Physician Groups

What arrives

The risk analysis
HIPAA Security Rule, 45 CFR 164.308(a)(1)(ii)(A). An accurate and thorough assessment of the risks and vulnerabilities to electronic protected health information.
Source
The MIPS attestation
Merit-based Incentive Payment System, 42 CFR 414.1375. Promoting Interoperability reporting that the clinician completed the Security Risk Analysis measure in the performance year.
Source
Breach notice
HIPAA Breach Notification Rule, 45 CFR 164.404. Notice to each affected individual without unreasonable delay, and no later than 60 calendar days after discovery.
Source
The BAA
HIPAA business associate contract, 45 CFR 164.504(e), including the business associate's duty to report breaches of unsecured protected health information to the covered entity.
Source
Hands typing on a white keyboard, a stethoscope on the desk beside it.

Request an Introduction