Sometimes it feels as if the relationship between a covered entity and their business associates is similar to the “friends” you have listed on your social media accounts. Maybe you truly know, have met in person, have spent time with, have had a meaningful conversation with very few of those people. I have spoken to some people who don’t even know a single one of the users on their list and yet they call them friend. We’ve all heard the stories of the long distance relationships where the two individuals truly considered themselves “in love”, yet have never met, their story is “all in the cloud”and a cellphone or two. Crazy! If you are one of those rare few who only accepts or follows people you actually have met in real life, do you follow that practice with your business associates as well? How do we truly know who we are dealing with if we never cross out of the “virtual”, “remote”, “on paper” reality? Is that feasible when it comes to our business associates?
“Oh East is East, and West is West, and never the twain shall meet…” Rudyard Kipling, Barrack-room ballads 1892.
Collaboration is the word that pops out again and again as we see the growing trend to provide better health care and timely service. With the changes to HIPAA via HITECH, business associates are not just the means to an end anymore, they are now more than ever a true partner, a “friend”. Okay, maybe you don’t have to take it as far as friend, but a healthy relationship with our business associates is going to be more fruitful, more efficient and less likely to have a negative impact on our ability to provide health care services.
Where should the collaboration begin?
The obvious first place is the agreement. Rather than approaching the development of the business associate agreement as a “check box”, why not approach it as the first opportunity to define and guide a healthy relationship? One in which both parties are aware of their obligations, expectations, and builds a communication standard that is multi-directional not covered entity driven.
The next place where collaboration would be very helpful to the business associate would be on security policies. By highlighting the need for them to be reviewed by the covered entity and providing detailed expectations for security and privacy outcomes, a collaboration will naturally occur. Business associates are not as well-versed in the requirements and a little guidance from the covered entity will help them frame the strategy that is appropriate for them while understanding the needs of the covered entity.
Now let’s be clear here, when we use the term collaboration,we are not saying, “What I say goes!”, “I” being the covered entity. To truly collaborate the business associate must also have a voice. The law does give them this voice. It states that security and privacy measures need to be reasonable and appropriate for the organization’s environment. The covered entity may suggest what they want them to do, but demanding them to do certain things may not be doable in their environment. If it is a “must have” then you may need to find a different business associate who can afford to implement and maintain that particular type of a provision. I think we forget sometimes that there is more than one way to secure data, and the law recognizes that, which is why it describes end results for security and privacy not specific tools.
Are you collaborating with your business associates? How would you describe your relationship?
Within HIPAA we have a clause that law enforcement can access protected health information without individual consent in order to investigate a potential crime, breach or fraudulent incident, 164.512 (f)(1)(ii)(C). Not having been as close to this industry when HIPAA was initially passed in 1996 and modified in 2003 where it first opened the door to law enforcement accessibility, I would be interested to hear from those of you that were, if there was a cry of “foul” at that time. It seems to have quietly passed and become an accepted practice in order to track down fraudsters and the criminally minded. Matter of fact several entities highlight in their Notice of Privacy Practices that they will provide your information to law enforcement without individual consent in order to assist in an investigation. On the other hand, some covered entities still insist on a warrant before providing the information. This is very interesting since in many cases individual protected health information is considered something much more private and personal to most folks and not something they particularly want shared with the masses especially if it is something of an embarrassing nature. But even the covered entity requesting the warrant isn’t notifying the individual patients that their information may be involved in a law enforcement investigation.
There will come a time, when the honeymoon will be over and a covered entity will no longer wish to do business or cannot do business with a business associate. Although we now have a National Break -Up Day which usually occurs on the Sunday in January before Martin Luther King’s Birthday weekend, to help people let go of their tumultuous personal relationships, ending a business relationship takes a lot more paperwork and planning. There may be outstanding invoices, mid-process transactions to finalize, but no matter how the relationship ended, the most important item that needs to be planned well in advance is: How do we get our PHI back?
This week’s post is more from a security perspective and not as compliance-focused as we typically tend to be. I hope within most organizations there is a working relationship between the security and compliance teams because without it, effectively protecting the organization will continue to be an uphill battle. To empower this relationship, it is important for the compliance team to spend some time understanding the challenges the security team faces and visa versa.
You must be logged in to post a comment.