Do the HIPAA Rules allow health care providers to use mobile devices to access ePHI in a cloud?
Do the HIPAA Rules allow health care providers to use mobile devices to access ePHI in a cloud?
If a CSP experiences a security incident involving a HIPAA covered entity’s or business associate’s ePHI, must it report the incident to the covered entity or business associate?
What if a HIPAA covered entity (or business associate) uses a CSP to maintain ePHI without first executing a business associate agreement with that CSP?
Which CSPs offer HIPAA-compliant cloud services?
Can a CSP be considered to be a “conduit” like the postal service, and, therefore, not a business associate that must comply with the HIPAA Rules?
If a CSP stores only encrypted ePHI and does not have a decryption key, is it a HIPAA business associate?
May a HIPAA covered entity or business associate use a cloud service to store or process ePHI?
Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?
What were the major modifications to the HIPAA Privacy Rule that the Department of Health and Human Services (HHS) adopted in August 2002?