Scope of This Overview
HIPAA applies differently depending on the parties, services, information, and role involved. When All State RCM acts as a business associate and a service requires access to PHI, applicable responsibilities, permitted uses, safeguards, reporting duties, and return or destruction requirements must be established in written agreements before access is provided.
Prospective clients should evaluate the specific service scope, systems, workforce access, vendors, and security documentation relevant to their engagement. Nothing on this page represents independent certification of a system or service.
What Is HIPAA?
The Health Insurance Portability and Accountability Act of 1996, commonly known as HIPAA, establishes national requirements concerning the privacy and security of protected health information.
The HIPAA Privacy Rule addresses uses and disclosures of protected health information by covered entities and their business associates. HIPAA’s Security Rule addresses administrative, physical, and technical safeguards for electronic protected health information. Applicable requirements and signed agreements—not this webpage—govern a client engagement.
Business Associate Agreements
A business associate agreement (BAA) is required when the relationship and services meet HIPAA’s business-associate requirements. The BAA should identify permitted uses and disclosures, required safeguards, incident and breach reporting duties, subcontractor obligations, access or amendment support where applicable, and the handling of PHI when the relationship ends.
Execution of a BAA does not by itself make a workflow compliant. Each party remains responsible for the obligations assigned to it by law and contract.
- Define the authorized service purpose and PHI involved
- Document each party’s security and reporting responsibilities
- Identify approved systems, communication channels, and access methods
- Confirm subcontractor and record-disposition requirements
Access and Confidentiality
Engagement design should follow role-based access and minimum-necessary principles where applicable. Access should be granted only through approved systems to people whose assigned work requires it, and removed when it is no longer needed.
- Role-appropriate access and unique accounts
- Approved methods for transmitting and storing PHI
- Authentication, logging, and access-review expectations
- Secure collaboration with authorized practice contacts
Safeguards to Review
Before work involving electronic PHI begins, the parties should review the safeguards relevant to the actual workflow. Requirements may vary according to risk, system architecture, client policy, and the service being performed.
- Administrative policies, workforce authorization, and training
- Physical protections for facilities and devices
- Technical access controls, transmission security, and audit capability
- Backup, contingency, and incident-response responsibilities
- Periodic risk review and remediation ownership
Incidents and Subcontractors
The engagement documents should identify how suspected unauthorized access, security incidents, and potential breaches are reported, investigated, documented, and escalated. Applicable legal deadlines and the client’s incident-response process should be confirmed before access to PHI is granted.
If an approved subcontractor will create, receive, maintain, or transmit PHI on behalf of a business associate, the appropriate written restrictions and safeguards must extend to that subcontractor. Vendor and subprocessor information should be reviewed for the specific service rather than assumed from this website.
Public Website and Contact Forms
The public website and its contact forms are not approved channels for PHI, patient records, medical details, credentials, or urgent security reports. Submit only general business contact information. Current clients should use the communication and incident-reporting channels established for their engagement.
Questions about this page?
Contact All State RCM at info@allstatercm.com or call (206) 486-8646.