Laserfiche WebLink
Interpretation and Implementation Specifications <br />There currently are no implementation specifications regarding this standard. <br />References: " <br />45 C.F.R. § 164.308(a)(8). <br />Business Associate Contracts and Other Arrangements <br />[Administrative Safeguard] <br />Standard <br />The Health Plan shall obtain satisfactory assurances that the business associate will appropriately <br />safeguard ePHI before permitting the business associate to create, receive, maintain, or transmit ePHI. <br />Interpretation and Implementation Specifications <br />Definition of "business <br />associate" <br />Identification of Business <br />Associates <br />References: <br />45 C.F.R. § 164.308(b)(1). <br />1. A business associate, means a person or entity who is <br />not an employee or workforce member of the Health <br />Plan, who performs or assists in the performance of a <br />function or activity on behalf of the Health Plan that <br />involves the use or disclosure of PHI, or provides legal, <br />actuarial, accounting, consulting, data compilation, <br />management, administrative, accreditation, or financial <br />services. <br />2. It is the Health Plan's obligation to ensure that all of the <br />Health Plan's business associates have a written valid <br />business associate agreement. <br />Written Contract or Other 3. Document the satisfactory assurances required by <br />Arrangement paragraph (b)(1) [the Business Associate Contracts and <br />(required) Other Arrangements] of this section through a written <br />contract or other arrangement with the business <br />associate that meets the applicable requirements of § <br />Technical Safeguards = Generally <br />Policy Statement <br />The Technical Safeguards portion of the Security Rule (collectively referred to as "Technical Safeguards ") <br />addresses technology and requires policy and procedures for its use that protect ePHI and control access <br />to it. <br />City of Ramsey HIPAA Security Policy - 11 - <br />