Large Medicaid Plan Corrects Vulnerability that Resulted in Disclosure to Non-BA Vendors A municipal social service agency disclosed protected health information while processing Medicaid applications by sending consolidated data to computer vendors that were not business associates. Among other corrective actions to resolve the specific issues in the case, OCR required that the social service agency develop procedures for properly disclosing protected health information only to its valid business associates and to train its staff on the new processes. The new procedures were instituted in Medicaid offices and independent health care programs under the jurisdiction of the municipal social service agency. |
BAA Facts
|
Sample BAA
|
Office Locations: 100 Florida Ave
|
|