45 CFR 164.504 is the section of the HIPAA Privacy Rule that sets HIPAA’s organizational requirements. It does two things: it lists the terms a business associate contract must contain before a covered entity can share protected health information with an outside vendor, and it sets the conditions a group health plan must meet before disclosing PHI to the employer or plan sponsor behind it.1eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements If you handle either relationship, this section is where your paperwork obligations come from.
What a Business Associate Contract Must Contain
A covered entity that shares PHI with an outside organization performing services on its behalf needs a written business associate agreement (BAA) in place before any data changes hands. Failing to execute a compliant BAA before sharing PHI is itself a Privacy Rule violation, whether or not the business associate ever mishandles the data.
The contract has to define the specific uses and disclosures the business associate is permitted to make, and those permitted activities cannot exceed what the covered entity itself could do under the Privacy Rule. The contract may allow the business associate to use PHI for its own management and administration, and to provide data aggregation services related to the covered entity’s healthcare operations.1eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements
Beyond defining permitted uses, 164.504(e)(2) requires the contract to obligate the business associate to:
- Use appropriate administrative, technical, and physical safeguards to prevent unauthorized use or disclosure, including Security Rule compliance for electronic PHI.
- Report any use or disclosure not allowed by the contract to the covered entity, along with breaches of unsecured PHI as required by the Breach Notification Rule.
- Ensure that any subcontractor that creates, receives, maintains, or transmits PHI on its behalf agrees to the same restrictions and conditions.
- Make PHI available to support individual access requests, amendments, and accountings of disclosures.
- Make its internal practices, books, and records relating to PHI available to the Secretary of HHS for compliance reviews.
- At termination of the contract, return or destroy all PHI it still holds, and if that is not feasible, limit further uses to the purposes that make destruction impractical.
The Same Rules Apply Down the Chain
Section 164.504(e)(5) applies a nearly identical set of requirements to the contract between a business associate and any subcontractor that handles PHI on its behalf. The result is that a fourth- or fifth-tier vendor holding PHI is contractually bound to the same privacy standards as the covered entity that originally released it. If you are a business associate, you have your own contracting obligation downstream; the covered entity’s BAA with you is not enough by itself.
When the Business Associate Isn’t Following the Contract
Signing the BAA is the beginning of the obligation, not the end. Under 164.504(e)(1), if a covered entity learns of a pattern of activity or practice by the business associate that constitutes a material breach of the contract, it must take reasonable steps to cure the breach or end the violation. If those steps fail, the covered entity must terminate the contract.1eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements
The same duty runs from business associate to subcontractor. A business associate that discovers a subcontractor engaged in an uncurable pattern of violations must end the subcontractor relationship if feasible.
Termination is not always feasible, particularly when the vendor provides a service that cannot easily be replaced. In that case, the covered entity has to report the problem to the HHS Office for Civil Rights.2HHS.gov. Business Associates Tolerating the violations without either fixing them, walking away, or notifying OCR is not one of the options.
When a Group Health Plan Wants to Share PHI With the Employer
The second half of 164.504 governs a scenario that catches many employers off guard. If your company sponsors a group health plan and wants access to enrollment or claims data, the plan sponsor is not automatically entitled to it just because the company funds the plan. Section 164.504(f) requires the plan documents to be amended first.1eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements
The amended plan documents must set out the uses and disclosures the plan sponsor is permitted to make with PHI it receives. The plan sponsor then has to certify in writing that it agrees to a specific list of conditions before the group health plan can release anything.
The Employment Decisions Prohibition
The most consequential condition is that the plan sponsor cannot use or disclose PHI for employment-related actions or decisions, and cannot use it in connection with any other benefit or benefit plan of the sponsor.3HHS.gov. Am I a Covered Entity Under HIPAA? An employer that receives claims data showing a serious diagnosis cannot factor that into a decision to promote, transfer, or terminate the employee.
Adequate Separation Between Plan and Sponsor
The plan documents must also provide for adequate separation between the group health plan and the plan sponsor. In practice, that means identifying which employees or classes of employees are authorized to access PHI, restricting access to those individuals, and defining the mechanism for resolving noncompliance by them. Typically only designated HR staff involved in plan administration qualify. The plan sponsor also has to agree to report any impermissible use or disclosure to the group health plan, to make PHI available for individual access and amendment requests, to pass restrictions down to any agents it uses, and to return or destroy PHI when it is no longer needed.1eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements
The Summary Health Information Exception
One narrow disclosure sits outside this whole framework. A group health plan can release summary health information to the plan sponsor for the purpose of obtaining premium bids or modifying, amending, or terminating the plan without going through the full amendment and certification process. Summary health information has most individual identifiers stripped, though it may still contain aggregated claims data at the five-digit zip code level. Enrollment and disenrollment information can also be shared with the plan sponsor without the full compliance package.
What Noncompliance Costs
The HHS Office for Civil Rights enforces the organizational requirements, and the most common enforcement targets under 164.504 are missing or incomplete business associate agreements. A covered entity that shares PHI with a vendor and has no BAA in place is exposed on every instance of that disclosure, and each affected patient record can count as a separate violation.
Penalties follow a four-tier structure keyed to the violator’s level of culpability, with amounts adjusted annually for inflation. As of 2025, the tiers run from $141 per violation at the low end of the “lack of knowledge” tier up to roughly $2.13 million per violation for willful neglect that is not corrected within 30 days, with the annual cap for each tier also around $2.13 million. The often-quoted $1.5 million annual cap is out of date.
The practical takeaway sits in the paperwork. If you share PHI with an outside organization, the BAA has to exist first and has to contain the terms 164.504(e) requires. If you are the employer behind a group health plan and you want data out of it, the plan documents have to be amended and you have to certify to the conditions in 164.504(f) before anything moves. Everything else in this section describes what happens when those steps are skipped or ignored.