• Contact
  • 888-54-FIRST
  • Client Login
    • Client Portal
    • Online Store
Search
First Healthcare Compliance
  • Solutions
    • Compliance Management Software
    • Online Compliance Courses
    • Compliance Management Suite
  • Plans
  • Resources
    • Blog
    • Virtual Education Hub
    • 1st Talk Compliance Podcast
    • Connect Magazine
    • Compliance Posters
    • Healthcare Compliance Books
    • Newsletter Signup
  • News & Events
    • Press Releases
  • Our Team
  • Request Demo
  • Menu Menu
  • Shopping Cart Shopping Cart
    0Shopping Cart

Blog

Q&A: HIPAA Compliance for Business Associates

December 8, 2020/in Blog, Business Associate, Data Security, HIPAA

Outsourcing HIPAA

Rachel V. Rose, JD, MBA, presented the webinar “HIPAA Compliance for Business Associates” recently and a recording can be viewed here. Rachel returned to answer many commonly asked questions from the webinar. Be sure to sign up for Rachel’s next webinar, The New AKS and Stark Laws Final Rules – Key Take-Aways about the Final Rules taking effect Jan 1, 2021. This webinar is happening December 17, 2020, 12 pm ET.  Sign up here.

Are business associates subject to HIPAA penalties?

Yes. As stated in both the HITECH Act and the Final Omnibus Rule, 78 Fed. Reg. 5566 (Jan. 25, 2013), business associates, which include subcontractors, can be held directly liable for HIPAA violations. For example, in 2016, a business associate’s failure to safeguard the protected health information of nursing home residents led to a $650,000 monetary penalty being assessed by HHS OCR. (https://www.hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/catholic-health-care-services/index.html)

If you were to give business associates and subcontractors one item that they need to do annually, what would it be?

Annual Risk Analysis because all technical, administrative and physical safeguards would be identified and corrected.

Is an indemnification provision required in BAAs?

No. In my practice, I see them included quite a bit; however, this particular provision is not a requirement under 45 CFR §164.504(e)(1) or that HHS indicated was preferred. See https://www.hhs.gov/hipaa/for-professionals/covered-entities/sample-business-associate-agreement-provisions/index.html.

Are class action cases something that should be considered as part of an enterprise risk management program?

Yes. The financial, legal, and reputational costs can be great and need to be considered. A good example of a HIPAA data breach which led to both an HHS OCR enforcement action of $16 million and a class action lawsuit settlement in excess of $115 million is Anthem BlueCrossBlueShield. An article that I wrote for Physicians Practice details these issues – https://www.physicianspractice.com/view/class-action-lawsuits-can-result-from-a-protected-health-information-data-breach.

Should business associates be familiar with the 21st Century Cures Act, as well as the ONC and CMS Final Rules?

Yes.  There is an intersection between HHS HIPAA App Guidance and the ONC and CMS Final Rules, in terms of patients accessing their data through apps. Be aware of unsecure apps and stay abreast of the compliance dates.

Rachel V. Rose – Attorney at Law, PLLC (Houston, Texas) – represents clients on healthcare, cybersecurity, securities and qui tam matters. She also teaches bioethics at Baylor College of Medicine. She has been consecutively named by Houstonia Magazine as a Top Lawyer (Healthcare) and to the National Women Trial Lawyer’s Top 25. She can be reached at rvrose@rvrose.com.

Be sure to look up a recording of this webinar on YouTube and a recording with Rachel on our podcast, 1st Talk Compliance. Take a look at our brand-new book: HIPAA Privacy and Security, and our online compliance training courses such as What is HIPAA?, and HIPAA Business Associate Agreements Under HITECH. And check out Rachel’s other blogs Q&A: HHS Final Rules, Patient Access to PHI & Health Apps Intersect, Recent HHS Guidance Underscores the Importance of HIPAA Compliance and Q&A: HIPAA and Health Apps.

