Category: Business Associate Agreements

  • Business Associate Agreements Under HIPAA

    Business Associate Agreements Under HIPAA: Regulatory Necessity and OCR Enforcement Lessons

    The HIPAA Privacy Rule permits covered entities to use vendors and service providers that create, receive, maintain, or transmit protected health information (PHI). However, this permission is conditional. Federal law requires covered entities to obtain written โ€œsatisfactory assurancesโ€ that such third partiesโ€”known as business associatesโ€”will appropriately safeguard PHI. These assurances must take the form of a Business Associate Agreement (BAA) that meets the regulatory requirements established by the U.S. Department of Health and Human Services (HHS).

    Under 45 C.F.R. ยง 164.502(e), a covered entity may not disclose PHI to a business associate unless it first obtains these assurances in writing. The regulation is unequivocal: in the absence of a compliant BAA, disclosures of PHI to a business associate are impermissible under HIPAA, regardless of whether a breach or misuse ultimately occurs. HHS guidance further clarifies that covered entities are prohibited from sharing PHI with a business associate until such an agreement is in place. [

    Required Elements of a HIPAAโ€‘Compliant Business Associate Agreement

    The mandatory content of a BAA is prescribed directly by regulation at 45 C.F.R. ยง 164.504(e)(2). To satisfy the Privacy Ruleโ€™s requirement for โ€œsatisfactory assurances,โ€ a Business Associate Agreement must include the following provisions:

    1. Permitted and Required Uses and Disclosures of PHI

    The agreement must establish the permitted and required uses and disclosures of PHI by the business associate and may not authorize conduct that would violate the HIPAA Privacy Rule if done by the covered entity.

    2. Safeguards to Protect PHI

    The agreement must require the business associate to use appropriate safeguards to prevent unauthorized uses or disclosures of PHI, including compliance with the HIPAA Security Rule for electronic PHI.

    3. Reporting Obligations

    The business associate must be required to report to the covered entity any use or disclosure of PHI not permitted by the contract, including breaches of unsecured protected health information.

    4. Subcontractor Flowโ€‘Down Requirements

    The agreement must require the business associate to ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to the same restrictions and conditions.

    5. Access to Records by HHS

    The agreement must permit the business associate to make its internal practices, books, and records available to the Secretary of HHS for purposes of determining compliance with HIPAA.

    6. Return or Destruction of PHI Upon Termination

    Upon termination, the agreement must require the return or destruction of PHI when feasible or require continued protection of the information if destruction is not feasible.

    7. Termination for Cause

    The agreement must authorize the covered entity to terminate the contract if the business associate violates a material term.

    If any of these elements are missing, the agreement does not meet HIPAA requirements.

    OCR Enforcement and Lessons Learned

    The HHS Office for Civil Rights (OCR) has repeatedly enforced the BAA requirement through resolution agreements and corrective action plans. OCR has taken the position that disclosures of PHI made in the absence of a compliant BAA violate the HIPAA Privacy Rule, even when no breach has yet occurred. OCR resolution agreements routinely require covered entities to identify all business associates, execute compliant BAAs, and implement processes to prevent disclosures of PHI without prior agreement.

    HHS regulations and OCR enforcement actions make one principle unmistakably clear: a Business Associate Agreement is a prerequisite to lawful disclosure of PHI. Covered entities that fail to execute and maintain compliant BAAs expose themselves to enforcement action, corrective obligations, and significant regulatory risk. In HIPAA compliance, the existence of a valid BAA is not optional, it is required.

    Colington Consulting

    HIPAA Compliance, Risk Assessment & Management

    Our company specializes exclusively in HIPAA compliance, with a focus on helping covered entities and business associates identify risk, implement compliant Business Associate Agreements, and align their operations with HHS and OCR regulatory expectations. Drawing on direct regulatory requirements and realโ€‘world OCR enforcement patterns, we assist organizations with business associate identification, BAA drafting and remediation, vendor management programs, and auditโ€‘ready compliance documentation. Book a free initial consultation to evaluate your current BAA posture, identify gaps that may expose your organization to enforcement risk, and outline practical, defensible steps to strengthen HIPAA compliance before issues arise.

    Helping Organizations Achieve HIPAA Complianceโ„ข

  • Understanding the Role of a HIPAA Business Associate

    by Catherine Wanjau and Jay Hodes, President โ€“ Colington Consulting

    The continued complexity of modern healthcare systems and growth of patientsโ€™ data mean that medical records can be stored in more places than just the doctorโ€™s office. The information may be kept and maintained offsite in a storage facility or on a cloud-based server operated by a third party. Any entity or individual that uses, processes, or discloses this data on behalf of the healthcare provider is called a HIPAA Business Associate. If an organization is contracted by a HIPAA Covered Entity (CE) to perform activities that involve accessing Protected Health Information (PHI) or electronic PHI (ePHI) in any way, they are considered a Business Associate (BA). Because Business Associates use protected patientsโ€™ data to support the operations of covered entities, the U.S. Department of Health and Human Services (HHS) requires adherence to the Code of Federal Regulations (CFR) to comply with HIPAA requirements.

    Business Associate Agreement (BAA)

    The HIPAA Privacy Rule states that, โ€œA covered entity must obtain satisfactory assurances from its Business Associate that the Business Associate will appropriately safeguard the protected health information it receives or creates on behalf of the covered entity. The satisfactory assurances must be in writing, whether in the form of a contract or other agreement between the covered entity and the business associate.โ€

    This means that before a covered entity can work with a Business Associate, the BA must sign a BAA stating that they will safeguard and treat PHI the way CFRs and the covered entity require them to. It does not matter whose version of the BAA is signed, whether provided by the CE or the BA, as long it is executed. According to the Health Information Technology for Economic and Clinical Health (HITECH) Act, a BAA must include specific information to meet HIPAA compliance such as a description of the required and allowed uses of PHI, declarations that the Business Associate will disclose information only as required by law, and proper safeguards to protect patientsโ€™ data from breach including steps to take should there be such security violations.

    Why are Some Business Associates Not Complying with HIPAA Regulations?

    One of the major reasons is that most of them have no idea that the law considers them Business Associates. Covered entities have made great strides in following HIPAA compliance requirements, but many Business Associates are still not aware of the need to comply or are just reluctant to do so. Under HITECH, the Office of Civil Rights (OCR) holds Business Associates liable for breaches, and it is imperative that these entities take the necessary steps to ensure HIPAA compliance. In this press release where a Business Associate pays $2.3 million to settle a breach, the OCR Director at the time, Roger Severino terms โ€œThe failure to implement the security protections required by the HIPAA Rules in an industry known as a target for hackers and cyber thievesโ€ inexcusable. Sure, following all the steps required to obtain HIPAA compliance may seem overwhelming, but it offers better protection for patientsโ€™ data, which helps Business Associates avoid these types of federal penalties.

    Helping Organizations Achieve HIPAA Complianceโ„ข

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.