By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: HIMSS 13: HHS Final Ruling Changes the Rules & Roles for HIPAA Hosting
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > Policy & Law > Health Reform > HIMSS 13: HHS Final Ruling Changes the Rules & Roles for HIPAA Hosting
Health ReformHospital AdministrationPolicy & Law

HIMSS 13: HHS Final Ruling Changes the Rules & Roles for HIPAA Hosting

onlinetech
onlinetech
Share
7 Min Read
HIMSS 13 HHS Presentation
SHARE

At HIMSS 13, I attended a session, A Dialogue on HIPAA/HITECH Compliance: Considerations Now That the HITECH Rules Are Here, that revealed insights into real-world applications of the new privacy and security rules, including the practical implications of the final breach notification rule for HIPAA hosting providers, other business associates (BAs) and covered entities (CEs) alike.

At HIMSS 13, I attended a session, A Dialogue on HIPAA/HITECH Compliance: Considerations Now That the HITECH Rules Are Here, that revealed insights into real-world applications of the new privacy and security rules, including the practical implications of the final breach notification rule for HIPAA hosting providers, other business associates (BAs) and covered entities (CEs) alike.

HIMSS 13 HHS Presentation

View the HIMSS13 HHS Presentation (PDF)

The session was presented by Leon Rodridguez, the Director of Office for Civil Rights from the Depart. of Health and Human Services (HHS), the governing body of HIPAA (Health Insurance Portability and Accountability Act) that sets regulatory standards on the healthcare industry to ensure patient data security and privacy. James Wieland, Principal of Ober Kaler Grimes & Shriver Attorneys at Law also presented.

One of the biggest changes that affects HIPAA compliant software and SaaS (software as a service) companies is that their hosting providers are now considered business associates under HIPAA. That means colocation and cloud hosting services that house PHI (protected health information)  now fall under the purview of HIPAA and are subject to civil & criminal penalties of up to $1.5M. These penalties and fines apply whether or not the hosting provider knowingly has PHI on their servers or in their data center.

More Read

Can Anyone Explain This?
Iowa’s in the National News Right Now, and It’s for a Reason You Wouldn’t Expect
Hospital Competition: Will Retail Medical Clinics Change From Foe to Friend?
A Whole New Way To Look At Medicine And Healthcare Innovation
ePatients: What’s the Big Deal?

The final ruling also makes it clear that healthcare & HIPAA compliant service and software companies must sign a BAA (business associate agreement) with their hosting providers and that the HIPAA compliant service & software companies have ultimate accountability for their hosting provider meeting or not meeting HIPAA requirements.

What Changed?
Before the final ruling, some cloud providers claimed that they were simply “conduits” – only housing, but never accessing PHI on their servers. With the final ruling, HHS made it clear that conduits are considered BAs, subject to HIPAA compliance if they have “persistence of custody” of PHI.

In other words, if PHI data is stored in a data center, or on a cloud server, then the hosting provider is considered a business associate and must be able to demonstrate that they can meet the HIPAA administrative, physical and technical requirements to assure the confidentiality, integrity and availability of electronic PHI.

Leon Rodriguez, Director of HHS’s for Office for Civil Rights made it clear – cloud and colocation providers are BA’s and are subject to criminal & civil penalties if they are not compliant with the law.

What does this mean to CE’s and BA’s that host their PHI at a colocation data center or with a cloud hosting provider?

  1. They must sign a BAA with their hosting provider.
  2. They must assure that their hosting provider is HIPAA compliant.
  3. They must assure that their hosting provider has signed BAAs with their subcontractors.
  4. They continue to hold ultimate accountability under the law if their hosting provider is found to not be compliant – and subject to fines that can reach $1.5M per violation.
  5. The final ruling is effective starting March 26, 2013 and enforcement starts on September 23rd.

Any BAA signed with a provider prior to Jan. 25, 2012 with a hosting provider is grandfathered in and can stand through Sept. 23, 2014.  If you sign a BAA with your hosting or colocation provider after Jan 25th, 2013, your BAA must meet all of the new requirements of the Final Ruling.

Questions to ask your colocation/cloud providers if they are hosting your PHI:

  1. Will you sign a BAA?  Can I get a copy of your BAA for review?
  2. Does your BAA meet the requirements of the HHS final ruling?
  3. Have you signed BAAs with all of your subcontractors?
  4. Have your been audited against HIPAA administrative, physical and technical requirements for security?
  5. Did your audit follow the Office of Civil Rights Audit Protocol?
  6. Can I have a copy of your HIPAA audit report?

To protect yourself and your company from an Office of Civil Rights Audit or Enforcement Action, the answer to all of these questions should be “Yes.”

