Haynes and Boone LLP's Approach to HIPAA Privacy Compliance for Employers
Our Approach
Haynes and Boone, LLP believes employers should determine the degree to which outside assistance is required in meeting their obligations under HIPAA’s privacy rules. Some groups are offering, at substantial fixed fees, turnkey packages for HIPAA privacy compliance. We do not think, however, that is the most efficient or economical way for many employers to address their responsibilities under the privacy rules. We prefer to work as part of a team with the employer to develop an approach to addressing privacy compliance that utilizes the employer’s internal resources and supplements those resources to the extent necessary.
Haynes and Boone, LLP’s HIPAA Privacy Practice Group has designed a process specifically for employers who maintain health plans for their employees. This process offers the employer the opportunity to determine how much of the compliance work they are able to do themselves with existing personnel, and who should be retained to do the balance of the work required for compliance. We can also work with either the employer’s internal staff resources or one of a number of subcontractors regarding the security aspects of privacy compliance. Moreover, since there are several steps required for compliance, some requiring unique skills, many employers will find that it is cheaper and more efficient to retain different groups to do different aspects of the outside work.