• Skip to main content
  • Skip to secondary menu
  • Skip to primary sidebar
  • Skip to secondary sidebar
  • Skip to footer

  • Opinion
  • Health IT
    • Behavioral Health
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Patient Engagement
    • Population Health Management
    • Revenue Cycle Management
    • Social Determinants of Health
  • Digital Health
    • AI
    • Blockchain
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • M&A
  • Value-based Care
    • Accountable Care (ACOs)
    • Medicare Advantage
  • Life Sciences
  • Research

Achieving HIPAA Compliance as a Business Associate

by Our Thought Leaders 01/06/2016 Leave a Comment

  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Key Lessons from Other Security and Privacy Standards

Business associates should be aware that data security and privacy are central to compliance beyond HIPAA, notably in SOC 1/2 reporting and PCI (payment card industry) standards. A closer inspection of specific requirements will reveal substantial overlap between standards. Companies can save significant time and money by tackling multiple standards at once, but proper execution is key. In diligence engagements, we have seen operators succeed to varying degrees.

On the low-performing end was an HCIT company that has been hugely successful in attracting and keeping hospital customers but was lacking in data security. Since their beginnings about a decade ago, they had grown to become the clear market leader, but at a price.

Despite the huge amount of data they were handling, they had not yet completed a risk assessment nor performed any penetration testing. In addition, they had recently acquired a company that had signed BA agreements with its client base. Yet, executives were unaware of the applicable HIPAA rules and accompanying liability. We promptly informed our client of these vulnerabilities and recommended next steps for the company that would allow it to play catch-up on all security and privacy concerns — HIPAA compliance was to be a priority, given that any breach would threaten their dominant position.

Rapid growth proved to be painful for another company we assessed, this time a provider of workforce management solutions. While they did not handle PHI and, as such, were not subject to HIPAA rules, the challenge they faced is likely to plague BAs seeking HIPAA compliance: a number of the data centers they were using to store customer data were unable to obtain SOC 2 certification.

In addition, their IT and engineering teams differed in their understanding of industry standards and the consequences of poor security. Luckily, investing in improved security was feasible for the company, and we advised them to increase IT/security resources as their cloud focus continued to expand.

On the other end of the spectrum was a business cloud services provider. Perhaps as a result of differentiators needed to stand out in a crowded market, the company had strong security and privacy processes across the board. They performed quarterly PCI v3 scans to ensure the integrity of any credit card information on their platform, hired a trusted firm to perform annual SOC 2 audits, and met NIST 800.53 standards through annual self-assessments.

Note that the last of these is particularly relevant to healthcare companies, as it is referenced in HIPAA rules (as well as FINRA regulations). Importantly, all of this was overseen by a single individual, VP of Security and Privacy, who was held accountable by the CTO. To this day, the company remains a strong example having an integrated approach for dealing with a number of compliance standards that often overlap.

Being Proactive About Compliance

In light of the game-changing HITECH Act, it is crucial that all organizations touching healthcare step back and evaluate their stance as it relates to HIPAA compliance. Regulatory burdens now fall more heavily on business associates, a category of wildly diverse organizations that provide different services and functions but have one thing in common: use or disclosure of protected health information. To achieve and maintain HIPAA compliance, business associates must act quickly and ensure that people, processes, and technology have all been brought up to new regulatory standards, either by outsourcing to compliance experts or with rigorous in-house efforts.

Along the way, you might find your company shoring up several other security and privacy gaps — the kind that could derail a nascent or growing venture. As partners of numerous healthcare-focused technology companies, we hope that these lessons learned and changes made in pursuit of HIPAA compliance, while tedious and expensive, will strengthen the organizations we work with and securely position them for the future.

Pages: Page 1 Page 2 Page 3
  • LinkedIn
  • Twitter
  • Facebook
  • Email
  • Print

Tap Native

Get in-depth healthcare technology analysis and commentary delivered straight to your email weekly

Reader Interactions

Primary Sidebar

Subscribe to HIT Consultant

Latest insightful articles delivered straight to your inbox weekly.

Submit a Tip or Pitch

Featured Insights

2025 EMR Software Pricing Guide

2025 EMR Software Pricing Guide

Featured Interview

Kinetik CEO Sufian Chowdhury on Fighting NEMT Fraud & Waste

Most-Read

2019 MedTech Breakthrough Award Category Winners Announced

MedTech Breakthrough Announces 2025 MedTech Breakthrough Award Winners

WeightWatchers Files for Bankruptcy to Eliminate $1.15B in Debt

WeightWatchers Files for Bankruptcy to Eliminate $1.15B in Debt

KLAS: Epic Dominates 2024 EHR Market Share Amid Focus on Vendor Partnership; Oracle Health Sees Losses Despite Tech Advances

KLAS: Epic Dominates 2024 EHR Market Share Amid Focus on Vendor Partnership; Oracle Health Sees Losses Despite Tech Advances

'Cranky Index' Reveals EHR Alert Frustration Peaks Midweek, Highest Among Admin Staff

‘Cranky Index’ Reveals EHR Alert Frustration Peaks Midweek, Highest Among Admin Staff

Madison Dearborn Partners to Acquire Significant Stake in NextGen Healthcare

Madison Dearborn Partners to Acquire Significant Stake in NextGen Healthcare

Wandercraft Begins Clinical Trials for Physical AI-Powered Personal Exoskeleton

Wandercraft Begins Clinical Trials for Physical AI-Powered Personal Exoskeleton

Chipiron Secures $17M to Transform MRI Access with Portable Scanner

Chipiron Secures $17M to Transform MRI Access with Portable Scanner

Abbott to Integrate FreeStyle Libre Glucose Data with Epic EHR

Abbott to Integrate FreeStyle Libre Glucose Data with Epic EHR

5 Ways New Trump Administration Tariffs Are Impacting U.S. Healthcare Now

5 Ways Trump Administration Tariffs Are Impacting U.S. Healthcare Now

iCAD, GE HealthCare Integrate to Advance Breast Cancer Detection with AI

RadNet to Acquire iCAD for $103M in All-Stock Transaction

Secondary Sidebar

Footer

Company

  • About Us
  • Advertise with Us
  • Reprints and Permissions
  • Submit An Op-Ed
  • Contact
  • Subscribe

Editorial Coverage

  • Opinion
  • Health IT
    • Care Coordination
    • EMR/EHR
    • Interoperability
    • Population Health Management
    • Revenue Cycle Management
  • Digital Health
    • Artificial Intelligence
    • Blockchain Tech
    • Precision Medicine
    • Telehealth
    • Wearables
  • Startups
  • Value-Based Care
    • Accountable Care
    • Medicare Advantage

Connect

Subscribe to HIT Consultant Media

Latest insightful articles delivered straight to your inbox weekly

Copyright © 2025. HIT Consultant Media. All Rights Reserved. Privacy Policy |