SAFEGUARD YOUR PHI
With health records of high value to patients and the dark web alike, Protected Health Information (PHI) is at risk for everything from unintentional employee mishandling to cyberattacks. Our HIPAA Privacy Risk Assessment thoroughly assesses your privacy practices to help you comply with HIPAA privacy rules, while elevating your overall security posture.
HIPAA PRIVACY RISK ASSESSMENTS
Under the Health Insurance Portability and Accountability Act (HIPAA) Privacy Rule, healthcare organizations are required to implement appropriate safeguards to protect the privacy of Protected Health Information (PHI) and to set limits and conditions on the uses and disclosures that may be made of such information without an individual’s authorization. The Rule also gives individuals rights over their PHI, including rights to examine and obtain a copy of their health records, to direct a covered entity to transmit to a third party an electronic copy of their PHI in an electronic health record, and to request corrections.
BAI Security’s HIPAA Privacy Risk Assessment is conducted in accordance with 45 CFR Part 160 and Subparts A and E of Part 164 of the HIPAA Privacy Rule.
BAI Security’s HIPAA Privacy Assessment addresses:
- Privacy Practices documentation
- Privacy Practices training documentation
- Policies and procedures in place over administrative, technical, and physical safeguards covering all forms of PHI
- Complaint handling policies and procedures
- Population of complaints over privacy practices made with the last year (complaint log)
- Sanction and disciplinary policies and procedures
HIPAA Privacy Rule safeguards covered in BAI Security’s assessment include:
- 164.502 Uses and disclosures of protected health information: General rules
- 164.504 Uses and disclosures: Organizational requirements
- 164.506 Uses and disclosures to carry out treatment, payment, or health care operations
- 164.508 Uses and disclosures for which an authorization is required
- 164.510 Uses and disclosures requiring an opportunity for the individual to agree or to object
- 164.512 Uses and disclosures for which an authorization or opportunity to agree or object is not required
- 164.514 Other requirements relating to uses and disclosures of protected health information
- 164.520 Notice of privacy practices for protected health information
- 164.522 Rights to request privacy protection for protected health information
- 164.524 Access of individuals to protected health information
- 164.526 Amendment of protected health information
- 164.528 Accounting of disclosures of protected health information
- 164.530 Administrative requirement
The professional experience and technical expertise made the choice an easy one… exceptional results. We are completely satisfied.
There are a lot of service providers out there, but your staff were personable, friendly, knowledgeable and made it very clear they were there to help us get better, not to find as many exceptions as possible.
They go out of their way to be helpful, offering their guidance and suggestions (as opposed to a cookie-cutter approach). Initially, we chose BAI because of their reputation. We went back to them the next few years because of their people and their professionalism, the depth of their technical and procedural knowledge, and friendliness.
Far more extensive test than any we have had in the past… The reps are 100% on your project and always available to give you feedback.
Outstanding platform for vulnerability remediation. Everyone I talked to from sales folks to technical experts were all great to work with and very knowledgeable.
The experience was great, and I felt that BAI had my back. The techs were great to work with and helped me resolve security issues. They were working with me to correct issues rather than just pointing out what was wrong.
There are many players in this field. I contacted some of my industry peers and asked who they used. BAI came in at the top.
I love how in the final deliverables recommendations are provided. I’ve seen other solutions (and past vendors) who simply tell you what’s wrong without any help to remediate.
The dedicated engineer that learns our environment is huge! Also, the reporting is as high level or granular as you need it to be.
We have worked with BAI Security for 5+ years. They are professional, knowledgeable and personable. The technicians have a great understanding of our complex infrastructure
Price was right, service was excellent, and the final deliverables were outstanding. Great team.