Tue. Apr 23rd, 2024
ARCHIVED CONTENT
You are viewing ARCHIVED CONTENT released online between 1 April 2010 and 24 August 2018 or content that has been selectively archived and is no longer active. Content in this archive is NOT UPDATED, and links may not function.
 

Editor’s Note: This article highlights considerations for HIPAA compliance in 2017 including salient points for organizations providing cloud services such as SaaS-based eDisovery providers.

Extract from article by Jeremy Meisinger

OCR’s recently released guidance on cloud computing is an example of an attempt to tackle new technology and indicates that OCR will be keeping a close eye on cloud services providers in the future.  OCR makes clear that cloud services providers are business associates for HIPAA once engaged to receive, maintain, and transmit electronically stored Protected Health Information (PHI).  Accordingly, the relationship between a covered entity and a cloud services provider should be governed by a written, HIPAA-compliant business associate agreement.

Cloud services providers are subject to HIPAA as business associates even if they are unable to view PHI, such as in an arrangement whereby a business associate receives and stores encrypted data but does not have a decryption key.  Encryption alone does not satisfy the security requirements of HIPAA but, the guidance makes clear, plays a role in apportioning responsibility for security.  The guidance gives the example of a covered entity providing encrypted data but no decryption key, and states that where such a covered entity implemented its own appropriate user authentication controls, the cloud services provider would not be required to verify user authentication also.  The guidance states that where a business associate agreement puts the lion’s share of security responsibility on the covered entity, a cloud services provider would not be responsible for “compliance failures that are attributable solely to the actions or inactions” of the covered entity.

Read the complete article at Cybersecurity 2017 – The Year In Preview: HIPAA Compliance

 

Have a Request?

If you have information or offering requests that you would like to ask us about, please let us know, and we will make our response to you a priority.

ComplexDiscovery OÜ is a highly recognized digital publication focused on providing detailed insights into the fields of cybersecurity, information governance, and eDiscovery. Based in Estonia, a hub for digital innovation, ComplexDiscovery OÜ upholds rigorous standards in journalistic integrity, delivering nuanced analyses of global trends, technology advancements, and the eDiscovery sector. The publication expertly connects intricate legal technology issues with the broader narrative of international business and current events, offering its readership invaluable insights for informed decision-making.

For the latest in law, technology, and business, visit ComplexDiscovery.com.

 

Generative Artificial Intelligence and Large Language Model Use

ComplexDiscovery OÜ recognizes the value of GAI and LLM tools in streamlining content creation processes and enhancing the overall quality of its research, writing, and editing efforts. To this end, ComplexDiscovery OÜ regularly employs GAI tools, including ChatGPT, Claude, Midjourney, and DALL-E, to assist, augment, and accelerate the development and publication of both new and revised content in posts and pages published (initiated in late 2022).

ComplexDiscovery also provides a ChatGPT-powered AI article assistant for its users. This feature leverages LLM capabilities to generate relevant and valuable insights related to specific page and post content published on ComplexDiscovery.com. By offering this AI-driven service, ComplexDiscovery OÜ aims to create a more interactive and engaging experience for its users, while highlighting the importance of responsible and ethical use of GAI and LLM technologies.