A guide to HIPAA and cloud computing
Cloud computing services offer cost-effective data storage and collaboration to healthcare organizations of various sizes. This helps these...
HIPAA defines cloud service providers as business associates when they handle patient data on behalf of covered entities or business associates.
The NIST defined cloud computing as, “Cloud computing is a model for enabling ubiquitous, convenient, on-demand network access to a shared
pool of configurable computing resources (e.g., networks, servers, storage, applications, and services)...”
CSPs are companies that offer networked computer system resources and services like data storage and computing power. The services are hosted in the cloud instead of local servers of personal devices. CSPs allow businesses and individuals to access powerful computing resources without the need for hefty capital investment in physical infrastructure.
CSPs offer services under models like Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), each serving different levels of management and customization based on user needs.
CSPs that manage electronic protected health information (ePHI) on behalf of covered entities are defined as business associates. According to the HHS, “...when a business associate subcontracts with a CSP to create, receive, maintain, or transmit ePHI on its behalf, the CSP subcontractor itself is a business associate.” This means that as a business associate responsible for creating, receiving, maintaining, or transmitting ePHI, they need to comply with the Privacy, Security, and Breach Notification rules to protect the data they handle.
Related: HIPAA Compliant Email: The Definitive Guide
An organization that provides healthcare services or pays for the cost of care and engages in certain electronic transactions covered under HIPAA.
A person or entity that performs certain functions or activities on behalf of covered entities.
A company hired by a business associate to help fulfill their duties and activities on of a covered entity.
Cloud computing services offer cost-effective data storage and collaboration to healthcare organizations of various sizes. This helps these...
Covered entities extend beyond healthcare, as non-healthcare industries are entrusted with sensitive personal information. These entities must...
According to a news story by HealthTech, “Healthcare is no stranger to managed service providers, as many health systems depend on temporary clinical...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.