Building a Healthy Relationship With Your Business Associates

Sometimes it feels as if the relationship between a covered entity and their business associates is similar to the “friends” you have listed on your social media accounts.  Maybe you truly know, have met in person, have spent time with, have had a meaningful conversation with very few of those people.   I have spoken to some people who don’t even know a single one of the users on their list and yet they call them friend. We’ve all heard the stories of the long distance relationships where the two individuals truly considered themselves “in love”, yet have never met, their story is “all in the cloud”and a cellphone or two. Crazy!  If you are one of those rare few who only accepts or follows people you actually have met in real life, do you follow that practice with your business associates as well?  How do we truly know who we are dealing with if we never cross out of the “virtual”, “remote”, “on paper” reality?  Is that feasible when it comes to our business associates?

“Oh East is East, and West is West, and never the twain shall meet…” Rudyard Kipling, Barrack-room ballads 1892.

Collaboration is the word that pops out again and again as we see the growing trend to provide better health care and timely service.  With the changes to HIPAA via HITECH, business associates are not just the means to an end anymore, they are now more than ever a true partner, a “friend”.  Okay, maybe you don’t have to take it as far as friend, but a healthy relationship with our business associates is going to be more fruitful, more efficient and less likely to have a negative impact on our ability to provide health care services.

Where should the collaboration begin?

The obvious first place is the agreement.  Rather than approaching the development of the business associate agreement as a “check box”, why not approach it as the first opportunity to define and guide a healthy relationship?  One in which both parties are aware of their obligations, expectations, and builds a communication standard that is multi-directional not covered entity driven.

The next place where collaboration would be very helpful to the business associate would be on security policies.  By highlighting the need for them to be reviewed by the covered entity and providing detailed expectations for security and privacy outcomes, a collaboration will naturally occur.  Business associates are not as well-versed in the requirements and a little guidance from the covered entity will help them frame the strategy that is appropriate for them while understanding the needs of the covered entity.

Now let’s be clear here, when we use the term collaboration,we are not saying, “What I say goes!”, “I” being the covered entity.  To truly collaborate the business associate must also have a voice.  The law does give them this voice.  It states that security and privacy measures need to be reasonable and appropriate for the organization’s environment.  The covered entity may suggest what they want them to do, but demanding them to do certain things may not be doable in their environment.  If it is a “must have” then you may need to find a different business associate who can afford to implement and maintain that particular type of a provision.  I think we forget sometimes that there is more than one way to secure data, and the law recognizes that, which is why it describes end results for security and privacy not specific tools.

Are you collaborating with your business associates?  How would you describe your relationship?

Will The Privacy Debate Impact Health Care?

So I’m going to throw this out there and see what sticks.  This post isn’t so much focused on business associates but privacy in health care in general.  Let’s start here: Apple vs FBI.  Snowden vs NSA.  These are two of the more high profile cases for this war on privacy.  The current court-ordered request for Apple to assist the FBI in a terrorist investigation is just embroiling the debate even further.  In this time of uncertainty and potential changes in the nation’s efforts to either muddy or clarify the line of individual privacy, one does have to wonder will it change the way HIPAA is written?

PrivacyWithin HIPAA we have a clause that law enforcement can access protected health information without individual consent in order to investigate a potential crime, breach or fraudulent incident, 164.512 (f)(1)(ii)(C).  Not having been as close to this industry when HIPAA was initially passed in 1996 and modified in 2003 where it first opened the door to law enforcement accessibility, I would be interested to hear from those of you that were, if there was a cry of “foul” at that time.  It seems to have quietly passed and become an accepted practice in order to track down fraudsters and the criminally minded.  Matter of fact several entities highlight in their Notice of Privacy Practices that they will provide your information to law enforcement without individual consent in order to assist in an investigation.  On the other hand, some covered entities still insist on a warrant before providing the information.  This is very interesting since in many cases individual protected health information is considered something much more private and personal to most folks and not something they particularly want shared with the masses especially if it is something of an embarrassing nature.  But even the covered entity requesting the warrant isn’t notifying the individual patients that their information may be involved in a law enforcement investigation.

Most individuals don’t even give a second thought to the fact that the covered entity may share their PHI with a business associate.  Individuals come in and expect to be treated and cured of whatever is ailing them at that moment in time.  They understand that the covered entity will take appropriate steps to ensure that only individuals responsible for providing that care have access to the information, but they aren’t asking for a list of who all that might be.  Sure with the changes in the law in 2009 they can now ask for a detailed accounting of disclosures, but how often do they?  In most of these situations where someone does request the information, they were tipped off by some suspicious behavior not so much just a question that came up in their mind of “what if?”.

