I have a signed BAA and the New Terms and conditions which go into effect on Sept 14 have raised some serious HIPAA concerns. Specifically: Section 1 ("Customer Data") and Section 2 ("License to Data") of your new terms raise significant compliance concerns.
I have written to the company and left a phone message and am waiting for a response. Has anyone else received clarification on the following points:
- Agreement Priority: If there is a conflict between these new Terms and Conditions and our existing BAA, which document takes legal priority? Do these new terms alter or replace any part of our existing BAA?
- HIPAA Marketing Restrictions: The new terms state that you may use Customer Data to "market Our products and services." Since our Customer Data contains Protected Health Information (PHI), how does this usage comply with HIPAA rules, which strictly forbid using PHI for marketing without explicit patient authorization?
- Data Return and Destruction: The updated terms grant your company a "perpetual, irrevocable" license to our data. Our BAA requires your company to return or destroy all PHI once our contract ends. How will you honor the BAA's data destruction requirements if you hold a permanent license to the data?
- Subcontractor Compliance: The terms permit data sharing with subcontractors through "multiple tiers." Can you confirm that your company executes HIPAA-compliant BAAs with every single tier of subcontractors before they are granted access to our data?
- De-identification Standards: When your company creates "De-identified Data" from our patient records, which specific HIPAA standard do you utilize (the Safe Harbor method or the Expert Determination method) to ensure the data is legally and fully de-identified?
In advance thanks for you input
