Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

When & Why You Need a Business Associate Agreement

April 20, 2021

We’ve all heard the saying ‘sharing is caring’ but sometimes doing a good deed could actually steer you into some consequences later down the road. Let’s say, for example, you just loaned your car to your best bud whose “quick trip to the store” actually consisted of running red lights and racking up parking tickets. Though you might not have been the one in the driver’s seat – your name will be the one on all of the lovely fines that wind up in your mailbox, not your BFF’s.

Now you’re probably wondering where we’re going with all of this. And while cars and protected health information (PHI) might not have a whole lot in common, it goes to show how certain situations in life require additional precautions to minimize the risk of being responsible for another’s wrongful actions. This idea rings especially true when it comes to working with and sharing something as valuable as sensitive health information.

HIPAA law provides a pretty specific roadmap for how your practice should be safeguarding PHI and outlines certain standards that if not met – could result in a hefty fine. But with all the government requirements, advancements in technology, and changing patient needs – it’s impossible today to run a practice without the help of third-party vendors. So whether it be an outside medical billing company, IT support, or document shredding company – any vendor that comes into contact with PHI is a business associate (BA) of your practice and requires their own set of directions for proper handling. 

Just as covered entities have obligations under HIPAA law, so do business associates – with one of the most important being a documented and signed Business Associate Agreement (BAA). A BAA is essentially a written agreement between your organization and the business associate, specifying each party’s responsibilities when accessing and maintaining PHI and it offsets the liability so that your practice can take a backseat if any incidents were to occur. 

As you probably wouldn’t hand over your keys to just anyone without laying down some ground rules first, the same goes for providing access to patients’ sensitive health information. Like most contracts, the terms and conditions in a proper BAA can be pretty lengthy and may vary based on the type of vendor you’re working with – but here are some of the basic HIPAA requirements that should be outlined: 

Permitted uses and disclosures of PHI

  • Whether you’re a healthcare provider or a business associate – you can’t just go around sharing PHI with whoever you feel like. All of the do’s and don’ts should be clearly identified within the agreement to ensure that everyone is on the same page when it comes to PHI use and disclosure. 

Specific safeguards that the BA is expected to establish

  • The BAA should highlight all of the technical, physical, and administrative safeguards that the vendor should have in place to best protect PHI. It should also provide additional safeguards based on the type of PHI they work with – for example if they access and share electronic protected health information (ePHI) you should document that proper encryption is required.  

Breach Notification requirements

  • In an effort to prepare for the worst-case scenario, the agreement should include specific requirements for reporting a data breach. These guidelines should cover the breach notification process and timeframe that the BA must notify your practice which is currently no later than 60 days upon discovery of a breach according to federal HIPAA law. The window they have for reporting could also be shorter based on the laws specific to the state where your practice is located. For example, California state law gives a much shorter timeframe of up to 15 days to report. 

Policies and procedures for providing PHI access at your practice’s or patient’s request

  • Patient right of access has continued to be a huge government enforcement focus so outlining the proper policies and procedures for responding to patient record requests is a key element in the agreement. It is also important to identify the requirements for the BA to respond to your practice’s PHI requests including the timeframe and procedures for sharing. 

Business Associate Training requirements

  • In order to best protect PHI, you need to have the know-how which is why all staff members within your organization need proper HIPAA training and so do all BA employees. 

Guidelines for how PHI should be returned or destroyed upon termination of the BAA

  • You might’ve reached the expiration date on the agreement, maybe you’ve found another vendor to work with, or just want to go your separate ways. Whatever the case may be, there should be guidelines in place for how PHI is handled upon termination of the BAA, ensuring that that it’s either returned to your practice or properly disposed of. 

Meeting all the requirements for what should be included in a BAA is just the first stretch of the drive, and something we’re often asked is, “What if one of my vendors refuses to sign?” Given the fact that having a signed BAA with all vendors you work with is a HIPAA requirement, it’s probably a good idea to put the brakes on any working relationship with a vendor who can’t agree to your terms and conditions. Just last year a medical practice found itself a victim of a HIPAA hit and run after filing a breach report stating that their EHR company was blocking access to the practices’ ePHI in exchange for $50,000 to be paid by the practice. While it might seem pretty obvious that the business associate was the driving force of the incident, because there was no BAA in place – the $100,000 in damage fell solely on the provider. 

