While there is not a governing body that certifies that vendors are HIPAA compliant, Greatland has aligned with ISO 27002:2013. This set of standards maps to the HIPAA security rule. Additionally, Greatland enters into a Business Associate Addendum when using Greatland’s technology products.
A business associate includes a subcontractor that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered individual – under the HIPAA regulations, service providers like Greatland are considered business associates. HIPAA guidelines typically require that covered entities and business associates enter into contracts to ensure that the business associates will appropriately safeguard PHI.
The business associate contract also serves to clarify and limit, as appropriate, the permissible uses and disclosures of protected health information by the business associate, based on the relationship between the parties and the activities or services being performed by the business associate. Greatland refers to these contracts as Business Associate Agreement Addendums.