https://www.channelfutures.com/wp-content/themes/channelfutures_child/assets/images/logo/footer-new-logo.png
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
Channel Futures
  • NEWSLETTER
  • Home
  • Technologies
    • Back
    • SDN/SD-WAN
    • Cloud
    • RMM/PSA
    • Security
    • Telephony/UC/Collaboration
    • Cable
    • Mobility & Wireless
    • Fiber/Ethernet
    • Data Centers
    • Backup & Disaster Recovery
    • IoT
    • Desktop
    • Artificial Intelligence
    • Analytics
  • Strategy
    • Back
    • Mergers and Acquisitions
    • Channel Research
    • Business Models
    • Distribution
    • Technology Solutions Brokerages
    • Sales & Marketing
    • Best Practices
    • Vertical Markets
    • Regulation & Compliance
  • MSP 501
    • Back
    • 2023 MSP 501 Application
    • 2022 MSP 501 Rankings
    • 2022 NextGen 101 Rankings
  • Intelligence
    • Back
    • Galleries
    • Podcasts
    • From the Industry
    • Reports/Digital Issues
    • Webinars
    • White Papers
  • Channel Futures TV
  • EMEA
  • Channel Chatter
    • Back
    • People on the Move
    • New/Changing Channel Programs
    • New Products & Services
    • Industry Honors
  • Resources
    • Back
    • Advisory Boards
    • Industry Organizations
    • Our Sponsors
    • Advertise
    • 2023 Editorial Calendar
  • Awards
    • Back
    • 2022 MSP 501
    • Channel Influencers
    • Circle of Excellence
    • DE&I 101
    • Technology Advisor 101 (TA 101)
    • Channel Leaders Lists
  • Events
    • Back
    • 2023 Call for Speakers
    • CP Conference & Expo
    • MSP Summit
    • Channel Partners Europe
    • Channel Partners Event Coverage
    • Webinars
    • Industry Events
  • About Us
  • DE&I
    • Newsletter
  • REGISTER
  • MSPs
  • VARs / SIs
  • Agents
  • Cloud Service Providers
  • Channel Partners Events
 Channel Futures

From the Industry


Sponsor Content

Getting Hip to HIPAA

  • Written by Kaseya Guest Blogger
  • June 25, 2019
Here’s what compliance looks like for ePHI and the role MSPs can play in helping clients achieve and maintain HIPAA compliance.

HIPAA has been around since 1996, but most people’s understanding is limited to a vague notion of protecting private information and having to constantly sign waivers when they check in for a doctor’s appointment. But the Health Insurance Portability and Accountability Act has far wider implications than just some extra signatures in the waiting room–it also represents a major opportunity for MSPs.

Although HIPAA’s original purpose was largely related to the ability to change jobs and health insurance without losing coverage or impacting medical care, the HIPAA Privacy and Security Rules are very relevant for the IT side of the house. Compliance with the privacy rules went into effect in 2003–along with it the definition of Private Health Information (PHI)–and medical organizations became responsible for protecting “any information held by a covered entity which concerns health status, the provision of healthcare, or payment for healthcare that can be linked to an individual.”

In 2005, HIPAA regulations got serious about “ePHI” (electronic versions of private health information), and organizations were now on the hook for adhering to additional safeguards specifically around administrative, physical and technical aspects of patient data stored electronically. When the Final Omnibus Rule went into effect in 2013, organizations were truly on the hook for compliance and faced serious financial penalties for breaches. This turned the tide for medical organizations as compliance became much less expensive than the potential fines they might face, not to mention criminal charges in more egregious cases.

ePHI Compliance

Let’s break down exactly what compliance looks like for ePHI and explore what role MSPs can play in helping clients achieve and maintain compliance.

