What is HIPAA Certification for Healthcare Vendors?
If your organization sells – or is planning to sell – software, products, or services to the U.S. healthcare sector, it is likely you will need to demonstrate your organization complies with all applicable standards of the Health Insurance Portability and Accountability Act (HIPAA).
This is because a HIPAA covered entity or business associate can only use a third party’s software, products, or services to create, receive, maintain, or transmit Protected Health Information if it receives satisfactory assurances in advance that the third party will safeguard the information.
Providing satisfactory assurances that your organization is “HIPAA compliant” is not straightforward. While it is possible to achieve any number of security certifications, none map exactly with the requirements of HIPAA. The gaps that remain could undermine your organization’s chances of securing a lucrative contract.
Why There is No One-Size-Fits-All Certification for HIPAA Compliance
The reason there is no one-size-fits-all certification for HIPAA compliance is that different HIPAA standards apply to healthcare vendors depending on the software, product, or service being provided to – or on behalf of – HIPAA covered entities and business associates.
For example, an EDI software provider that provides a customer support service in which support personnel have full visibility of transactions, will have to comply with all the HIPAA Security Rule safeguards plus develop privacy policies to guide support personnel on using and disclosing only the minimum necessary permissible Protected Health Information.
Conversely, a cloud storage service provider that has “no view” access to Protected Health Information – because the information is encrypted and the healthcare customer maintains the decryption key – will have to comply with far fewer HIPAA Security Rule safeguards, and will not have to develop any privacy policies.
However, although there is no one-size-fits-all certification for HIPAA compliance, it is still possible for healthcare vendors to get certified as HIPAA compliant.
How Can Healthcare Vendors Get Certified As HIPAA Compliant?
There are two ways in which healthcare vendors can get certified as HIPAA compliant. The first is to engage a HIPAA compliance consultant. The consultant will advise your organization on the measures that have to be implemented to support compliance with applicable HIPAA standards, and – once the measures are implemented – the consultant will certify your organization as HIPAA compliant.
The issue with this type of HIPAA certification is that it is a point-in-time certification. It only certifies that, at the time the certification was issued, the measures existed to support compliance with HIPAA. It does not certify that the measures are being used in compliance with HIPAA. For some healthcare customers, point-in-time certifications do not provide the assurances necessary to meet their due diligence requirements.
The second way healthcare vendors can get certified is to subscribe to a HIPAA compliance software service. HIPAA compliance software services provide similar customizable guidance to HIPAA compliance consultants, but also provide ongoing compliance activities so organizations can demonstrate HIPAA compliance in real-time – better satisfying healthcare customers’ due diligence requirements.
The Benefits of HIPAA Certification for Healthcare Vendors
In the context of selling software, products, or services to the U.S. healthcare sector, the primary benefit of HIPAA certification for healthcare vendors is that it accelerates business negotiations. Being able to demonstrate real-time HIPAA compliance to prospective customers reduces the due diligence burden, and makes your product or service more attractive compared to competitors who are not certified – or who are unable to demonstrate up-to-date HIPAA certification.
The second benefit of HIPAA certification for healthcare vendors is that, by maintaining compliance with all applicable HIPAA standards, your organization is less susceptible to cyberattacks and privacy violations. This is important because the most common consequence of cyberattacks at healthcare vendors is the cancellation of service contracts by customers. In addition, healthcare vendors with a history of cyberattacks are less likely to attract new customers.
If despite your best efforts your organization still experiences a data breach, a further benefit of HIPAA certification is that you will be able to demonstrate compliance with a security framework if the data breach is investigated by the HHS’ Office for Civil Rights. The advantage of this is that, under the “Safe Harbor” amendment to HITECH, HHS’ Office for Civil Rights has the authority to mitigate the extent of financial penalties, corrective action plans, and other remedies.
Five-Step Approach to HIPAA Certification for Healthcare Vendors
Assess Your HIPAA Obligations
The first step to HIPAA certification for healthcare vendors is to work out what HIPAA standards apply to your software, product, or service – and to your organization. It is important not to forget that your organization has to demonstrate compliance with the applicable standards of HIPAA in order to achieve HIPAA certification for healthcare vendors. It is not enough to demonstrate that (for example) software you have developed has the capabilities to support HIPAA compliance.
