The Compliance Divas Podcast
Our podcast covers current topics such as infection prevention and control, OSHA and HIPAA compliance for dentistry. We discuss the latest regulatory information, answer frequently asked questions and give suggestions for dental practices to make compliance easy and sustainable. The Compliance Divas are a trusted source for consistent, accurate information based upon current guidelines, standards, science, and recommendations.
The Compliance Divas Podcast
Episode #25 HIPAA: Business Associate Agreements
Use Left/Right to seek, Home/End to jump to start or end. Hold shift to jump forward or backward.
Knowing you has access to your patient's data is not only mission critical for your practice, it's required by HIPAA. In this episode, the Divas discuss how to identify business associates in your practice along with the significance of a Business Associate Agreement. Make no mistake, this aspect of HIPAA compliance plays an important role in protecting your patients' protected health information.
Welcome. I'm Leslie Cannon. I'm Mary Gavoni. I'm Linda Harvey.
SPEAKER_01I'm Olivia Juan, and together we are the Compliance Divas. Hello everyone. I'm Olivia Juan with the Compliance Divas. This episode, we will be talking about complying with obtaining business associate agreements. The compliance divas bring clarity and simplicity to compliance by navigating regulatory compliance to keep you on course. Please subscribe to the Compliance Divas podcast through your favorite podcast channel or on our website, thecompliancedeevas.com. Resources that we mentioned during our podcast can be found at thecompliancedivas.com. We welcome your questions at support at thecompliancedivas.com. Hello, divas, let's get started. Leslie, we would love for you to talk to us about business associate agreements, explaining what actually is the business associate agreement and why are we required to have them in place?
SPEAKER_00Well, to start out, we want to make sure that we have an understanding of what a business associate is. And it doesn't mean the associate dentist that is in your practice. This is not a workforce member of a covered entity. And we're going to say covered entities are dentists for the most part that have to comply with all parts of the HIPAA regulations. So this person either performs a function or an activity regulated by HIPAA on behalf of the dentist. And when they create, receive, maintain, or transmit protected health information, including electronic protected health information, or provide other professional services that requires disclosure of protected health information, you can see how that individual would need to have a contract between the dentist and the business associate. So this way it can establish permitted and required uses of disclosure of protected health information by the business associate. It also means that the business associate will not use or further disclose that information other than permitted or required by the contract or as required by law. And the business associate needs to implement appropriate safeguards to prevent unauthorized use or disclosure of information. So a contract between a covered entity and a dentist, who is a dentist in this case, or for our compliance diva's conversation, would be essential to lay the groundwork for these expectations. Not only are the expectations that a dentist would have of a business associate, but it also satisfies HIPAA's requirement to have the dentist verify that that information of the patient is safe in the hands of that business associate. Whether that's from a technological standpoint, perhaps an IT company where an IT company may have a subcontractor that comes in and does some work on behalf of the IT company and they have exposure to protected health information. So the business associate needs to make sure that all of the individuals who work under them or work for them are also included as protecting the protected health information of the patients. Now, um sometimes uh this doesn't happen because uh we get sometimes very casual relationships with companies that we work with in dentistry. So uh just to be safe and to make sure that we meet all compliance checkpoints, a business associate's agreement is going to review those things, including what would happen in the event that the business associate has a breach of information and uh the patients of the dentist now have exposure, not only their protected health information, but other information, uh social security number, date of birth, or other things that could put them at risk financially of identity theft. Uh, another thing with business associates uh, we want to make sure that at the termination of the contract, that the business associate either returns all the information or destroys all the protected health information. So it isn't something that has an opportunity to be collected by unauthorized individuals at a later date. I think sometimes when we uh work with uh dental consultants at dental practices, um, one case comes to mind where a dental consultant had asked the dentist to provide her with a copy of the accounts receivable in the aging report. And she was going to study that in her hotel room, review all of the information, and then come back to the practice and share with the team her thoughts on how to get those accounts receivables uh in better shape and how to reach out to the clients andor patients and make the collection call. And uh what happened was that information she misplaced it. So there was patient information that uh she doesn't know whether it got picked up and thrown away or whether somebody picked up and actually knew what to do with an aging report. So if a business associate's agreement is in place, it means that the contractor or subcontractor, anybody who who has access to that patient information, uh, makes a promise uh in writing, uh, signs a contract and says, I agree to protect that information.
