What Makes an AI Investment Worthwhile?
What separates a promising AI initiative from an expensive experiment? The answer often has less to do with technology and more to do with how...
Healthcare is predicted to be the most targeted industry for cyberattacks in 2017, according to the 2017 Data Breach Industry Forecast from Experian. “Electronic health records remain likely to be a top target for hackers,” Experian found. To further...
Healthcare is predicted to be the most targeted industry for cyberattacks in 2017, according to the 2017 Data Breach Industry Forecast from Experian. “Electronic health records remain likely to be a top target for hackers,” Experian found. To further heighten & complicate these risks, providers’ responsibilities for protecting personal health information (PHI) under the Health Insurance Portability and Accountability Act (HIPAA) extend to certain vendors, referred to as “business associates (BAs)” in the HIPAA regulations. Healthcare, behavioral health and other organizations that maintain and process PHI need to have sound controls, policies and procedures to protect patients’ PHI, and these controls, policies and procedures must also extend to all BAs who have access to PHI.

A business associate is any organization or person working in association with, or providing services to a covered entity (HIPAA-covered entities include health plans, clearinghouses, and health care providers in certain situations). Some of the most common BAs with access to PHI include: lawyers, accountants, outsourced billing providers, consultants, data/cloud storage vendors, contracted healthcare/ancillary service providers, translators/interpreters, IT vendors, and claims/coding consultants.
AAFCPAs advises covered entities to implement a robust HIPAA/PHI training and education program for all members of the workforce. We also advise providers to develop and institutionalize a Risk Management Program, including an ongoing risk assessment process. The risk management program & assessment for HIPAA covered entities should incorporate BAs and the extension of risk they pose for a healthcare organization.
One of the key themes within HIPAA is to limit the collection and transmission of PHI to the minimum necessary. Providers should implement policies and controls that anonymizes key PHI to limit what is available to BAs. This can be done through removing personal identifiers from reports provided to BAs, or by building parameters into electronic medical record (EMR) or other systems to limit identifiers or make them anonymous.
In many cases, PHI breaches occur in the transmission of data between healthcare organizations and their BAs. These transmissions typically occur at the beginning of an engagement with a BA, and at the conclusion of an engagement or project. AAFCPAs recommends that clients have a clear understanding of your BAs’ controls, processes and procedures and the risks they pose for the covered entity. Providers must have compensating controls to ensure vendors and BAs are properly securing and transmitting PHI.
Business associate agreements (BAAs) can be a critical tool for understanding & documenting these controls, processes and procedures, and ultimately in protecting PHI. BAAs are a contract between a HIPAA-covered entity and a HIPAA business associate, and they stipulate and document how the BA will use, disclose and reproduce PHI, safeguard PHI, and notify the covered entities in the event a breach of PHI occurs.
AAFCPAs reminds clients that the BAA document in and of itself does not eliminate your risk. These agreements serve as a guide in understanding risks and control activities, but formal risk assessments provide management with assurance that key business processes have control activities in place, and that they are achieving the organization’s objectives to protect PHI.
The ramifications of a PHI breach, including damage to a provider’s reputation as well as criminal and civil fines, are too significant to not have key preventative measures in place to mitigate the risks of breach or violation.
AAFCPAs advises clients in developing and institutionalizing risk management programs, including establishing ongoing risk assessment processes. In addition, our Business and IT Advisory practice helps clients better secure patient data by providing HIPAA Security Rule assessments, subservice provider controls assessments, IT security assessments, and data de-identification /Safe Harbor Rule.
If you have any questions, please contact your AAFCPAs’ partner, or Charlie Webb, CPA at 774.512.4046, cwebb@aafcpa.com.
What separates a promising AI initiative from an expensive experiment? The answer often has less to do with technology and more to do with how...
A proposed Treasury and IRS rule could place certain scholarship, admissions, and institutional policies under heightened scrutiny, creating potential implications for tax-exempt status, fundraising, governance,...
Trusted client relationships are built over time through sound judgment, technical excellence, and a commitment to understanding what matters most to each organization. AAFCPAs’ latest...