To assure vendor compliance with the UMHS policies, vendor representatives who work on site with University health care providers or who have access to sensitive information created or maintained by those providers are required to follow the UMHS Code of Conduct and Compliance Program and execute our Code of Conduct Attestation.
HIPAA stands for the Health Insurance Portability and Accountability Act of 1996. While the title suggests that this rule only applies to insurance information, a major part of HIPAA addresses the privacy of "Protected Health Information," the patient's health information (PHI). Patients are provided information about how we use and share patient information through our Notice of Privacy Practices. A copy of The HIPAA Privacy and Security Regulations in a Nutshell is available here.
PHI is information:
HIPAA requires the University of Michigan to sign a Business Associate Agreement (BAA) with all of its business associates. A Business Associate is someone who does not work for the University of Michigan and needs access to our patients’ protected health information (PHI).
What are some examples of when a Business Associate Agreement may or may not be required?
Scenario | Business Associate Agreement with Vendor |
1. Technical vendors who have access into computer systems or database containing PHI | Required |
2. Accreditation organizations | Required |
3. Temporary agencies that place personnel in areas where they may have access to PHI | Required |
4. Record storage facilities | Required |
5. Lawyers, accountants, consultants (non-university employees) | Required |
6. A non-covered entity with access to PHI (e.g. orthotics manufacturer) | Not required if the entity is also a health care provider |
7. Vendors who only have incidental access usually are not considered Business Associates (e.g., copy repair technicians) | Not required |
Vendors uncertain of their status as a Business Associate should contact the Procurement buyer handling their current contract. Contact information for the Procurement Teams is available on the Contacts page.