With regards to business associates, during a recent conversation with a covered entity they mentioned that they didn’t turn on a particular option for a vendor’s solution because it would require the decryption of PHI on a vendor server giving access to the data by the vendor and the vendor refused to sign a business associate agreement. This highlights something that I think will be at the center of this debate for health care, that the covered entity is actually more concerned with privacy than the actual patient might be because of the way HIPAA is currently worded.

So that leads to how the covered entity is handling the privacy issue on their patient’s behalf.  How many of your vendors have access to your clear text PHI even though it may have been encrypted during transmission?  Do you have a business associate agreement (BAA) with them?  Do they have a privacy and security clause in their service level agreement which enumerates what they will and won’t do if you don’t have a BAA? How many of your third party suppliers would feel they are in the same situation as Apple should a criminal investigation be warranted?

Maybe just opening a can of worms, but one does have to wonder.

Ending the Relationship With a Business Associate – Now What?

breaking upThere will come a time, when the honeymoon will be over and a covered entity will no longer wish to do business or cannot do business with a business associate.  Although we now have a National Break -Up Day which usually occurs on the Sunday in January before Martin Luther King’s Birthday weekend, to help people let go of their tumultuous personal relationships, ending a business relationship takes  a lot more paperwork and planning.  There may be outstanding invoices, mid-process transactions to finalize, but no matter how the relationship ended, the most important item that needs to be planned well in advance is: How do we get our PHI back?

I believe we mentioned this a while back when discussing business associate agreement clauses.  Did you remember to put that one in there?  How do you get your PHI back?  How do you ensure that there are no residual fragments “laying” around?  

What happens if the business associate files bankruptcy?  Ouch, that’s a tough one.  Do you file a claim as a creditor?  Who ensures the data is secure while on-going proceedings determine final disposition of assets?

What happens if the business associate refuses to cooperate?  Good example of an on going case for this one, State of Texas vs Xerox The State of Texas later reports a breach caused by Xerox putting themselves in jeopardy of being fined.  And it wouldn’t be a small fine.  The claim alleges that Xerox still has 2 million records.   This case is still on-going.  So we’ll have to check back to see how this pans out for both parties.  For breach details read more here.

Does filing a breach due to an inability to get the data back create a liability for the covered entity or the business associate?  A judge and/or jury will decide that one.  It will more than likely be based on evidence of how well the relationship was managed by the covered entity.  What protocols were put in place to prevent the risk if possible?  How were attempts made to retrieve the data?  When were attempts made to retrieve the data?  Is it reasonable to expect the data to be compromised if it remains with the business associate?

This does make me wonder how many past relationships were ended and the PHI is floating around in no-man’s land.  What happens if someone stumbles across it today?  Hopefully that doesn’t happen, but it may be worth it to retrace steps and make sure it can’t happen.  Preventing the situation would be best.  Planning an “out” is not only good business, it is also good sense.  

How far along is your business associate risk management program?  Does it include tracking relationships that have ended and the process of reclaiming any PHI shared?  If it doesn’t, it should.   

 

 

Will HHS Get More Money?

Keeping it simple this week and providing an update on funding initiatives currently being pursued by the federal government to give HHS more money to conduct additional audits.  As we have previously been warned, this next round will include business associates.  Do you know how well your partners will do?

From here I’ll turn it over to the informative HealthCare Info Security team.

Read More…

Enjoy the President’s holiday weekend and if you celebrate have a Happy Valentine’s Day!

 

Who Should be Invested in Business Associate Risk Management?

When it comes to the potential risk of a PHI breach, it isn’t only the compliance department’s job to know and remediate the potential risks, but requires many “investors” to effectively manage an organization’s risk profile, including the risks represented by your business associates.  Who have you invited to the table?

In a previous post, I mentioned the collaborative effort between security and compliance that can make any risk management process more effective.  With business associate risk management, that same team is needed in addition to a few others that you may or may not have considered or may not have the best relationship with today.

Have you considered or do you already work closely with your legal team?  

Have you considered or do you already work closely with your finance team?

Do you have any assigned project managers that work directly with specific types of business associates?

Do you communicate with the various locations, department heads, etc. to maintain a dialogue on concerns they may have about a particular business associate(s)?

Do you have an open communication with business associates that allows them to ask for help or seek guidance?

When looking at your team of “investors”, we want to establish those relationships that will more effectively help us reach our goal of decreasing the risk to the organization.  No one person or department can make that happen, this has been proven time and time again in organizations of all sizes.  There is only so much time in the day to complete the myriad of activities that need to be addressed, the emails that need to be responded too, and deadlines to meet.  We want an effective team that can divide and conquer the challenge that is business associate risk management.

Who have you invited to your table?

 

How Did We Get HERE?

