|
As a world-leading supplier of advanced and innovative radiation oncology and neurosurgery solutions and services for precise treatment of cancer and brain disorders, Elekta is committed to helping its customers comply with new and existing transaction, privacy, and security standards. Elekta understands the importance of the privacy and security of a patient’s Protected Health Information (PHI), and agrees to protect that right to the extent necessary under current laws and regulations, including the Health Insurance Portability and Accountability Act (HIPAAn). For purposes of this statement, PHI is any data or other information as defined by the Department of Health and Human Services in the Code of Federal Regulations, 145 CFR Part 164.501. This statement describes various methods in which Elekta supports its customers’ efforts for HIPAA compliance.
The HIPAA regulations require health care providers to identify all businesses with which they do business and may disclose patient health information. Once identified, the covered entity is required to enter into Business Associate Contracts with these identified businesses. These business associate contracts generally require the recipients of such information to use appropriate safeguards to protect the patient health information they receive., Elekta personnel may need access to patient health information maintained by its customers in order to perform certain service and support functions. As a result, Elekta may be considered a "business associate" of customers to whom it provides such services. Elekta’s agreement to enter into business associate contract will generally assure its customers that the company will use patient information obtained from them to provide services and support only and will safeguard that information from misuse.
Elekta’s Privacy and Security Policy will protect the confidentiality and integrity of the patient information it receives and will be implemented by:
- Agreeing that it shall not use or disclose any patient’s PHI for any purpose not expressly stated in applicable Business Associate Agreements. Further, Elekta shall not use or disclose PHI in any manner or context prohibited by the Health Insurance Portability and Accountability Act of 1996 (HIPAA) (and subsequent federal regulations). If Elekta does use or disclose PHI for a purpose not expressly stated in applicable Business Associate Agreements, it shall immediately cease the unauthorized use or disclosure, and shall notify the customer in writing of such use or disclosure.
|
|
- Further agreeing that any subcontractors or other persons or entities not directly employed by Elekta, and who uses or discloses PHI obtained from our customers shall abide by terms of appropriate clauses of applicable agreements. Any subcontractor or other person or entity not directly employed by Elekta who has used or disclosed PHI without proper authorization (as defined in HIPAA and subsequent federal regulations) shall be considered to have acted as an agent of Elekta, and violated the terms of applicable Business Associate Agreements. Our customer may consider this use or disclosure a material breach of this Agreement, and may seek termination of applicable Agreements without recourse by Elekta.
- Assure our customers that we meet the minimum safeguards necessary to protect unauthorized use or disclosure of PHI to any person or entity not party to this Agreement. Such safeguards shall include the security safeguards outlined by HIPAA and subsequent federal regulations, including physical access to PHI, technical access to PHI, and administrative policies and procedures addressing security of PHI.
- Report to our customers any instance or circumstance in which PHI has been used or disclosed by an unauthorized person or entity, including accidental disclosure by Elekta.
- Incorporate any amendments or corrections to the PHI at your request should you find PHI used or disclosed to Elekta to be inaccurate or incomplete.
- Return or destroy to the satisfaction of our customers any PHI held or maintained by Elekta at the termination of a Business Associate Agreement.
- Provide for the storage and transmission of patient health information received from customers in a secure manner that protects the integrity, confidentiality and availability of the information. All remote access to customer facilities by Elekta product support personnel will be made using a fully encrypted protocol.
|
|