HIPAA breaches and cloud providers
I think we can all agree, cloud computing is here to stay. It's cheaper, more reliable and oftentimes more secure than maintaining your own server...
In 2023, 37.5% of all HIPAA breaches, whether resolved or still under investigation, involved a business associate. This statistic shows why the business associates handling protected health information (PHI) need to be HIPAA compliant. These organizations often handle the storage, transmission and disclosure in ways that need to be protected.
See also: How to know if you’re a business associate
Based on a passage from the HHS website: “Provide that the business associate will not use or further disclose the protected health information other than as permitted or required by the contract or as required by law; and Require the business associate to use appropriate safeguards to prevent a use or disclosure of the protected health information other than as provided for by the contract. Where a covered entity knows of a material breach or violation by the business associate of the contract or agreement, the covered entity is required to take reasonable steps to cure the breach or end the violation, and if such steps are unsuccessful, to terminate the contract or arrangement.”
The need for compliance comes from the frequent handling, processing, and transmitting of PHI by business associates on behalf of covered entities. These email systems incorporate security measures like TLS 1.2 and higher degrees of encryption, which secures emails from the point of sending to receipt, and access control measures that only allow authorized personnel to view the PHI.
They also provide detailed audit trails, which log every access and action taken on an email containing PHI, necessary for investigating breaches or proving compliance during audits. Email systems also often include mechanisms for secure email archiving, ensuring that PHI can be stored safely and retrieved as required by law, and obtaining electronic PHI (ePHI) consent forms.
See also: HIPAA compliance for email in 3 easy steps
Here are five methods for encrypting email:
A business associate is an individual or entity that performs certain functions or activities on behalf of healthcare organizations.
Health plans, healthcare clearinghouse, or a healthcare provider.
The National Institute of Standards and Technology (NIST).
I think we can all agree, cloud computing is here to stay. It's cheaper, more reliable and oftentimes more secure than maintaining your own server...
Microsoft 365 is a cloud-based productivity suite that provides tools for collaboration, communication, and document management.
Healthcare organizations routinely share information with vendors, contractors, consultants, and service providers to deliver high-quality patient...
Every Friday we bring you the most important news from Paubox. Our aim is to make you smarter, faster.