Dental Service Organizations

What arrives

The risk analysis
HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A). An accurate and thorough assessment of the risks and vulnerabilities to electronic protected health information.
Source
The BAA
HIPAA business associate contract, 45 CFR 164.504(e), including the business associate's duty to report breaches of unsecured protected health information to the covered entity.
Source
Breach notice
HIPAA Breach Notification Rule, 45 CFR 164.404. Notice to each affected individual without unreasonable delay, and no later than 60 calendar days after discovery.
Source
The six-year file
45 CFR 164.316(b)(2). Security Rule policies, procedures and required records retained six years from creation or from the date last in effect.
Source
A bright dental surgery with a patient chair, a monitor and wall cabinets.

Request an Introduction