A Business Associate Agreement not only lays out the rules of the road for how PHI should be handled but holds the BA directly liable for any non-compliance that happens when they’re behind the wheel. Having a proper agreement in place with each and every vendor you work with ensures that they’re best protecting your patients’ PHI and means that your practice can steer clear of the hefty HIPAA fines if they don’t.

RECENT POSTS

  • Ambry Phishing Settlement
    $700K HIPAA Settlement: What the Ambry Genetics Phishing Breach Teaches Every Practice
  • Azul Vision Right of Access
    Right of Access Enforcement Hits Eye Care: Inside the Azul Vision Settlement
  • OSF Healthcare HIPAA Settlement
    What OSF Healthcare's Ransomware Fine Teaches Every Practice About SRAs
PrevPreviousWhat is the HIPAA Whistleblower Exception?
NextOregon Optometric Physicians Association & Abyde Partner To Deliver HIPAA Compliance to Independent Eye Care ProvidersNext

Related posts

Ambry Phishing Settlement
Abyde News, Fines, HIPAA

$700K HIPAA Settlement: What the Ambry Genetics Phishing Breach Teaches Every Practice

September 21, 2026 Penelope Schweitzer No comments yet

September 21, 2026   The HHS Office for Civil Rights (OCR) has announced its biggest HIPAA settlement of the year, reaching nearly a million dollars.  Ambry, a genetic testing and clinical genomics provider based in Aliso Viejo, California is at the center of this enforcement. A settlement was reached over a 2020 phishing attack that exposed the Protected Health Information (PHI) of more than 225,000 individuals. This settlement is a clear reminder that even large organizations trip up on HIPAA requirements.    What happened In January 2020, an employee email account at Ambry was compromised through a phishing attack.  The breach potentially exposed a wide range of PHI, including names, addresses, dates of birth, Social Security Numbers, financial details, and more. Ambry reported the breach to OCR in March 2020, which kicked off the investigation.    Where OCR found gaps OCR’s investigation identified several HIPAA Security Rule gaps, including: No accurate, thorough risk analysis of risks and vulnerabilities to ePHI No process for cutting off access to ePHI when an employee left or no longer needed access No unique user IDs for tracking who was accessing ePHI systems These are baseline HIPAA requirements that every Covered Entity and Business Associate is expected to have in place.   The settlement terms Ambry paid $700,000 and agreed to a two-year corrective action plan, under which it must: Complete a thorough risk analysis of ePHI confidentiality, integrity, and availability Build and execute a risk management plan addressing what that analysis turns up Review and update Security Rule policies and procedures as needed Implement unique user identification across all ePHI systems Train the whole workforce on those updated policies The takeaway for practices When 90% of healthcare hacks start with a successful phishing attempt, it’s key your team is aware of the role they play to keep data safe. Every practice should ask; Do we know exactly where our ePHI lives and how it moves through our systems? Do we have a current, documented risk analysis? Would we catch it fast if a former employee’s access wasn’t revoked? Looking for the first step of addressing these gaps? Meet with one of our compliance experts to see where you currently stand. 