 Administrative

This area covers the various policies and plans required to ensure an organization is following the rules. This includes:

  • Employee training-A defined, followed and documented schedule for making sure all employees understand the policies and awareness of identifying potential malware and attacks.
  • Third-party access limits-Guarding against partners and subcontractors gaining access to ePHI, as well as ensuring business associate agreements are in place with any individuals or firms that will have access to ePHI as part of their agreed upon role.
  • Conducting risk assessments-Identifying all areas where ePHI is utilized, along with any potential areas where a breach could occur.
  • Risk management policy-Regularly scheduled risk assessments, along with a sanctions policy for employees found out of compliance.
  • Contingency planning and testing of the plan-How to continue operations during an emergency without compromising the integrity and security of ePHI.

MSPs have an opportunity to serve as a trusted advisor for the administrative compliance aspects of ePHI. Providing education, training, boilerplate templates and best practices, MSPs can reduce the time and energy required for medical organizations to put these processes and procedures into place.

This represents a one-time revenue opportunity for setting things up and ongoing revenue opportunities for periodic training and refreshes. Most importantly, it creates a deeper relationship with clients—one that goes beyond pure technology. Compliance can be overwhelming for medical offices more interested in servicing patients than deciphering regulations and securing their IT systems, so a helpful MSP willing to go the extra mile can be seen as a gamechanger.

Physical

Although most entities are worried about breaches and malware entering their systems via the Internet, the physical world also represents its own share of threats. The tasks of protecting devices, servers and facilities from natural and environmental hazards, as well as unauthorized entry and access, are also part of the HIPAA regulations.

While MSPs aren’t likely to be responsible for guarding medical offices and hospitals from these threats, they similarly apply to an MSP’s own facilities along with anywhere else that might be hosting sensitive data. To meet expectations, every location dealing with this information requires plans for disaster recovery, a facility security plan to prevent unauthorized access, person-level or role-based security access (so people only have access to what they require to do their particular job), and a full record of all maintenance activities for the facilities themselves, even renovations and changing the locks. Similar guidelines should be followed regarding physical access to servers.

Devices and media storage also require special care. If a device is being disposed of or reused, it must be completely wiped of all data. Additionally, there must be a record of any transfer of data from one device to another and documentation as to where any ePHI is present. And any data backups or storage–regardless of whether they are on a physical device or are cloud-based—require a contingency plan for removal and storage in the case of a physical incident.

  • Page 1
  • Page 2
Tags: MSPs Business Models From the Industry Intelligence Security Specialty Practices Strategy Kaseya Sponsor Content

Most Recent


  • Seattle
    Microsoft Job Cuts Hit Hundreds More Workers in Seattle Area
    In January, Microsoft initiated a plan to shed about 10,000 workers.
  • boxing gloves
    Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart
    There's always something to buzz about in the channel.
  • Celebrating millionaire geezer
    AT&T Alliance Channel Awards: Telarus Wins, Avant Rises, Intelisys Slides
    TD Synnex was among the partners joining this awards list for the first time. See who else earned accolades from the carrier.
  • Cisco African American Partner Community Eyes Hiring, HBCU Opportunities
    Cisco is working with 14 Black-owned partner firms in a "high-touch" manner to invest in their growth.

Leave a comment Cancel reply

-or-

Log in with your Channel Futures account

Alternatively, post a comment by completing the form below:

Your email address will not be published. Required fields are marked *

Related Content

  • Flashlight in darkness
    Scare Up New Business by Making Your Customers Afraid of the ‘Dark’
  • Close up of computer cable plugs
    Treat Every Day Like it’s Backup Day
  • Close up of laptop and mobile phone screen on small round table
    2019 MSP Benchmark Survey Results Report
  • PC Endpoint Security
    A Patch Made in Heaven - Tip Sheet

Upcoming Events

View all

Channel Partners Conference & Expo

May 1, 2023 - May 4, 2023

Channel Partners Europe

June 13, 2023 - June 14, 2023

Channel Futures Leadership Summit

October 30, 2023 - November 2, 2023

Galleries

View all

Channel Conflict, Controversy: Avaya Bankruptcy, Mass Layoffs, High-Profile Execs Depart