SPEAKER_01Thank you, Leslie. That's great information. So to summarize, a business associate is a person or an entity who performs functions or activities on behalf or provide services for the covered entity, which in the scope that we're talking about would be that dental practice that involves access to protected health information. The HIPAA rules require that the business associate will appropriate safeguard protected health information. And notice it's not should, it's will appropriately safeguard PHI. And the business associate agreement serves to clarify and limit, as appropriate, the permissible uses and disclosures of PHI by the business associate, which Leslie so beautifully described. And the business associate is directly liable under the HIPAA rules and actually subject to civil and criminal penalties, just like a dental office would be for making uses and disclosures of protected health information that are not authorized or failing to safeguard that information. So this is such a serious aspect of compliance for a dental office. Mary, how do we identify a business associate? Can you help our users there?
SPEAKER_03Absolutely, Olivia and Leslie, thank you for that great explanation and Olivia as well as to what a business associate agreement is. So I always recommend that a dental practice sits down and literally makes a list of everyone that they do business with. So it's your software vendors, um, your credit card, um, processing companies, your accountants, any consultants that you work with. And then you do the test of do they meet the criteria? Do they have access to protected health information or not? Do they utilize protected health information or transmit it? So those are your criteria, and you have to make sure that you are very um thorough in um looking at who are all the folks that you work with. So anyone that can access your server and your patient database for either transmitting information for claims, for um sending transactions from your um your practice and all of those, those that's how you identify who they are. Who has access to your patient's protected health information? A lot of it's done electronically, but I love the example that you gave, um, Leslie, about the the consultant. And early on, when um the HIPAA rules came into effect, I was doing some management consulting with a major consulting company. And I would go in, and the first thing I would do is take a business associate agreement with me for them to sign, and they would say, Well, why? Why do you need to do this? Because I'm going to have access to your patient data and you need the assurance that I'm going to use it appropriately and not do, you know, as you said, Leslie, print it off and then leave it somewhere where someone else could maintain access or gain access to that information. So the the criteria again is do they have access to it? And that means that they need access to it by doing their job, or do they is it transmitted and somehow they are working with that data? Now, here's a good example of a misuse of a business associate agreement. A lot of times people will have a business associate agreement with their cleaning service, and that actually doesn't come under the definition of a business associate because cleaning the office does not require them to have access to patient information, to transmit, to utilize or do anything with patient information, yet they may have access if all the workstations aren't shut down, if they're not password protected, if there are paper charts or information that is left laying on a desk that's accessible to someone when they're doing their job. So in that case, Olivia, I would love for you to weigh in on this as well, that a confidentiality agreement is more appropriate there than if someone might have access, but it's still the onus goes on the practice for making sure that information is secure when someone comes in who isn't authorized to access that information.
SPEAKER_01Yeah, I agree, Mary, that the janitorial service or contractors that come into the building to provide uh work or restorative remodeling would be confidentiality agreements. And even a dental lab would not meet the definition of a business associate. So it's important to zero in on who our business associates are and gather those agreements. So once we identify these business associates, Linda, how should we go about vetting the business associate?
