The Health Insurance Portability and Accountability Act establishes national standards to protect sensitive patient health information from being disclosed without consent.
HIPAA applies to Covered Entities and their Business Associates who handle Protected Health Information (PHI).
Business Associate Agreements (BAAs): Any vendor that handles PHI on behalf of a Covered Entity must sign a BAA and comply with HIPAA requirements.
HIPAA compliance is built on three fundamental rules
Establishes national standards for protecting individually identifiable health information. Defines patient rights and limits on use and disclosure of PHI.
Requires administrative, physical, and technical safeguards to ensure confidentiality, integrity, and availability of electronic PHI (ePHI).
Requires covered entities and business associates to notify individuals, HHS, and sometimes media following a breach of unsecured PHI.
Penalties are based on the level of culpability and knowledge of the violation.
Manage Business Associate relationships and ensure PHI is protected across your vendor ecosystem.
Protect patient health information and meet regulatory requirements.