Orange County NC Website
DocuSign Envelope ID:818337D8-7142-453C-8DE1-5D9B9A037D1E <br /> it <br /> f TRATUS <br /> AGREEMENT FOR SERVICES <br /> Exhibit C <br /> Health Insurance Portability and Accountability Act (HIPAA) <br /> Compliance Process <br /> Background <br /> The Health Insurance Portability and Accountability Act (HIPAA) governs the documentation and dissemination <br /> of all patients' healthcare information by medical providers, insurance companies, and certain third parties <br /> (Covered Entities). <br /> HIPAA rules require that Covered Entities and their Business Associates apply appropriate administrative, <br /> technical, and physical safeguards to ensure the privacy of Protected Health Information (PHI) and Electronic PHI <br /> (EPHI). <br /> HIPAA includes both the Privacy Rule and the Security Rule: <br /> • The Privacy Rule. Gives individuals rights over their health information, whether oral, written or <br /> electronic. <br /> • The Security Rule. Protects all health information in electronic form, ensuring that all EPHIs are secure. <br /> There is no governing agency, commission, or standards body that certifies HIPAA compliance. However, <br /> Department of Justice is tasked with investigating and adjudicating HIPAA violations by Covered Entity and <br /> Business Associates. <br /> It is up to the Covered Entity or Business Associate to determine and maintain it's own compliance with the <br /> Privacy and Security rules. <br /> Discussion <br /> Stratus recognizes that we must provide our services and solutions that are HIPAA complainant and support the <br /> requirements outlined in a Business Associate Agreement. Stratus designed and developed our services to <br /> operate in accordance with your HIPAA requirements. <br /> Specific Stratus Video Features to ensure HIPAA compliance: <br /> 1) Data Security. <br /> a) Stratus requires a site-to-site Virtual Private Network (VPN) between the hospital and the Stratus Video <br /> Network. This Cisco VPN supports AES encryption of the signaling and data streams (both video and <br /> audio). This protects all hospital video systems including Stratus Video, or legacy video equipment <br /> connecting to the Stratus Video Network. <br /> b) Stratus does not record video calls so no protected health information is captured or stored in the <br /> Stratus Video system at any point and as such,fits the definition of data not at rest. <br /> c) Access to Stratus software on the devices is Password Protected <br /> d) Video software does not allow Auto Answer feature, preventing unauthorized access to video calls. <br /> AFS-7/10/2015 Confidential and Proprietary Page 6 of 7 <br />