{"id":558,"date":"2017-02-02T17:53:00","date_gmt":"2017-02-03T01:53:00","guid":{"rendered":"https:\/\/blog.sprucehealth.com\/?p=558"},"modified":"2023-10-26T06:14:23","modified_gmt":"2023-10-26T13:14:23","slug":"hipaa-compliance-baa-care","status":"publish","type":"post","link":"https:\/\/sprucehealth.com\/blog\/hipaa-compliance-baa-care\/","title":{"rendered":"HIPAA Compliance: What Is a BAA and Why Should I Care?"},"content":{"rendered":"<p>Even the simplest\u00a0medical practice is actually fairly complex, and because of this, almost no healthcare organization handles all of its activities internally. With needs ranging from coding to billing to EHR software provision, a typical medical practice will have necessary relationships with at least a few outside\u00a0companies. The federal government regulates interactions with such\u00a0&#8220;business associates&#8221; via HIPAA, and a crucial piece of this regulation is found in the &#8220;business associate agreements&#8221; (BAAs) that the law mandates.<\/p>\n<p>For this piece, we&#8217;re also excited to welcome Dr. Carlene MacMillan of <a href=\"http:\/\/www.brooklynminds.com\/\">Brooklyn Minds<\/a> as an expert reviewer and commenter. Practicing in psychiatry, one of the most privacy-sensitive fields of medicine, Dr. MacMillan has developed a uniquely deep understanding of the crucial role that BAAs play in modern healthcare, and we&#8217;ll feature her tips and insights throughout the\u00a0article.<\/p>\n<p>At heart, the BAA requirement under HIPAA is simple for care providers: <strong>every\u00a0<span style=\"text-decoration: underline;\">covered entity<\/span> must have a\u00a0<span style=\"text-decoration: underline;\">written agreement<\/span> with\u00a0each of its <span style=\"text-decoration: underline;\">business associates<\/span>, or else it is not\u00a0compliant with HIPAA\u00a0regulations.<sup>1,2<\/sup><\/strong><\/p>\n<p>That summation is succinct, but it likely raises a few\u00a0big questions for you:<\/p>\n<ol>\n<li>Am I a covered entity?<\/li>\n<li>Who are my business associates?<\/li>\n<li>What things have to be in\u00a0a business associate agreement?<\/li>\n<li>Why should I care about any of this?<\/li>\n<\/ol>\n<p>So let&#8217;s answer those!<\/p>\n<h1>Am I a Covered Entity?<\/h1>\n<p><strong>If you are providing\u00a0healthcare in the United States, you are most likely considered\u00a0a &#8220;covered entity&#8221; under\u00a0HIPAA, which means that you must\u00a0abide by all of its regulations.<\/strong><\/p>\n<p>[perfectpullquote align=&#8221;right&#8221; cite=&#8221;&#8221; link=&#8221;&#8221; color=&#8221;&#8221; class=&#8221;&#8221; size=&#8221;&#8221;]&#8221;There are many apps out there that offer high-level encryption for text and video, but all that is useless to me if the company will not sign a BAA.&#8221; &#8211; Dr. MacMillan[\/perfectpullquote]<\/p>\n<p>The exact definition of a covered entity is slightly more nuanced, though, and if you want to dig deeper on this, we\u00a0covered the\u00a0topic more thoroughly in a\u00a0<a href=\"https:\/\/sprucehealth.com\/blog\/hipaa-compliance-apply-to-me\/\">previous article<\/a>. The government also provides <a href=\"https:\/\/www.cms.gov\/Regulations-and-Guidance\/Administrative-Simplification\/HIPAA-ACA\/AreYouaCoveredEntity.html\">useful information<\/a>, including a <a href=\"https:\/\/www.cms.gov\/Regulations-and-Guidance\/Administrative-Simplification\/HIPAA-ACA\/Downloads\/CoveredEntitiesChart20160617.pdf\">flowchart<\/a>\u00a0to help you determine your status.<\/p>\n<p>Again, though, if you&#8217;re providing healthcare in America, you are safest assuming that you are a covered entity and that you must follow HIPAA.<\/p>\n<h1>Who Are My Business Associates?<\/h1>\n<p><strong>The short answer is that a &#8220;business associate&#8221; under HIPAA is any<\/strong><strong>\u00a0outside person or company that interacts with\u00a0your organization&#8217;s protected health information (PHI).<sup><span style=\"font-size: 13.3333px;\">3<\/span><\/sup><\/strong><\/p>\n<p>As always, the long answer is longer, but it does not change the overall correctness\u00a0of this rule of thumb for the majority of cases. Notably, the actual language\u00a0of HIPAA imparts business associate status on any entity that\u00a0&#8220;creates, receives, maintains, or transmits protected health information&#8221; on behalf of a covered entity. That set of verbs ensures that basically anybody outside of your organization counts as your business associate if they touch your PHI in any way.