Stillwater Medical Center: another breach, another shutdown
Stillwater Medical Center, which operates in Oklahoma, is the latest healthcare provider to become a victim of a data breach. The health system...
DrChrono is a software platform and mobile application designed to provide healthcare providers with a single solution for electronic medical records and medical practice management.
DrChrono is designed for healthcare providers to create easy on-the-go access to various forms of patient data. They offer a range of features and functionalities that enhance the efficiency and convenience of medical practice management. These include:
As a software platform that handles sensitive PHI and provides services to healthcare providers, DrChrono is considered a business associate under HIPAA. A business associate is any entity that handles PHI on behalf of a covered entity, such as a healthcare provider.
To comply with HIPAA regulations, DrChrono recognizes the importance of securing patient privacy and security. As mentioned on its website, DrChrono explicitly states the need for covered entities to sign a business associate agreement (BAA) when using its services. The BAA is a legally binding contract that establishes the responsibilities and obligations of Drchrono as a business associate, ensuring that appropriate safeguards are in place to protect PHI.
By signing a BAA, the covered entity and DrChrono establish a mutual understanding of their HIPAA compliance obligations, including the requirements for safeguarding PHI, reporting breaches, and complying with HIPAA regulations.
Covered entities must carefully review and sign a BAA with any business associate, including Drchrono, to ensure HIPAA compliance and protect patient privacy and security when using their services.
Related: Business associate agreement provisions
DrChrono is HIPAA compliant. When considering the use of Drchrono or any other HIPAA compliant software, it's recommended that healthcare providers thoroughly review the security measures and capabilities of the platform, including data encryption, access controls, and compliance with industry standards like HIPAA, to ensure the protection of patient information.
Stillwater Medical Center, which operates in Oklahoma, is the latest healthcare provider to become a victim of a data breach. The health system...
According to the HHS HIPAA Basics for Providers, "HIPAA establishes standards to protect people's medical records and other protected health...
“The HIPAA Privacy Rule establishes national standards to protect individuals' medical records and other individually identifiable health information...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.