Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
27
12:00 AM - Arab Health 2020
29
1
7
10
12
14
16
20
23
25
27
28
29
1
Arab Health 2020
2020-01-27 - 2020-01-30    
All Day
ABOUT ARAB HEALTH 2020 Arab Health is an industry-defining platform where the healthcare industry meets to do business with new customers and develop relationships with [...]
12th International Conference on Acute Cardiac Care
2020-01-28 - 2020-01-29    
All Day
ABOUT 12TH INTERNATIONAL CONFERENCE ON ACUTE CARDIAC CARE Acute Cardiac Care has been undergoing a substantial transformation in recent years as the population ages and [...]
30 Jan
2020-01-30 - 2020-01-31    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Annual Lower and Upper Canada Anesthesia Symposium 2020 (LUCAS)
2020-01-31 - 2020-02-02    
All Day
ABOUT ANNUAL LOWER & UPPER CANADA ANESTHESIA SYMPOSIUM 2020 (LUCAS) On behalf of the Departments of Anesthesia of McGill University, Queen’s University, and the University [...]
RF - 577th International Conference On Medical & Health Science - ICMHS 2020
2020-02-02 - 2020-02-03    
All Day
577th International Conference on Medical & Health Science - ICMHS 2020. It will be held during 2nd-3rd February, 2020 at Berlin , Germany. ICMHS 2020 [...]
ISER- 747th International Conference On Science, Health And Medicine ICSHM
2020-02-02 - 2020-02-03    
All Day
ISER- 747th International Conference on Science, Health and Medicine ICSHM is a prestigious event organized with a motivation to provide an excellent international platform for [...]
International Conference On Medical And Health SciencesICMHS-2020
2020-02-03 - 2020-02-04    
All Day
The ICMHS conference is an international forum for the presentation of technological advances and research results in the fields of Medical and Health Sciences. The [...]
Medlab Middle East 2020
2020-02-03 - 2020-02-06    
All Day
ABOUT MEDLAB MIDDLE EAST 2020 Medlab Middle East is the only medical laboratory industry event that offers manufacturers the opportunity to meet a diverse audience [...]
Cloud Architecture Implementation Healthcare 2020
2020-02-04 - 2020-02-06    
All Day
This summit brings together leaders from healthcare organizations to scale up their cloud infrastructure, implement cloud technology and share use cases about the success and [...]
4th Microbiome Movement - Drug Development Summit Europe 2020 - London, UK
2020-02-04 - 2020-02-06    
All Day
A unique forum focusing on pursuing disease causation to foster the creation of targeted Microbiome-based therapeutics, biomarkers and diagnostics. Time: 8:30 am - 5:50 pm [...]
Structural Heart Intervention And Imaging Feb 2020 CME Conference-San Diego
2020-02-05 - 2020-02-07    
All Day
The Scripps Structural Heart Intervention and Imaging conference features live case demonstrations, lectures from renowned faculty, hands-on workshops, and extensive satellite symposia. Time: 7:00 am [...]
Structural Heart Intervention And Imaging Feb 2020 CME Conference-San Diego
2020-02-05 - 2020-02-07    
All Day
The Scripps Structural Heart Intervention and Imaging conference features live case demonstrations, lectures from renowned faculty, hands-on workshops, and extensive satellite symposia. Time: 7:00 am [...]
18th Annual South Beach Symposium
2020-02-06 - 2020-02-09    
All Day
ABOUT 18TH ANNUAL SOUTH BEACH SYMPOSIUM The 18th Annual South Beach Symposium will take place in Miami Beach, Florida from February 6-9, 2020 at the [...]
Primary Care CME In Clearwater Beach, Florida February 2020
2020-02-08 - 2020-02-10    
All Day
Topics include latest hypertension guidelines, cancer screening, cholesterol management, immunizations, COPD, skin and soft tissue infections, etc. Time: 08:00 - 11:00
Primary Care CME In Clearwater Beach, Florida February 2020
2020-02-08 - 2020-02-10    
All Day
Topics include latest hypertension guidelines, cancer screening, cholesterol management, immunizations, COPD, skin and soft tissue infections, etc. Time: 08:00 - 11:00  
World Congress On Medical Imaging And Clinical Research WCMICR-2020
2020-02-09 - 2020-02-10    
All Day
The WCMICR conference is an international forum for the presentation of technological advances and research results in the fields of Medical Imaging and Clinical Research. [...]
Medical Design & Manufacturing (MD&M) West
2020-02-11 - 2020-02-13    
All Day
