By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works Collective
  • Health
    • Mental Health
    Health
    Healthcare organizations are operating on slimmer profit margins than ever. One report in August showed that they are even lower than the beginning of the…
    Show More
    Top News
    An Expert’s Guide To Building and Improving Endurance
    June 30, 2022
    medical assistants
    What Do Medical Assistants Do On a Day to Day Basis?
    April 5, 2022
    superfoods to help with prostate health
    10 Healthy Foods That Can Help Protect Your Prostate
    August 29, 2022
    Latest News
    3 Ways To Deal With Health Issues In Cities With High Pollution
    March 22, 2023
    What Tools Should Your Caregiver Have?
    March 22, 2023
    How to Combat Home Sickness After Moving Abroad
    March 19, 2023
    4 Ways to Recover from a Broken Hip
    March 14, 2023
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
    Policy and Law
    Get the latest updates about Insurance policies and Laws in the Healthcare industry for different geographical locations.
    Show More
    Top News
    Missouri Argues Against Constitutionality of Reform Law
    September 13, 2017
    What Would You Give Up?
    May 6, 2011
    You Probably Thought the Public Option Was Dead
    June 1, 2011
    Latest News
    3 Ways to Improve the U.S. Healthcare System By 2030
    March 14, 2023
    6 Steps To Ensure Speed And Efficiency Of Clinical Studies
    March 14, 2023
    5 Most Valuable Healthcare Programs in 2023
    March 8, 2023
    The Everest Foundation’s Mission to Support Inclusive Healthcare
    February 24, 2023
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: How the Final Omnibus Rule Affects HIPAA Cloud Computing Providers
Share
Sign In
Notification Show More
Latest News
health issues for office workers
Biggest Health Issues Office Workers Need to Content With
News
pollution impact on health
3 Ways To Deal With Health Issues In Cities With High Pollution
Health
caregiver importance
What Tools Should Your Caregiver Have?
Medicare
boost body energy level
The Best Natural Ways to Boost Your Body Energy & Focus
Wellness
virtual reality in optometry
What Are the Implications of Virtual Reality in Optometry?
Technology
Aa
Health Works CollectiveHealth Works Collective
Aa
Search
Have an existing account? Sign In
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > How the Final Omnibus Rule Affects HIPAA Cloud Computing Providers
eHealth

How the Final Omnibus Rule Affects HIPAA Cloud Computing Providers

onlinetech
Last updated: 2013/01/19 at 5:57 AM
onlinetech
Share
5 Min Read
SHARE

The long-awaited final modifications to the HIPAA Privacy, Security, Enforcement and Breach Rules were introduced Thursday. The 563-word document outlines the changes that were initially slated for implementation last summer (remember the omnibus rule?). So how do these modifications affect HIPAA cloud providers?

The long-awaited final modifications to the HIPAA Privacy, Security, Enforcement and Breach Rules were introduced Thursday. The 563-word document outlines the changes that were initially slated for implementation last summer (remember the omnibus rule?). So how do these modifications affect HIPAA cloud providers?

While cloud providers have generally been considered and treated as business associates in the industry, the modifications make it even clearer that data center operators are officially considered business associates and are also directly liable for being compliant with the HIPAA standards that apply to business associates. The federal document states:

A data storage company that has access to protected health information (whether digital or hard copy) qualifies as a business associate, even if the entity does not view the information or only does so on a random or infrequent basis. Thus, document storage companies maintaining 26 protected health information on behalf of covered entities are considered business associates, regardless of whether they actually view the information they hold.  To help clarify this point, we have modified the definition of “business associate” to generally provide that a business associate includes a person who “creates, receives, maintains, or transmits” (emphasis added) protected health information on behalf of a covered entity.

