ARTICLE
26 October 2016

OCR Guidance On Cloud Computing

HK
Holland & Knight

Contributor

Holland & Knight is a global law firm with nearly 2,000 lawyers in offices throughout the world. Our attorneys provide representation in litigation, business, real estate, healthcare and governmental law. Interdisciplinary practice groups and industry-based teams provide clients with access to attorneys throughout the firm, regardless of location.
In recent guidance, OCR confirmed a number of positions it has taken informally over the years regarding how HIPAA affects cloud computing arrangements.
United States Technology
To print this article, all you need is to be registered or login on Mondaq.com.

Shannon Hartsfield Salimone is a Partner in our Tallahassee office.

In recent guidance, OCR confirmed a number of positions it has taken informally over the years regarding how HIPAA affects cloud computing arrangements. For example, OCR stated that a company that stores protected health information (PHI) in the cloud for an entity subject to HIPAA is a business associate, even if the PHI is encrypted and the business associate has no way to access it. Failure to enter into a business associate agreement with a cloud service provider (CSP) storing PHI would violate the HIPAA regulations. OCR noted that CSPs generally do not qualify as conduits that would not need to enter into business associate agreements.

CSPs may store PHI outside of the United States, although the risks associated with such arrangements must be analyzed. A particularly helpful portion of the guidance makes it clear that a business associate is not required to subject itself to audits by the covered entity or provide special documentation to the covered entity documenting its security practices. The guidance is designed to assist both CSPs and the covered entities and business associates that use them.

The content of this article is intended to provide a general guide to the subject matter. Specialist advice should be sought about your specific circumstances.

We operate a free-to-view policy, asking only that you register in order to read all of our content. Please login or register to view the rest of this article.

See More Popular Content From

Mondaq uses cookies on this website. By using our website you agree to our use of cookies as set out in our Privacy Policy.

Learn More