Policy Number: 22.214.171.124
Category: HIPAA Hybrid Entity Designation Policy
Effective: July 1, 2022
Revision History: Originally effective July 1, 2019; minor revision July 1, 2022
Review Date: June 30, 2025
PURPOSE AND SCOPE
- The purpose of this Policy is to designate West Virginia University, West Virginia University Institute of Technology, and Potomac State College of West Virginia University (collectively the “University) as a Hybrid Entity under HIPAA.
- This Policy applies to all schools, departments, clinics, programs, and functions designated as a University Health Care Component.
THE UNIVERSITY AS A HYBRID ENTITY:
- The University is a single legal entity, comprised of multiple and distinguishable schools, departments, clinics, programs, and functions, some of which may conduct both Covered Functions and non-covered functions under HIPAA.
- The University has determined that there are a number of its components that either do or do not use or disclose PHI; accordingly, to effectively and efficiently safeguard the use and disclosure of PHI and to focus its HIPAA compliance efforts on University Health Care Components, the University hereby elects to designate itself as a Hybrid Entity.
- Under Exhibit A, the University has designated the schools, departments, clinics, programs, or functions that either meet the definition of a Covered Entity, if each were a separate legal entity, or perform Covered Functions as a University Health Care Component.
- Under Exhibit A, the University has designated all schools, departments, clinics, programs, or functions that perform certain functions on behalf of a University Health Care Component that involves the use or disclosure of PHI as a University Business Component.
- The University will conduct periodic reviews to add or remove one or more University Health Care Component or University Business Component designation(s).
UNIVERSITY HEALTH CARE COMPONENT RESPONSIBILITIES:
- All University Health Care Components are subject to and must ensure compliance with applicable HIPAA requirements, including, without limitation, the requirements of the HIPAA privacy and security rules.
- University Health Care Components may only use and disclose PHI to a University non-health care component to the same extent, and in the same manner, as it is permitted to use or disclose PHI to individuals or entities that are legally separate from the University.
- University Health Care Components shall provide compliance reports to the Health Sciences Center Privacy Officer on a periodic basis. Such compliance reports will be facilitated via annual risk assessment conducted by the University.
UNIVERSITY BUSINESS COMPONENT RESPONSIBILITIES:
- All University Business Components are subject to and must ensure compliance with the same HIPAA requirements that are applicable to the designated University Health Care Component to which it is providing services. In that respect, and to avoid confusion, University Business Components shall be considered to be and are hereby designated as University Health Care Components.
- The University shall only permit the use and disclosure of PHI between a University Business Component and a University non-health care components to the same extent, and in the same manner, as the University is permitted to use or disclose PHI to individuals or entities that are legally separate from it.
- Each University Business Component shall provide compliance reports to the Health Sciences Center Privacy Officer on a periodic basis.
- "Covered Entity" means any health plan, health care clearinghouse, or health care provider that transmits PHI in electronic form in connection with a Covered Transaction.
- "Covered Function" means functions that a Covered Entity performs which makes it a health plan, health care provider, or health care clearinghouse.
- "Covered Transaction" means the transmission of information between two parties to carry out financial or administrative activities related to health care and includes: health care claims or equivalent encounter information; health care payment and remittance advice; coordination of benefits; health care claim status; enrollment and disenrollment in a health plan; eligibility for a health plan; health plan premium payments; referral certification and authorization; first report of injury; health claims attachments; health care electronic funds transfers (EFT) and remittance advice; or other transactions that the Secretary of the Department of Health and Human Services may prescribe by regulation.
- "HIPAA" means the Health Insurance Portability and Accountability Act of 1996, as amended, the Health Information Technology for Economic and Clinical Health Act of 2009 (HITECH), and all other regulations promulgated thereunder.
- "Hybrid Entity" means a single legal entity that conducts both covered and non-covered functions and designates health care components in accordance with HIPAA.
- "PHI" means individually identifiable protected health information transmitted by or maintained in electronic media or any other form of medium, excluding education records covered by the Family Education Rights and Privacy Act, as amended, employment recorded held by the Covered Entity as an employer, and information about a person who has been deceased for more than 50 years.
- "University Business Component" means a University school, department, program, clinic, or function that creates, receives, maintains, or transmits PHI to perform certain functions or activities on behalf of a University Health Care Component or provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services for a University Health Care Component and the provision of the service involves the disclosure of PHI.
- "University Health Care Component" means any University school, department, program, clinic, or function that (1) meets the definition of a HIPAA Covered Entity, if it were a separate legal entity; (2) performs Covered Functions; or (3) for purposes of this Policy, is a University Business Component.
ENFORCEMENT AND INTERPRETATION:
- Any employee, workforce member, or agent who violates this Policy shall be subject to appropriate disciplinary action.
- Any student who violates this Policy shall be subject to appropriate disciplinary action in accordance with the Student Code of Conduct.
- Any other individual who violates this Policy shall be subject to appropriate corrective action, including, but not limited to, termination of their relationship with the University
- The University’s Chief Information Officer, supported by the Chief Information Security Officer, will coordinate with appropriate University entities on the implementation and enforcement of this Policy.
- Responsibility for interpretation of this Policy rests with the Chief Information Officer.
Authority and References:
- BOG Rule 1.11 – Information Technology Resources and Governance
All other University policies may also apply to the protection and privacy of PHI,
and such policies remain in full force and effect. Relevant institutional
policies include, but are not limited to:
- Sensitive Data Protection Policy
- PHI Disclosure Standard
- PHI De-Identification Standard
- PHI Protection Standard