
HIPAA
Wiggin and Danaโs HIPAA practice group helps local, national, and international clients develop and implement practical, tailored strategies to stay compliant with the far-reaching and complex requirements of privacy laws applicable to the digital health industry. Working with our Cybersecurity and Privacy Practice Group, we help clients address HIPAA as well as other privacy and security requirements that might apply, such as various state laws, the GLBA, FERPA, and the EUโs GDPR.
For decades, we have worked with a broad range of organizations and companies within the healthcare industry โ and vendors that provide IT consulting, data analytics, artificial intelligence (AI), and other services to them โ employing our deep understanding of privacy, security, and data exchange issues.
Renowned academic medical centers, health care systems and networks, universities, provider associations, pharm and biotech companies, software and app developers, employers with self-insured health plans, and vendors of all kinds rely on our expertise in both information digital health law and HIPAA. We can provide some or all of the following services, tailored to your needs.
Services
- Build a HIPAA compliance program from the ground up, including developing policies and procedures for compliance with the HIPAA Privacy, and Breach Notification Rules and other applicable privacy and security laws
- Review and update existing policies and procedures to ensure ongoing compliance with HIPAA and HITECH, and other applicable privacy and security laws
- Assist with reviewing and negotiating agreements and resolving legal issues and questions arising in business associate-covered entity relationships
- Perform audits to determine compliance with privacy and security requirements and develop and implement remediation plans to address areas of non-compliance
- Assist with the development of auditing tools and ongoing monitoring and compliance programs and provide overall coordination of internal auditing and monitoring efforts
- Consult on interpretative questions arising in day-to-day operations or from compliance audits
- Develop training materials and programs to educate workforce members about legal requirements related to information privacy and security
- Draft and/or negotiate contracts between covered entities and business associates
- Provide counsel on the implications of operational and system changes and of changes in legal requirements that may affect the organizationโs compliance with privacy and security requirements
- Assist with investigating and mitigating privacy and security breaches
- Advise on breach notification obligations and provide guidance on reports to, and interactions with, affected individuals, the federal Department of Health and Human Services Office for Civil Rights (OCR), state Attorneys General, and the media
- Provide counsel on government investigations and responding to complaints filed with OCR, state agencies, the office of the stateโs Attorney General, and others
- Interpret and incorporate applicable data privacy and security laws relevant to the organizationโs information security, policies and procedures and its use of information technology systems