HIPAA / HITECH Compliance Kit For

Employer Health Plans and Business Associates

In January 2013, HHS issued significant new HIPAA regulations. The primary purpose of the regulations is to implement the HITECH amendment to HIPAA. In addition, HHS released new sample business associate agreement provisions. Employers need to update their prior HIPAA compliance efforts in response to the new regulations.

Compliance Kit

Miller Johnson has prepared a compliance kit to assist employers in their capacity as health plan sponsors to update their HIPAA privacy and security procedures and documents for HITECH and the new final regulations. The kit includes a hard copy and electronic versions of the following:

  • Compliance instructions
  • Updated HIPAA policies and procedures incorporating the final regulations, including the new breach notification procedures
  • Sample notice to individuals in the event of a breach of unsecured protected health information (“PHI”)
  • Revised participant notice of privacy practices
  • New business associate agreement. Included with the business associate agreement is a cover letter to the business associate describing the changes which have been made in order to comply with the final regulations and providing the rationale why your version of the business associate agreement should be used rather than any version supplied by the business associate
  • Two sample Power Point training documents. The first is to provide training to existing employees in the group with access to PHI regarding the final regulations and to provide refresher training regarding the HIPAA privacy and security rules. The second is to provide initial HIPAA training (for example, to a new hire or employee transferred into the group with access to PHI)
  • Annual checklist to facilitate ongoing compliance

Cost

Miller Johnson is offering employers a new compliance kit to address the final regulations and all of the employer’s HIPAA / HITECH compliance requirements. If you are an employer that previously purchased a compliance kit from Miller Johnson, the cost of the new kit is $500. It is intended to replace the prior kit. If you are an employer that has not previously ordered a compliance kit from Miller Johnson, we are also making the kit available to you. Your cost of the kit is $850.

Intended Use

The kit is intended for use by employers in their capacity as health plan sponsors. It is for the purpose of addressing all of the documents needed in order to comply with the final regulations. As a result, it should update and replace prior HIPAA and HITECH compliance efforts.

Business Associates

If you are a business associate (including a subcontractor), the final regulations require you to directly comply with HIPAA in a manner similar to employer health plans. Miller Johnson also offers a compliance kit specifically designed for business associates. It updates and replaces the prior kit for business associates offered by Miller Johnson. If you are a returning customer, we are making the kit available to you for $400. If you are a business associate that previously has not ordered a kit from Miller Johnson, the cost of the kit is $600.

Kit Amendments – 2024

New HIPAA Rules Require Immediate Action By Employers and Business Associates

As noted in our October 31, 2024 client alert, in response to the Supreme Court’s overturning of Roe v. Wade, the Office of Civil Rights (OCR) within the Department of Health and Human Services (HHS) – the agency with the jurisdiction to enforce HIPAA – issued new guidance to address the protection of protected health information (PHI) that is related to reproductive health care.

Immediate Action Required

Covered Entities (i.e., health plans) and Business Associates must train applicable workforce members and amend their HIPAA policies and procedures by December 23, 2024 with respect to the requirements of this new guidance.  These entities must also update their Notice of Privacy Practices (NPP), but the updated NPP is not required until February 16, 2026.

To comply with the requirements of this new guidance, we have HIPAA kit amendments available to purchase below. These amendments, which include the amendment to the HIPAA policies and procedures, a sample attestation, and a copy of the training webinar, with slides are available for sale for $500 apiece.

How to Order a Kit

HIPAA / HITECH Compliance Kit Amendment

Only if you previously purchased a HIPAA / HITECH Kit.

For Employer Health Plans (including Medical FSAs and HRAs)

For those who have already purchased the Employer Health Plan HIPAA kit, this amendment updates the kit to comply with the Reproductive Health Care Final Rule.

If you purchase this amendment, you will get a $500 credit toward the updated Employer Health Plan HIPAA kit in 2025.

For Business Associates

For those who have already purchased the Business Associate HIPAA kit, this amendment updates the kit to comply with the Reproductive Health Care Final Rule.

If you purchase this amendment, you will get a $500 credit toward the updated Business Associate HIPAA kit in 2025.

HIPAA / HITECH Compliance Kit

If you need the whole kit (which includes the amendment and materials described above), the kits are for sale here for $1,350 apiece.

For Employer Health Plans (including Medical FSAs and HRAs)

This kit will help companies with self-funded health plans comply with HIPAA rules.

It includes the amendment and materials described above.

For Business Associates

This kit will help entities acting as Business Associates for group health plans comply with HIPAA rules.

It includes the amendment and materials described above.