Can protected health information be sent to a third-party service provider?
Before protected health information can be provided to a third-party service provider, HIPAA requires that a Business Associate Contract be signed stating that the third-party will implement reasonable safeguards to protect the confidentiality and integrity of protected health information. The Office of General Counsel should be engaged to assist in the development of such a contract. The Information Security Office should also be engaged to ensure there are no additional security requirements beyond that of HIPAA. Send email to iso@andrew.cmu.edu if you would like someone within the Information Security Office to review a third-party service contract prior to signing.
Related Questions
- May a health care provider disclose protected health information to a health plan for the plans Health Plan Employer Data and Information Set (HEDIS)?
- Which third-party service provider offers e-procurement software for CPA reverse auctions?
- Can protected health information be sent to a third-party service provider?