ABOUT MEDICAL DESIGN & MANUFACTURING (MD&M) WEST Medical Design & Manufacturing (MD&M) West is where serious professionals find the technologies, education, and connections to stay [...]
Third International Conference On Zika Virus And Aedes Related Infections
2020-02-13    
All Day
This Conference will bring together multidisciplinary experts aiming to tackle the challenges that Aedes related infections present including zika, dengue, yellow fever, and chikungunya. Time: [...]
The IRES - 791st International Conferences On Medical And Health Science ICMHS
2020-02-15 - 2020-02-16    
All Day
The IRES - 791st International Conferences on Medical and Health Science ICMHS aimed at presenting current research being carried out in that area and scheduled [...]
4th International Conference on Chronic Diseases
2020-02-17 - 2020-02-18    
All Day
ABOUT 4TH INTERNATIONAL CONFERENCE ON CHRONIC DISEASES It takes immense pleasure to invite you to attend the 4th International Conference on Chronic Diseases (Chronic Diseases [...]
European Gynecology and Obstetrics Congress
2020-02-17 - 2020-02-18    
All Day
ABOUT EUROPEAN GYNECOLOGY AND OBSTETRICS CONGRESS Gynecology 2020 destine to endeavor leading-edge memoranda of eminent keynote speakers, universal personalities, special sessions and poster presentations attracting [...]
18 Feb
2020-02-18 - 2020-02-20    
All Day
Technology Networks is a global online scientific publication that covers the latest research, industry news, and technologies. Our 12 online communities provide focused coverage of [...]
6th International Conference On Food And Beverages
2020-02-19 - 2020-02-20    
All Day
Meetings International Meetings Int. invites you to attend the ‘6th International Conference on Food and Beverages 2020” which is to be held on February 19-20, [...]
10th Global Summit on Neuroscience and Neuroimmunology
2020-02-19 - 2020-02-20    
All Day
ABOUT 10TH GLOBAL SUMMIT ON NEUROSCIENCE AND NEUROIMMUNOLOGY 10th Global Summit on Neuroscience and Neuroimmunology (Neuroimmunology 2020) is aimed at improving health across the globe, [...]
Mayo Clinic Nephrology And Transplantation For The Clinician 2020
2020-02-21 - 2020-02-22    
All Day
Nephrology and Transplantation for the Clinician: 18th Annual Update From Mayo Clinic is a two-day course designed to u-p-d-a-t-e participants on nephrology topics relevant to [...]
28th International Conference on Cancer Research and Pharmacology
2020-02-21 - 2020-02-22    
All Day
ABOUT 28TH INTERNATIONAL CONFERENCE ON CANCER RESEARCH AND PHARMACOLOGY PULSUS Conferences is glad to invite all the participants across the globe to attend 28th International [...]
Rocky Mountain Winter Conference On Emergency Medicine 2020
2020-02-22 - 2020-02-26    
All Day
Each day the conference starts with a hot breakfast followed by engaging, cutting edge didactics led by experts from the countrys top academic programs. Please [...]
CRT20 Conference
2020-02-22 - 2020-02-25    
All Day
ABOUT CRT20 CONFERENCE CRT, one of the world’s leading interventional cardiology conferences, is attended by more than 3,000 interventional and endovascular specialists. At the 2019 [...]
3rd International conference on  Diabetes, Hypertension and Metabolic Syndrome
2020-02-24 - 2020-02-25    
All Day
About Diabetes Meet 2020 Conference Series takes the immense Pleasure to invite participants from all over the world to attend the 3rdInternational conference on Diabetes, Hypertension and [...]
3rd International Conference on Cardiology and Heart Diseases
2020-02-24 - 2020-02-25    
All Day
ABOUT 3RD INTERNATIONAL CONFERENCE ON CARDIOLOGY AND HEART DISEASES The standard goal of Cardiology 2020 is to move the cardiology results and improvements and to [...]
Medical Device Development Expo OSAKA
2020-02-26 - 2020-02-28    
All Day
ABOUT MEDICAL DEVICE DEVELOPMENT EXPO OSAKA What is Medical Device Development Expo OSAKA (MEDIX OSAKA)? Gathers All Kinds of Technologies for Medical Device Development! This [...]
Events on 2020-01-27
Arab Health 2020
27 Jan 20
Dubai
Events on 2020-01-28
Events on 2020-01-30
Events on 2020-01-31
Events on 2020-02-03
Events on 2020-02-06
18th Annual South Beach Symposium
6 Feb 20
Miami Beach
Events on 2020-02-09
Events on 2020-02-11
Events on 2020-02-17
Events on 2020-02-18
18 Feb
Events on 2020-02-22
CRT20 Conference
22 Feb 20
National Harbor
Events on 2020-02-26
Latest News

