Security and Compliance Built into the Working Relationship
Our Approach
ATS Healthcare maintains policies and procedures designed to support compliance with applicable HIPAA requirements when its services involve protected health information. Security and compliance responsibilities are defined through the service agreement, access model and, where required, a Business Associate Agreement.
How Security Fits into the Engagement
Defined access | System access and user responsibilities are established according to the service scope and information required for the work. |
Confidential handling | Practice, financial and patient information is handled according to applicable policies, agreements and authorized purposes. |
Responsible people and vendors | Team members and applicable third parties are expected to follow the privacy, security and confidentiality requirements assigned to their work. |
Escalation and review | Questions, exceptions and suspected incidents follow defined channels, and procedures can be reviewed when services, systems or requirements change. |
HIPAA and Business Associate Responsibilities
When ATS performs services that create, receive, maintain or transmit protected health information on behalf of a covered entity, the applicable responsibilities are addressed through a Business Associate Agreement and the service relationship. The agreement defines permitted uses and disclosures, safeguarding obligations, incident reporting and other responsibilities relevant to the engagement.
Shared Responsibility
Security depends on both ATS and the practice following the agreed operating model. Practices remain responsible for managing their own users, systems, devices and internal procedures, while ATS is responsible for the safeguards and actions assigned to it under the applicable agreement.
Security and Compliance Questions
Is ATS Healthcare HIPAA compliant?
ATS maintains policies and procedures designed to support compliance with applicable HIPAA requirements for the services it provides. The specific responsibilities for each engagement are defined in the service agreement and, where required, a Business Associate Agreement.
Will ATS sign a Business Associate Agreement?
When the services and relationship require one, the applicable Business Associate Agreement is reviewed as part of contracting and defines the permitted handling of protected health information.