New

For business associates

A HIPAA assessment built for the vendors practices rely on.

IT providers, billing companies and other vendors that handle patient data get their own assessment covering the HIPAA obligations of a business associate, without the practice's front-desk and patient-notice items.

Who it's for

If you handle patient data for a practice, HIPAA applies to you too.

IT providers and MSPs

You manage the servers, backups and accounts that hold patient data.

Billing and coding companies

You work with claims and patient records every day.

Other vendors

Cloud and hosting, records storage and shredding, answering services and others that handle patient data.

What's different

Your obligations, without the practice's.

A business associate doesn't run a waiting room or send patients a privacy notice. Your assessment drops those questions, adds the ones HIPAA asks of business associates, and keeps the Security Rule core.

Added

Questions just for business associates

  • Notify your client of a breach. Tell the covered entity you serve within 60 days (45 CFR 164.410).
  • BAAs with your own subcontractors. Your vendors that touch client data need agreements too (45 CFR 164.308(b)(2)).
  • Use data only as the BAA allows. Client data is used only for the purposes in the agreement (45 CFR 164.504(e)).
  • Return or destroy at contract end. Client data doesn't outlive the relationship.
  • Minimum necessary access. Technicians reach only the patient data the job requires (45 CFR 164.502(b)).
  • Training for your technicians. Security awareness training for your own workforce (45 CFR 164.308(a)(5)(i)).
  • Wiping retired media. Drives and devices that held client data are wiped before they leave.
Shared

The Security Rule core, same as practices

Risk analysis, Access control, Multi-factor authentication, Encryption, Backups and restore tests, Logging, Incident response, Offboarding, and more.

Removed

Practice-only items you won't see

  • Notice of privacy practices
  • Patient record requests
  • Breach letters to patients and the HHS breach log
  • Privacy Official, privacy training and privacy sanctions
  • Waiting-room screen rules
  • Practice-specific wording on device disposal and vendor BAAs
Coming

Shared responsibility

An IT provider often runs the very things a practice is asked about, like backups or the locked server room. Soon you'll be able to answer those questions in your client's assessment, and the practice will see them marked as handled by their IT provider. One answer, given by the people who actually do the work.

The same complete record

You get the same score, remediation plan, evidence record and auditor packet that practices get, so you can show the practices you serve exactly how you protect their patients' data. It documents your program. It is not a certification.

Questions

Questions from business associates

Who counts as a business associate?

Any organization that creates, receives, maintains or sends protected health information on behalf of a covered entity such as a medical or dental practice. Common examples are IT providers, billing companies and cloud or records-storage vendors.

How is it different from the practice assessment?

Practice-only questions, such as the notice of privacy practices and patient record requests, are removed. Questions specific to business associates are added, such as notifying your client of a breach and having BAAs with your own subcontractors. The Security Rule core is the same.

Which organizations get the business-associate assessment?

Organizations set up as an IT provider or MSP, a billing or coding company, or another vendor that handles protected health information.

Can an IT provider answer questions for its clients?

Not yet. We are working on shared responsibility, so an IT provider can answer the items it runs for a practice, such as backups or the server room, and the practice sees them marked as handled by their IT provider.

What do we get at the end?

The same score, remediation plan, evidence record and auditor packet that practices get.

Is this a HIPAA certification?

No. There is no official HIPAA certification. ComplianceAX helps you assess, improve and document your program. It does not certify compliance.

See the business-associate assessment.

Request a demo and tell us about your organization and the practices you serve. We'll walk you through the assessment built for business associates.