Before 2013, HIPAA enforcement against business associates was indirect. You violated your Business Associate Agreement, the covered entity violated HIPAA, and enforcement flowed through them. The 2013 Omnibus Rule changed that. Business associates are now directly regulated under HIPAA. OCR can investigate you, fine you, and enter into resolution agreements with you — without the covered entity being involved at all.
If you're a healthcare IT vendor, billing company, transcription service, managed service provider, or any other organization that handles PHI on behalf of covered entities, this is about you.
What the Security Rule Requires of Business Associates Directly
The Omnibus Rule made HIPAA's Security Rule directly applicable to BAs. This means BAs must independently implement:
Security Management Process (§164.308(a)(1)): Conduct a risk analysis, implement a risk management plan, maintain workforce sanctions for Security Rule violations, and review information system activity. The risk analysis requirement for BAs is identical to the requirement for covered entities — documented, accurate, thorough assessment of risks to ePHI.
Security Officer designation (§164.308(a)(2)): One individual must be responsible for security policies and procedures. For a small BA, this might be the owner or a senior technical person. It has to be someone.
Workforce training and management (§164.308(a)(3) and (a)(5)): Authorization and supervision of workforce members with access to ePHI. Background checks where appropriate. Training on security policies. Process for reporting security incidents.
Written security policies and procedures (§164.316(a)): Document your security policies, implement them, and maintain them. "We follow best practices" is not a documented policy.
Contingency planning (§164.308(a)(7)): Data backup plan, disaster recovery plan, emergency mode operation plan. Evidence of periodic testing.
Technical safeguards (§164.312): Access controls, audit logging, integrity controls, authentication, transmission security. Everything that applies to a covered entity applies to a BA handling ePHI.
The Sub-BA Obligation That Most Organizations Miss
§164.308(b)(3) requires business associates to ensure that their own subcontractors — the vendors who handle ePHI on the BA's behalf — also have appropriate safeguards in place and have signed Business Associate Agreements.
These downstream BAs are sometimes called "sub-BAs."
This catches organizations off guard because they sign a BAA with a covered entity and assume that satisfies their HIPAA obligations. It doesn't. If you're a healthcare IT company that uses:
- AWS to host your application and store ePHI
- Twilio for patient appointment reminders that include PHI
- A third-party analytics platform that processes ePHI
- A subcontractor who performs maintenance on systems containing ePHI
...then each of those relationships requires a BAA. If your analytics vendor says they don't need a BAA because "we only process aggregate data," but they're receiving ePHI to produce that aggregate data, you need a BAA with them.
AWS, Azure, and Google Cloud all offer BAAs for services used to store and process ePHI. You need to actually sign them and use the covered services, not just assume the BAA covers all use cases automatically.
Direct OCR Enforcement Against BAs
OCR has exercised its direct enforcement authority against business associates in multiple high-profile cases:
CHSPSC LLC (Community Health Systems) — $2.3 million (2023): CHSPSC is the IT service provider — a business associate — to Community Health Systems' hospital affiliates. OCR found failures in security management, risk analysis, and implementing technical safeguards across the BA's systems. This was a direct BA enforcement action; the covered entity hospitals were not the primary target.
The pattern: OCR follows the PHI. If a breach originates at a BA, or if a complaint suggests a BA's practices are inadequate, OCR investigates the BA directly. The covered entity's compliance doesn't protect you.
The Most Common BA Compliance Failures
No documented risk analysis: The risk analysis requirement for BAs is real and routinely missing. "We have good security" isn't a risk analysis.
No BAAs with sub-BAs: Cloud providers, development contractors, analytics vendors — if they touch your ePHI, they're sub-BAs. Most organizations don't have this covered.
No incident response plan: If a breach occurs at your organization, you have notification obligations to the covered entity — without unreasonable delay, and no later than 60 days from discovery. Without a plan, you're improvising at the worst possible moment.
Unencrypted ePHI on portable media or laptops: This is still one of the most common breach scenarios. A laptop with unencrypted PHI gets stolen, and now you have a breach that's both your problem and the covered entity's problem.
Workforce access to ePHI without training: Staff who access ePHI need to know what they can and can't do with it. HIPAA minimum necessary standards apply to BA workforce members too — accessing more PHI than is necessary to perform a job function is a violation even if the staff member didn't do anything obviously wrong.
Scope creep in BAA permitted uses: If your BAA with a covered entity defines specific permitted uses, and your staff access PHI for purposes outside those uses — even legitimate internal business purposes — you're outside the BAA.
Practical Priorities for BAs
If you're a business associate building or improving your HIPAA compliance program, prioritize in this order:
-
Document your risk analysis. This is the most commonly cited gap in enforcement. If you haven't done a formal, documented analysis of where ePHI is, what could happen to it, and what you're doing about it — do this first.
-
Inventory your sub-BAs. Get a list of every vendor who touches ePHI in your operations. For each one, confirm a BAA exists or get one signed.
-
Document your security policies. At minimum: access control, incident response, acceptable use, breach notification procedure. These don't need to be long — they need to be real.
-
Establish a breach notification procedure. You must notify the covered entity without unreasonable delay — and in no case later than 60 days from discovery. Know who makes that call, what information you need to gather, and what the CE needs from you.
-
Train your workforce. Anyone who accesses ePHI needs to know your policies, understand HIPAA minimum necessary, and know how to report potential incidents.
Being a business associate doesn't mean HIPAA is the covered entity's problem. It means you share it.
SOURCES
- 45 CFR §164.308(b) — Business Associate Contracts and Other Arrangements: ecfr.gov
- HHS, "Business Associates": hhs.gov/hipaa/for-professionals/privacy/guidance/business-associates/index.html
- HHS Omnibus Rule Final Rule (2013): federalregister.gov/documents/2013/01/25/2013-01073/modifications-to-the-hipaa-privacy-security-enforcement-and-breach-notification-rules-under-the
- OCR Resolution Agreements — CHSPSC: hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
Building a HIPAA compliance program as a business associate? Schedule a consultation to talk through what your obligations actually are.