Therefore, it is essential that you assess your HIPAA obligations and plan for events that may not only impact how your software, product, or service works, but that might also impact the confidentiality, integrity, or availability of Protected Health Information processed or maintained on behalf of a healthcare customer. Your plans should include both external events such as severe climate change and cyberattacks, and internal events such as employee snooping and insider theft.
Execute Agreements with Subcontracted Services
If your software, product, or service itself uses a third party’s software, product, or service to function – for example, if your software collects data and stores it in the Microsoft Cloud – you will need to enter into a Business Associate Agreement with every “downstream” third party vendor to whom you will disclose Protected Health Information. The Agreements protect your organization from liability in the event of a downstream data breach – either by a third party vendor or one of their subcontractors.
Before entering into a Business Associate Agreement with a third party vendor, you will have to ensure – by conducting your own due diligence – that the vendor is HIPAA compliant. If a third party vendor is unable to demonstrate HIPAA compliance – or is unwilling to enter into a Business Associate Agreement – you will be unable to use their software, product, or service in connection with Protected Health Information and will have to look elsewhere for an alternate software, product, or service to support your own.
Implement Security Measures and Compliance Policies
The third step towards achieving HIPAA certification for healthcare vendors requires implementing security measures to protect PHI and developing compliance policies. Organization should start with a detailed risk assessment to catalog potential vulnerabilities to data confidentiality, integrity, and availability. Then deploy measures that collectively mitigate threats and vulnerabilities to a level considered reasonable and appropriate under the HIPAA Security Rule.
Compliance policies should stipulate how the measures implemented to protect PHI must be used, and must include details of workforce sanctions for policy violations. Depending on the nature of service being provided and the terms of an upstream Business Associate Agreement, it may also be necessary to develop procedures to accommodate patients exercising their HIPAA rights, and to notify downstream subcontractors when a patient requests privacy protections.
Develop Security Incident Reporting and Breach Protocols
Under HIPAA, any attempt – successful or not – to access, use, alter, or destroy PHI or systems on which it is maintained qualifies as a security incident. Healthcare vendors must develop and maintain protocols to detect, document, and report all such incidents to upstream covered entities and business associates, irrespective of whether the incident leads to an actual breach. You should also have protocols in place for receiving and forwarding incident reports from downstream subcontractors.
Should an incident escalate into a breach of unsecured PHI, you must have response plans to contain the event, assess its impact, and remediate vulnerabilities. Protocols must be in place to notify upstream covered entities and business associates promptly, and – when included in the terms of a Business Associate Agreement – to notify affected individuals, HHS’ Office for Civil Rights, State Attorneys General, and the media if applicable.
Develop, Deliver, and Document Workforce HIPAA Training
Every HIPAA covered entity and Business Associate must develop and deliver a customized HIPAA training program that covers security awareness, privacy obligations, and breach notification protocols. Generic, off-the-shelf courses generally fall short of HIPAA’s comprehensive requirements, making it essential to tailor content to your specific policies, workflows, and regulatory responsibilities.
It is important to remember that workforce HIPAA training is not a one-off event. The HIPAA standard regarding security awareness training states that the training should be a “program”, while HIPAA Privacy training must be repeated whenever there is a material change to policies and procedures that affect workforce functions. Most compliance experts advocates quarterly security awareness training and annual HIPAA privacy training if a material change has not occurred in the previous twelve months.
Other Compliance Requirements to Consider
Even if your operations do not classify you as a business associate or subcontractor, pursuing HIPAA certification can still deliver value. Many federal statutes and the majority of state privacy laws mirror HIPAA’s standards. Several jurisdictions have explicitly adopted HIPAA benchmarks for data protection. As a result, your enterprise may need to adhere to HIPAA-like safeguards, regardless of its official HIPAA designation.
It is also worth noting that, depending on the capabilities of the software, product, or service you wish to market to the U.S. healthcare sector, there may be further compliance requirements to consider in addition to HIPAA. These include (but are not limited to) the Health Information Technology Standards for certified health IT, FDA regulations for medical devices, and The FTC’s Healthcare Breach Notification Rule for consumer health apps.
