You’re probably saying to yourself, “Hey, I’m a lawyer! Why is this guy telling me about HIPAA?”

The short answer is you may very well NOT need to care about it. On the other hand, depending on the types of cases you handle and the types of clients you serve, you may very well NEED to be concerned with HIPAA.

Why? Because there is something known as a “business associate” which has recently been expanded to cover not only those doing business with so-called “covered entities” like doctors, dentists, hospitals, and insurance companies but also those doing business with those doing business with covered entities, and all the way down the line.

It all has to do with access to PHI – protected health information. If you are working on cases for doctors, dentists, hospitals, or other covered entities as defined by HIPAA, and you may have access to PHI, then you are considered a business associate and are regulated by HIPAA.  With the recent “OMNIBUS” rules, that has been expanded so that if you are working on cases for a business associate of a covered entity, and you may have access to PHI, then YOU are considered a business associate as well and are regulated by HIPAA.  You may have absolutely no medical clients but may STILL be regulated by HIPAA because you may have clients that are business associates of one.

Let’s say that you are working on a case for an accountant, and that accountant does work for a doctor’s office. Through that accountant’s work for the doctor’s office, he or she has access to PHI, which may very well be included in the doctor’s books (names, procedures done, etc.).  If your case gives you access to those books, you have access to PHI, and thus, you’re considered a business associate.

But the accountant never had me sign a HIPAA BAA (business associate agreement)?

That’s their failing, and their HIPAA non-compliance. You are still considered a business associate, and are still regulated under HIPAA.

But my bar association says that I don’t have to worry?

Will they defend you if you’re found in violation? Professional associations do stupid things all the time, and many have financial reasons for doing so.  The ADA has been advising dentists that all they need is a cursory signed BAA that doesn’t even cover most of the things that are required in a BAA and they’re automatically compliant.  Doesn’t matter what they do in their own offices.  The ADA also managed to send out thousands of thumb drives infected with a virus.  Would YOU trust them – or other professional organizations?

Ok, so I’m a business associate. What does that mean?

Well, it means that you’re regulated by HIPAA, and must obey all of the security and privacy rules. That includes getting a BAA from anyone who services YOUR business and who may have access to PHI.  That includes computer people, who would, in turn, have to be HIPAA compliant.  It means training all of your staff on the security and privacy rules.  It means doing an audit of your risks.  It means having a designated HIPAA security officer.  It means that all of your software and systems and procedures must not cause non-compliance.

Will YOUR IT company sign a HIPAA BAA? Do THEY know anything about HIPAA?  Are THEY compliant?