Business associates: Understanding the true risks - Insurance News | InsuranceNewsNet

InsuranceNewsNet — Your Industry. One Source.™

Sign in
  • Subscribe
  • About
  • Advertise
  • Contact
Home Now reading Newswires
Topics
    • Advisor News
    • Annuity Index
    • Annuity News
    • Companies
    • Earnings
    • Fiduciary
    • From the Field: Expert Insights
    • Health/Employee Benefits
    • Insurance & Financial Fraud
    • INN Magazine
    • Insiders Only
    • Life Insurance News
    • Newswires
    • Property and Casualty
    • Regulation News
    • Sponsored Articles
    • Washington Wire
    • Videos
    • ———
    • About
    • Advertise
    • Contact
    • Editorial Staff
    • Newsletters
  • Exclusives
  • NewsWires
  • Magazine
  • Newsletters
Sign in or register to be an INNsider.
  • AdvisorNews
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Exclusives
  • INN Magazine
  • Insurtech
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Video
  • Washington Wire
  • Life Insurance
  • Annuities
  • Advisor
  • Health/Benefits
  • Property & Casualty
  • Insurtech
  • About
  • Advertise
  • Contact
  • Editorial Staff

Get Social

  • Facebook
  • X
  • LinkedIn
Newswires
Newswires RSS Get our newsletter
Order Prints
September 29, 2014 Newswires
Share
Share
Tweet
Email

Business associates: Understanding the true risks

Johnson, Gary
By Johnson, Gary
Proquest LLC

How to keep on top of HIPAAs latest requirements.

New Health Insurance Portability and Accountability Act (HIPAA) rules put in place to safeguard patient data are putting hospitals' business associate relationships and policies front and center. The stepped-up regulations greatly expand the number of vendors that fall into the business associate (BA) category, and all agreements between hospitals and BAs must be in compliance with the new rules by September 22, 2014.

In truth, however, the rules are not the central reason hospitals should be concerned about how their BAs handle patient data. Equally important is the fact that BA data breaches are high-impact, high-probability events that can dramatically affect a hospital's reputation as a trusted provider.

Breaches are also expensive, costing an average $316 per patient record, according to the Ponemon Institute ("2014 Cost of Data Breach Study: Global Analysis"). The penalties for HIPAA violations can be steep, with fines ranging from $ 100 to $50,000 per violation. For example, New York Presbyterian Hospital and Columbia University recently agreed to a $4.8 million settlement with the U.S. Department of Health & Human Services (HHS) Office for Civil Rights (OCR) for a breach that caused the protected health information of 6,800 individuals to be publically accessible via Internet search engines.

Hospitals are also on the hook for costs associated with not attaining Meaningful Use Stage 1, which requires them to have strong data security policies and procedures in place to oversee BA vendors (Core Measure 15). AIS Health reports that the Centers for Medicare & Medicaid Services (CMS) is taking an all-or-nothing approach - hospitals must return their entire Meaningful Use incentive payment if an audit turns up even a minor error in a core measure ("CMS Recoups All Meaningful Use Money From Providers if Audits Turn Up Errors," Nina Youngstrom, September 9, 2013).

Tracking breaches

The OCR tracks all reported patient data breaches, both accidental and malicious. This year, for instance, more than 931 breaches involving more than 500 patients already have been posted, affecting more than 31 million patients overall. OCR does not always indicate BA involvement, so the numbers vary.

A significant percentage - around 35 percent - of BA breaches involve theft, in part because health records are attractive to identity thieves. An April 2014 report from the FBI's Cyber Division said cyber criminals regularly sell partial EHRs for $50 each on the black market, compared to $1 each for stolen social security numbers or credit card numbers. Nor are attacks on healthcare systems likely to abate. The report predicts that lax cyber-security standards, the mandatory transition to EHRs and the high financial payout for medical records will likely lead to an increase in cyber intrusions.

Hospitals earn low marks in pilot audit

The Health Information Technology for Economic and Clinical Health Act (HITECH) requires periodic audits of providers and business associates. In April 2013, OCR released the findings of its 2011 pilot audit program, which measured the efforts of 115 covered entities.

OCR found that most evaluated entities did not meet HIPAA standards for breach notification, privacy and security. It found that two-thirds failed to perform a comprehensive, accurate security risk assessment and that the most common cause of noncompliance was ignorance of the requirement.

