US

HIPAA: Business Associates

Business Associates [45 CFR 164.502(e), 164.504(e)]

Rule: Covered entities may only disclose PHI to business associates under a written Business Associate Agreement (BAA) that establishes permitted uses and required safeguards.

What is a Business Associate?

A person or entity that:

  1. Performs functions or activities on behalf of a covered entity, AND
  2. Involves the use or disclosure of PHI

Common Business Associate Examples

CategoryExamples
TechnologyEHR vendors, cloud hosting, IT support with PHI access
AdministrativeBilling companies, claims processing, collections
Professional servicesAttorneys, accountants, consultants with PHI access
ManagementPractice management, PHRs, patient portals
OtherShredding companies, transcription services

NOT Business Associates

CategoryReason
Janitorial servicesIncidental access, not using PHI
Electrical/plumbingNo access to PHI
Courier servicesTransport only, not accessing content
Patients’ family/friendsNot performing services for CE
Other covered entitiesCE-to-CE disclosure rules apply

Business Associate Agreement Requirements [§164.504(e)]

Every BAA must include:

RequirementDescription
Permitted usesDescribe what BA may do with PHI
Prohibited usesMay not use or disclose except as permitted
SafeguardsRequire appropriate safeguards
ReportingReport breaches and security incidents
Subcontractor complianceEnsure subcontractors comply
Individual rightsSupport covered entity’s obligations
Access to recordsMake information available for HHS
Return/destroyAt termination, return or destroy PHI
TerminationAuthorize termination for violation

Business Associate Direct Obligations

Under HITECH, business associates are directly liable for:

ObligationCitation
Privacy Rule limits on use/disclosure§164.502(a)
All Security Rule requirements§164.302-318
Breach notification to covered entity§164.410
Subcontractor BAA requirements§164.502(e)(1)(ii)

Subcontractor Requirements

Business associates must:

  1. Enter BAAs with subcontractors who access PHI
  2. Ensure subcontractors agree to same restrictions
  3. Remain responsible for subcontractor compliance

Penalties for Non-Compliance

Business associates are subject to same penalties as covered entities:

  • Civil monetary penalties up to $1.9M per violation category
  • Criminal penalties for knowing violations
  • State attorneys general enforcement

Citation

45 CFR 164.504(e) — Business associate contracts

Contains public sector information licensed under the Open Government Licence v3.0 where applicable. This is not legal advice. Always refer to official sources for authoritative text.

llms.txt