teche
Member
- Reaction score
- 3
I'm just starting out on my own and have spoken with a few potential HIPAA compliant customers (neurologist, medical supply company, dentist) and the more I research HIPAA the more it scares the **** out of me! I mean, if I can get everything straight, there's money to made. I'm just at the point of paralysis by analysis!
As I read it, we are held to the same standards as the CE. Do you just sign a BAA and go with it? Or do you go (a lot) further? Ongoing training, security assessments, etc. My initial thinking was pretty simple. Sign a BAA and make sure the customer data is safe. Then I started reading some of the items I was agreeing to in the BAA (template from HHS). Are there different levels of requirements? Typical break/fix = BAA. Fully managed services and network security = full blown training, certification even?
I'm currently using GFI for monitoring and they will sign a BAA. Same with Office 365. Does that cover me? Do I need a separate BAA for repairs and network support?
Sorry for so many questions. My head is just spinning and I have no one else to bounce ideas off of! Any feedback is greatly appreciated.
As I read it, we are held to the same standards as the CE. Do you just sign a BAA and go with it? Or do you go (a lot) further? Ongoing training, security assessments, etc. My initial thinking was pretty simple. Sign a BAA and make sure the customer data is safe. Then I started reading some of the items I was agreeing to in the BAA (template from HHS). Are there different levels of requirements? Typical break/fix = BAA. Fully managed services and network security = full blown training, certification even?
I'm currently using GFI for monitoring and they will sign a BAA. Same with Office 365. Does that cover me? Do I need a separate BAA for repairs and network support?
Sorry for so many questions. My head is just spinning and I have no one else to bounce ideas off of! Any feedback is greatly appreciated.