Many experts predict that the next round of audits will focus on timely and thorough security risk assessments, effective and ongoing risk mitigation plans, breach notification procedures, encryption, training, and policies and procedures.

"What typically happens is you sign on a new vendor and get the BA agreement [BAA] signed. But then a year goes by, and they fail to keep their documentation up to date and no one realizes it," says Jane Girling, Assistant Vice President of Corporate Materials Management of CentraState Hospital in Freehold, NJ. "For us, it's been critical to tie our vendor and managed care contract requirements to the compliance piece."

Without at least partial automation of the process, getting these policies in place can be overwhelming. "The Deficit Reduction Act is being very stringently administered in New Jersey, so I had to get notices out to vendors concerning state and federal compliance laws on an annual basis, which would have been a total nightmare without a vendor management system. Now, that system is helping us with BAA audits," says Alice Guttler, Sr. Vice President & Corporate Counsel at CentraState.

Hospitals underestimate BA numbers

Correctly identifying all BAs is the biggest problem hospitals encounter as they work to comply with HIPAA Omnibus (which expands the definition of a BA vendor). Assessing a hospital's entire vendor list is a major undertaking. The majority of hospitals have 5,000 or more total vendors, and a significant number of them meet the definition of BA under Omnibus. Every unidentified BA is an unmanaged BA, adding to a hospital's degree of risk.

"Until you start the BAA audit process, you don't realize how many vendors you're actually dealing with," says Guttler. "We have about 2,500 employees and 283 beds, but we're dealing with hundreds of vendors. Initially, the Office of Civil Rights will be [playing an educational role], but they'll start assessing penalties, and that may become pretty costly."

Often, BA risk assessment and oversight is done by the compliance or legal department without coordination with supply chain/purchasing. Because purchasing agents are responsible for vendor selection, managing the relationship and contractual fulfillment, this lack of synchronization can lead to serious challenges. It's not unusual for the number of BAs identified in an initial assessment to be around 250, when the actual number obtained through a complete vendor analysis is closer to 750 or more.

Furthermore, individuals in charge of identifying BAs and overseeing their health information policies often are so laser focused on getting vendors to sign a business associate agreement that other policy omissions result. For each BA, for example, hospitals should have breach notification policies on file.

Best practices for trustee oversight and governance

Effective board oversight of BAs begins with an understanding of HIPAA Omnibus, Meaningful Use Stage 1 and the risks related to noncompliance. To ensure a hospital is taking necessary steps, trustees should ask senior managers the following:

1. How many BA vendors does the hospital have? How many have an up-to-date (compliant) BAA?

2. How often is a report on BA/BAA status distributed, and to whom?

3. Does the hospital have a single, up-to-date vendor master file, or is the data stored in multiple files?

4. What percentage of the hospital's vendors have been screened for BA risk?

5. How many patient data breaches have occurred in the last two years? What was the nature of the breaches? What steps have been taken to prevent similar breaches?

6. How many of the patient data breaches that occurred in the last two years have involved a vendor?

7. What is the status of the hospital's compliance with all the requirements needed to fulfill Core Measure 15 of Meaningful Use Stage 1?

8. Which individuals will be in charge of preparing for an OCR audit? How many days do they estimate they will need to prepare?

With these basics established, board focus should turn to investigating whether or not the organization is adequately preparing for an audit. HHS has specifically stated that covered entities must take dual responsibility for patient data protection by obtaining satisfactory assurances from each BA.

Armed with a full understanding of the challenges of breach prevention - as well as the financial and reputation-related consequences of not meeting the new HIPAA standards - board members can successfully assist senior management with proper planning and budgeting for best practices.

Every unidentified BA is an unmanaged BA, adding to a hospital's degree of risk.

