Search Close Search
Search Close Search
Page Menu

Third Parties and PHI Standard Operating Procedure

Accountability Act (HIPAA). UMass Memorial Health Care and the UMass Chan Medical School have entered into a Business Associates Agreement (BAA) that delineates the conditions under which the clinical system shares PHI with the medical school. Based on the agreement, while the medical school is not a Covered Entity, the medical school is a Business Associate and as such is required to protect clinical data in compliance with the HIPAA Security and Privacy rules.

The clinical system will allow the medical school to enable access to PHI in order to further the mission of research as long as standard operating procedures are established and followed to ensure appropriate protection of the data. Additionally, no third party, unless they are part of the UMass Chan Data Lake development project and have an established contract for UMass Chan Data Lake development work with the medical school, will have direct access to UMass Chan Data Lake or associated systems that store data.

▼ Open All
|
▲ Close All

3rd Party Process Steps