HIPAA
A signed HIPAA business associate agreement with every practice
My Dental IT signs a formal HIPAA business associate agreement (BAA) with every customer to maintain patient confidentiality. Here is what a BAA is, what HIPAA says it must cover, and how we help protect your patients’ data.
Protecting patient dataWhat we take care of
- Office networkSecured against intruders and unauthorized users
- Malware protectionKeeps digitally stored patient information safe
- Backup systemsSet up so vital data is not lost
- Kept informedChanges, planned maintenance and system updates
Signed HIPAA BAA with every customer
The basics
What a HIPAA business associate is
HIPAA’s Privacy and Security Rules are built around covered entities: health plans, health care clearinghouses and health care providers that conduct certain transactions electronically, such as sending insurance claims. A dental practice that bills insurance electronically is generally a covered entity.
Under 45 CFR 160.103, a business associate is a person or company outside your workforce that creates, receives, maintains or transmits protected health information (PHI) on your behalf. An IT company that supports the computers, server and software holding your patient records usually fits, because it can reach that information while doing its job.
- Covered entity: your practice, which holds patient information and is responsible for protecting it.
- Business associate: an outside company that handles PHI for you, such as an IT provider or a billing service.
- Subcontractor: a company your business associate hands part of its work to that also handles PHI. HIPAA treats it as a business associate too.
- Dental practice
- IT company
- Subcontractor
Business associate agreementsNeeded at each link in the chain
- Dental practiceCovered entity that holds patient information
- IT companyBusiness associate of the practice
- SubcontractorBusiness associate of the IT company
What the rule requires
What a HIPAA business associate agreement must cover
HIPAA requires a covered entity to have a written contract with any business associate that creates, receives, maintains or transmits PHI on its behalf, and it sets out what that contract has to say.
The requirement appears in the Privacy Rule at 45 CFR 164.502(e) and 164.504(e), and in the Security Rule at 45 CFR 164.308(b), with the Security Rule’s contract terms in 164.314(a). HHS publishes sample business associate agreement provisions that show how these terms are commonly written. Every agreement is worded differently, but the rules require these terms.
| Requirement | What it means | Where in 45 CFR |
|---|---|---|
| Permitted uses and disclosures | Says how the business associate may use and disclose PHI. It may not use or disclose it any other way unless the law requires it. | 164.504(e)(2)(i) and (ii)(A) |
| Appropriate safeguards | The business associate uses appropriate safeguards and follows the Security Rule for electronic PHI. | 164.504(e)(2)(ii)(B); 164.314(a)(2)(i)(A) |
| Reporting incidents and breaches | It reports uses or disclosures the contract does not allow, security incidents, and breaches of unsecured PHI. | 164.504(e)(2)(ii)(C); 164.314(a)(2)(i)(C) |
| Subcontractors | Any subcontractor that handles the PHI agrees to the same restrictions and conditions. | 164.504(e)(2)(ii)(D); 164.314(a)(2)(i)(B) |
| Return or destruction | When the contract ends, PHI is returned or destroyed if feasible. If not, its protections continue. | 164.504(e)(2)(ii)(J) |
| Patient rights and HHS access | It helps with patients’ access, amendment and accounting rights, and makes its records available to HHS for compliance reviews. | 164.504(e)(2)(ii)(E) to (G) and (I) |
| Termination | The covered entity can end the contract if the business associate violates a material term. | 164.504(e)(2)(iii) |
Data is your most valuable asset. Protecting it is our number one responsibility.
Our part
How My Dental IT helps protect your patients’ data
We don’t take that responsibility lightly. Alongside the signed agreement, we look after the systems that store your patient information.
A formal BAA with every customer
HIPAA expects an IT provider that handles your patient information to sign a business associate agreement. We sign a formal one with every customer.
A secure office network
We configure your network to be secure without slowing your team, and protect it against intruders and unauthorized users. See dental office network security.
Malware and virus protection
We install and maintain malware and virus protection that keeps digitally stored patient information safe.
Backups against data loss
Backup systems and recovery software help make sure vital patient and practice data is not lost.
You are kept informed
We tell you about changes to your network, planned maintenance and system updates, so you know what is happening to the systems that hold patient data.
Built for dental offices
Our founding members have more than 10 years of hands-on dental practice IT experience. Read how My Dental IT started inside a dental practice.
Know the limits
What a BAA does not do
A signed business associate agreement is a requirement, not a compliance program. It does not make your practice compliant with HIPAA on its own, and it does not move your own obligations onto your IT company.
As a covered entity, your practice still needs its own safeguards under the Security Rule (45 CFR Part 164, Subpart C) and its own Privacy Rule practices. A BAA cannot cover these for you.
- Your own risk analysis: an accurate and thorough assessment of the risks to the electronic PHI your practice holds (164.308(a)(1)(ii)(A)).
- Risk management, so the risks you find are reduced to a reasonable and appropriate level (164.308(a)(1)(ii)(B)).
- Written policies and procedures, kept up to date and available to the people who use them (164.316).
- Security awareness training for everyone on your team, including management (164.308(a)(5)).
- BAAs with your other vendors that handle PHI, not only your IT company.
- Privacy Rule duties, such as your notice of privacy practices and patients’ right to see their records.
Questions
Questions about HIPAA business associate agreements
Does My Dental IT sign a HIPAA business associate agreement?
Yes. Every customer has a formal HIPAA business associate agreement with My Dental IT, which maintains the confidentiality of your patients’ information. We install and maintain the computers, servers and software that hold patient records, so the agreement matters. To ask about it or get started, send us a message through our contact page or call us.
Does a signed BAA make my practice compliant with HIPAA?
No. A BAA covers one requirement: written assurances from a business associate that handles PHI for you. Your practice is still responsible for its own risk analysis, risk management, written policies and procedures, and workforce training under the Security Rule, along with its Privacy Rule duties. Our HIPAA Security Rule IT checklist covers the IT side.
Which of my vendors need a business associate agreement?
Generally, any outside company that creates, receives, maintains or transmits PHI on your behalf is a business associate and needs a BAA. Common examples include IT providers, billing services and document-destruction companies. Your own employees are part of your workforce, not business associates. When you compare IT companies, put a signed BAA on your list; see how to choose a dental IT provider.
What happens to patient data when a business associate relationship ends?
HIPAA requires the agreement to address this. When the contract ends, the business associate must return or destroy all PHI it received or created for the practice, if that is feasible, and keep no copies. If return or destruction is not feasible, the agreement must extend its protections to that information and limit further uses and disclosures to the reasons that make return or destruction infeasible (45 CFR 164.504(e)(2)(ii)(J)).
IT support that starts with a signed BAA
Tell us about your office, and we’ll talk you through how we look after the systems that hold your patients’ information.