Gary Johnson, Chief Marketing Officer, Vendormate

Copyright:  (c) 2014 NP Communications, LLC
Wordcount:  1285

Older

Losing the veil of confidentiality

Newer

Analyzing failure to prevent problems

Advisor News

  • Global economic growth will moderate as the labor force shrinks
  • Estate planning during the great wealth transfer
  • Main Street families need trusted financial guidance to navigate the new Trump Accounts
  • Are the holidays a good time to have a long-term care conversation?
  • Gen X unsure whether they can catch up with retirement saving
More Advisor News

Annuity News

  • Pension buy-in sales up, PRT sales down in mixed Q3, LIMRA reports
  • Life insurance and annuities: Reassuring ‘tired’ clients in 2026
  • Insurance Compact warns NAIC some annuity designs ‘quite complicated’
  • MONTGOMERY COUNTY MAN SENTENCED TO FEDERAL PRISON FOR DEFRAUDING ELDERLY VICTIMS OF HUNDREDS OF THOUSANDS OF DOLLARS
  • New York Life continues to close in on Athene; annuity sales up 50%
More Annuity News

Health/Employee Benefits News

  • Guess which country pays the most for health care
  • GUEST COLUMN: Working is no guarantee you’ll have health insurance
  • THE PUBLIC PULSE Sunday Public Pulse
  • Stafford woman's premiums set to rise to $2,240 a month Stafford woman's premiums set to rise to $2,240 a month
  • Dec. 15 last day for ACA health coverage starting Jan. 1
Sponsor
More Health/Employee Benefits News

Life Insurance News

  • Legals for December, 12 2025
  • AM Best Affirms Credit Ratings of Manulife Financial Corporation and Its Subsidiaries
  • AM Best Upgrades Credit Ratings of Starr International Insurance (Thailand) Public Company Limited
  • PROMOTING INNOVATION WHILE GUARDING AGAINST FINANCIAL STABILITY RISKS ˆ SPEECH BY RANDY KROSZNER
  • Life insurance and annuities: Reassuring ‘tired’ clients in 2026
More Life Insurance News

- Presented By -

Top Read Stories

More Top Read Stories >

NEWS INSIDE

  • Companies
  • Earnings
  • Economic News
  • INN Magazine
  • Insurtech News
  • Newswires Feed
  • Regulation News
  • Washington Wire
  • Videos

FEATURED OFFERS

Slow Me the Money
Slow down RMDs … and RMD taxes … with a QLAC. Click to learn how.

ICMG 2026: 3 Days to Transform Your Business
Speed Networking, deal-making, and insights that spark real growth — all in Miami.

Your trusted annuity partner.
Knighthead Life provides dependable annuities that help your clients retire with confidence.

Press Releases

  • National Life Group Announces Leadership Transition at Equity Services, Inc.
  • SandStone Insurance Partners Welcomes Industry Veteran, Rhonda Waskie, as Senior Account Executive
  • Springline Advisory Announces Partnership With Software And Consulting Firm Actuarial Resources Corporation
  • Insuraviews Closes New Funding Round Led by Idea Fund to Scale Market Intelligence Platform
  • ePIC University: Empowering Advisors to Integrate Estate Planning Into Their Practice With Confidence
More Press Releases > Add Your Press Release >

How to Write For InsuranceNewsNet

Find out how you can submit content for publishing on our website.
View Guidelines

Topics

  • Advisor News
  • Annuity Index
  • Annuity News
  • Companies
  • Earnings
  • Fiduciary
  • From the Field: Expert Insights
  • Health/Employee Benefits
  • Insurance & Financial Fraud
  • INN Magazine
  • Insiders Only
  • Life Insurance News
  • Newswires
  • Property and Casualty
  • Regulation News
  • Sponsored Articles
  • Washington Wire
  • Videos
  • ———
  • About
  • Advertise
  • Contact
  • Editorial Staff
  • Newsletters

Top Sections

  • AdvisorNews
  • Annuity News
  • Health/Employee Benefits News
  • InsuranceNewsNet Magazine
  • Life Insurance News
  • Property and Casualty News
  • Washington Wire

Our Company

  • About
  • Advertise
  • Contact
  • Meet our Editorial Staff
  • Magazine Subscription
  • Write for INN

Sign up for our FREE e-Newsletter!

Get breaking news, exclusive stories, and money- making insights straight into your inbox.

select Newsletter Options
Facebook Linkedin Twitter
© 2025 InsuranceNewsNet.com, Inc. All rights reserved.
  • Terms & Conditions
  • Privacy Policy
  • InsuranceNewsNet Magazine

Sign in with your Insider Pro Account

Not registered? Become an Insider Pro.
Insurance News | InsuranceNewsNet