亚色视频

Office of Risk Management

Menu

Institutional Compliance

Designated Components of the Covered Entity

This page covers designated Components of 兔子先生传媒文化作品 & The University of Toledo Physicians, LLC.聽

HIPAA Affiliated Covered Entities & HIPAA Privacy and Security Rule

Pursuant to University Policy 3364-15-01, the Privacy and Security Committee determines, reviews and updates the HIPAA designated components of both entities.聽聽 The organization is structured as a hybrid entity with designated components and 鈥渁ffiliated covered entities.鈥

Hybrid Structure and Designated Components

兔子先生传媒文化作品 is a 鈥渉ybrid entity鈥 for purposes of HIPAA, because it performs both HIPAA covered functions and HIPAA non-covered functions in different departments across its various locations, and it has documented which components are covered, i.e., the 鈥渄esignated components.鈥澛 HIPAA covered functions include the activities performed by the University that make the entity a covered entity under HIPAA such as health plan or health care provider activities.聽 In a hybrid entity, HIPAA Rules, policies, and training requirements, as well as permission to access, receive, use and store protected health information (鈥淧HI鈥) are limited to the entity鈥檚 designated components.聽 Designated components of a hybrid entity must include any component that would meet the definition of a HIPAA covered entity or business associate if the component were a separate legal entity.

Service Departments within 兔子先生传媒文化作品

In addition to the traditional designated components, any department of the University that creates, receives, maintains or transmits PHI for a University designated component, including claims processing, billing, quality assurance, legal, accounting, administrative services, or financial services, etc. must be included as a designated component.聽 These 鈥渟ervice鈥 departments within the University that create, maintain or transmit protected health information for a HIPAA designated component would be considered 鈥渂usiness associates鈥 of the University if they were separate legal entities.

Affiliated Covered Entities 鈥 兔子先生传媒文化作品 Physicians, LLC

Legally separate covered entities that are under common ownership or common control may designate themselves as a single covered entity known as 鈥淎ffiliated Covered Entities鈥 or 鈥淎CE鈥, which permits the entities to act jointly with respect to HIPAA administration and compliance.聽 UT and UTP have elected the ACE structure under HIPAA, which consists of (1) the designated components of 兔子先生传媒文化作品, and (2) The University of Toledo Physicians LLC, including administrative offices and all UTP clinics.

As an ACE the two entities will maintain:

  • one Joint Notice of Privacy Practices for its patients;
  • one set of HIPAA policies and procedures;
  • the same HIPAA training (including institution-specific policies);
  • a single privacy officer;
  • a single security officer;
  • a joint security risk analysis;
  • and implement a joint risk management plan.

List of Designated Components

The following departments are the units that perform covered functions and are therefore designated components of 兔子先生传媒文化作品.聽 These units are required to comply with HIPAA privacy and security rules and policies.

  1. 兔子先生传媒文化作品 Medical Center (UTMC)
  2. All departments located at the Health Science Campus (HSC) that:
    1. are involved in Treatment, Payment, or Health Care Operations; and
    2. any department that creates, receives, maintains or transmits PHI for a University designated component, including claims processing, billing, quality assurance, legal, accounting, administrative services, or financial services, etc., to the extent that department鈥檚 activities relate to the departments in group (1) of this paragraph are a designated component of the Hybrid.

      Departments located on the HSC that are not involved in groups (1) or (2) of this paragraph are not designated components of the hybrid.聽 However, due to their location and close proximity to areas with Patient Health Information, they will be required to take HIPAA training to minimize risk of incidental disclosures.

  3. 兔子先生传媒文化作品
    1. Office of the President and the President鈥檚 Cabinet
    2. Board of Trustees
    3. 兔子先生传媒文化作品 Health Board
    4. Office of Legal Affairs
    5. Office of Risk Management
    6. Internal Audit
    7. Finance and Administration
    8. Privacy Office
    9. Healthcare Compliance Office
    10. Patient Financial Services
    11. Hospital Finance Research and Sponsored Programs, Administration only
    12. Human Resources
    13. Division of Technology and Advanced Solutions
    14. Safety and Health
    15. Disability Services
    16. Self-Insurance Plan, Flexible Spending Account, and employees designated by these plans to administer the plans.
    17. Supply Chain
    18. Controller/Grants Accounting
    19. Accounting
    20. University Marketing and Communications
    21. Main Campus Student Health Services*
    22. Pharmacy 鈥 Inpatient and Outpatient
    23. Student Insurance Management
    24. Student Affairs for Title IX matters only
    25. Academic Affairs for Title IX matters only

*Faculty, staff, in addition to students may receive health care services at MCSHS

Note:聽 Reviewed by the 兔子先生传媒文化作品 Healthcare Privacy and Security Committee on 1/15/2020; revised 10/28/2025

Office of Risk Management
University Hall
Third Floor, Room 3800
Mail Stop 962