HIPAA Topic:
Business Associates
1.
I have an existing contract with a business associate that will renew automatically before April 14, 2003. Does this automatic renewal mean I have to modify the contract by April 14, 2003, to make it compliant with the HIPAA Privacy Rule's business associate contract provisions or can I still take advantage of the transition period?
2.
Do physicians with hospital privileges have to enter into business associate contracts with the hospital?
3.
Has the Secretary exceeded the HIPAA statutory by requiring "business associates" to comply with the Privacy Rule, even if that requirement is through a contract?
4.
Are the following entities considered "business associates" under the HIPAA Privacy Rule: US Postal Service, United Parcel Service, delivery truck line employees and/or their management?
5.
If the only protected health information a business associate receives is a limited data set, does the HIPAA Privacy Rule require the covered entity to enter into both a business associate agreement and data use agreement with the business associate?
6.
Is a business associate contract required with organizations or persons where inadvertent contact with protected health information may result - such as in the case of janitorial services?
7.
When is a health care provider a business associate of another health care provider?
8.
Does the definition of "Business Associate" in 45 CFR section 160.103 apply to a network that links providers and payers (health plans) together in order to help facilitate certain health care transactions, but does not convert or otherwise touch the data that pass between payers (health plans) and providers?
9.
Do health care providers and other covered entities need to monitor their business associates?
10.
Is a health care provider or other covered entity going to be considered a business associate of a health plan or other payer?
11.
A patient calls their health care provider and receives the provider's answering service. The service records the patient's name, telephone number and symptoms and pages the health care provider. Does this answering service fall under the HIPAA regulations and are they a business associate?
12.
If a health care provider stores old medical records in an offsite location, does he need a Business Associate Contract with the storage company?
13.
Are health care providers required to have a Business Associate Contract with other health care providers in order to electronically send patient test results to their offices?
14.
Are health care providers required to have a Business Associate Contract when requesting slides and other materials from laboratories?
15.
What happens if a business associate refuses to sign a Business Associate Contract with a health care provider?
16.
Is a list of patients requiring special diets sent to a dietary contract service provider covered by HIPAA regulations?
17.
Are health care providers required to have a Business Associate Contract with other health care providers in order to send patient test results or protected health information to their offices?
18.
Is a Business Associate Contract required for an electrician to visit our offices?
19.
Is a Business Associate Contract required for a janitor to visit our offices?
20.
Is a Business Associate Contract required for the postman or mail couriers to visit our offices?
21.
Is a Business Associate Contract required for a plumber, gardner, carpenter, or heating or air conditioning technician to visit our offices?
22.
Is a Business Associate Contract required for a pharmaceutical rep to visit our offices?
23.
Is a Business Associate Contract required for a computer technician to visit our offices?
24.
Is a Business Associate Contract required for a window washer to visit our offices?
25.
Is a Business Associate Contract required for a pizza delivery person to visit our offices?
26.
The Privacy Rule requires that a health care provider obtain satisfactory assurances from its business associate that the business associate will appropriately safeguard the protected health information it receives or creates on behalf of the health care provider. Are there exceptions to the rule?
27.
What are some examples of business associates?
28.
What are some examples of business associate services?
29.
What are some examples of business associate activities and functions?
30.
I have heard a lot about "Chain of Trust Agreements" and "Trading Partner Agreements". What are they? And what is the difference between them and a "Business Associate Contract"?
31.
Does the HIPAA Privacy Rule require a business associate to provide individuals with access to their protected health information or an accounting of disclosures, or an opportunity to amend protected health information?
32.
Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?
33.
Are business associates required to restrict their uses and disclosures to the minimum necessary? May a covered entity reasonable rely on a request from a covered entity's business associate as the minimum necessary?
34.
I want to hire the intended recipient of a limited data set to also create the limited data set as my business associate. Can I combine the data and use agreement and Business Associate Contract?
35.
Under the HIPAA Privacy Rule, may a covered entity contract with a business associate to create a limited data set the same way it can use a business associate to create de-identified data?
36.
If the only protected health information a business associate receives is a limited data set, does the HIPAA Privacy Rule require the covered entity to enter into both a Business Associate Contract and data use agreement with the business associate?
37.
Has the Secretary exceeded the HIPAA statutory authority by requiring "satisfactory assurances" for disclosures to business associates?
38.
Is a reinsurer a business associate of a health plan?
39.
Are business associates required to restrict their uses and disclosures to the minimum necessary? May a covered entity reasonably rely on a request from a covered entity's business associate as the minimum necessary?
40.
Are accreditation organizations business associates of the covered entities they accredit?
41.
Would Business Associate Contracts in electronic form, with an electronic signature, satisfy the HIPAA Privacy Rule's Business Associate Contract requirements?