More Read

social media addiction is harming teenage mental health

5 Ways Social Media Affects Teen Mental Health

6 Innovative Technologies Making Medical Diagnostics More Predictive
A Guide to Medical Billing Services for Small Practices
How to Use E-Cigarettes to Stop Smoking
Healthcare Blogging: How to Become a Trusted Medical Source

As I wrote about in Healthcare Organizations: Seeking a Cloud Provider? BAAs Required, healthcare organizations need to be cautious about signing with ‘HIPAA-ready’ or ‘HIPAA certified’ cloud hosting providers. Being ‘HIPAA compliant’ or ‘HIPAA audited’ means they have undergone an independent audit, preferably measured against the latest OCR HIPAA Audit Protocol that outlines each requirement and auditor testing criteria.

If you use a cloud service, it should be your business associate. If they refuse to sign a business associate agreement, don’t use the cloud service. – David S. Holtzman of the Health Information Privacy Division of OCR during a speech at the Health Care Compliance Association’s 16th Annual Compliance Institute.

Another point they make is that business associates must also adhere to the Breach Notification Rule – including the subcontractors of business associates. For an example of what a breach notification clause might look like in a business associate agreement (BAA), read our BAA Breach Notification Clause.

Covered entities and business associates should take note – the document also states that “these proposed changes would make covered entities and business associates liable under § 160.402(c) for the acts of their business associate agents, in accordance 61 with the Federal common law of agency, regardless of whether the covered entity has a compliant business associate agreement in place.”

While business associates and agents are directly liable under HIPAA, covered entities are also directly held responsible for any actions of their business associates and other contractors down the chain of command; making a great case for why it’s important to carefully choose your HIPAA cloud hosting provider. Healthcare Software as a Service (SaaS) companies, EHR providers and other supporting healthcare vendors need to ensure their cloud Infrastructure as a Service (IaaS) providers undergo annual HIPAA audits, train their staff in security, and have the policies and procedures in place that adhere to security guidelines.

 

References:
HHS: Modifications to the HIPAA Privacy, Security, Enforcement and Breach Notification Rules (PDF)

The post How the Final Omnibus Rule Affects HIPAA Cloud Computing Providers appeared first on Managed Data Center News.

TAGGED: cloud computing, data security, HIPAA

Sign Up For Daily Newsletter

Be keep up! Get the latest breaking news delivered straight to your inbox.
By signing up, you agree to our Terms of Use and acknowledge the data practices in our Privacy Policy. You may unsubscribe at any time.
onlinetech January 19, 2013
Share this Article
Facebook Twitter Copy Link Print
Share
Previous Article eVisits: More Evidence That They Are a Good Idea
Next Article HIPAA Final Rule on Privacy, Security, Breach Notification and Enforcement Issued, Finally

Stay Connected

1.5k Followers Like
4.5k Followers Follow
2.8k Followers Pin
136k Subscribers Subscribe

Latest News

health issues for office workers
Biggest Health Issues Office Workers Need to Content With
News March 22, 2023
pollution impact on health
3 Ways To Deal With Health Issues In Cities With High Pollution
Health March 22, 2023
caregiver importance
What Tools Should Your Caregiver Have?
Medicare March 22, 2023
boost body energy level
The Best Natural Ways to Boost Your Body Energy & Focus
Wellness March 22, 2023

You Might also Like

healthcare video marketing
MarketingSocial Media

How to Maintain a Successful YouTube Channel as a Healthcare Organization: Advantages of Video Marketing for your Medical Practice

November 9, 2022
Health

How Does Cloud Computing Support Healthcare Organizations With Daily Functions

November 7, 2022
come up with a HIPAA compliance plan
Global HealthcarePolicy & Law

What Every Business Needs To Know About HIPAA Compliance

October 27, 2022
Electronic Health Records
BusinesseHealthHospital AdministrationMedical Records

Top Benefits of Electronic Health Records for Psychiatrists and Psychologists

August 15, 2022
//

We influence million of users and is the most authentic source of information on healthcare business and technology news.

Quick Links

  • About
  • Contact
  • Privacy
Subscribe

Subscribe to our newsletter to get our newest articles instantly!

Follow US

© 2008-2023 HealthWorks Collective. All Rights Reserved.

Removed from reading list

Undo
Welcome Back!

Sign in to your account

Lost your password?