March 28, 2023

Cisco African American Partner Community Eyes Hiring, HBCU Opportunities

March 28, 2023

National Women’s History Month: Channel Women Recall ‘the Best Thing’

March 28, 2023

Industry Perspectives

View all

Why You Should Include Audiovisual Solutions in Your UC Services

March 28, 2023

Selling Your MSP: Strategic vs. Financial Buyers

March 22, 2023

10 Strategic Smart Enterprise Drivers for 2023

March 16, 2023

Webinars

View all

Give Customers the Power: How MSPs Can Leverage Cloud Choice

April 4, 2023

DE&I Dialogue: How the Right DE&I Initiatives Can Propel Your Business

April 5, 2023

Meet the 2023 Channel Futures Channel Influencers

April 13, 2023

White Papers

View all

6 UCaaS Reseller Challenges and How Real World Businesses Solved Them

February 1, 2023

Frost Radar: North American UCaaS Market, 2022

February 1, 2023

The Complete Guide to White-Label UCaaS for Reseller Success

February 1, 2023

Channel Futures TV

View all

Coffee with Craig and James Episode 121: Hewlett Packard Enterprise

Aryaka ‘Driving Value to the Channel Community’ with Throttle

March 24, 2023

Real-Life M&A: Advice for a Successful Channel Deal

March 13, 2023

Coffee with Craig and James Episode 120: Ronnell Richards

March 3, 2023

Twitter

ChannelFutures

“Every decade a new technology emerges that is truly disruptive.”-- #AI sentiments from @RingCentral @Microsoft… twitter.com/i/web/status/1…

March 29, 2023
ChannelFutures

Check out this edition of Channel Futures TV! Glen Lomond discusses @HitachiVantara's approach to as-a-service of… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

.@Microsoft #layoffs target more workers in Seattle area. dlvr.it/SldRzg https://t.co/DGtDBBU4m0

March 28, 2023
ChannelFutures

[email protected] buys 5 MSPs to expand geographic footprint dlvr.it/SldPyq https://t.co/GnewmOXRch

March 28, 2023
ChannelFutures

.@Lacework announces partner program updates, new #MSP program. #security dlvr.it/SldP9H https://t.co/hUKTOYgoY3

March 28, 2023
ChannelFutures

Learn how MSPs can generate new revenue streams with audiovisual solutions. @shure #ucservices #channelpartners… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

⭐ 2023 #ChannelInfluencer spotlight: @andrewsage from @Cisco! Congratulations on this incredible honor from your pe… twitter.com/i/web/status/1…

March 28, 2023
ChannelFutures

The latest @ATTPartners awards give a nice glimpse of how M&A is shaping partner hierarchies.… twitter.com/i/web/status/1…

March 28, 2023

MSP 501

The industry's largest and most comprehensive partner awards program.

Newsletters and Updates

Sign up for The Channel Report, Channel Futures Update, MSP 501 Newsletter and more.

Live Channel Events

Get the latest information on the next industry-leading Channel Partners event.

Galleries

Educational slide shows and images from live events.

Media Kit And Advertising

Want to reach our audience? Access our media kit.

DISCOVER MORE FROM INFORMA TECH

  • Channel Partners Events
  • Telecoms.com
  • MSP 501
  • Black Hat
  • IoT World Today
  • Omdia

WORKING WITH US

  • Contact
  • About Us
  • Advertise
  • Newsletter

FOLLOW Channel Futures ON SOCIAL

  • Privacy
  • CCPA: “Do Not Sell My Data”
  • Cookie Policy
  • Terms
Copyright © 2023 Informa PLC. Informa PLC is registered in England and Wales with company number 8860726 whose registered and Head office is 5 Howick Place, London, SW1P 1WG.
This website uses cookies, including third party ones, to allow for analysis of how people use our website in order to improve your experience and our services. By continuing to use our website, you agree to the use of such cookies. Click here for more information on our Cookie Policy and Privacy Policy.
X