42.
Is a Business Associate Contract required for a covered entity to disclose protected health information to a researcher?
43.
I have an existing contract with a business associate that will renew automatically before April 14, 2003. Does this automatic renewal mean I have to modify the contract by April 14, 2003, to make it compliant with the HIPAA Privacy Rule's Business Associate Contract provisions or can I still take advantage of the transition period?
44.
Are covered entities that engage in joint activities under an organized health care arrangement (OHCA) required to have Business Associate Contract with each other?
45.
Is a covered entity liable for, or required to monitor, the actions of its business associates?
46.
Are business associates required to restrict their uses and disclosures to the minimum necessary? May covered entity reasonable rely on a request from a covered entity's business associate as the minimum necessary?
47.
May a covered entity share protected health information directly with another covered entity's business associate?
48.
Do physicians and other health care providers with hospital privileges have to enter into Business Associate Contracts with the hospital?
49.
Instead of entering into a contract, can business associates self-certify or be certified by a third party as compliant with the HIPAA Privacy Rule?
50.
I want to hire the intended recipient of a limited data set to also create the limited data set as my business associate. Can I combine the data and use agreement and Business Associate Contract?
51.
Is a health insurance issuer or HMO who provides health insurance or health coverage to a group health plan a business associate of the group health plan?
52.
Under the HIPAA Privacy Rule, may a covered entity contract with a business associate to create a limited data set the same way it can use a business associate to create de-identified data?
53.
Has the Secretary exceeded the HIPAA statutory by requiring "business associates" to comply with the Privacy Rule, even if that requirement is through a contract?
54.
Is a health care provider required to have Business Associate Contracts with a photocopy machine repairmen who provide repair services in a health care provider's office?
55.
Is a physician or other health care provider considered to be a business associate of a health plan or other payer?
56.
What are a covered entity's obligations under the HIPAA Privacy Rule with respect to protected health information held by a business associate during the contract transition period?
57.
If the only protected health information a business associate receives is a limited data set, does the HIPAA Privacy Rule require the covered entity to enter into both a Business Associate Contract and data use agreement with the business associate?
58.
Is a software vendor a business associate of a covered entity?
59.
When is a health care provider a business associate of another health care provider?
60.
Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?
61.
Is a Business Associate Contract required with organizations or persons where inadvertent contact with protected health information may result?
62.
Does the HIPAA Privacy Rule require a business associate to provide individuals with access to their protected health information or an accounting of disclosures, or an opportunity to amend protected health information?
63.
Is there a standard Business Associate Contract for health care providers or do health care providers need an attorney to make one?
64.
Can health care providers be held responsible when a business associate makes improper disclosures of protected health information?
65.
If a health care provider already has a contract with a billing service or clearing house that extends beyond the HIPAA compliance date of April 14, 2003, do they need to execute a new Business Associate Contract with the service now, or can they wait until it is up for renewal?
66.
Do health care providers need to have a Business Associate Contract with the hospital to which the provider admits patients?
67.
Are health care providers required to have a Business Associate Contract with other providers they consult with?
68.
Do health care providers need to have a Business Associate Contract with other providers in their practice?
69.
If a health care provider were to find that a person with whom he has a Business Associate Contract is non-compliant, who is responsible and who gets fined?
70.
What ia a "business associate"?
71.
Is a business associate relationship created every time protected health information is discussed with another health care provider?
72.
What is "data aggregation" and how does it apply to the activities of a business associate?
73.
Can health care providers disclose protected health information to business associates?
74.
If a health care provider believes that one of his business associates has misused his protected health information, what are his obligations?
75.
What does it mean to "know" of a pattern of activity or practice of the business associate that constitutes a material breach or violation of the contract?
76.
Can business associates be subject to the HIPAA penalties for violations of the contract or for misuse of a health care provider's protected health information?
77.
Are employees and staff of health care providers considered business associates?
78.
Must health care providers have Business Associate Contracts with affiliated organizations?
79.
Are collection agencies considered business associates?
80.
Are the JCAHO and other accrediting agencies considered business associates?
81.
Are health care providers required to have contracts with their business associates?
82.
What is required in the contracts between health care providers and their business associates?
83.
Where can health care providers get a sample of a business contract?
84.
How specific must health care providers be in the contract regarding permissible and impermissible uses and disclosures by the business associate?
85.
What are the assurances that must be included in the Business Associate Contract?
86.
What is required in the Business Associate Contract regarding termination of the contract?
87.
Is it necessary to have a separate contract with each of our business associates?
88.
What does HIPAA say about a health care provider that is also a government agency and their business associate is a government entity?
[
Back To Previous
Page] - [
Back To All HIPAA FAQ Topics]