Final HIPAA Rules Clarifies Direct Liability of Business Associates and Subcontractors
Client Alert | 3 min read | 02.08.13
The HIPAA omnibus rule contains important changes concerning business associate and downstream contractor liability. These changes implement provisions of the HITECH Act, which sought to make business associates more accountable for the use, disclosure and security of PHI. Under the HIPAA Final Rule, business associates and their subcontractors now face HIPAA enforcement actions and are directly liable for violating the HIPAA Security Rule as well as certain provisions of the Privacy and Breach Notification Rules.
In the HIPAA Final Rule, HHS clarified the provisions for which business associates and subcontractors now face direct liability. These provisions include: (1) impermissible uses and disclosures1; (2) failure to provide breach notification to the covered entity2; (3) failure to provide access to a copy of electronic PHI to either the covered entity, the individual, or the individual's designee (whichever is specified in the business associate agreement)3; (4) failure to make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request4; (5) failure to enter into business associate agreements with subcontractors that create or receive PHI on their behalf5; failure to disclose PHI where required by the Secretary to investigate or determine the business associate's compliance with the HIPAA Rules6; failure to provide an accounting of disclosures (if subject to those requirements pursuant to the BA agreement)7; and (7) failure to comply with the requirements of the Security Rule.8
Business associates are not required to comply with other provisions of the Privacy Rule, such as providing a notice of privacy practices or designating a privacy official, unless the covered entity has chosen to delegate such a responsibility to the business associate.
The Final Rule clarifies that a person or an entity is a business associate as a result of receiving PHI from a covered entity in the performance of services, regardless of whether they have entered into a written BA agreement.
The final rule also establishes a parallel set of contracting requirements for subcontractors of business associates who create, receive, maintain, or transmit PHI on behalf of the business associate. The final rule requires covered entities to obtain satisfactory assurances regarding the protection of PHI from their business associates, and business associates must do the same with their subcontractors, and so on, no matter how far "down the chain" the information flows. Furthermore, a subcontractor is a business associate to the extent that it is carrying out a delegated function for a BA, subject to the same legal obligations as a BA that has contracted directly with a CE, again regardless of whether they have entered into a written BA agreement.
The agreement between a business associate and a subcontractor may not permit the subcontractor to use or disclose PHI in a manner that would not be permissible if done by the business associate. In short, each agreement in the business associate chain must be as stringent or more stringent as the agreement above with respect to the permissible uses and disclosures.
The final rule makes clear that a covered entity is not required to enter into a direct contract or other arrangement with subcontractors of its business associates. HHS believes that making subcontractors directly liable for violations of the applicable provisions of the HIPAA Rules will help to alleviate concern on the part of covered entities that PHI is not adequately protected when provided to subcontractors.
1 See § 164.502(a)(3).
2 See § 164.410.
3 See § 164.502(a)(4)(ii).
4 See § 164.502(b).
5 See § 164.502(e)(1)(ii).
6 See § 164.502(a)(4)(i).
7 See 76 Fed. Reg. 31426 (May 31, 2011).
8 Section 13401 of the HITECH Act provides that the Security Rule's administrative, physical, and technical safeguards requirements in §§ 164.308, 164.310, and 164.312, as well as the Rule's policies and procedures and documentation requirements in § 164.316 apply to business associates.
Contacts
Insights
Client Alert | 5 min read | 08.21.26
FTC Proposes Enforcement Policy Statement on Personalized Pricing: What Businesses Need to Know
On August 19, 2026, the Federal Trade Commission (FTC) announced a proposed Enforcement Policy Statement on personalized pricing — the practice of companies using consumers’ personal data to set individualized prices, discounts, coupons, or other incentives. The proposed statement, which is open for public comment for 30 days following publication in the Federal Register, marks a major step up in the FTC’s focus on data-driven pricing strategies and puts businesses across industries on notice that undisclosed or inadequately disclosed personalized pricing will not be tolerated. Importantly, while the proposed statement is not a binding legal requirement and does not create new legal obligations, it serves as an enforcement warning that the FTC is prepared to use its existing enforcement authority under Section 5 of the FTC Act (Section 5) and is also a potential harbinger of rulemaking. Businesses that engage in — or are considering — personalized pricing should carefully assess their disclosure practices and data collection procedures against the standards articulated in this statement.
Client Alert | 7 min read | 08.19.26
CMS’s Final Rule Bans Federal Medicaid Funding for Youth Gender-Affirming Care
Client Alert | 2 min read | 08.19.26