As the first month of the New Year, quickly comes to a close, I took a moment to think about the progression of HIPAA, the threat evolution, and the varying changes in the health care industry over the years.  I saw an article the other day “threatening” yet again to make changes to Meaningful Use.  We saw the last few modifications from the 2009 enactment of HITECH take effect in 2015.  A doctor was just found guilty of Medicare fraud to the tune of $20 Million.  There has been an uptake in the legal cases between companies providing cyber insurance and covered entities with both parties instigating the litigation for or against denied payouts.  Hackers are loading malware on medical devices to breach covered entity networks.  AND there were some positive developments too…but one can only start to imagine, what will be next?

But before we do, lets quickly take a look at the transition of the 1996 HIPAA to the 2009 HIPAA/HITECH.  And lets focus on what it has meant for business associates versus what has changed for covered entities.  For covered entities, if you break it down to the nuts and bolts, not much of the intent has actually changed, so why beat that to death.  For business associates, however, this stuff just got REAL!

Business Associates have suddenly had the light shined on them and the darkness was hiding some pretty disappointing realities.  But now that these issues are uncovered, we can start to address them and decrease the risk footprint to the covered entity.

REALITIES

Business Associates didn’t necessarily have satisfactory assurances in place, just hoped they would never be checked up on.  Gone are the days of covered entity only audits, business associates are targets of opportunity for HHS now and have hopefully taken an active approach to being prepared.  As the covered entity though, it is now more important than ever that steps are taken to ensure that there will be no surprises if one of your business associates come under the microscope.

Business Associates are not as well-versed in the need for security and privacy and need some training.  For several of the business associates I have worked with over the last couple of years, HIPAA is a caged beast that is easier to shut the door on rather than tame.  Covered entities need to spend some time determining to what level are their critical business associates lacking in their understanding of the requirements and provide action plans for them to meet the expectations.  Yes, I know, easier said than done, but doable.

Business Associates hope they won’t get caught.  Well, who doesn’t, but unfortunately the breach numbers have painted an ugly picture we can no longer ignore.  Leaving business associates unattended is playing with a live stick of dynamite.  Rather than waiting for it to explode, covered entities need to take the necessary steps to keep the dynamite from becoming active.  The nature of sensitive data transactions will always be like a stick of dynamite, but we know that if we keep it away from an ignition source, it is less likely to explode.  

A NEW YEAR

2016 is here, its begun, its a new year of opportunities and challenges.  What will you do differently this year?  I hope you tame the “caged beast” or as we so commonly like to refer to them around here your “hipaa-potumus”.

 

Business Associates and The Covered Entity’s Network

Sample NetworkThis week’s post is more from a security perspective and not as compliance-focused as we typically tend to be. I hope within most organizations there is a working relationship between the security and compliance teams because without it, effectively protecting the organization will continue to be an uphill battle.  To empower this relationship, it is important for the compliance team to spend some time understanding the challenges the security team faces and visa versa.

Let’s take a look at the Target breach.

Target? But their a retailer.  Uh huh…with in-house Pharmacy services…this could have been even worse than it was.

In 2014, the breach was due to a “backdoor” that allowed a sub-contractor network access to Target’s main network where the hackers eventually downloaded malware on a large majority of the POS machines nationwide.

For Target, a little more homework needed to be done when it came to verifying that the contractor could only access the information they needed to provide services and “lock the door behind them” when access was not needed.  How common do you think this is for most covered entities?  HIPAA isn’t the only regulatory concern here, but also PCI-DSS requirements that need to be met to ensure that this type of access is appropriate and secure if needed.  Securing the perimeter has grown into a challenge that many are not meeting.  Never mind the fact that the “perimeter” has now expanded outside of the organization’s physical walls for their own employees who may work from home or work for more than one provider.

To address this scenario as a covered entity, we must first identify business associates and group them in such a manner that you know who actually needs to touch your network in order to provide services and/or access ePHI.  Did you do that part? Even better if you can figure out how to avoid any network access.  Once, we scale down the list of potential threats (business associates), we can start looking at how they need to access a database, or an EHR tool, or a file share, etc.

The security team needs to look at these vectors and determine how to protect the transmission of the ePHI, grant permissions to access the data, and ensure the integrity of the data is maintained.   Encryption being our get out of jail free card is only a small part of the response.  The Security team might ask and need to answer:

  1. Is a VPN tunnel appropriate and necessary?
  2. Is there a need for two-factor authentication to protect against malicious internal actors or a man-in-the-middle attack?
  3. Would a web gateway provide enough protection for web-based portal access?
  4. Should we look into the concept of a Software Defined Perimeter?
  5. What type of permission does the BA need to access an application; read-only, download allowed, upload allowed, etc.?

…and on and on and on depending on how advanced any existing technology already is, the skill-set of the security team, and even the abilities of the business associate.

Security leads to compliance, compliance does not lead to security.  Hopefully this concept is followed and applied in your organization.  Helping the security team complete the gap analysis to better protect against a breach stemming from a business associate activity can be very fruitful for both security and compliance.  No one likes the finger to be pointed at them when an incident occurs.  Identifying how much network access a business associate really needs to provide services is a group effort.  Be on the side of prevention rather than reaction.

