ARTICLE
15 November 2016

Cloud Service Providers Beware, You May Be Subject To HIPAA Without Knowing It

B
BakerHostetler

Contributor

BakerHostetler logo
Recognized as one of the top firms for client service, BakerHostetler is a leading national law firm that helps clients around the world address their most complex and critical business and regulatory issues. With five core national practice groups — Business, Labor and Employment, Intellectual Property, Litigation, and Tax — the firm has more than 970 lawyers located in 14 offices coast to coast. BakerHostetler is widely regarded as having one of the country’s top 10 tax practices, a nationally recognized litigation practice, an award-winning data privacy practice and an industry-leading business practice. The firm is also recognized internationally for its groundbreaking work recovering more than $13 billion in the Madoff Recovery Initiative, representing the SIPA Trustee for the liquidation of Bernard L. Madoff Investment Securities LLC. Visit bakerlaw.com
The use of cloud service providers has exploded in the past several years. According to estimates from Gartner, the market for cloud services is expected to reach $204 billion in 2016.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

The use of cloud service providers has exploded in the past several years. According to estimates from Gartner, the market for cloud services is expected to reach $204 billion in 2016. But the use of cloud service providers raises significant privacy and security concerns, especially for health care providers who are subject to the Health Insurance Portability and Accountability Act (HIPAA).

Last month, the Department of Health and Human Services Office for Civil Rights (OCR) issued guidance on the storage of protected health information (PHI) in the cloud. Not surprisingly, the OCR reiterated its expectation that covered entities enter into business associate agreements with service providers and provide prompt notice of unauthorized access. However, one of the more surprising takeaways from that guidance was the OCR’s position that a cloud service provider (CSP) could be subject to HIPAA merely by storing encrypted PHI. Specifically, the OCR has said, “When a covered entity engages the services of a CSP to create, receive, maintain, or transmit ePHI (such as to process and/or store ePHI), on its behalf, the CSP is a business associate under HIPAA[.] This is true even if the CSP processes or stores only encrypted ePHI and lacks an encryption key for the data. Lacking an encryption key does not exempt a CSP from business associate status and obligations under the HIPAA Rules[.]”

This is huge! Even if a CSP is unable to read or access PHI, the CSP would STILL be considered a business associate. Consider that under many state breach notification laws, encryption that renders data unreadable or indecipherable is a safe harbor in the event of unauthorized access. The position taken by the OCR holds CSPs to a higher standard than those who gain unauthorized access. This has significant ramifications for those CSPs who have explicitly sought to limit their exposure and regulatory compliance obligations by restricting their access to PHI. It seems those efforts may have been in vain. To the extent any CSP stores or maintains PHI on behalf of a covered entity, even if encrypted, that CSP must comply with HIPAA.

All CSPs should take a close look at PHI storage practices and evaluate their potential HIPAA compliance obligations in light of this guidance.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More