Lobbying Affiliate: MML&K Government Solutions
{ Banner Image }

Healthcare Law Blog

Comprehensive Healthcare law services.
It's kind of our bag.

Contact Us

250 Character(s) Remaining
Type the following characters: foxtrot, mike, three, papa

* Indicates a required field.

Categories

McBrayer Blogs

Related Blogs

Reminder: Update Your “Grandfathered” HIPAA Business Associate Agreements Now!

In January 2013, the Department of Health and Human Services (“HHS”) published its Final Rule, which significantly increased the privacy and security responsibilities for the “business associates” of “covered entities,” as those terms are defined by HIPAA. A provision within the Final Rule mandated that all covered entities and their business associates revise their business associate agreements to reflect the new responsibilities. Specifically, a business associate must now, among other things:

  • Report breaches of unsecured protected health information (“PHI”) to the covered entity;
  • Comply with the HIPAA Security Rule;
  • Execute business associate agreements with subcontractors (who are now considered business associates under the Final Rule).

Business associate agreements that were in compliance with the HIPAA Privacy Rule prior to January 25, 2013 were considered “grandfathered” and permitted to remain in place until September 23, 2014 – if they were not updated prior to the September date. This date, however, is almost expired and now all business associate agreements must be updated to include the additional requirements created by the Final Rule. Business associate agreements that were put into place after January 25, 2013 should already comply with the Final Rule.

It is important to note that the Final Rule also expanded the definition of a BA to cover new entities and persons. Now, a BA includes health information organizations, e-prescribing gateways, data transmission entities that routinely access PHI, and vendors of PHI records, in addition to subcontractors of business associates that create, receive, maintain, or transmit PHI on behalf of the business associate.

Calendar September 2014

If you have any questions regarding updating grandfathered business associate agreements, contact a McBrayer Health Care Law attorney today. The deadline is rapidly approaching – let us help you ensure that you are operating in accordance with the Final Rule provisions.

Services may be performed by others.

This article does not constitute legal advice.

Lexington, KYLouisville, KYFrankfort, KYFrankfort, KY: MML&K Government Solutions