If a CSP receives and maintains only information that has been de-identified in accordance with the HIPAA Privacy Rule, is it is a business associate?
No. A CSP is not a business associate if it [...]
No. A CSP is not a business associate if it [...]
No. The HIPAA Rules require covered entity and business [...]
Yes, provided the covered entity (or business associate) enters into [...]
No, the HIPAA Rules generally do not require a business [...]
Yes. Health care providers, other covered entities, and business associates [...]
Yes. The Security Rule at 45 CFR § 164.308(a)(6)(ii) requires [...]
If a covered entity (or business associate) uses a CSP [...]
OCR does not endorse, certify, or recommend specific technology or [...]
Generally, no. CSPs that provide cloud services to a covered [...]
Yes, because the CSP receives and maintains (e.g., to process [...]