HIPAA experts alert business associates of covered facilities

Article

Most HIPAA dialogue has focused on the big players: large healthcare systems, hospitals, and national health plans. But the class of businesses that have working relationships with those big players may be considered "covered entities" and thus subject

Most HIPAA dialogue has focused on the big players: large healthcare systems, hospitals, and national health plans. But the class of businesses that have working relationships with those big players may be considered "covered entities" and thus subject to the law as well.

"The effects of HIPAA on business associates of covered entities - equipment vendors, consultants, accountants, law firms - have not been fully explored in the media," said Tracy Field, an attorney with Arnall Golden Gregory in Atlanta.

The privacy rule also applies to enterprises that use or disclose protected health information in order to perform a function or activity on behalf of a covered entity. Covered entities must therefore enter into written contracts that bind their business associates to several obligations under the privacy rule.

Clearly, firms assisting in radiographic imaging and storing the data on the tapes are considered to be business associates. Several nuances in the regulations determine whether an agreement is needed, however, said Kristen Hughes, general counsel and director of HIPAA services for SG&A Consulting.

If the relationship does not involve the use or disclosure of protected information, for example, an agreement may not be needed at all. Conversely, companies performing services on behalf of a covered entity that involve or may involve the use or disclosure of such information will likely be asked to execute a business associate agreement, Hughes said.

"Business associates should be careful about contracts they are asked to sign because there were some HIPAA modifications made in August. Some versions still floating on the Web have not been updated," Field said.

It is important to understand that HIPAA does not directly regulate third parties, according to Hughes. Only covered entities are required to adhere to HIPAA's standards. It is the covered entity that will be held accountable under HIPAA and must answer for noncompliance. Therefore, business associates need to be aware that agreements will likely be written from the provider's perspective.

In particular, many providers seek indemnification in the event of a privacy breach.

"Before signing all those contracts, be sure you have insurance coverage," Field said. "There are some business associate contracts in which the hospital may want access to all your record keeping. You may not want them to have that access, and it's not required under the business associate agreements."

Newsletter

Stay at the forefront of radiology with the Diagnostic Imaging newsletter, delivering the latest news, clinical insights, and imaging advancements for today’s radiologists.

Recent Videos
SNMMI: Emerging PET Insights on Neuroinflammation with Progressive Apraxia of Speech (PAOS) and Parkinson-Plus Syndrome
Improving Access to Nuclear Imaging: An Interview with SNMMI President Jean-Luc C. Urbain, MD, PhD
SNMMI: 18F-Piflufolastat PSMA PET/CT Offers High PPV for Local PCa Recurrence Regardless of PSA Level
SNMMI: NIH Researcher Discusses Potential of 18F-Fluciclovine for Multiple Myeloma Detection
SNMMI: What Tau PET Findings May Reveal About Modifiable Factors for Alzheimer’s Disease
Emerging Insights on the Use of FES PET for Women with Lobular Breast Cancer
Can Generative AI Reinvent Radiology Reporting?: An Interview with Samir Abboud, MD
Mammography Study Reveals Over Sixfold Higher Risk of Advanced Cancer Presentation with Symptom-Detected Cancers
Combining Advances in Computed Tomography Angiography with AI to Enhance Preventive Care
Study: MRI-Based AI Enhances Detection of Seminal Vesicle Invasion in Prostate Cancer
Related Content
© 2025 MJH Life Sciences

All rights reserved.