Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
22
23
24
25
26
27
28
29
30
1
2
3
4
5

Events

Latest News

Digital Health Care Alert: Is Your Health Care App Subject To HIPAA?

Digital Health Care Alert

The U.S. Department of Health & Human Services’ Office for Civil Rights (OCR) recently released two HIPAA compliance documents that provide useful guidance to health care app developers.

By: Stefano Quintini and Hilary A. Cox

April 5, 2016

    OCR’s Compliance Guidance for Health Care App Developers

    The U.S. Department of Health & Human Services’ Office for Civil Rights (OCR) recently provided guidance (in the form of six “real-life” scenarios) to help health care app developers (“Developers”) determine whether their consumer data collection activities make them subject to HIPAA. In general, those apps offered directly to consumers for them to use to track their fitness activities, blood pressure levels, glucose levels, etc. are not required to comply with HIPAA (however, other state data protection laws might apply to the collection and use of personal information). On the other hand, apps that are offered in conjunction with a covered health care provider or a health plan are more likely to be candidates for HIPAA compliance.

    The key question is whether the Developer is creating, receiving, maintaining and transmitting protected health information (PHI) on behalf of a Covered Entity. If the answer is yes, then the Developer would have to comply with HIPAA rules as a Business Associate of the Covered Entity.

    OCR’s guidance states that those apps that give consumers the ability to upload a copy of their medical records that they have previously downloaded from their provider’s Electronic Health Record (EHR) will not be subject to HIPAA unless the Developers are maintaining that health information on behalf of those providers or those providers’ vendors as Business Associates of the Covered Entity. Even if a doctor recommends a specific health care app to his or her patient and the patient downloads that app, enters his or her health information and shares that information with the doctor through the app, the Developer is still not required to comply with HIPAA as long as the Developer has not contracted with the doctor to provide the app’s services. The fact that the patient used the app to share his or her information with the doctor does not, in and of itself, make the Developer a Business Associate of the doctor.

    OCR specifically called out those apps that offer users the ability to connect to a health care provider’s or health plan’s EHR—where there’s an interoperability arrangement between those entities and the app developer and no other business relationship between the parties—as a scenario in which HIPAA compliance would likely not be required. However, if, for instance, at the direction of a provider, a patient downloads a health app to his or her smart phone, and  the provider has contracted with the Developer for patient management services (examples are: remote patient health counseling, monitoring of patients’ food and exercise, patient messaging, EHR integration and application interfaces), and the information provided by the patient is automatically incorporated into the provider’s EHR, then the Developer would be considered a Business Associate since the app is a means for providing those patient management services.

    In a more nuanced scenario, a Developer would have to comply with HIPAA rules if the app is offered by the consumer’s health plan (the example mentioned in the guidance relates to a mobile PHR that allows users to download and store health plan records and check the status of claims and coverage decisions, and also contains the plan’s wellness tools for members). However, if the Developer were to also offer a separate, direct-to-consumer version of the app, the Developer’s activities with respect to such version would not be subject to HIPAA rules (the implication being, however, that the health information collected from these two versions of the app would need to be separately stored).

    The guidance document also contains a list of “Key Questions” to help Developers determine if they will be considered a Business Associate under HIPAA. As with the scenarios above, these questions are organized around the issues of who the Developer’s customers are and how much control a consumer/user has over his or her data. If you are a Developer and your customers are Covered Entities under HIPAA (e.g., hospitals, doctors’ offices, clinics, pharmacies, or other health care providers that conduct electronic transactions, health plans, wellness programs offered as part of an employer’s self-funded health plan), or Business Associates to a Covered Entity, you will need to comply with HIPAA. If you are only offering your app directly to consumers, and your users independently select your app and control all decisions as to whether to send their data to a third party, you are probably not required to comply with HIPAA—although other data protection laws will apply.

    Click here to read OCR’s complete guidance.

