Covered Entities trust Athreon to safeguard their PHI under HIPAA and HITECH.
The Health Insurance Portability and Accountability Act of 1996 (HIPAA) sets guidelines for securing patient information. HIPAA guards against unauthorized disclosures of health information. It mandates a national set of security and privacy standards that shield Protected Health Information (PHI), including PHI in electronic form (ePHI). PHI consists of any information used to identify a patient, including names, birthdates, photos, emails, medical record numbers, and more.
HIPAA is comprised of a Privacy Rule, Security Rule, and Breach Notification Rule. The office for Civil Rights (OCR), under the US Department of Health and Human Services, enforces these rules. The OCR began enforcing HIPAA in 2003. In 2009, the Health Information Technology for Economic and Clinical Health (HITECH) Act expanded the HIPAA regulations.
Anyone that creates, transmits, receives, or stores Protected Health Information (PHI) needs to comply with HIPAA. Individuals, organizations, or agencies may be classified as a Covered Entity or Business Associate under HIPAA.
Common examples of Covered Entities include healthcare providers like physicians, dentists, psychologists, and chiropractors. Hospitals and clinics are classified as covered entities as well. Other examples of Covered Entities include health insurance companies, HMOs, and universities.
Business Associates include any person or organization that uses or discloses PHI on behalf of a Covered Entity. Examples of Business Associates include IT vendors, laboratories, call centers, cloud providers, and legal services. Business Associates are required to protect PHI just as a Covered Entity would, and Business Associates must notify Covered Entities in the event of a data breach. Athreon is considered a Business Associate under HIPAA.
We only use the Protected Health Information entrusted to us to deliver our contracted solutions. Athreon never sells PHI or uses it for non-contracted purposes. We have implemented robust administrative, technical, and physical controls to protect PHI. Our methods safeguard PHI from misuse. To further comply with HIPAA, we use audit trails to identify what happens with all the PHI in our care. Our technology tracks who accesses PHI, when they access it, what they do with it, and from where they access it. For technical information about our security and privacy practices, visit this link.
HIPAA mandates that Covered Entities and Business Associates must enter into Business Associate Agreements to define expectations and responsibilities for keeping PHI safe. Athreon can review BAAs from Covered Entities or provide a BAA. In addition to signing BAAs with Covered Entities, we enter into BAAs with our technology partners, subcontractors, and anyone else who may support us in providing solutions that involve PHI.