Skip to content
Lawwise

      Subjects

      This handbook

      Healthcare Regulation

      Business Associate Agreements and Downstream Liability

      A vendor becomes a business associate because of what it does with patient records, not because anyone signed a document. The agreement is the permission that makes the disclosure lawful, and its obligations have to be pushed down every level of the supply chain.

      Healthcare Regulation6 min readFederal and stateHealth information

      A server rack door standing ajar in a cool corridor, with bundled network cables running along the ceiling tray.
      Most records leave a provider's building long before anyone reads the contract that let them go. — Blogtrepreneur, CC BY 2.0, source.

      The rule in short

      A person who creates, receives, maintains or transmits protected health information on behalf of a covered entity for a regulated function is a business associate, and so is any subcontractor doing the same for that associate. A written agreement containing specified terms is the condition on which the disclosure is permitted. Business associates are directly liable for defined obligations, and a covered entity that knows of a pattern of material breach and does nothing is itself in violation.

      Status is functional. A person who creates, receives, maintains or transmits protected health information on behalf of a covered entity, for a function or activity the rule regulates, is a business associate. Nobody has to agree to it. The unsigned vendor is a business associate handling records without the agreement that would have made the disclosure lawful, which is a violation by the covered entity as well as by the vendor.

      Identifying the relationship

      The definition reaches claims processing, data analysis, utilization review, quality assurance, billing, benefit management and practice management. It separately reaches legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation and financial services where the service involves the disclosure of protected health information. It expressly includes health information organizations, electronic prescribing gateways, entities providing data transmission services that require routine access, and persons offering a personal health record on a covered entity's behalf.

      Two exclusions matter. A disclosure to a health care provider for treatment of the individual does not create the relationship, which is why a referral to a specialist needs no agreement. And an entity that transports information without routine access to it is treated as a conduit rather than an associate. The conduit category is narrower than vendors claim: it turns on transient transmission rather than on encryption or on a promise not to look.

      What the agreement has to say

      The contents are prescribed rather than negotiable in substance. The agreement must establish the permitted and required uses and disclosures, and must provide that the associate will not use or further disclose the information otherwise. It must require appropriate safeguards, including compliance with the security standards for electronic information. It must require the associate to report any use or disclosure not provided for, including security incidents and breaches.

      It must also require the associate to make information available so the covered entity can satisfy individual rights of access, amendment and accounting; to make its internal practices, books and records available to the enforcement agency; to return or destroy the information at termination where feasible; and to authorize termination by the covered entity if the associate materially breaches. Missing any of these makes the agreement noncompliant even where the parties behave perfectly.

      Flow-down is an obligation, not a recommendation

      A business associate must obtain satisfactory assurances from any subcontractor that creates, receives, maintains or transmits the information on its behalf, and the assurances must be at least as protective as those the associate gave upstream. The chain has no defined end. A billing vendor's analytics provider's storage host is a business associate of a business associate of a business associate, and the terms have to reach it. Diligence that stops at the first tier misses where most incidents actually originate.

      PartyRelationship to the recordsWritten agreement requiredDirectly liableBreach reporting duty
      Covered entityHolds the records in its own rightWith each associateYes, for the whole ruleTo individuals, media and the agency
      Business associateHandles records on the entity's behalfWith the entity and each subcontractorYes, for defined obligationsUpward, to the covered entity
      SubcontractorHandles records on the associate's behalfWith the associate above itYes, on the same footingUpward, to the associate
      ConduitTransports without routine accessNoNoNone under this rule
      Treating providerReceives records for treatmentNoYes, as a covered entity in its own rightAs a covered entity

      What a business associate answers for on its own

      Business associates are directly liable for a defined set of obligations rather than for the whole rule. The list includes impermissible uses and disclosures, failure to provide breach notification to the covered entity, failure to provide the enforcement agency with records for an investigation, failure to disclose information where required, failure to enter compliant agreements with subcontractors, and failure to comply with the security standards including the risk analysis requirement.

      Notably absent is the obligation to provide individuals with access to their records; that duty stays with the covered entity, and the associate's obligation is to make the information available so the entity can meet it. Contracts that shift the access obligation outright are describing an allocation the rule does not make, and the individual's remedy still runs against the covered entity.

      Incidents that begin at a vendor

      An associate that discovers a breach must report it to the covered entity without unreasonable delay and no later than sixty days after discovery. That is the outer limit under the rule, not a sensible contract term, because the covered entity's own deadline under the breach reporting framework runs from its own discovery and it needs time to investigate, draft and mail. Agreements routinely compress the vendor window to a small number of days for exactly this reason.

      Where the incident is bad enough to attract an enforcement review, the review examines the agreement, the diligence performed before engagement, the risk analysis, and whether the covered entity knew of prior problems. A known pattern left unaddressed converts a vendor's failure into the entity's violation, and the resolution usually carries the obligations described in corrective action plans and integrity agreements.

