HIPAA Training for Business Associates
Online Training Certificate Course
Updated HIPAA Training for Business Associates
Recently updated, this one-hour online course covers current HIPAA responsibilities for Business Associates, BAA guidance, cybersecurity, and federal healthcare updates.
This course is offered in partnership with HIPAA Exams, a 360training® company.
This updated HIPAA Training for Business Associates focuses on the responsibilities of vendors, contractors, consultants, and service providers that work with Protected Health Information (PHI) for Covered Entities. The one-hour course explains how Business Associates should protect PHI and electronic Protected Health Information (ePHI) while performing their services.
Course content includes the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules as well as responsibilities established under the Omnibus Rule. The updated training also addresses Business Associate Agreements (BAAs), cybersecurity risks, patient access, interoperability, and other current federal healthcare guidance.
This course is in partnership with HIPAA Exams. HIPAA Exams and Compliance Training Online™ are divisions of the 360training.
This course is intended for people working for Business Associates and individual contractors whose services involve creating, receiving, maintaining, or transmitting PHI on behalf of a Covered Entity.
Examples include:
- Medical billing and coding professionals
- Claims processing personnel
- Medical transcription service providers
- IT and software vendors
- Cloud and data hosting providers
- EHR and practice management vendors
- Healthcare consultants
- Independent IT contractors
- Marketing professionals with access to patient information
Case Study: In spring of 2015, Cornell Pharmacy, an independent pharmacy in Denver, was fined $125,000 for HIPAA violations related to improper disposal of PHI. The OCR found that this small health care provider, whose primary customers are hospice care organizations, had failed to establish policies and procedures for PHI disposal. Cornell Pharmacy had improperly disposed the medical records of 1,610 patients by placing them in an open trash container accessible to the public. Furthermore, no training had been provided to the Cornell Pharmacy workforce. In addition to the hefty fine, the pharmacy was required to adopt an action plan, implement HIPAA standards, and provide training to its workforce within 30 days.
Key Takeaways: Having a plan in place is not optional. The plan must outline the policies for HIPAA compliance, and provide guidelines for everyone associated with the covered entity who handles materials with PHI. Even more important, the covered entity must train its workforce to ensure that the plan is executed without fail.
Governing Regulations
HIPAA establishes privacy and security requirements for PHI and gives Business Associates direct responsibility for complying with certain provisions of the HIPAA Rules. Business Associates may also have obligations defined through their Business Associate Agreements with Covered Entities.
This course addresses the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules and responsibilities established under the Omnibus Rule. The updated curriculum also discusses current federal guidance affecting Business Associates, including interoperability, patient access, information blocking, and cybersecurity.
What You'll Learn
Course Topics
This course focuses on the following topics:
- Introduction to HIPAA
- HIPAA Privacy Rule
- HIPAA Security Rule
- HIPAA Enforcement and Breach Notification Rules
Course Learning Objectives
By the end of this course, learners will be able to:
- Explain the purpose of HIPAA legislation.
- Explain the changes implemented to HIPAA by the Omnibus Final Rule.
- Identify the key elements of the Privacy Rule, Security Rule, and Enforcement Rule.
- Explain the process for Breach Notification.
- Describe the Unique Identifiers and Transaction and Code Set Rules.
- Illustrate how to apply these rules within the responsibilities of a Business Associate.
HIPAA Training for Business Associates is a one-hour, self-paced course covering the responsibilities associated with handling PHI on behalf of Covered Entities. It addresses the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules as well as Business Associate responsibilities under the Omnibus Rule.
The course goes beyond definitions by using Business Associate scenarios, decision-making exercises, interactive activities, and knowledge checks. Learners can use these activities to evaluate their understanding of HIPAA requirements and their application to Business Associate responsibilities.
The course has been refreshed with current HIPAA content and federal healthcare guidance relevant to Business Associates. New and revised material includes:
- Updated Privacy Rule content for Business Associates
- ONC Cures Act and information blocking guidance
- CMS interoperability and patient access updates
- Individual access to ePHI requirements
- Ransomware, malware, and phishing awareness
- Cloud computing security considerations
- Mobile device and BYOD security
- Updated Business Associate and BAA responsibilities
- Current enforcement and breach notification information
- Revised compliance scenarios and knowledge checks
This course is intended for employees of organizations that create, receive, maintain, or transmit PHI while providing services to Covered Entities. It can also apply to individual contractors who qualify as Business Associates and need training relevant to their responsibilities.
Common examples include:
- Third-party service providers: Medical billing and coding companies, claims processors, and transcription services
- Technology vendors: IT and software providers, cloud and data hosting services, and EHR or practice management vendors
- Contractors and consultants: Healthcare consultants, independent IT contractors, and marketing agencies that work with patient information
Explore additional healthcare training options for other healthcare roles and training needs.