    New Compliance Guidance for the HIPAA Security Rule

    OCR has also published a “Crosswalk” that maps the connections between the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity Framework (“NIST Framework”) and the HIPAA Security Rule’s standards. The NIST Framework is a voluntary, risk-based approach that helps organizations in any industry understand, communicate and manages cybersecurity risks. Since the Security Rule’s standards are scalable and technology-neutral, this Crosswalk provides more concrete/practical guidance for “how” Business Associates (and Covered Entities) can assess their current compliance status, from a technical standpoint, and identify any possible gaps. For instance, one of the “required” standards under the Security Rule is the performance of a Risk Assessment. Within that standard, the Crosswalk sets out five subcategories that are fairly granular (e.g., asset vulnerabilities are identified and documented; threat and vulnerability information is received from information sharing forums and sources; threats, both internal and external, are identified and documented, etc.) and provides more clarity on the components of a Risk Assessment. One caveat—OCR states that compliance with the Crosswalk is not a “guarantee” of HIPAA compliance. Nevertheless, the crosswalk should go some way to making the Security Rule standards less nebulous.

    Click here for a copy of the Crosswalk.​​

    Source

    HIMSS Special Part 1: HIT Visionary Zach Fox
    Check out industry insight from HIT visionary and DrFirst Executive VP and GM, Zach Fox. Visit DrFirst at HIMSS Booth 6232.
    We respect your privacy. Your information is safe and will never be shared.
    Don't miss out. Subscribe today.
    ×
    ×
    WordPress Popup
    HIMSS Special Part 1: HIT Visionary David Lareau
    Check out industry insight from HIT visionary and Medicomp CEO, David Lareau. Visit Medicomp at HIMSS Booth 3421
    We respect your privacy. Your information is safe and will never be shared.
    Don't miss out. Subscribe today.
    ×
    ×
    WordPress Popup
    casipoldiyarbetetabetetabetw88w88w88betfokusbetfokuslordbahisparobetparobetbuzbahisbullbahiscasino sérieuxcasino sérieuxcasino sérieuxcasino sérieuxcasino en ligne populairemeilleur site de jeux casino en lignemeilleur site de jeux casino en lignecasino en ligne en francecasino en ligne en francecasino en ligne de confiancebetbinanstwinplayistanbulbahisistanbulbahisistanbulbahisparis sportifs hors arjelonwin üyeliksahabet üyelikrestbet girişpulibetsüperbetinbtcbahiscanlı casino sitelerionline casino1xbet mobilligobet mobilcapitolbetmostbet üyelikbizbet üyelikgobahis girişmatbet girişikimisli girişbordobet girişbetcio girişalfabahisalfabahisbetgoowinxbetwinxbetwinxbetwinxbetbetkanyontaksimbetrexabetrexabetrexabetenobahisbookmaker hors arjelparis sportifs en Italieparier sur les cornersparier sur le nombre de tirsmystake chickenparis hippiques en ligneplinko francecasino diceBetzinoVasyCbetCasino Lucky8betkanyonbetkanyontaksimbettaksimbettaksimbettaksimbetbetistbetistbetistenobahisenobahisenobahisbetkolikbetkoliksmartbahissmartbahissmartbahistrendbettrendbetgamabetgamabetgamabetgamabetaspercasinoaspercasinoaspercasinonisanbetnisanbetnewbahismelbetonbahisbetonredbetonredromabettipobettipobetefes casinobetandreasfixbetbetbababetbababuzbahisbuzbahisbullbahisbullbahisbetsofbetsofall right casinokombinebetbetbinansbetbinansbetbinansmaksatbahisbetbabaorisbetorisbetbizimbahissiyahbethayalbahishayalbahishilbetsantosbettingsantosbettingsantosbettingsantosbettingnerobetnerobetswordbetswordbetswordbetinbahislevabetlevabetlevabetcasiveracasiveracasiverakordonbetkareasbetprincessbetkikbetkikbetkikbetbetmarketbetmarketbetmarketyapbahsinibetingoasyabahishipercasinocasinoperbahisnowsüpertotobetalibahisfaulbetfaulbetrelaxbahisbetingoasyabahiscasinopercasinoperbahisnowbahisnowpiyasabetpiyasabetyonjabetcasinoslotbetibombetibomredwinbitslercresus