Because the university only uses and engages in electronic transactions involving HIPAA protected health information for a part of its operations, the university has designated itself as a hybrid entity for purposes of HIPAA compliance. The university's health care components, and components that perform activities that would make the component a business associate of the university if it were legally separate, are therefore subject to the specific requirements of HIPAA. The components subject to the requirements of HIPAA shall be designated in the university's HIPAA privacy policy as it may be amended from time to time. Other components may be designated as part of the hybrid as may be required to comply with changes in the law, or as necessary for the orderly operation of the university as determined in writing by the vice president for legal affairs and general counsel.
In the event an additional university component is designated as part of the university's hybrid entity, the vice president for legal affairs and general counsel shall report such designation to the board for information at its next regular meeting.
Replaces: 3361:10-5-20
Ohio Admin. Code 3361:10-5-20
Promulgated Under: 111.15
Statutory Authority: 3361
Rule Amplifies: 3361
Prior Effective Dates: 07/15/2011