Important Updates on HIPAA Compliance
The Department of Labor (DOL) has updated cybersecurity guidance requiring health plans to actively monitor vendor compliance with cybersecurity standards, beyond just relying on signed contracts. Privacy and Security Officers must ensure that vendors handling Protected Health Information (PHI) comply with HIPAA and DOL guidelines, including having Business Associate Agreements (BAAs) in place and conducting vendor assessments. They must also manage incidents and breaches, ensuring proper notifications to affected members and authorities.