← All guides

Business Associate Due Diligence

Breaches and enforcement8 min read

Business Associate Due Diligence

A business associate is any organization that creates, receives, maintains or transmits protected health information on a covered entity's behalf. Since the 2013 Omnibus Rule, business associates and their subcontractors are directly liable under the Security Rule and parts of the Privacy Rule, but the covered entity remains responsible for its own choice of vendors and for the contract that governs them.

The business associate agreement is a required contract with required terms. It is not, by itself, due diligence. OCR settlements have repeatedly cited entities that had an agreement on file but never assessed the vendor, never got assurances about safeguards, and never noticed when the vendor's environment changed.

In the current breach data roughly a third of reports involve a business associate, and the largest incidents of the decade have been vendor incidents that surfaced as hundreds of separate reports. Vendor risk is therefore not a side program; it is where the largest exposure sits for most covered entities.

Key points

  • Required BAA terms

    Permitted uses and disclosures; safeguards; reporting of breaches and security incidents; subcontractor flow-down; individual rights support; availability of books and records to HHS; return or destruction of PHI at termination; and termination for material breach.

  • Proportionate assessment

    Scale the assessment to the PHI at stake: a SOC 2 Type II or HITRUST report and a questionnaire for a cloud EHR host; a short attestation for a shredding vendor. Document the tiering logic.

  • Security incident versus breach reporting

    The Security Rule requires business associates to report security incidents, not only breaches. Contracts should define what counts, the deadline, and the contact path, or the default 60-day breach clock will be all you get.

  • Subcontractors

    Your vendor's vendors are business associates too. Ask for the list, require flow-down, and understand where your data physically and legally sits.

  • Monitoring after signature

    Watch for the vendor's name in breach reports, advisories and recalls, review assurance reports on renewal, and re-tier when the service changes. The watchlist feature on this site exists for exactly this.

  • Termination and offboarding

    Plan the exit before the entry: data return format, destruction certificates, and access revocation, because the last day of a contract is when data most often goes missing.

Common mistakes

  • Conduit versus business associate

    The conduit exception is narrow: entities that only transmit PHI with transient access, like a courier. Cloud storage, hosting and email providers are business associates even if they never open a file.

  • BAA on file versus vendor assessed

    A signed agreement satisfies the contract requirement. The risk analysis and risk management requirements still apply to the vendor relationship.

  • Vendor certified versus service in scope

    A SOC 2 report covers the systems and period described in it. Check that the service you buy and the region you use are in scope, and read the exceptions.

Sources

;

See it in the live data.

Add your vendors to a watchlist