// SEC_HIPAA_Ethics8 terms
SEC, HIPAA and legal ethics
17 CFR 248.30 · 45 CFR 160, 164 · ABA Model Rule 1.6
Covered institution
SEC, HIPAA, ethicsAny broker or dealer, any investment company, and any investment adviser or transfer agent registered with the Commission (the SEC) or another appropriate regulatory agency. An affiliated SEC-registered adviser puts a second safeguards regime, with its own clocks, on any systems the accounting firm shares with it.
Sensitive customer information
SEC, HIPAA, ethicsAny part of customer information, alone or combined with other information, whose compromise could create a reasonably likely risk of substantial harm or inconvenience to the person it identifies. Examples: Social Security and taxpayer ID numbers. After unauthorized access or use, the covered institution must notify each affected person, whatever the count, unless it finds harmful use not reasonably likely.
Service provider (Regulation S-P)
SEC, HIPAA, ethicsAny person or entity that receives, keeps, processes or is otherwise allowed to access customer information by serving a covered institution directly. The institution’s policies must be reasonably designed so the provider reports a breach of its customer information systems as soon as possible, within 72 hours of becoming aware. Making sure affected people are notified stays the institution’s duty.
Covered entity (HIPAA)
SEC, HIPAA, ethicsA health plan, a health care clearinghouse, or a health care provider that transmits any health information electronically in connection with a transaction the HIPAA rules cover. The HIPAA security, privacy and breach rules in 45 CFR Part 164 apply to it. Wisconsin’s breach notice law, Wis. Stat. 134.98, does not apply to one that complies with Part 164.
Business associate (HIPAA)
SEC, HIPAA, ethicsAn outside person or firm that handles protected health information for a covered entity’s HIPAA-regulated work. It also includes a firm doing legal, accounting, consulting or financial work for one, where the work involves receiving protected health information. If your firm is one, the client may share that information with you only under a written business associate agreement.
Protected health information
SEC, HIPAA, ethicsAlso PHI; the electronic part is ePHI (electronic protected health information)
Identifiable information, in any form, about a person’s health, care or payment for care, created or received by a health care provider, health plan, employer or health care clearinghouse. Exclusions include FERPA education records, employment records a covered entity holds as an employer, and information on anyone dead over 50 years. What is kept or sent electronically is ePHI.
Breach (HIPAA)
SEC, HIPAA, ethicsAcquiring, accessing, using or disclosing protected health information in a way HIPAA’s privacy rules do not permit, compromising its security or privacy. Apart from three exclusions, this is presumed a breach unless a risk assessment shows a low probability of compromise. For unsecured information, the covered entity must notify affected people without unreasonable delay, within 60 calendar days of discovery.
Information relating to the representation
SEC, HIPAA, ethicsThe category the duty of confidentiality protects: all information relating to the representation, not only what the client marked confidential. Rule 1.6(c) requires reasonable efforts to prevent inadvertent or unauthorized disclosure of, or unauthorized access to, that information. Each state adopts its own version and the state’s text governs.