top of yours.<\/li>\n<\/ul>\n<p>As a BA for the healthcare industry, undergoing a HIPAA audit conducted by a third-party and using the new<a href=\"https:\/\/www.onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#OCRprotocol\"> OCR HIPAA Audit Protocol<\/a> criteria ensures you will be able to pass an audit conducted by the government. Read more about Online Tech&#8217;s <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">100% compliance<\/a> and our <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/technical-security\">technical<\/a>, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">physical<\/a> and <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">administrative security<\/a> we both use internally and provide as a service to our clients.<\/p>\n<p>If you\u2019re a covered entity\/healthcare organization, you might need to reassess your vendors now that the final omnibus rule dictates that covered entities are held liable for the actions of their BAs\/subcontractors. Read <a href=\"https:\/\/otavawebsite.wpengine.com\/reference\/five-questions-to-ask-your-hipaa-hosting-provider\/\">Five Questions to Ask Your HIPAA Hosting Provider<\/a> that will help ensure you can meet the HHS\u2019s deadline this spring.<\/p>\n<p>References:<br \/>\n<a href=\"https:\/\/www.healthdatamanagement.com\/news\/hipaa-privacy-security-breach-enforcement-final-rule-45524-1.html\">HHS Releases Final Omnibus HIPAA Rule<\/a><br \/>\n<a href=\"https:\/\/www.healthdatamanagement.com\/news\/hipaa-privacy-security-breach-enforcement-final-rule-45525-1.html\">MGMA Concerned About Compliance Period in HIPAA Rule<\/a><br \/>\n<a href=\"https:\/\/s3.amazonaws.com\/public-inspection.federalregister.gov\/2013-01073.pdf\">HHS: Modifications to the HIPAA Privacy, Security, Enforcement and Breach Notification Rules<\/a> (PDF)<\/p>\n","protected":false},"excerpt":{"rendered":"<p>The final HIPAA omnibus rule released late last week holds business associates (BAs) and subcontractors (the BA of a business associate) directly liable for compliance with the HIPAA rules, and sets a deadline for compliance with the new modifications. There\u2019s some cushion time though &#8211; the final rule isn\u2019t officially effective until March 26, and even after the date, covered entities and business associates of all sizes will have 180 days to be in compliance. According to HealthDataManagement.com, covered entities will have one year from the compliance date to modify business associate agreements to match the new requirements. This may not be enough time for BAs and subcontractors to achieve compliance with the modified rules, especially for those that were never initially in compliance. However, this works two-fold to 1) weed out quality HIPAA hosting providers that focus on the healthcare compliance market from the rest; 2) increase the ease of covered entities in securing patient data and maintaining patient privacy by limiting the hosting provider market. Compliance is time-consuming and expensive, but the service providers that are willing and able to make that commitment will fare well in the healthcare market, especially since covered entities and BAs are now&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-2231","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>HIPAA Omnibus Rule Narrows the HIPAA Hosting Market | OTAVA<\/title>\n<meta name=\"description\" content=\"The final HIPAA omnibus rule holds business associates (BAs) and subcontractors directly liable for compliance with the HIPAA rules.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market\" \/>\n<meta property=\"og:description\" content=\"The final HIPAA omnibus rule holds business associates (BAs) and subcontractors directly liable for compliance with the HIPAA rules.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2013-01-21T00:00:00+00:00\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market\",\"datePublished\":\"2013-01-21T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\"},\"wordCount\":851,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\",\"url\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\",\"name\":\"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"datePublished\":\"2013-01-21T00:00:00+00:00\",\"description\":\"The final HIPAA omnibus rule holds business associates (BAs) and subcontractors directly liable for compliance with the HIPAA rules.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market | OTAVA","description":"The final HIPAA omnibus rule holds business associates (BAs) and subcontractors directly liable for compliance with the HIPAA rules.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/","og_locale":"en_US","og_type":"article","og_title":"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market","og_description":"The final HIPAA omnibus rule holds business associates (BAs) and subcontractors directly liable for compliance with the HIPAA rules.","og_url":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/","og_site_name":"OTAVA","article_published_time":"2013-01-21T00:00:00+00:00","author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market","datePublished":"2013-01-21T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/"},"wordCount":851,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/","url":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/","name":"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"datePublished":"2013-01-21T00:00:00+00:00","description":"The final HIPAA omnibus rule holds business associates (BAs) and subcontractors directly liable for compliance with the HIPAA rules.","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/hipaa-omnibus-rule-narrows-the-hipaa-hosting-market\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"HIPAA Omnibus Rule Narrows the HIPAA Hosting Market"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2231","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=2231"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2231\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=2231"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=2231"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=2231"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=2231"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}