Digital Health Care Alert: Is Your Health Care App Subject To HIPAA?

Digital Health Care Alert

The U.S. Department of Health & Human Services’ Office for Civil Rights (OCR) recently released two HIPAA compliance documents that provide useful guidance to health care app developers.

By: Stefano Quintini and Hilary A. Cox

April 5, 2016

    OCR’s Compliance Guidance for Health Care App Developers

    The U.S. Department of Health & Human Services’ Office for Civil Rights (OCR) recently provided guidance (in the form of six “real-life” scenarios) to help health care app developers (“Developers”) determine whether their consumer data collection activities make them subject to HIPAA. In general, those apps offered directly to consumers for them to use to track their fitness activities, blood pressure levels, glucose levels, etc. are not required to comply with HIPAA (however, other state data protection laws might apply to the collection and use of personal information). On the other hand, apps that are offered in conjunction with a covered health care provider or a health plan are more likely to be candidates for HIPAA compliance.

    The key question is whether the Developer is creating, receiving, maintaining and transmitting protected health information (PHI) on behalf of a Covered Entity. If the answer is yes, then the Developer would have to comply with HIPAA rules as a Business Associate of the Covered Entity.

    OCR’s guidance states that those apps that give consumers the ability to upload a copy of their medical records that they have previously downloaded from their provider’s Electronic Health Record (EHR) will not be subject to HIPAA unless the Developers are maintaining that health information on behalf of those providers or those providers’ vendors as Business Associates of the Covered Entity. Even if a doctor recommends a specific health care app to his or her patient and the patient downloads that app, enters his or her health information and shares that information with the doctor through the app, the Developer is still not required to comply with HIPAA as long as the Developer has not contracted with the doctor to provide the app’s services. The fact that the patient used the app to share his or her information with the doctor does not, in and of itself, make the Developer a Business Associate of the doctor.

    OCR specifically called out those apps that offer users the ability to connect to a health care provider’s or health plan’s EHR—where there’s an interoperability arrangement between those entities and the app developer and no other business relationship between the parties—as a scenario in which HIPAA compliance would likely not be required. However, if, for instance, at the direction of a provider, a patient downloads a health app to his or her smart phone, and  the provider has contracted with the Developer for patient management services (examples are: remote patient health counseling, monitoring of patients’ food and exercise, patient messaging, EHR integration and application interfaces), and the information provided by the patient is automatically incorporated into the provider’s EHR, then the Developer would be considered a Business Associate since the app is a means for providing those patient management services.

    In a more nuanced scenario, a Developer would have to comply with HIPAA rules if the app is offered by the consumer’s health plan (the example mentioned in the guidance relates to a mobile PHR that allows users to download and store health plan records and check the status of claims and coverage decisions, and also contains the plan’s wellness tools for members). However, if the Developer were to also offer a separate, direct-to-consumer version of the app, the Developer’s activities with respect to such version would not be subject to HIPAA rules (the implication being, however, that the health information collected from these two versions of the app would need to be separately stored).

    The guidance document also contains a list of “Key Questions” to help Developers determine if they will be considered a Business Associate under HIPAA. As with the scenarios above, these questions are organized around the issues of who the Developer’s customers are and how much control a consumer/user has over his or her data. If you are a Developer and your customers are Covered Entities under HIPAA (e.g., hospitals, doctors’ offices, clinics, pharmacies, or other health care providers that conduct electronic transactions, health plans, wellness programs offered as part of an employer’s self-funded health plan), or Business Associates to a Covered Entity, you will need to comply with HIPAA. If you are only offering your app directly to consumers, and your users independently select your app and control all decisions as to whether to send their data to a third party, you are probably not required to comply with HIPAA—although other data protection laws will apply.

    Click here to read OCR’s complete guidance.

    New Compliance Guidance for the HIPAA Security Rule

    OCR has also published a “Crosswalk” that maps the connections between the National Institute of Standards and Technology (NIST) Framework for Improving Critical Infrastructure Cybersecurity Framework (“NIST Framework”) and the HIPAA Security Rule’s standards. The NIST Framework is a voluntary, risk-based approach that helps organizations in any industry understand, communicate and manages cybersecurity risks. Since the Security Rule’s standards are scalable and technology-neutral, this Crosswalk provides more concrete/practical guidance for “how” Business Associates (and Covered Entities) can assess their current compliance status, from a technical standpoint, and identify any possible gaps. For instance, one of the “required” standards under the Security Rule is the performance of a Risk Assessment. Within that standard, the Crosswalk sets out five subcategories that are fairly granular (e.g., asset vulnerabilities are identified and documented; threat and vulnerability information is received from information sharing forums and sources; threats, both internal and external, are identified and documented, etc.) and provides more clarity on the components of a Risk Assessment. One caveat—OCR states that compliance with the Crosswalk is not a “guarantee” of HIPAA compliance. Nevertheless, the crosswalk should go some way to making the Security Rule standards less nebulous.

    Click here for a copy of the Crosswalk.​​

    Source