SPEAKER_02Well, Olivia, that's a good question. I'd like to give an analogy to that of selecting any business partner for a practice. Uh, so when we're when a dental practice is selecting any business or company or vendor that they want to do business with, and then because that company or vendor is going to provide a service to the practice, whether it's you know, webmaster or as Olivia, as you and Mary and Leslie have mentioned, you know, even if it's not a business associate, but the areas where we're focusing on now for vetting is strictly business associates. So whether it's a webmaster, an IT company, a software company of any sort, we want to determine, you know, what's their business purpose. And we want typically a practice wants to select the best company they can to do business with for the best results. And that's one side of making a business decision. But the other side is if this business or vendor rises to the level and meets the criteria of being a business associate, then the practice has that legal legal obligation, as you mentioned, to vet the company to be sure they are compliant with the HIPAA security rule in particular. So, what's their level of compliance is the next choice for selecting a vendor or company for a practice to do business with. Because if they're selecting a company only on what they bring value to the practice from helping them to make more money or provide better care, if they have not reached that level of having the value of providing good HIPAA services and being compliant, that a covered entity has not done their due diligence in actually vetting a business that they're going to work with. So vetting a business associate, the office has the legal responsibility of obtaining satisfactory assurances. And that means that in addition to obtaining that business associate agreement, the office has the obligation to go a little further and inquire about the security processes and the means by which this other company is compliant. Um, is very important. So when you think about that level, we're thinking about more than just having a piece of paper signed. It's much more than just signing a business contract and saying, oh, I'm hiring XYZ company to do marketing or website or consulting or IT services, whatever the service is. It's much more than that. It's obtaining satisfactory assurances in a number of ways, one of which is through the business associate agreement. And actually reading that, the off the doctor or the office manager, usually it's the doctor because it's their practice. It's very important that they read this document and see how it outlines the business associates' responsibilities as well as the covered entities' responsibilities. Because we know that there have been documented security incidences such as ransomware, as well as actual breaches involving business associates. And there's been a number of IT vendors across the country for years now, dental IT companies that have had ransomware, and that because of the way it filtrates through their practice, their security techniques, it gets right to their clients, and everybody ends up being locked down. Some of those are more than a security incident, some rise to the level of being a breach, and some have not. But there are other actual incidents where there has been a breach that has been reportable to the Office of Civil Rights, and both the covered entity as well as a business associate was fined for not having the BAA in place, Olivia. So when we think about this, because the security rule, when we think about what do we want to find out from our vendor, our IT company or our software company, see the security rule requires that both covered entities and business associates have administrative, physical, and technical safeguards in place. And under those three categories, there are subcategories of requirements. And those requirements for the technical term are called implementation specifications. But just to be more simple and just kind of talk in general, administrative safeguards consist of things like the security awareness training we're providing our team. So it's more than just a generic HIPAA training. It consists of the written policies and procedures that a business associate would have. And I mentioned I mentioned security training, not just for our teams in the Dillon office, but for the teams, the business associate teams. And then are they doing their security risk analysis like the covered entities are required to do? And so that's a really big point. The physical safeguards would be how are they safeguarding your data? How are they safeguarding, you know, how are they managing your passwords? How are they logging into your server? All those pieces. And then the technical safeguards are guarding against unauthorized access, for example. And that's not an exhaustive list, but those are simple level, high-level examples of administrative, physical, and technical safeguards. So what I'm saying then is that the doctor, the business owner, has the responsibility of asking their business associate these types of questions, whether you put it in a form of an email so you have some documentation, or whether you actually have a questionnaire, that's very important. So the next question is how do they know what to ask? I'm going to give them a simple tip, Olivia. Go back to your insurance application for your cyber risk insurance carrier. And the questions that you have to answer every year about your technical and security safeguards are the questions you should turn around and ask your IT vendor or anybody else that you're working with to be sure they are compliant under the HIPAA laws.
