Compliance

HIPAA and third-party risk: business associate agreements and subcontractor flow-down

HIPAA does not regulate every vendor a healthcare organization uses - it regulates any vendor that touches protected health information, and it does so mainly through one document: the business associate agreement. Here is what a BAA must actually contain, how the subcontractor chain works, and why "business associate" has meant direct legal liability since 2013.

HIPAA's Privacy and Security Rules (45 CFR Parts 160 and 164) bind two kinds of organizations: covered entities (health plans, health care clearinghouses, and most health care providers) and business associates - anyone else who creates, receives, maintains, or transmits protected health information (PHI) on a covered entity's behalf. See the definition at 45 CFR 160.103. That second category is the one a TPRM program actually manages: billing services, cloud-hosted EHR platforms, e-prescribing networks, claims clearinghouses, IT and security vendors with access to PHI, and increasingly the AI vendors processing clinical data all fall inside it. A narrow conduit exception covers organizations that only transport data without routine access to it - the postal service, an ISP, a courier - but the exception is read narrowly by HHS and does not extend to a vendor that can access the content it moves, such as a cloud storage provider.

The business associate agreement (BAA)

A BAA is the contract HIPAA requires before a covered entity may let a business associate touch PHI, and its required content is split across two rules that are easy to conflate. The Privacy Rule content, at 45 CFR 164.504(e), requires the contract to spell out the permitted and required uses and disclosures of PHI, bar the business associate from using or disclosing PHI beyond what the contract or law allows, require it to support the covered entity's obligations around individual access, amendment, and accounting of disclosures, make its books and practices available to HHS for a compliance investigation, and - at termination - return or destroy all PHI, or if that is infeasible, extend the same protections indefinitely to what remains. The Security Rule content, at 45 CFR 164.314(a), separately requires the business associate to implement administrative, physical, and technical safeguards for electronic PHI and to report security incidents, including breaches, to the covered entity. A BAA that only recites one set of these provisions - a common gap when a legal team drafts from an old template - is missing half of what HIPAA actually requires.

Subcontractor flow-down: business associates of business associates

The single most misunderstood part of this regime is that it does not stop at the first vendor. Since the 2013 Omnibus Rule, a subcontractor - defined at 45 CFR 160.103 as anyone a business associate delegates a function, activity, or service to - that itself creates, receives, maintains, or transmits PHI on the business associate's behalf is itself a business associate under HIPAA, with its own direct obligations, not merely a party bound by someone else's contract. 45 CFR 164.504(e)(5) and 164.314(a)(2)(iii) apply the same contract requirements to a business associate/subcontractor relationship that apply between a covered entity and its business associate, and 164.308(b) makes clear the covered entity itself does not need a direct assurance from the subcontractor - that obligation belongs to the business associate one link up the chain. In practice this means every subcontractor a vendor engages to touch PHI - the cloud host behind its EHR platform, the transcription service it outsources to, the analytics vendor it feeds de-identified-in-name-only data to - is a HIPAA business associate in its own right, and the chain of BAAs has to actually reach it. This is the same fourth-party problem covered generally in fourth-party risk, expressed here as a named legal requirement rather than a best practice.

Direct liability since HITECH and the 2013 Omnibus Rule

Before 2009, a business associate's HIPAA obligations lived entirely in its contract with the covered entity - a breach of the BAA was a contract dispute, not a federal violation the business associate itself could be fined for. The HITECH Act of 2009 (Public Law 111-5, Subtitle D) changed that by extending certain Security Rule and Privacy Rule provisions directly to business associates, and the 2013 Omnibus Rule implemented it: business associates - and, per the subcontractor flow-down above, their own subcontractors - are now directly subject to HHS civil money penalties for violations, independent of whatever the contract with the covered entity says. 45 CFR 160.402 sets this out plainly and adds that a business associate is also liable, under federal common-law agency principles, for violations committed by its own workforce or agents acting within their authority. A signed BAA is still necessary, but it is no longer the only thing standing between a vendor's failure and a federal enforcement action against that vendor.