Minimizing Risk with De-identified Data

De-identifiying protected health information (PHI) can be a challenge but implementing a manageable process may be one of the more strategic ways to minimize risk when sharing information with business associates.  When referencing the legal requirements we see from 164.514 that this type of strategy would apply under Other requirements relating to uses and disclosures of protected health information.  If we can de-identify the information then we don’t need an agreement or relationship to the level that may be appropriate for other business associates and we minimize the risk of a breach since the information shared with the other organization is no longer PHI.

(a) Standard: De-identification of protected health information. Health information that does not identify an individual and with respect to which there is no reasonable basis to believe that the information can be used to identify an individual is not individually identifiable health information.

Process

In order to determine if de-identification is a viable risk avoidance method, we first need to define a process for using this type of control.  The questions that would define our process would be in line with the questions that may be integrated into a business associate risk management program.  Let’s highlight the ones that would be beneficial for this scenario:

  • Does the business associate need PHI to perform the services that support our operations?
  • Would they still be able to perform the service with de-identified information?
  • If yes, what identifiers need to be removed?
  • How do we remove those identifiers?
  • Can an individual be identified after those identifiers are removed?
  • If no, how do we secure the methodology to remove the identifiers?

These questions get us started and define the profile of the business associate that would fit this model, the outcome of the final file/document that would be used to provide services, as well as ensuring that the outcome cannot be reversed engineered to identify an individual if the information is compromised.

Tools

In our world of technology and do more with less, the next question is how do we automate the process of de-identifying and tracking when the process is used?  Some organizations may be able to take advantage of a data classification tool which could be used to verify that any files created did not contain PHI. The methodology for data classification tools has come a long way but may not be as fined tuned to meet this strategy if you don’t have a team that works with the solution daily.

On the other hand, there are tools available on the market that are designed to do exactly what we would like, de-identify PHI.  Selecting one of these tools requires a firm understanding of your process, the desired outcomes, and evaluation of the security protocols that are in place to ensure that the methodology used to de-identify the PHI cannot be reproduced outside of the tool.

De-identification of PHI is smart for both the covered entity and the business associate.  The end result: minimizing risk of a breach.

Medical Devices and PHI

wireless med devices

Ahhh….the new Year 2016.  What joyous news of threats, vulnerabilities and plain annoyances will this year bring?  Many in the industry are predicting that medical devices will be the target of choice for hackers in the coming year.  A much talked about topic as early as 2013, but not much significant chatter since.  That’s a little scary since this type of hack has some very serious and potentially deadly outcomes, its not just about data being stolen. Usually when the industry is quiet, the hackers are busy and planning their next assault.

The advancement of technology to remotely monitor a person with health issues and help prevent or treat a condition “from afar” definitely sounds good on paper, but what do we have to deal with in reality?  Not only are there HIPAA implications, but also FDA, FCC, and even some state laws that govern what is and what isn’t acceptable for these types of devices.  Some would say there still isn’t enough guidance surrounding this frontier and we are navigating the unknown.  The Center for Internet Security started a joint effort partnering with Medical Device Innovation, Safety and Security, but even they have been pretty quiet of late.  If this is the case, we really need to answer a key question sooner rather than later:

Who is responsible for implementing the controls to prevent these types of devices from being compromised, the covered entity that provides the data and prescribes the device or the business associate that builds and/or maintains the device?

When we break it down there could potentially be multiple business associates that come into play for just one type of medical device; the hardware manufacturer, cloud services, the software developer if different from the hardware manufacturer, etc.  All of these relationships lead to liability issues, breach risks, and unfortunately potential loss of life.

For those of us who think this is still an unlikely event, I remind you that we have already seen hackers take over similar devices in vehicles and cause major accidents along with just the unimaginable feeling of terror that someone else is controlling your vehicle while you are supposed to be driving it.  We’ve already had breaches linked to malware in medical devices that hackers used to bypass network security and steal sensitive data, it just didn’t make as a big a splash as they hoped.

Your business associate agreements are going to be key to managing this potential nightmare.  The lawyers on both sides are going to want their two cents documented and a compromise is going to be hard fought and not always won.  As is typical in this “stage of seemingly newness”, do you act or wait to react?

Holiday Wishes

As the last few holidays of the winter season wrap-up and we start to think about what the New Year will bring, I just wanted to take a moment to say, “Thank You!” for being a part of our conversation.

Although it is often times one sided, hopefully the information you have found here is helpful and actionable.  We are always interested in the community’s feedback and requests for additional information.  Please keep them coming or post your first comment/question that might help others take that next step to developing and implementing a business associate risk management program.

Merry Christmas!