|
Covered
Entity Analysis
Although
most clients have already performed this initial HIPAA assessment
activity, FOX recognizes that this the cornerstone for any
HIPAA compliance effort is to conduct a comprehensive Covered
Entity Analysis (also known as a HIPAA Applicability Analysis).
All HIPAA activities flow from the covered entity analysis
because it determines if an organization is covered by the
HIPAA regulations (e.g., health plan, health care provider)
and, if so, to what degree.
|
 |
|
FOX
Systems, Inc. (FOX)
specializes in performing Covered Entity Analyses for complex
organizations that are typically multi-function (i.e., perform
both HIPAA provider and health plan functions) as well as
hybrid organizations (have both HIPAA covered and non-HIPAA
covered business functions) and those that perform public
functions (i.e., health care oversight and public health organizations).
We also help establish which level or part of the organization
is the “HIPAA entity". All of these determinations
have a significant impact on HIPAA compliance requirements
and how organizations should be structured to best comply,
so an organization might be best served to partner with a
firm such as FOX, which has the experience and expertise to
address the questions.
To gather the information necessary for the client to make
final decisions regarding covered entity status, FOX performs
the following tasks:
-
Documents
the current environment of the client
-
Surveys
each program identified by the client
-
Develops
a summary of business processes and systems used
-
Utilizes
the FOX automated analytical tools to produce a report containing
HIPAA applicability determinations and a list of decisions
required by the client
FOX
meets with representatives from all of the client’s
departments or programs to collect the documentation needed
to make the HIPAA covered entity determination. FOX employs
various proprietary analytical tools (including FOX Covered
Entity Decision Trees and Tables) that prompt our analysts
on the various categorical questions to ask about each department
and program.
The
following key questions are answered as part of this process:
-
Does
the program administer or manage a named health plan?
-
Does
the program provide the cost of or pay for medical care?
-
Does
the program qualify for a government-funded or other health
plan exception?
-
Does
the program provide healthcare services?
-
Does the program conduct standard transactions?
-
Does the program perform any public functions?
-
Does the program
maintain, utilize, or transmit protected health information
(PHI)?
Responses
to these and other structured questions form the basis of
the HIPAA applicability findings and designation of covered
entity status. FOX reviews the decision logic with its client
to ensure that it is applicable, and uses the results as a
guide for continuing assessment and compliance planning interviews
and other data collection processes.
FOX
will produce a detailed Covered Entity Analysis report, if
desired, that identifies those divisions and programs of the
organization that are HIPAA-covered entities and subject to
the requirements of HIPAA rules. As expected, these reports
specify each program and their HIPAA entity status, but they
also provide a discussion of the potential impacts. It should
be noted that the findings of the Covered Entity assessment
have application to all HIPAA regulations (i.e., Transactions
and Code Sets, Privacy and Security).
Copyright © Fox Systems 2004-2010, All rights
reserved. |
|