Breach notification down the chain

45 CFR 164.400-414 sets the notification chain in motion at the business associate: on discovering a breach of unsecured PHI, a business associate must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, and a subcontractor owes the same notice up to the business associate that engaged it. The covered entity then has its own 60-day clock to notify affected individuals, HHS, and - for a breach affecting more than 500 residents of a state or jurisdiction - local media. The 60-day figure is a ceiling, not a target: OCR has treated sitting on a known breach as its own violation even when the eventual notice fell inside 60 days. A BAA that lets a vendor take most of that window to notify leaves a covered entity almost no time to meet its own deadline, which is why the notification timeline belongs in the contract as a negotiated number of days, not a restatement of the regulatory maximum.

A pending change: the 2025 Security Rule update

HHS's Office for Civil Rights published a notice of proposed rulemaking on 6 January 2025 that would be the first major overhaul of the Security Rule in two decades - removing the current distinction between "addressable" and "required" implementation specifications (making nearly everything mandatory), and adding specific requirements such as multi-factor authentication and encryption of ePHI at rest and in transit, applied to business associates as well as covered entities. It has not moved quickly: the comment period closed in March 2025, and per the Fall 2026 Unified Agenda entry for RIN 0945-AA22, HHS has moved the rule to its Long-Term Actions list with anticipated final action in July 2027, after sustained industry pushback over the roughly $9 billion first-year compliance cost HHS's own analysis projects. The existing Security Rule remains fully enforceable in the meantime - a BAA program built only to today's addressable-safeguard baseline should treat MFA and encryption as coming requirements to plan for, not a maybe.

Turning HIPAA into TPRM actions

None of this requires a particular platform - it requires a current business associate and subcontractor inventory, evidence that BAAs actually cover both the Privacy and Security Rule content, and fast enough visibility into vendor incidents to leave room inside the 60-day clock. Rescana is built around that continuous, evidence-based model; governance-heavy platforms such as OneTrust and ProcessUnity are particularly strong at holding the BAA library and subcontractor-tracking workflow itself. The fit depends on whether the harder problem in a given program is a vendor incident going undetected until it is too late to meet the clock, or a BAA library that has drifted out of date.

Frequently asked questions

What is a HIPAA business associate agreement (BAA) and when is one required?

A business associate agreement (BAA) is the contract HIPAA requires before a covered entity - a health plan, health care clearinghouse, or most health care providers - may let a vendor create, receive, maintain, or transmit protected health information (PHI) on its behalf. It is required for any vendor that touches PHI in that way, not just vendors that are obviously 'in healthcare' - billing services, cloud-hosted EHR platforms, IT vendors with access to PHI, and AI vendors processing clinical data are all typically business associates. A narrow conduit exception covers organizations that only transport data without routine access to its content, such as a postal carrier, but HHS reads that exception narrowly.

What must a HIPAA business associate agreement contain?

A compliant BAA has to satisfy two separate sets of requirements. Under the Privacy Rule (45 CFR 164.504(e)), it must spell out the permitted and required uses and disclosures of PHI, bar the business associate from using or disclosing PHI beyond what the contract or law allows, require it to support the covered entity's obligations for individual access, amendment, and accounting of disclosures, make its records available to HHS for a compliance investigation, and require it to return or destroy PHI when the relationship ends. Under the Security Rule (45 CFR 164.314(a)), it must separately require the business associate to implement administrative, physical, and technical safeguards for electronic PHI and to report security incidents and breaches to the covered entity. A BAA drafted from an old template often covers only one of these two baskets.

Are a business associate's subcontractors themselves subject to HIPAA?

Yes. Since the 2013 Omnibus Rule implementing the HITECH Act, a subcontractor that itself creates, receives, maintains, or transmits PHI on a business associate's behalf is itself a business associate under 45 CFR 160.103, with its own direct HIPAA obligations - not merely a party bound by someone else's contract. The business associate must obtain the same kind of satisfactory assurances from its subcontractor that the covered entity obtained from it (45 CFR 164.504(e)(5) and 164.314(a)(2)(iii)), and the covered entity itself does not need a direct contract with that subcontractor for the obligation to apply. In practice this means the BAA chain has to actually reach every fourth-party vendor that touches PHI, not stop at the first-tier vendor.

What happens if a business associate causes a HIPAA breach?

Under 45 CFR 164.400-414, a business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, so the covered entity can meet its own 60-day duty to notify affected individuals, HHS, and, for large breaches, local media. Since the HITECH Act and the 2013 Omnibus Rule, the business associate is also directly liable to HHS for civil money penalties under 45 CFR 160.402 - independent of any breach-of-contract claim the covered entity might separately bring - and is liable for violations by its own workforce or agents acting within their authority.