SPEAKER_01Great information, Mary. So it's very advantageous to ask questions of the business associate, as you mentioned. Are they training their staff? Do they have policies? Do they conduct a risk assessment? And what are they actually practicing? So good, good thoughts. I wanted to mention to our listeners about corporate agreements when the dental practice requests a business associate agreement, and rather than the corporate group signing the one they submit, the corporate agency submits one to them. And one of the things to be cautious about is one, make sure you read it, just like Linda pointed out, because if you sign it, that means you agree to the terms, and it is a binding contract. And so we want to look for things such as indemnification clauses or limitations on damages. Some years back I reviewed a business associate agreement where the business associate limited their damages, if there was a security breach, to one month's cost of their services. And that cost was only $200. And so the way the contract read, that you know, if the dental practice incurred thousands or even millions of dollars of expenses, they limited their damages to $200. And so if the dentist or management person entered into that agreement, they they would be contractually bound to those provisions. So I just want to caution people just do not randomly sign these documents. You need to read them, discuss them with your risk management person or your attorney, because this could have an adverse effect on your practice. Uh, let's talk now with the different divas about examples that they'd like to share with our listeners. Uh, divas, which one would like to share some thoughts with our listeners about business associate agreements?
SPEAKER_00Leslie. I find that sometimes we hire um family members or friends to do some of our IT work. And uh many times that's uncomfortable to ask them to sign a business associates agreement because they're not familiar with HIPAA and they're not familiar with uh setting up a dental or a medical practice. So if that's the case, um, or when there's the case of a company that does claim that they uh do IT and have other medical or dental clients, but they're not willing to sign a business associates agreement. So either they don't know what they're required to do to protect uh under HIPAA, to protect the patient's information, or they're uh uncomfortable uh signing something. So in in those two circumstances, Olivia, it would be best not to work with those IT companies. Would I be correct there?
SPEAKER_01I agree with you, Leslie, that if they're not willing to sign an agreement, then obviously we cannot have confidence in their program. Linda, what would you like to share?
SPEAKER_02Olivia, I'd like to add to the point that when we talked about signing the business associate agreement, you mentioned so perfectly that obviously they need to read it, but I would say obviously, but you know how human nature is. Let's go ahead and sign this. We're excited about doing business and you don't take time to read it. But the other piece of that is to be sure that you sign that business associate agreement in a timely fashion. It should be signed, in my humble opinion, as close to the subject date on your contract of doing business with that company, because otherwise, it looks like you shared protected health information with a company that you did not have satisfactory assurances as required by law. So that's a piece that I stress quite a bit, Olivia, to go back and make sure. Because that one very famous landmark case involving a data storage company called File Facts, this happened up in the Illinois area, that subsequently that company went out of business. But neither they nor their businesses, neither they or their covered entity could find their updated business associate agreement. So when they were required to be updated in 2012, 2013, all they could produce was the original one. So neither one of them had that, which implied that perhaps there was no business associate agreement in place, an updated one. And they both got fined and there were issues from that. So, Mary, did you experience something similar?
SPEAKER_03I did, and I'm so glad that you that you brought that up, that you need to. Make sure that, as we've just said, if they're not willing to sign an agreement, don't do business with them. If you don't have something in place right when you start doing services or um they start serving you and um having access to your data, be very careful, very careful. Um, the other thing I wanted to do is go back to and thank you, Olivia, for raising the issue about dental labs, because this has been kind of an ongoing um issue for a number of years, that the relationship of a dental practice with a dental laboratory is considered to be an extension of services, just like referral to a specialist or referral of a specialist to a general practice. We don't need a business associate agreement, we don't need anything in place or um contractually with HIPAA for that referral because patients are agreeing to that. But what happens sometimes is the we don't know what the training is that the laboratory staff have or what their practices are about protecting patient information. And I have two things that happened a number of years ago with clients that I worked with. I stressed so much that they should have a confidentiality agreement with their dental laboratory. Um, and they got a lot of pushback and said, Oh, we don't need to do that. But yet there was a breach of confidentiality with a patient who um, and this is a whole other interesting story. Uh patient