<\/p>\n<p>[perfectpullquote align=&#8221;left&#8221; cite=&#8221;&#8221; link=&#8221;&#8221; color=&#8221;&#8221; class=&#8221;&#8221; size=&#8221;&#8221;]&#8221;As an outpatient child and adolescent psychiatrist in private practice, being able to text with patients and use video chat are two aspects of my practice that are directly impacted by the need for a BAA. I do not want patients and families texting me on my personal cell, so looking for a service that would allow that and also sign a BAA was challenging.&#8221; &#8211; Dr.\u00a0MacMillan[\/perfectpullquote]<\/p>\n<p>The government also provides\u00a0<a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/privacy\/guidance\/business-associates\/index.html?language=es\">summary guidance<\/a>\u00a0on\u00a0the topic of HIPAA business associates, which gives more exact detail, should you want it. And if you&#8217;re wondering whether\u00a0the phone company or\u00a0postal service might count as your business associate because you use it\u00a0to\u00a0&#8220;transmit&#8221; PHI, don&#8217;t worry:\u00a0HIPAA prevents this with\u00a0the &#8220;conduit exception,&#8221; which we covered in a <a href=\"https:\/\/sprucehealth.com\/blog\/phone-lines-faxes-hipaa-oh-my\/\">previous discussion<\/a>. This exclusion\u00a0only applies to certain types of transmission, however, so\u00a0the\u00a0phone company does\u00a0indeed\u00a0become\u00a0your business associate if you use it for other purposes, such as\u00a0storing voicemail.<\/p>\n<p>One final important note: if a business associate has its own downstream business associate (a &#8220;subcontractor&#8221;), then the two\u00a0organizations must also have a HIPAA-compliant written contract in place between each other. There has to\u00a0be an intact chain of agreements stretching from the covered entity through to all organizations that touch its PHI. The covered entity itself does not need BAAs with subcontractors, but its business associates must have them.<\/p>\n<h1>What Things Have to Be in a BAA?<\/h1>\n<p><strong>HIPAA mandates\u00a0that every BAA contain certain basic\u00a0elements, and it enumerates these in a good amount of detail.<sup>4,5<\/sup><\/strong>\u00a0The major focus\u00a0of the requirements is to make it explicit that a\u00a0business associate is just as beholden to HIPAA as is a\u00a0covered entity, and the totality of the\u00a0requirements functions as\u00a0a blueprint that essentially every BAA should follow.<\/p>\n<p>[perfectpullquote align=&#8221;right&#8221; cite=&#8221;&#8221; link=&#8221;&#8221; color=&#8221;&#8221; class=&#8221;&#8221; size=&#8221;&#8221;]&#8221;It is also important to check if all the features of a company you work with are covered by the BAA. For example, the program we use in our practice for email and cloud storage has a BAA covering those aspects but not their VoIP phone service so we use a separate service for phone\/video\/texting.&#8221; &#8211; Dr. MacMillan[\/perfectpullquote]<\/p>\n<p><span style=\"font-weight: 400;\">Helpfully, the\u00a0government provides<\/span><span style=\"font-weight: 400;\">\u00a0<a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/covered-entities\/sample-business-associate-agreement-provisions\/index.html\">sample BAA language<\/a>\u00a0that\u00a0implements these stipulations, which can be used to construct\u00a0a new BAA or to compare against an existing agreement\u00a0that you are being offered. While BAAs do not have\u00a0to use the exact government language, they should all\u00a0be conceptually similar and have\u00a0mostly the same pieces.<\/span><\/p>\n<p>BAAs may also contain contractual provisions that HIPAA does not require. You should review any BAA carefully before signing it to make sure that it protects you and your organization adequately and that it does not place any undue demands on you or cause you to forfeit any important rights. BAAs are legal documents, and as such, a lawyer may be useful (or vital) in your review of them.<\/p>\n<h1>Why Should I Care?<\/h1>\n<p><strong>The <a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/enforcement-process\/index.html\">federal government<\/a> has the latitude to impose both civil monetary fines and criminal punishments upon individuals and organizations\u00a0that\u00a0violate HIPAA.<\/strong> Under the current\u00a0omnibus HIPAA rules, each violation can incur a penalty of up to $50,000, with repeat violations of the same provision costing as much as\u00a0$1.5 million per year.