5 ms·
A forensic lab doing things with DNA may have no business relationship whatsoever with any covered entity (in fact I would guess that this is the most likely ca
by dontreact 5y ago
A forensic lab doing things with DNA may have no business relationship whatsoever with any covered entity (in fact I would guess that this is the most likely case).
- theli0nheart 5y agoDoesn’t matter. If you’re a business associate, you’re liable (both criminally and civilly) for violations of the privacy rule, and if you share HIPAA covered data with other businesses, those businesses must also adhere to it.
- Dracophoenix 5y agoHow does that work for Apple Health?
- theli0nheart 5y agoApple Health facilitates transmitting electronic health records on one's device with covered entities such as clinics. For this reason, they are required by law to maintain HIPAA compliance when entering into a business agreement with these covered entities.
- tzs 5y agoThere still has to be a covered entity involved. The HIPAA business associate rules are for business associates of covered entities. In the case of a police department collecting DNA data for analysis by a police forensic lab there is no covered entity involved. Other entities besides most state and local law enforcement that often have medical data but that are not covered by HIPAA include most private employers, state agencies such as child protective services, and most schools and school districts [1]. [1] https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/understanding/special/emergency/final_hipaa_guide_law_enforcement.pdf https://www.hhs.gov/sites/default/files/ocr/privacy/hipaa/un...
- theli0nheart 5y agoMy implication is that there’s no way to link up DNA to an individual without having a reference point. A hospital or lab (both covered entities) would provide this data (perhaps under subpoena?), and would ostensibly be working directly with the forensics lab in these cases. How else would they link up DNA (which is by itself not PHI) to an identity?
- dontreact 5y agoSo then the hospital or lab are under HIPAA, but not the forensic lab.
- theli0nheart 5y agoThat's not how it works. If the hospital or lab provides PHI (protected health information) to the forensic lab, the forensic lab must sign a business associate agreement with the HIPAA covered entity that gives assurances to them that any PHI will be protected. If a breach occurs, then the forensic lab is liable for full HIPAA penalties.