      Testing a vendor before the records move

      Four questions settle most engagements. What function is the vendor performing, and does it fall inside the definition. What will the vendor be permitted to do with the records, expressed in the same vocabulary as the permitted uses of health information rather than in commercial terms. Who sits below the vendor, and are those parties bound. And has the vendor performed and documented a security risk analysis that the covered entity has actually seen.

      Remote service platforms deserve particular attention, because a single vendor often stores records, transmits sessions and provides scheduling across several states at once, which layers the questions in cross-border remote practice on top of the privacy analysis. The agreement is cheap to get right before deployment and expensive to renegotiate after the records are already there.

      Points to carry away

      • Business associate status turns on the function performed, not on whether an agreement exists.
      • A subcontractor handling the same information is a business associate of the business associate.
      • The agreement must require the associate to bind its own subcontractors to the same restrictions.
      • Business associates are directly liable for impermissible uses and for security rule compliance.
      • A covered entity aware of a pattern of material breach must cure it or terminate the arrangement.
      • A vendor that merely transports data without routine access is not a business associate.

      Questions readers ask

      Is a cloud storage provider a business associate if the data is encrypted and it holds no key?

      Yes. A provider that maintains protected health information on behalf of a covered entity is a business associate even where it cannot read what it stores, because maintenance is one of the enumerated functions and persistence distinguishes it from transmission. Encryption reduces the risk that an incident becomes a reportable breach; it does not remove the relationship or the need for an agreement. The narrow exception for transport applies to entities that move data without storing it and without routine access.

      What happens to the records when the arrangement ends?

      The agreement must require the associate to return or destroy all protected health information received or created on the covered entity's behalf, including copies held by subcontractors, at termination. Where return or destruction is not feasible, the agreement must extend the protections to the retained information and limit further uses to whatever makes the return infeasible. Vendors routinely retain data in backups and archives, so the feasibility question should be settled before signature rather than during an exit.

      Can a covered entity be liable for what its vendor did?

      In two ways. Where the associate acted as an agent of the covered entity within the scope of the agency, the associate's acts are attributed to the entity under ordinary agency principles, and the degree of control the entity retained is what decides agency. Separately, a covered entity that knew of a pattern of activity amounting to a material breach of the agreement and failed to take reasonable steps to cure it or to terminate the arrangement is in violation on its own account.

      Sources

      1. eCFR — 45 CFR 160.103, DefinitionsThe definition of business associate, its inclusions and its exceptions.
      2. eCFR — 45 CFR 164.504, Uses and Disclosures: Organizational RequirementsThe required contents of a business associate agreement and the knowledge-of-pattern rule.
      3. eCFR — 45 CFR 164.314, Organizational RequirementsThe security rule terms an agreement must carry, including subcontractor flow-down.
      4. eCFR — 45 CFR 164.308, Administrative SafeguardsThe risk analysis and workforce controls a business associate must implement.
      5. eCFR — 45 CFR Part 164 Subpart C, Security Standards for the Protection of Electronic Protected Health InformationThe security standards applying directly to business associates.
      6. eCFR — 45 CFR 160.402, Basis for a Civil Money PenaltyHow liability is attributed between a covered entity and its agents.

      Lawwise is a publication, not a law firm. This article states general rules and cites its sources; it is not advice about any particular case, and the law differs by state and changes over time.

      More in Healthcare Regulation

      Healthcare Regulation

      Using Health Information Without Written Authorization

      A covered entity may use or disclose protected health information without authorization to the individual, for treatment, payment and health care operations, under an opportunity to agree or object, and for an enumerated set of public interest purposes. Everything outside that list requires a written authorization, and psychotherapy notes, marketing and any sale of information require one regardless. Permitted disclosures are separately limited to the minimum necessary to accomplish the purpose.

      5 min readFederal and state

      Healthcare Regulation

      The Self-Referral Prohibition and the Exceptions to It

      Where a physician or an immediate family member holds an ownership interest in or a compensation arrangement with an entity, the physician may not refer designated health services to that entity for federal payment and the entity may not present a claim for them, unless the arrangement satisfies an exception in full. Liability does not depend on intent. Amounts collected on prohibited referrals must be refunded, and knowing violations carry additional penalties.

      5 min readFederal and state

      Healthcare Regulation

      Provider Enrollment, Revalidation and Revocation

      Enrollment establishes the effective date from which claims may be paid, and certain practitioner types may bill retrospectively for up to thirty days before it. Enrollment must be revalidated every five years, or every three for equipment suppliers, and a revalidation request must be answered within sixty calendar days. Revocation carries a reenrollment bar of one to ten years, extended to twenty for a second revocation, and it takes effect thirty days after the notice is mailed.

      5 min readFederal and state