HIPAA applies to Covered Components, which are health care providers, health plans, and clearinghouses that engage in certain types of transactions electronically. Only portions of Boston University are covered under HIPAA:

  • Faculty Staff Assistance Program
  • Sargent College Rehabilitation Services
  • School of Dental Medicine: Dental Clinic
  • School of Dental Medicine: Oral and Maxillofacial Pathology Lab
  • School of Medicine Center for Human Genetics
  • Student Health Services (with exceptions)
  • The B.U. Health Plan
  • The B.U. Dental Plan
  • The Danielsen Institute
  • The Occupational Health Center

HIPAA also applies to anyone working for one of the Covered Components in any capacity, such as students, faculty, and staff (including grant-funded, part time, volunteer, or casual/temporary employees).

Departments at Boston University that support our HIPAA users and electronic protected health information (ePHI) servers also need to comply with the Security Policies. These include but are not limited to:

  • Buildings & Grounds
  • Information Services & Technology
  • Human Resources
  • Information Systems Planning & Support
  • Internal Audit
  • Office of General Counsel
  • Business Associates – Vendors/contractors performing services on behalf of BU