Business Associate Agreements and HITECH: When to Amend?

June 24, 2011
The HITECH Act requires that certain new provisions be included in HIPAA business associate agreements by February 18, 2010.  The problem is that

The HITECH Act requires that certain new provisions be included in HIPAA business associate agreements by February 18, 2010. The problem is that the Department of Health and Human Services ("HHS") has yet to offer clarification regarding the precise provisions that must be included in these new business associate agreements or sample contract language.

On May 29, in a posting on a Health Care Compliance Association listserv, Susan McAndrew, Senior Policy Specialist with the HHS Office for Civil Rights ("OCR"), stated that OCR will be working over the summer on a proposed rule that should be issued later this year. Ms. McAndrew also noted that OCR has not yet updated the model business associate agreement on the OCR website.

So what do you do if you must enter into a business associate agreement today that will have a term that will run through February 18, 2010? You can either take your best shot at addressing HITECH requirements, with the understanding that subsequent modifications may be necessary, or you can amend the agreement in late 2009 or early 2010 when (hopefully) recommended sample provisions and additional guidance will be available. These are questions that HIPAA covered entities and business associates are grappling with right now. One consideration favoring amending business associate agreements early is the fact that the new security breach notification obligations imposed on business associates will become effective by September 18, 2009 (or sooner, depending on when HHS issues final regulations on the subject).

Sponsored Recommendations

A Cyber Shield for Healthcare: Exploring HHS's $1.3 Billion Security Initiative

Unlock the Future of Healthcare Cybersecurity with Erik Decker, Co-Chair of the HHS 405(d) workgroup! Don't miss this opportunity to gain invaluable knowledge from a seasoned ...

Enhancing Remote Radiology: How Zero Trust Access Revolutionizes Healthcare Connectivity

This content details how a cloud-enabled zero trust architecture ensures high performance, compliance, and scalability, overcoming the limitations of traditional VPN solutions...

Spotlight on Artificial Intelligence

Unlock the potential of AI in our latest series. Discover how AI is revolutionizing clinical decision support, improving workflow efficiency, and transforming medical documentation...

Beyond the VPN: Zero Trust Access for a Healthcare Hybrid Work Environment

This whitepaper explores how a cloud-enabled zero trust architecture ensures secure, least privileged access to applications, meeting regulatory requirements and enhancing user...