Tags: Business Associates, covered entity, Data Security, HIPAA, Offshore Contractor, PHI
Share this
  • Share on Facebook
  • Share on X
  • Share on LinkedIn
  • Share on Reddit
  • Share by Mail
https://1sthcc.com/wp-content/uploads/2020/12/hipaa-business-associates-rose_ft.jpg 758 1200 Catherine Short https://1sthcc.com/wp-content/uploads/2022/10/1sthcc-logo-1024x378.jpg Catherine Short2020-12-08 09:56:132025-04-15 12:43:36Q&A: HIPAA Compliance for Business Associates
You might also like
cybersecurity, data privacy, and electronic discovery Updates on Data Privacy Regulations
breach HIPAA Breach: To Be Or Not To Be?
First Healthcare Compliance to Showcase Compliance Solutions at the 27th Annual Compliance Institute in Anaheim, California First Healthcare Compliance to Showcase Compliance Solutions at the 27th Annual Compliance Institute in Anaheim, California
Upcoming Presentations by Rachel Rose covering HIPAA and FWA Upcoming Presentations by Rachel Rose covering HIPAA and FWA
Vendor Management Data Breach Q&A: Vendor Management In Healthcare: The High Cost of Failing to Triage Your Vendors
Health Data Health Data, A Value Proposition: Legal Risks with Innovative Data Sharing Projects – Audio Version of the Webinar

Subscribe to Weekly eNewsletter

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Recent Posts

  • OSHA Recordkeeping in Healthcare: Answers to Frequently Asked Questions
  • Naughty or Nice? The Rules of Giving and Receiving in Healthcare
  • fraud waste abuse healthcare compliance
    FWA in Healthcare: How to Respond Appropriately to Detected Offenses
  • Infographic: 6 Areas of Potential Liability for Healthcare Providers
    6 Areas of Potential Liability for Healthcare Providers
  • 5 Benefits of Automating Incident Reporting in Healthcare
  • Compliance Primer Series: Fraud, Waste and Abuse

 

First Healthcare Compliance is a division of Panacea Healthcare Solutions. Learn more

Subscribe

Get the latest healthcare compliance updates straight to your inbox.

Subscribe to Newsletter

Connect

Get started: Request Demo

Call: 1-888-54-FIRST

E-mail: Contact us

  • Link to Instagram
  • Link to Youtube
  • Link to Facebook
  • Link to LinkedIn
  • Link to X
© Copyright 2026 Panacea Healthcare Solutions, LLC | Disclaimer | Privacy Policy and Copyright Notice
Scroll to top Scroll to top Scroll to top

We and our third-party partners use cookies to improve and personalize your experience on the site and with our services in addition to delivering and reporting on ads. Please visit our Privacy Statement for more information. By continuing to browse the site, you are agreeing to our use of cookies. Read Privacy Statement.

OKDismiss

Cookie and Privacy Settings



How we use cookies

We may request cookies to be set on your device. We use cookies to let us know when you visit our websites, how you interact with us, to enrich your user experience, and to customize your relationship with our website.

Click on the different category headings to find out more. You can also change some of your preferences. Note that blocking some types of cookies may impact your experience on our websites and the services we are able to offer.

Essential Website Cookies

These cookies are strictly necessary to provide you with services available through our website and to use some of its features.

Because these cookies are strictly necessary to deliver the website, refusing them will have impact how our site functions. You always can block or delete cookies by changing your browser settings and force blocking all cookies on this website. But this will always prompt you to accept/refuse cookies when revisiting our site.

We fully respect if you want to refuse cookies but to avoid asking you again and again kindly allow us to store a cookie for that. You are free to opt out any time or opt in for other cookies to get a better experience. If you refuse cookies we will remove all set cookies in our domain.

We provide you with a list of stored cookies on your computer in our domain so you can check what we stored. Due to security reasons we are not able to show or modify cookies from other domains. You can check these in your browser security settings.

Other external services

We also use different external services like Google Webfonts, Google Maps, and external Video providers. Since these providers may collect personal data like your IP address we allow you to block them here. Please be aware that this might heavily reduce the functionality and appearance of our site. Changes will take effect once you reload the page.

Google Webfont Settings:

Google Map Settings:

Google reCaptcha Settings:

Vimeo and Youtube video embeds:

Privacy Policy

You can read about our cookies and privacy settings in detail on our Privacy Policy Page.

Privacy Policy and Copyright Notice
Accept settingsHide notification only