• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Business Associate

Don’t Be Unprepared for a Breach by a Business Associate

May 12, 2016/in Blog, Business Associate, HIPAA

Covered entities should be very concerned about the possibility of a major breach of protected health information (PHI) originating from a Business Associate (BA).  According to the Health and Human Services’ Wall of Shame, a single breach in 2015 by a BA in Indiana affected more than 3.9 million individuals which is more than all individuals affected by breaches from covered entities and BAs listed to date in 2016.

Source: HHS Wall of Shame

 

In order to be prepared, a covered entity must first understand what constitutes a BA.  By definition, a BA is an entity or individual who is not part of the covered entity’s workforce and stores, transmits or receives PHI on behalf of the covered entity.

As required by HIPAA, a covered entity must have a written business associate agreement (BAA) in place for any of the following BAs: practice or benefit management, answering service, billing company, collection agency, document shredding company, claims processing, accountant, legal, utilization review, actuarial, healthcare clearing house, medical transcriptionist, electronic health record (EHR) or an e-prescribing gateway.   Examples of those not considered to be a BA of a covered entity include: health plans, laboratories, pharmacies, janitorial services or conduits such as a telephone service provider, US Post Office, UPS, or Fed Ex.

Last year’s breach by a Business Associate occurred as a result of hackers gaining unauthorized access into an EHR, compromising PHI at 44 locations in 3 states.   This may seem small compared to the largest breach ever reported, the Anthem breach in 2014 affecting over 80 million individuals.  Similarly, this incident was the result of a cyber attack on a server such that the full extent of this breach remains under investigation and the actual numbers are still yet to be determined.

What if Anthem had been a large EHR provider instead of a covered entity?  Let’s not find out. To this end, healthcare providers need to be ready for any size cyber security incident and this should be reflected in your BAA. The recent April 2016 OCR Cyber-Awareness Monthly Update highlights important measures every covered entity should take when dealing with business associates:

  1. Defining in their service-level or BAA how and for what purposes  PHI shall be used or disclosed in order to report to the covered entity any use of disclosure of PHI not provided for by its contract, including breaches of unsecured PHI, as well as any security incidents.
  2. Indicating in the service-level or BAA the time frame they expect business associates or subcontractors to report a breach, security incident, or cyber attack to the covered entity or BA, respectively.
  3. Identifying in the service-level or BAA the type of information that would be required by the BA or subcontractor to provide in a breach or security incident report. 
  4. Finally, covered entities and BAs should train workforce members on incident reporting and may wish to conduct security audits and assessments to evaluate the BAs’ or subcontractors’ security and privacy practices.  If not, ePHI or the systems that contains ePHI may be at significant risk.  

Keep in mind that not all breaches are related to hacking incidents.   For this year, breaches by BAs are overwhelmingly attributed to theft and unauthorized access or disclosure.  Fortunately, these types of breaches should be much easier to prevent than trying to avoid a sophisticated cyber attack.   Just like covered entities, BAs must have appropriate physical, technical and administrative safeguards in place.

In the event of a breach, the Business Associate must notify the covered entity immediately upon discovery.  In addition to the breach notification procedure to alert the covered entity, the BAA should clearly state the BA’s obligations of notification to the individuals, HHS and the media, if applicable, as well as any costs associated with the notification process or costs related to individual identity protection.

 

Tags: business associate, business associate agreements, HHS, HIPAA, PHI
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2016/05/BA-Breach-scaled.jpg 1706 2560 First Healthcare Compliance Staff https://1sthcc.com/wp-content/uploads/2026/07/1stHCC_Logo_HORZ_LRG.png First Healthcare Compliance Staff2016-05-12 11:00:462025-04-15 12:58:01Don’t Be Unprepared for a Breach by a Business Associate
You might also like
Business Associate Who are your Business Associates?
Legal Risks With Health Data Sharing: Q&A Are Your Patients Involved In Medical Record Accuracy?
HIPAA Privacy and Security Summit 2020 Widener University Delaware Law School and First Healthcare Compliance Announce Speakers for Virtual HIPAA Privacy and Security Summit on November 12, 2020
Legal Risks With Health Data Sharing: Q&A Who are your Business Associates?
compliance myths 4 Common Compliance Myths Debunked
Legal Risks With Health Data Sharing: Q&A Legal Risks With Health Data Sharing: Q&A

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • The OIG Exclusions List: First Line of Employment Defense
  • Navigating the HIPAA Security Landscape: A Comprehensive Guide to Security Risk Assessments
  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only