Final HIPAA Rules Clarifies Direct Liability of Business Associates and Subcontractors
Client Alert | 3 min read | 02.08.13
The HIPAA omnibus rule contains important changes concerning business associate and downstream contractor liability. These changes implement provisions of the HITECH Act, which sought to make business associates more accountable for the use, disclosure and security of PHI. Under the HIPAA Final Rule, business associates and their subcontractors now face HIPAA enforcement actions and are directly liable for violating the HIPAA Security Rule as well as certain provisions of the Privacy and Breach Notification Rules.
In the HIPAA Final Rule, HHS clarified the provisions for which business associates and subcontractors now face direct liability. These provisions include: (1) impermissible uses and disclosures1; (2) failure to provide breach notification to the covered entity2; (3) failure to provide access to a copy of electronic PHI to either the covered entity, the individual, or the individual's designee (whichever is specified in the business associate agreement)3; (4) failure to make reasonable efforts to limit PHI to the minimum necessary to accomplish the intended purpose of the use, disclosure, or request4; (5) failure to enter into business associate agreements with subcontractors that create or receive PHI on their behalf5; failure to disclose PHI where required by the Secretary to investigate or determine the business associate's compliance with the HIPAA Rules6; failure to provide an accounting of disclosures (if subject to those requirements pursuant to the BA agreement)7; and (7) failure to comply with the requirements of the Security Rule.8
Business associates are not required to comply with other provisions of the Privacy Rule, such as providing a notice of privacy practices or designating a privacy official, unless the covered entity has chosen to delegate such a responsibility to the business associate.
The Final Rule clarifies that a person or an entity is a business associate as a result of receiving PHI from a covered entity in the performance of services, regardless of whether they have entered into a written BA agreement.
The final rule also establishes a parallel set of contracting requirements for subcontractors of business associates who create, receive, maintain, or transmit PHI on behalf of the business associate. The final rule requires covered entities to obtain satisfactory assurances regarding the protection of PHI from their business associates, and business associates must do the same with their subcontractors, and so on, no matter how far "down the chain" the information flows. Furthermore, a subcontractor is a business associate to the extent that it is carrying out a delegated function for a BA, subject to the same legal obligations as a BA that has contracted directly with a CE, again regardless of whether they have entered into a written BA agreement.
The agreement between a business associate and a subcontractor may not permit the subcontractor to use or disclose PHI in a manner that would not be permissible if done by the business associate. In short, each agreement in the business associate chain must be as stringent or more stringent as the agreement above with respect to the permissible uses and disclosures.
The final rule makes clear that a covered entity is not required to enter into a direct contract or other arrangement with subcontractors of its business associates. HHS believes that making subcontractors directly liable for violations of the applicable provisions of the HIPAA Rules will help to alleviate concern on the part of covered entities that PHI is not adequately protected when provided to subcontractors.
1 See § 164.502(a)(3).
2 See § 164.410.
3 See § 164.502(a)(4)(ii).
4 See § 164.502(b).
5 See § 164.502(e)(1)(ii).
6 See § 164.502(a)(4)(i).
7 See 76 Fed. Reg. 31426 (May 31, 2011).
8 Section 13401 of the HITECH Act provides that the Security Rule's administrative, physical, and technical safeguards requirements in §§ 164.308, 164.310, and 164.312, as well as the Rule's policies and procedures and documentation requirements in § 164.316 apply to business associates.
Contacts
Insights
Client Alert | 4 min read | 07.25.25
On July 24, the European Commission announced the imposition of new EU countermeasures in response to U.S. tariffs further to an agreement reached among EU Member States. These measures are adopted through Commission Implementing Regulation (EU) 2025/1564 and take the form of additional customs duties on U.S. products as well as export restrictions for certain EU products. In total, these measures concern about EUR 93 billion ($109 billion) worth of customs duties, the highest volume of bilateral trade caught by the EU so far. The EU countermeasures are set to enter into force as of August 7.
Client Alert | 5 min read | 07.25.25
Client Alert | 16 min read | 07.25.25
Client Alert | 1 min read | 07.24.25
Commission In Limbo: SCOTUS Puts CPSC Commissioners Back Out of Action