| Type | Examples |
|---|---|
| Covered Entity (CE) | Health plans, hospitals, clinics, insurers, clearinghouses |
| Business Associate (BA) | SaaS vendors, cloud providers, analytics platforms, billing services, benefits portals (like Lantern) |
| Sub-contractor | Vendors hired by BAs who touch PHI — must also sign BAA |
| Required: Business Associate Agreement (BAA) signed before any PHI is accessed or processed | |
| Control Area | What's Required | How to Implement (AWS / SaaS context) | Type |
|---|---|---|---|
| Access Control | Unique user IDs; role-based access; no shared accounts | → IAM roles + least privilege; Okta SSO; MFA on all PHI systems; quarterly access reviews | Technical |
| Audit Controls | Log who accessed/modified ePHI; tamper-evident logs | → CloudTrail + CloudWatch Logs; S3 Object Lock (WORM); 6-yr retention minimum | Technical |
| Encryption at Rest | Addressable but effectively required; AES-256 | → S3 SSE-KMS; RDS encryption; EBS volumes encrypted; KMS CMKs per PHI data store | Technical |
| Encryption in Transit | TLS 1.2+ for all ePHI transmission | → Enforce HTTPS-only (S3 bucket policy, ALB redirect); disable TLS 1.0/1.1; cert rotation via ACM | Technical |
| Integrity Controls | Detect unauthorized alteration or destruction of ePHI | → S3 versioning + Object Lock; file integrity monitoring (AWS Config rules); checksums on exports | Technical |
| Automatic Logoff | Terminate sessions after inactivity | → Session timeout in app (15–30 min); Cognito/Okta idle session policies | Technical |
| Risk Analysis | Annual written risk assessment of all ePHI flows | → Data flow diagram → threat modeling → risk register with likelihood/impact scores; review after major changes | Administrative |
| Workforce Training | All staff with PHI access trained at hire + annually | → LMS tracking; phishing simulations; role-specific PHI handling modules; sign-off records | Administrative |
| Incident Response | Written IR plan; breach identification, containment, reporting | → Playbooks per incident type; 60-day notification SLA tracked; tabletop exercise annually | Administrative |
| BAA Management | Signed BAA with every vendor touching ePHI | → Vendor inventory with BAA status; AWS BAA auto-active for eligible services; annual renewal review | Administrative |
| Physical Safeguards | Workstation policy; device disposal; facility access | → MDM + full-disk encryption on endpoints; secure wipe policy; AWS handles data center (inherit via SOC 2) | Physical |
| De-identification | Remove all 18 identifiers OR expert determination | → Safe Harbor method in data pipelines; mask/tokenize in non-prod environments; never use real PHI in dev/test | Technical |
| Role | Key Obligations |
|---|---|
| CISO / Security | Own risk analysis; oversee technical controls; manage incident response |
| GRC / Compliance | Policy maintenance; BAA tracking; audit readiness; breach log; HHS reporting |
| Engineering | Implement encryption, access controls, audit logs; no PHI in logs/dev; secure SDLC |
| Product | Pre-deployment risk assessments; minimum-necessary data design; consent flows |
| Legal / Privacy | BAA negotiation; NPP drafting; patient rights responses; state law overlay |
| HR / People Ops | Workforce training records; sanction policy enforcement; background checks |
| Executive / Board | Designate Privacy & Security Officers; resource allocation; accountability |
| Tier | Cause | Per Violation | Annual Cap |
|---|---|---|---|
| Tier 1 | Didn't know; reasonable diligence | $100–$50K | $25K |
| Tier 2 | Reasonable cause; not willful neglect | $1K–$50K | $100K |
| Tier 3 | Willful neglect — corrected | $10K–$50K | $250K |
| Tier 4 | Willful neglect — not corrected | $50K+ | $1.9M |
| Criminal — Knowing misuse: up to 10 years imprisonment | |||