HITECH and Business Associates: Tom Walsh episode artwork

EPISODE · Apr 19, 2010

HITECH and Business Associates: Tom Walsh

from Healthcare Information Security Podcast · host HealthcareInfoSecurity.com

Healthcare organizations must revamp their business associate contracts to help ensure compliance with the HITECH Act's breach notification rule, says security expert Tom Walsh. In an interview, Walsh points out that under the rule, business associates, such as banks, billing firms and software companies, that have access to protected health information must report breaches to their healthcare partners, such as hospitals and physician groups, as well as affected patients. He advises healthcare organizations revamping contracts to: Spell out what breach-related information the business associate must collect to meet HITECH requirements. Specify who the business associate should contact by phone at a healthcare organization in the event of a breach, and prohibit the use of e-mail for notification. Require the business associate to have insurance to cover the cost of breach-related expenses. Spell out that the business associate must comply with all aspects of the HIPAA security rule. Require the business associate to use encryption to take advantage of the HITECH safe harbor, which states breaches of encrypted information need not be reported to regulators or consumers. Walsh is president of Tom Walsh Consulting, an Overland Park, Kan.-based firm that advises healthcare organizations on risk management strategies. He is one of the authors of a new book, "Information Security in Healthcare: Managing Risk," published by the Healthcare Information and Management Systems Society.

Episode metadata supplied by the publisher feed · Published Apr 19, 2010

Embed this episode

NOW PLAYING

HITECH and Business Associates: Tom Walsh

0:00 0:00

No transcript for this episode yet

We transcribe on demand. Request one and we'll notify you when it's ready — usually under 10 minutes.

No similar episodes found.

No similar podcasts found.

Frequently Asked Questions

When was this Healthcare Information Security Podcast episode published?

This episode was published on April 19, 2010.

Can I download this Healthcare Information Security Podcast episode?

Yes. Use the download control on the episode player to save the publisher-provided media file.
URL copied to clipboard!