HIPAA in the Cloud: Business Associates Baas and Protecting Ephi
46 questions
46 questions on HIPAA in the cloud, answered and cited by the UpLaw editorial team.
- Are the proposed HIPAA Security Rule changes in effect yet?
- Can a covered entity use real patient data to train an AI model?
- Can clinicians access ePHI from mobile devices under HIPAA?
- Does a business associate need a signed BAA to be liable under HIPAA?
- Does a fitness tracker or health app fall under HIPAA?
- Does a "no-view" promise turn a cloud vendor into a conduit?
- Does HIPAA give a customer the right to audit its cloud provider's security?
- Does the covered entity contract directly with every vendor in the chain?
- How are HIPAA civil monetary penalties structured?
- How can encryption both fail to exempt a vendor from HIPAA and exempt a breach from notification?
- How can health data be de-identified so that HIPAA no longer applies?
- How do a BAA and a service level agreement relate to each other?
- How do BAAs handle the security incident reporting problem in practice?
- How does the Privacy Rule apply to a cloud provider?
- How do Security Rule obligations split between a cloud customer and its provider?
- How is HIPAA enforced, and can OCR pursue a cloud provider directly?
- How long may a cloud provider keep ePHI after the contract ends?
- Is a cloud storage provider a HIPAA business associate even if it only stores encrypted data it cannot read?
- May a cloud provider store ePHI on servers outside the United States?
- Should a covered entity grant an AI vendor training rights to its patient data?
- What are the four verbs that determine business associate status?
- What are the HIPAA breach notification deadlines for a covered entity and a business associate?
- What are the limits of the HIPAA encryption safe harbor?
- What are the two most common causes of HIPAA penalties?
- What does "HIPAA-eligible" mean when a cloud provider uses the term?
- What does the HIPAA Security Rule require, and does it mandate encryption?
- What happens if a BAA omits a required term?
- What happens when a business associate hires a vendor without a BAA?
- What happens when a vendor both transmits and stores health data?
- What is a breach under the HIPAA Breach Notification Rule?
- What is a security incident under the HIPAA Security Rule, and why is it a problem?
- What is a subcontractor under HIPAA, and how far down does liability run?
- What is a working compliance checklist for a cloud HIPAA arrangement?
- What is HIPAA's 30-day cure window?
- What is HIPAA's most counterintuitive feature?
- What is the conduit exception, and does it apply to cloud providers?
- What is the flow-down requirement in a business associate agreement?
- What is the HIPAA encryption safe harbor?
- What is the shared responsibility model in cloud HIPAA compliance?
- What is the underlying principle that makes cloud vendors business associates?
- What terms must a business associate agreement contain?
- What unresolved HIPAA questions does clinical AI raise?
- What would the 2024-2025 HIPAA Security Rule proposal change?
- Who does HIPAA actually bind?
- Who is responsible when a cloud breach is caused by the customer's misconfiguration?
- Why doesn't encryption exempt a cloud vendor from business associate status?