<\/p>\n<p>These potential sums\u00a0are not just theoretical. In a recent case, the government imposed a <a href=\"http:\/\/www.beckershospitalreview.com\/healthcare-information-technology\/care-new-england-400k-hipaa-settlement-highlights-importance-of-updated-business-associate-agreements.html\">$400,000 fine<\/a> on a healthcare organization that could have avoided the punishment by having an adequate BAA in place.\u00a0The modern healthcare regulatory environment clearly demands that physicians and other providers pay careful attention to HIPAA and its attendant BAAs or else be ready to pay out for the consequences.<\/p>\n<hr \/>\n<p>Up-to-date and complete business associate agreements are vital to every healthcare organization&#8217;s HIPAA compliance plan. If a company will not sign an appropriate BAA with your organization, then you should not trust them with your patients&#8217; PHI. It&#8217;s that simple and also that important.<\/p>\n<p><em>This article is part of a series of posts relating to HIPAA law and regulation. The information provided is\u00a0meant as general guidance only and is not intended to be legal advice.<\/em><\/p>\n<hr \/>\n<table class=\" alignleft\" style=\"background-color: #dff5fa;\">\n<tbody>\n<tr style=\"height: 256.5px;\">\n<td style=\"width: 641px; height: 256.5px; padding: 30px;\"><strong>Need a BAA for your patient voicemails and messages?<\/strong><\/p>\n<p>Join thousands of practices that are making communication\u00a0simple, reliable, and HIPAA-compliant on Spruce.<\/p>\n<p>Ready to learn more? Reach out to support@sprucehealth.com.<\/td>\n<\/tr>\n<\/tbody>\n<\/table>\n<p><strong>References:<\/strong><\/p>\n<ol>\n<li><a href=\"http:\/\/www.ecfr.gov\/cgi-bin\/text-idx?SID=938e08839465e82e2c30c3bd4a359ce2&amp;node=pt45.1.164&amp;rgn=div5%23se45.1.164_1402#se45.1.164_1308\">45 CFR \u00a7164.308(b)(3)<\/a><\/li>\n<li><a href=\"http:\/\/www.ecfr.gov\/cgi-bin\/text-idx?SID=938e08839465e82e2c30c3bd4a359ce2&amp;node=pt45.1.164&amp;rgn=div5%23se45.1.164_1402#se45.1.164_1502\">45 CFR \u00a7164.502(e)(2)<\/a><\/li>\n<li><a href=\"http:\/\/www.ecfr.gov\/cgi-bin\/retrieveECFR?gp=1&amp;n=se45.1.160_1103&amp;r=SECTION&amp;ty=HTML\">45 CFR \u00a7160.103<\/a>, definition for &#8220;business associate&#8221;<\/li>\n<li><a href=\"http:\/\/www.ecfr.gov\/cgi-bin\/text-idx?SID=815296c05127750fdc4675a322fe31fe&amp;mc=true&amp;node=se45.1.164_1504&amp;rgn=div8\">45 CFR \u00a7164.504(e)<\/a><\/li>\n<li><a href=\"http:\/\/www.ecfr.gov\/cgi-bin\/retrieveECFR?gp=&amp;SID=815296c05127750fdc4675a322fe31fe&amp;mc=true&amp;n=pt45.1.164&amp;r=PART&amp;ty=HTML#se45.1.164_1314\">45 CFR \u00a7164.314(a)<\/a><\/li>\n<\/ol>\n","protected":false},"excerpt":{"rendered":"<p>Even the simplest\u00a0medical practice is actually fairly complex, and because of this, almost no healthcare organization handles all of its activities internally. With needs ranging from coding to billing to EHR software provision, a typical medical practice will have necessary relationships with at least a few outside\u00a0companies. The federal government regulates interactions with such\u00a0&#8220;business associates&#8221; via HIPAA, and a crucial piece of this regulation is found in the &#8220;business associate agreements&#8221; (BAAs) that the law mandates.<\/p>\n","protected":false},"author":1,"featured_media":572,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"slim_seo":{"title":"HIPAA Compliance: What Is a BAA and Why Should I Care? - Spruce Blog","description":"Even the simplest\u00a0medical practice is actually fairly complex, and because of this, almost no healthcare organization handles all of its activities internally."},"footnotes":""},"categories":[18,14],"tags":[25,15,5],"different-template":[],"class_list":["post-558","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-expert-interviews","category-hipaa","tag-featured","tag-hipaa","tag-telehealth"],"acf":[],"_links":{"self":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/558","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/comments?post=558"}],"version-history":[{"count":0,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/posts\/558\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media\/572"}],"wp:attachment":[{"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/media?parent=558"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/categories?post=558"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/tags?post=558"},{"taxonomy":"different-template","embeddable":true,"href":"https:\/\/sprucehealth.com\/blog\/wp-json\/wp\/v2\/different-template?post=558"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}