HIPAA Compliant Hosting White PaperFor more on secure hosting for HIPAA compliant solutions, read our HIPAA Compliant Hosting white paper. Questions to ask your HIPAA hosting provider, data center standards cheat sheet and a diagram of the technical, physical and administrative security components of a HIPAA hosting solution (including HIPAA compliant clouds) are included.

Related Articles:

HIPAA Hosting Provider BAAs Need to Reflect HHS Final HIPAA Privacy & Security Rules
Does your HIPAA hosting provider have a legal BAA (business associate agreement)? I just got off the phone with our attorneys who are updating our business associate agreement to reflect the changes required in the HHS final HIPAA Privacy and … Continue reading →

Final HIPAA Omnibus Rule: Business Associate Agreements & Roadmap to Compliance
In addition to redefining business associates (BAs) and including subcontractors in the scope of liability, the final HIPAA omnibus rule has prompted the release of a new sample business associate agreement by the Dept. of Health and Human Services (HHS). … Continue reading →

How the Final Omnibus Rule Affects HIPAA Cloud Computing Providers
The long-awaited final modifications to the HIPAA Privacy, Security, Enforcement and Breach Rules were introduced Thursday. The 563-word document outlines the changes that were initially slated for implementation last summer (remember the omnibus rule?). So how do these modifications affect … Continue reading →

The post HIMSS 13: HHS Final Ruling Changes the Rules & Roles for HIPAA Hosting appeared first on Managed Data Center News.

TAGGED:HIMSS 13HIPAA Privacy Rules
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

health and wellness
Redefining Self-Care: Health and Wellness Beyond the Trends 
Health Uncategorized
February 28, 2026
Understanding Leaky Gut Syndrome
Understanding Leaky Gut Syndrome
Health
February 25, 2026
Invisalign for Adults: Is It Too Late to Straighten Your Teeth?
Dental health Specialties
February 24, 2026
roads are important for health
How Everyday Roads Create Lasting Health Consequences 
Health
February 24, 2026

You Might also Like

ACO’s and CMS

July 2, 2011
Image
BusinessHealth ReformPolicy & LawPublic Health

Millions of Americans Could Lose ACA Subsidies

July 21, 2014

Six Ideas and Questions for GAVI’s New CEO

March 9, 2011
The ACA has put patients at the center of healthcare services. A patient-centric healthcare approach in this digital era means a revised definition of quality in the physician-patient relationship. When it comes to healthcare services, patients shell out a hefty amount from their pocket and want nothing less than the best. The services in healthcare are no longer limited to just cost as consumers now evaluate quality and experience in the same equation. Research highlights from the 2015 Healthcare Consumer Trends by National Research Corporation states that reputation in healthcare matters more to consumers when choosing a brand than any other industry, e.g. hospitality, retail, airline, etc. The new generation of quality measurements in healthcare require a different mind-set and a different 'toolbox' to handle the hurdles. It’s the need of the hour for healthcare providers and others across the healthcare value chain to adopt the patient-centric approach for surviving in the vast competitive ocean of healthcare services. Patient-centric care is an approach that develops through effective communication, empathy and a positive physician-patient relationship. The primary purpose is to improve patient care outcomes and satisfaction and to reduce patient symptoms and unnecessary costs. It’s a win-win situation for both physicians and patients. While healthcare providers are able to support their patients in becoming more compliant with treatment and management of their conditions/diseases, patients feel more satisfied with the care that they are receiving. PwC’s Health Research Institute’s annual report 2016 states that health systems should keep an eye on the consumer experience as they expand and extend. More partnerships and more caregivers could mean confusion for patients and poor customer experiences. To differentiate their practice among competitors, patient satisfaction can be used as a competitive distinguishing factor. Although patient satisfaction cannot really provide tangible benefits, but an experience that exceeds patient expectations for what a practice/hospital can provide is very important as it creates loyal patients who return for future health needs and refer their family and friends. Happy and satisfied patients are a secret marketing weapon for healthcare providers, whether they are physicians, dentists, physiotherapists or hospitals. Your patients are the new-age digital health decision-makers. In this era of Internet and social media, they now have multichannel access to information related to health. Needless to mention, they have gained new power to make their decisions; whether it’s choosing a healthcare provider or referring a physician to family and friends. By converting your satisfied patients to be your brand advocates, you can capitalize and use their voice as an effective marketing strategy to reach out to many other potential patients. To strive and thrive, in the U.S. many healthcare organizations are applying patient-centric approaches to healthcare. It’s all about what matters to patients, so it makes a lot of sense for the healthcare industry to place patients' healthcare experience at the center of their policies and procedures. The best deliverables are a combination of great communication for a positive physician-patient relationship, disciplined measurement and analysis of patient feedback and commitment to technology innovation – the formula for improving patient engagement and care.
BusinessHealth ReformWellness

The Link Between Patient Satisfaction and Long-Lasting Relationships

April 28, 2016
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?