Business Associate Compliance

HIPAA Compliance for
Business Associates

Under the HITECH Act, a business associate answers to HIPAA on its own. We help BAs set up sound ways to handle PHI, keep watch over their vendors, and run BAAs that hold up.

How We Help Business Associates Handle PHI

Under the HITECH Act and the Omnibus Rule, a business associate answers directly for the HIPAA Security Rule, and for parts of the Privacy Rule. So if you create, receive, maintain, or transmit PHI for a covered entity, the duties are yours too. They do not stop with the practice that hired you.

One Guy Consulting maps where PHI comes into your work, how it moves once it is there, and where the risk piles up. Then we build safeguards around those spots. You get real controls, not a stock checklist.

Key BA duties under HIPAA: Put administrative, physical, and technical safeguards in place (45 CFR 164.308-312). Tell the covered entity about a breach without unreasonable delay, and no later than 60 days (45 CFR 164.410). Get a signed BAA from any subcontractor that handles PHI (45 CFR 164.502(e)).

1

PHI Flow Mapping

We trace how PHI comes in, moves through, and leaves your systems, so you know just what you are guarding.

2

Security Rule Implementation

Access controls, encryption, audit logs, and a plan for when things go wrong, built to fit the way your team works.

3

Breach Response Planning

A written process for how you spot a breach, hold it down, and report it to the covered entity in time.

Managing Your Own Subcontractors and Vendors

If you are a business associate and your subcontractors can reach PHI, you owe the same watch over them that a covered entity owes you. That means a BAA with each one, notes on the checks you ran, and a running view of where each one stands.

We set up a way to manage vendors that grows with how many you have and how much risk they carry.

🔍

Vendor Inventory and Risk Tiering

List every vendor that touches PHI. Sort them into risk tiers by what they can reach, how much data they hold, and how deeply they tie into your systems.

📋

Due Diligence Documentation

Set questions for each vendor, and one place to keep their answers, so you can show your work to a covered entity or an auditor.

🔄

Ongoing Compliance Monitoring

A set review cycle, renewal dates you can see, and a clear next step when a vendor slips.

For the full take on risk tiers and our five-step process, see HIPAA Vendor Management.

Business Associate Agreement Lifecycle

A BAA is not a box to tick. It sets out how PHI may be used and disclosed, what safeguards each side owes, and who answers for what. We help business associates handle BAAs from the first signing through renewal, changes, and the end of the deal.

1

BAA Inventory Audit

Find every covered entity you work with that needs a BAA. Flag the ones you never got, and the drafts no one signed.

2

Contract Review and Gap Analysis

Read the BAAs you already have against what HIPAA asks for now. Spot the clauses that take on more than you meant, and the ones that leave something out.

3

Execution and Documentation

Get them signed. Keep every signed copy in one place you can audit, with a record of each version.

4

Renewal and Amendment Tracking

Watch the end dates. Flag any BAA that needs work because the scope shifted, a new service came online, or the rules changed.

5

Termination and PHI Return

When the work ends, run the return or the wipe of PHI that HIPAA calls for, and write down that it was done.

For what the terms mean, what it costs, and how the portal works, see BAA Management Services.

Common Business Associate Types

IT and MSPs

Managed service providers, cloud hosts, and IT support firms that reach ePHI while they run your systems.

Billing and Revenue Cycle

Billing services, clearinghouses, and coding firms that work on claims that hold PHI.

EHR and SaaS Vendors

Software firms that store, handle, or send PHI as part of what they sell to a covered entity.

Shredding and Disposal

Shredding firms and media wipe services that get rid of PHI on paper or on a drive.

Legal and Accounting

Law firms, CPAs, and consultants who see PHI while they do work for a covered entity.

Answering Services

After-hours call centers and patient messaging tools that take in or pass along PHI for a practice.

For the full picture on BA consulting, see HIPAA for Business Associates.

Business Associate Compliance Questions

Yes. Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly subject to HIPAA enforcement. OCR can investigate and impose penalties on BAs independently of the covered entity. BAs must comply with the Security Rule, applicable Privacy Rule provisions, and breach notification requirements.
Yes. Under 45 CFR 164.308(a)(1)(ii)(A), business associates must conduct their own Security Risk Assessment covering the ePHI they create, receive, maintain, or transmit. The covered entity's risk assessment does not cover the BA's internal systems and workflows.
The BA must have BAAs in place with every subcontractor that creates, receives, maintains, or transmits PHI on its behalf. This requirement flows downstream - each subcontractor has the same duties as the BA itself under 45 CFR 164.502(e)(1)(ii).
A business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering the breach, per 45 CFR 164.410. Many BAAs specify shorter notification windows, so check your agreement.

Need Help With Business Associate Compliance?

Book a short call. We will tell you where you stand and what to fix first.

Book Your Free 30 Minute HIPAA Compliance Review

Questions About BA Compliance?

Business Associate Agreements: Key Compliance Facts

An employee is workforce, not a business associate, and signs a confidentiality agreement rather than a BAA.