What Information Can Be Shared by a Covered Entity to a Business Associate

avril 13, 2022 Non classé 0

Question: We have a regular weekly cleaning service that comes to our office and their team may monitor patients in the waiting room or even accidentally see patient information on the desk or in the trash. Are you a business partner? Disclosure means the disclosure, transfer, provision of access or disclosure of information in any way outside the company that owns the information. General provision. The confidentiality rule requires that a registered entity receive satisfactory assurance from its trading partner that the business partner is adequately protecting the protected health information it receives or creates on behalf of the captured entity. Satisfactory assurances must be given in writing, whether in the form of a contract or other agreement between the targeted entity and the business partner. Transitional provisions for existing treaties. Covered entities (other than small health insurance companies) that entered into an existing contract (or other written agreement) with a business partner before 15 October 2002 may operate under that agreement for an additional year beyond the performance date of 14 April 2003, unless the contract is renewed or amended before 14 April. 2003. This transitional period applies only to written contracts or other written agreements. Verbal contracts or other agreements are not eligible during the transition period. Companies covered with qualified contracts can be admitted up to 14.

April 2004 or until the renewal or amendment of the agreement under these contracts with their counterparties, whichever comes first, whether or not the contract meets the applicable contractual requirements of the rule under 45 CFR 164.502(e) and 164,504(e). A data subject company must also comply with the data protection rule, e.B. only make authorized disclosures to the business partner and allow individuals to exercise their rights under the rule. See 45 CFR 164.532(d) and (e). A business partnership agreement can allow a business partner to use and specify the PSRs to which the relevant company itself is entitled under the HIPAA privacy rule. See 45 C.F.R. § 164.504(e). In addition, the data protection rule of a business partnership agreement allows a business partner (e.B. to authorize an HIO): (1) use and disclose PHI for the proper administration and administration of the business partner in accordance with 45 C.F.R.

§ 164.504 (e) (4); and (2) the provision of data aggregation services related to the health services of the relevant undertakings for which it has concluded agreements. In most cases, the permitted uses and disclosures set out in a business partnership agreement vary depending on the specific characteristics or services that the business partner is expected to provide to the captured company. Similarly, the business partnership agreement of a covered entity with an HIO depends on a number of factors, such as.B. the purpose of the electronic exchange of health information that the HIO is intended to manage, the specific functions or services that the HIO is intended to perform for the collected company, and any other legal obligations that an HIO may have in connection with the HIO. Answer: No. While affected companies may share protected health information with their subcontractors who meet the definition of “business partners” under the HIPAA privacy rule, this definition is limited to subcontractors who receive protected health information to perform or assist in performing certain health operations on behalf of the covered companies. Therefore, with a few exceptions, business partners cannot use protected health information for their own purposes. [T]he data protection rule expressly prohibits . Prevent healthcare providers from selling protected health information to third parties without permission for the third party`s own marketing activities. For example, a pharmacist without a patient license cannot sell a list of patients to a pharmaceutical company so that the pharmaceutical company can market its own products to the people on the list. .