had a full upper denture. The spouse didn't know that the patient had a full upper denture. This was a, you know, a marriage later on in life and didn't know. And the patient came in to have the denture relined, and it was sent out to the lab. Somebody at the lab recognized the name, called the house and said, Oh, got the husband or the spouse and said, Oh, don't worry, we're gonna get this done really fast today so they don't have to be without their denture for the whole day. And it just blew up on everybody because it was a major breach in confidentiality. Um, and some of the liability ended up going um back on the practice. They were sued civilly over this whole thing, and they had no kind of an agreement with that dental laboratory about confidentiality. And another instance that I witnessed myself, I'm in a small town where everybody kind of knows everybody, and one of the delivery service drivers came in and had a whole bunch of cases from a nationally recognized laboratory. And at that time, they would put the a label on the outside of the box that had the patient name and what the case was. No need for that whatsoever. And so the poor driver for the delivery services, looking at the boxes, reading down the list of names, and said, Oh, I didn't know so-and-so had a denture. And so we quickly took this young man into a conference room and he was absolutely terrified, just shaking. We're like, You did nothing wrong. We just want you to assure us that you won't repeat that information because we she may be sensitive about this. So don't say anything to anybody, but it's not your fault. And called the dental lab and they said, We did nothing wrong. We're like, nah, yeah, you did. So that's why you need those confidentiality agreements to be in place, even if there's pushback. And I know that it's tough if you have a long history of work experience with a particular lab and they push back at you, then you need to tell them, I'm sorry, but I won't continue to do business unless you change your practices. That's not appropriate. So those are my two very big horror stories from that not using a confidentiality agreement.
SPEAKER_01Thank you for that information, Mary. Uh, a couple of years ago, I had an experience where a dentist was sued by the patient without representation for what she called faulty work. It was an issue over some crowns and whatnot. And it was actually in the wrong court, but I counter-sued her for breach of contract for not paying for those crowns that she said she didn't like. Uh, at any rate, her claim, her cause of action was dismissed because it was in the wrong court. And I prevailed with breach of contract that she never paid in full for her services. But long story short, when I was working with this dentist as the attorney, we entered into a business associate agreement and I limited the scope. And so don't be surprised if you're working with a business associate, such as an attorney or a transition specialist, they may limit the scope according to how the associate is working with the practice. So in this example, I limited the scope to this particular patient's name because I didn't have access to any other information other than hers. And so that's something we can look for in evaluating agreements and making sure we have the necessary documentation in place. So we realize that our listeners are really busy people. You're having to have all your policies and procedures in place, audit the business associate agreements, make sure that they are current, as Linda pointed out. And you may need to even revisit the content to be sure that the current content meets today's standards. Mary, do you have additional suggestions for our listeners?
SPEAKER_03I do, Olivia, a couple of things. Um, one is just a reminder that HIPAA's safe harbor rule would come into play, especially if uh practice has or doesn't have a business associate agreement in place. So we need to yet another reason to make sure that we have them in place and up to date. And then, sort of an aside to this week's topic, um, because many of us have been getting phone calls from practices that are getting solicitation phone calls from companies that want to do a security risk assessment questionnaire with somebody from a practice on the phone. It first and foremost, it's a sales call. It is someone who is trying to solicit you as a client, but they make it sound very official that you must do this and you have to do it right now and have it in place. And we need to spend, you know, 30 minutes and get this done. You first of all need to make sure who it is that you're talking to. Excuse me, who am I speaking to? How did you get my name? Why are you calling me? Because HIPAA does not do unsolicited phone calls to any healthcare providers for doing security risk assessments. So that would be a thank you very much for contacting me. Please take me off your calling list and hang up the phone.
SPEAKER_01Thank you, Mary. So it's critical that the dental office does not give out information. I've had the same support call rolling through our company. So we see that the business associate agreement aspect of our practice does consume quite a bit of time. And we realize that our listeners are very busy people. The compliance divas bring clarity and simplicity to compliance by navigating regulatory to compliance to keep you on course. Please subscribe to the compliance divas podcast through your favorite podcast channel or on our website, thecompliance divas.com. If you have a question about today's episode, please give us an email at support at thecompliancedivas.com. Thanks for listening.