- Report breaches of unsecured protected health information to the covered entity;
- Comply with the HIPAA Security Rule;
- Execute business associate agreements with subcontractors (who are now considered business associates under the Final Rule).
Business associate agreements that were in compliance with the HIPAA Privacy Rule prior to January 25, 2013, were considered “grandfathered” and permitted to remain in place until September 23, 2014, if they were not updated prior to the September date. This date, however, is almost expired and now all business associate agreements must be updated to include the additional requirements created by the Final Rule. Business associate agreements that were put into place after January 25, 2013, should already comply with the Final Rule.
It is important to note that the Final Rule also expanded the definition of a BA to cover new entities and persons. Now, a BA includes health information organizations, e-prescribing gateways, data transmission entities that routinely access PHI, and vendors of PHI records, in addition to subcontractors of business associates that create, receive, maintain, or transmit PHI on behalf of the business associate.
Emily M. Hord
McBrayer, McGinnis, Leslie & Kirkland, PLLC