(Part 1 of 4)
 
The last quarter of the year traditionally is reserved for reflection and making resolutions to implement improvements/changes in the new year. Unfortunately, most of us are too busy and rush head-long into the new year. In today’s healthcare business environment that can be a serious mistake. Taking the time needed for reflection and planning how to go forward is something every business in the healthcare industry (i.e., medical practices, clinics, laboratories, home equipment vendors, hospitals, nursing facilities, etc.) should consider doing during the first quarter of 2014. This is the first of four articles that highlight a total of 10 issues businesses in the healthcare industry should review at least annually
 
One of the most significant developments in the business of healthcare during the past year has been the final implementation of the provisions of HIPAA-HITECH. This article reviews three of the changes that are most likely to impact all healthcare businesses, both providers and their vendors.
 
1. Business Associate Compliance.
As of September 24, 2013 every Covered Entity (“CE”) and its Business Associates (“BA”) were supposed to have Business Associate Agreements (“BAA”). Under the provisions of HIPPA-HITECH, many of the duties and responsibilities of CEs now are imposed on BAs. In addition, both parties face civil and criminal liability if they fail to perform their HIPPA-HITECH requirements.
 
Covered Entities need to identify all of their BAs and make sure they have a current BAAs. Business Associates that subcontract with other vendors in order to perform some of their duties may need to have BAAs with those vendors too.
Many vendors who do business with CEs or BAs do not realize that they too fall within the ambit of HIPPA-HITECH and have these same obligations. For example, a vendor that leases photocopiers to a medical practice may have responsibilities under HIPPA-HITECH.
 
2. Mobile Devices and PHI.
Healthcare providers and their BAs have been quick to adopt mobile devices (laptop computers, tablets and smartphones) as part of their day-to-day business operations. Mobile devices have become an important aspect of the effort to make information readily available, ensure continuity of care and reduce the overall cost of care. However, protecting the privacy and security of the PHI placed in these device memories is a serious HIPAA-HITECH compliance concern.
 
There are numerous reported cases of lost or mobile devices that contained PHI, and the ensuing enforcement actions and lawsuits. There is a very reasonable expectation that these devices will include measures that protect the PHI stored in them. These measures may include limiting access via biometric recognition software, adopting access controls that require complex authentication codes, encrypting the PHI, and installing software that permits a remote party the ability to wipe the device’s memory.
 
The problem becomes more acute when employees and others who are authorized to have access to PHI store that information on their own devices, rather on devices owned and controlled by a Covered Entity. When individuals are permitted/ to "bring their own device" ("BYOD"), it becomes much more difficult for a CE or BA to insist that encryption or memory wiping software be installed. Nevertheless, HIPAA-HITECH does not make a distinction between devices that are supplied by a CE/BA, BYOD, or devices that are not mobile (for example, computer mainframes). All of these devices must include measures that ensure that the PHI stored in their memories does not become accessed by unauthorized parties.
 
3. Notice of Privacy Practices
Recently the HHS-OCR published a model Notice of Privacy Practices that CEs can consider adopting for their businesses. The model NPP may need to be revised to reflect the specific circumstances of the business; for example, if a medical practice provides PHI to a third party as part of a clinical study that will need to be disclosed. Revisiting the terms of its NPP should be part of every CE’s annual HIPAA-HITECH compliance review.
 
Complying with the provisions of HIPAA-HITECH can be a very counterintuitive and frustrating process. Failing to comply with all of HIPAA-HITECH’s requirements, however, can have serious consequences. Covered Entities and BAs should seek the assistance of legal counsel with expertise in this area of the law as well as other consultants who deal with patient privacy issues.