top of page
HIPAA Plan Privacy Officer  Services

Many employers that are not otherwise subject to HIPAA struggle complying with HIPAA requirements for their sponsored health plans.  Under HIPAA, employer sponsored Health Plans are Covered Entities.  As Covered Entities, Health Plans must appoint a HIPAA Privacy Officer and a HIPAA Security Officer. 

 

The HIPAA Privacy Officer is the individual responsible for ensuring an organization’s compliance with the HIPAA Privacy Rule and the protection of Protected Health Information (PHI). This role serves as the central authority for developing, implementing, and maintaining HIPAA privacy policies, acting as the primary point of contact for patient inquiries, workforce training, and regulatory compliance.

 

Key responsibilities include:

  • Policy Development: Creating, updating, and enforcing HIPAA privacy policies that govern the collection, use, and disclosure of PHI, ensuring alignment with HIPAA as well as state privacy laws.

  • Patient Rights Management: Overseeing processes for Plan members to access, amend, or restrict their health records, and handling related complaints or investigations.

  • Training and Education: Conducting regular HIPAA privacy training for all workforce members that handle PHI to ensure they understand privacy protocols and procedures.

  • Risk Assessment and Auditing: Performing HIPAA privacy risk assessments and audits to identify vulnerabilities, monitor compliance, and implement corrective actions.

  • Breach and Incident Management: Coordinating the investigation of HIPAA privacy incidents, managing HIPAA breach notifications, and ensuring proper documentation of corrective measures.

  • Business Associate Oversight: Managing Business Associate Agreements (BAAs) to ensure third-party vendors also comply with HIPAA privacy standards.

  • Regulatory Liaison: Serving as the organization’s expert on HIPAA privacy regulations and interfacing with the Office for Civil Rights (OCR) during audits or investigations.

 

While HIPAA technically requires that Covered Entities designate a Privacy Officer and a Security Officer, most corporations already have a Security Officer.  This new offering from ABLAW  focusing on Privacy Rule compliance, assuming that the Security Officer will be responsible for HIPAA Security Rule compliance.

While it is recommended that HIPAA Privacy Officers be an employee of the organization, when the organization does not have access to a qualified individual, ABLAW can step in and fill the gap.

DPO Services 

Effective May 25, 2018, GDPR requires entities that process personal information of EU residents to appoint an independent data protection officer (DPO) if the entity is a public authority/body, or if the entity carries out certain types of processing activities.

DPOs assist covered entities in monitoring internal compliance, inform and advice on data protection obligations, provide advice on Data Protection Impact Assessments (DPIAs) and act as a contact point for employees, data subjects and the supervisory authority (ICO).

 

DPOs must be independent, must have expertise in data protection, be adequately resourced, and report to the highest management level.

 

DPOs can be existing employees or externally appointed.

Monitoring compliance with GDPR and other data protection laws, e.g. CCPA, HIPAA, and state laws. 

Advice on compliance with GDPR and other data protection laws.

Workforce training on compliance with GDPR and other data protection laws. 

Serve as point of contact for the ICO, employees and

individuals.

bottom of page