casinocresus casino aviscresus casino gratuitcresus casino connexioncresus casino connexioncresus casino connexioncresus casino applicationwild sultanwild sultan casino en lignewild sultan aviswild sultan francewild sultan bonuswild sultan vipwild sultan viptortuga casinotortuga casinotortuga casino en lignetortuga casino avistortuga casino bonus sans dépôttortuga casino applicationtortuga casino applicationmadnixmadnix casino avismadnix casino avismadnix casino en lignemadnix casino en lignemadnix casino bonus sans dépôtmadnix casino bonus sans dépôtmadnix casino retraitmadnix casino mon comptemadnix casino mon comptewinouiwinouiwinoui casinowinoui casino connexionwinoui casino connexionwinoui casino en lignemagical spinmagical spin casino50 free spins magical spinmagical spin code promomagical spin code promoazur casinoazur casinoazur casino avisazur casino en ligneazur casino en ligneazur casino mobileazur casino mobileazur casino mon comptelucky8lucky8lucky8lucky8 se connecterlucky8 avislucky8 avislucky8 mon comptebetifybetifybetifybetify avisbetify casinobetify retraitcasino jokacasino jokacasino joka vipcasino joka vipcasino joka connexionjoka casino en lignelucky31lucky31lucky31 casinolucky31 connexionlucky31 avislucky31 avislucky31 francespace fortunaspace fortunaspace fortunaspace fortuna casinospace fortuna avisspace fortuna connexionspace fortuna gmkjackpot bobjackpot bobjackpot bobjackpot bob avis777 jackpot bob777 jackpot bobjackpot bob casino bonus sans dépôtjackpot bob casino bonus sans dépôtamon casinoamon casinoamon casinoamon casinoamon casino en ligneamon casino bonus sans depotamon casino bonus sans depotamon casino applicationamon casino applicationamon casino applicationmoi casinomoi casinomoi casinomoi casino avismoi casino avismoi casino avismoi casino connexionamon casino bonus sans depotmoi casino applicationlucky8 interdit en francebetify connexionjoka casino avisjoka casino avislucky31 blackjackspace fortuna retraitjackpot bob applicationamon casino inscriptionmoi casino en lignejackpot bob inscriptionamon casino retraitamon casino retraitmoi casino inscriptionmoi casino retraitmadnix applicationmadnix inscriptiontortuga casino retraittortuga casino retraittortuga casino compte bloquétortuga casino mon compteazur casino bonusazur casino applicationmagical spin 10 eurosmagical spin retraitbetpas üyelikbetboo üyeliksüperbetin üyelikspace fortuna bonus sans dépôtspace fortuna applicationspace fortuna inscriptionbetify bonusbetify promo codebetify inscriptioncasino joka applicationcasino joka bonus sans dépôtcasino joka inscriptionlucky31 bonus sans depotlucky31 retraitmariobetbetsat üyelikpinup üyeliklucky31 applicationbetpas üyeliksüperbetin üyeliksultanbet üyeliklucky31 inscriptionwild sultan bonus sans depotwild sultan bonus sans depotwild sultan retraitwild sultan retraitwild sultan retraitwild sultan casino bonus sans dépôtcresus casino bonuscresus casino compte bloquécresus casino privéwinoui casino bonus sans dépôtwinoui casino françaiswinoui problèmewinoui applicationwinoui inscriptionbetmatik üyelikmariobet üyelikmariobet üyelikbetsat üyelikbetonred üyelikbetonred üyelikbetonred üyelikbetonred üyelik7slots üyelikstarda üyelikmaslakcasinomaslakcasinomaslakcasinobahisbeyportbetportbetportbetrbetrbetrbetrbetsahabet üyelik1xbet üyeliktipobet üyeliktipobet üyelikmostbet üyelikmostbet üyelikmostbet üyelikmostbet üyelikligobet üyelikbizbet üyelikbahsinebetsahasantabetegobetwolbetkralbetbetorspininterbahisgobahisbordobetbordobetretrobetbetciofreybetfavorisenbetboxbetmabetbetmabetbetmüzebetgitmislibetshowbahisyonjabetviplobyhedefbetlucky8 bonuslucky spinlucky8 bonus sans dépôtlucky8 compte bloquélucky8 compte bloquémakrobetilbetvdcasinomaltcasinomaltcasinoceltabitceltabitlordcasinolordcasinohızlıbahishızlıbahisprestijbetbetzmarkbetzulaenobahismedyabahis