Azul Vision Right of Access
Abyde News, Fines, HIPAA

Right of Access Enforcement Hits Eye Care: Inside the Azul Vision Settlement

September 1, 2026 Penelope Schweitzer No comments yet

September 1, 2026   The Office for Civil Rights (OCR) announced its 55th settlement under the HIPAA Right of Access Initiative, and this one is a good reminder that “we’ll get to it” is an easy shortcut to a massive financial penalty.   What happened Azul Vision, Inc., a California optometry enterprise healthcare provider, took nearly two years to provide a patient her healthcare records failed to give a patient timely access to her health records. She requested her records in January 2023. She didn’t actually receive them until January 2025, or two years later, and only after OCR opened an investigation following her complaint in April 2023.   The importance of Right of Access The HIPAA Privacy Rule’s Right of Access is straightforward: patients are entitled to their healthcare records within 30 days of a request, with one possible 30-day extension if needed.    The cost Azul Vision agreed to a two-year, OCR-monitored corrective action plan and paid $50,000. The corrective action plan requires the practice to: Review and revise its written policies and procedures for Privacy Rule compliance.  Regularly report to HHS a log of every PHI access request it receives, including when it came in and when it was resolved, Train all workforce members on right of access requirements and the practice’s own procedures.   Practical takeaways Have a documented, assigned process for access requests: not an informal “someone will handle it” arrangement. Track every request against the 30-day (or extended 60-day) clock: If nothing is timestamping requests, nothing is catching the ones that slip. Train staff specifically on right of access: this is a distinct Privacy Rule obligation from general HIPAA awareness, and it’s clearly one OCR is actively enforcing.   The bottom line A single records request that went unanswered turned into a $50,000 penalty, two years of federal monitoring, and a detrimental hit to the organization’s reputation. That’s a steep price for what really comes down to a missing process. If your team can’t answer “what happens the moment a patient asks for their records?” right now, that’s the gap to close before your practice ends up as OCR’s next enforcement case. Want a streamlined way to close your compliance gaps? Meet with an Abyde expert today!

OSF Healthcare HIPAA Settlement
Abyde News, Fines, HIPAA

What OSF Healthcare’s Ransomware Fine Teaches Every Practice About SRAs

August 5, 2026 Penelope Schweitzer No comments yet

August 5, 2026 The latest HIPAA fine is another clear reminder that ransomware attacks are, unfortunately, here to stay in the healthcare industry. A settlement involving the OSF Healthcare System was recently announced by the Office for Civil Rights (OCR). As an enterprise healthcare provider in the midwest, the organization serves 174 locations, including 16 hospitals – a prime target for a ransomware attack.    So, what happened?  In April 2021, OSF discovered that they joined the unlucky club of ransomware victims when a malicious actor deployed Nephilim, a ransomware strain made to target larger organizations. Once the ransomware infected OSF systems, the hacker demanded payment or patient Protected Health Information (PHI) would be leaked online. In this attack, sensitive information like financial account information, driver’s license numbers, medical record numbers, and more, were all exposed. Over 53,000 patient records were exposed in this attack.  When ransomware attacks in healthcare have soared 278% in recent years, it’s more of a when then an if your organization doesn’t have the right safeguards in place.  While the breach was discovered in April, OSF healthcare reported the breach to the OCR in October. The OCR took it from there, digging into what precautions (or lack thereof) let this happen.  What did the OCR discover? If you’ve read any of our other fine breakdowns, you already know where this is going: another missing Security Risk Analysis (SRA).  The SRA is a required document every HIPAA-regulated entity (ie: every practice and their Business Associates that handle patient information) needs to complete. The SRA is a thorough review of the physical, technical, and administrative safeguards in place to prevent PHI ending up in the wrong hands. While the OCR didn’t specify exactly how the ransomware got into OSF’s system, a technical safeguard vulnerability was very likely the entry point. A proactive SRA could have flagged that gap before it turned into a major breach. In addition to missing this required documentation, OSF also took too long to report the breach to the OCR and notify affected patients. This is a direct violation of the Breach Notification Rule, which requires organizations to notify patients within 60 days of a discovered breach. Moreover, since the breach impacted more than 500 patients, OSF was also required to report this breach to the OCR within 2 months as well. Time is of the essence in every component of a breach, from securing systems to ensuring affected parties are aware to protect themselves and an over five month delay was unacceptable in the eyes of the OCR.    What was the result?  OSF’s settlement tops the list as the largest fine of the year, coming in at $552,250, plus government monitoring for the next two years.  It’s very important to note that this breach occurred in 2021, meaning that over five years were spent from the initial breach, to investigations, to the public press releases. Also, the average cost of a healthcare breach is over 7 million dollars –  from implementing secure systems, notifying patients, legal fees, and more. The Takeaway While the settlement payment and Corrective Action Plan (CAP) are just the cherries on top, this experience was a tremendous cost of time, money, and resources, highlighting the importance of making sure everything is secure before a situation occurs.  So, when was the last time you looked at your SRA? It’s time to seriously analyze your current compliance posture. Ransomware groups don’t check whether you’re a small dental office or a 16-hospital health system before they attack, they check whether the door was left open. Time and again, OCR’s findings come back to the same root cause: organizations can’t secure what they haven’t even identified as a problem. Looking to review your current compliance standings? Meet with our team of experts for a complimentary educational consultation. 

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS