HIPAA Compliance Checklist for Business Associates

If your organization creates, receives, maintains, or transmits protected health information on behalf of a covered entity, HIPAA applies to you directly, and this HIPAA compliance checklist for business associates walks through every obligation you need to meet. Since the HITECH Act, business associates carry the same safeguard duties and the same civil and criminal exposure as the covered entities they serve.1U.S. Department of Health and Human Services. Summary of the HIPAA Security Rule Civil penalties in 2026 reach up to $2,190,294 per violation category, and criminal convictions can add prison time on top.

Confirm You Are a Business Associate

A business associate is any person or organization that creates, receives, maintains, or transmits protected health information on behalf of a covered entity for a regulated function. Claims processing, billing, data analysis, utilization review, quality assurance, benefit management, and practice management all qualify.2eCFR. 45 CFR 160.103 – Definitions So do outside legal, actuarial, accounting, consulting, and financial professionals who access patient data while serving a covered entity.

The definition also captures organizations you might not immediately connect to healthcare: health information exchanges, e-prescribing gateways, personal health record vendors operating on behalf of a covered entity, and cloud hosting providers that store health data.2eCFR. 45 CFR 160.103 – Definitions Your own subcontractors that touch protected health information are business associates too. The safest working test: if any protected health information passes through your systems or your people during work you do for a covered entity, you are a business associate.

Put a Business Associate Agreement in Place Before Any Data Moves

Before any protected health information changes hands, a signed Business Associate Agreement must exist. The Privacy Rule and the Security Rule both require it, and operating without one is itself a violation.3eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements The agreement must define permitted uses and disclosures, restrict you from anything beyond those uses, and require appropriate safeguards.

Under the Security Rule’s organizational requirements, the agreement also has to require you to report security incidents to the covered entity, ensure subcontractors sign equivalent agreements, and make your internal practices available to HHS for compliance review.4eCFR. 45 CFR 164.314 – Organizational Requirements OCR has pursued settlements specifically because no agreement existed between a covered entity and a vendor handling patient data, in one case for $1.55 million.5U.S. Department of Health and Human Services. Resolution Agreements

Address What Happens When the Contract Ends

The agreement needs to state what happens to protected health information when the contract ends. It should require you to return or destroy all such information upon termination. If return or destruction is not feasible, because of a legal retention requirement or a similar reason, the agreement must extend its protections indefinitely to the retained data and limit further use or disclosure to the purpose that makes return or destruction infeasible.3eCFR. 45 CFR 164.504 – Uses and Disclosures: Organizational Requirements

Run a Documented Risk Analysis

A thorough risk analysis is the backbone of everything else. Without it, you are choosing safeguards by guess rather than by evidence. The Security Rule requires the analysis as a core part of the security management process, and OCR’s 2024-2025 audit program targets Security Rule compliance with a specific focus on hacking and ransomware.6U.S. Department of Health and Human Services. OCR’s HIPAA Audit Program

Start by mapping every place electronic health information enters, moves through, and exits your organization. For each point, identify potential threats and vulnerabilities, assess the likelihood and impact of each, and evaluate whether your current safeguards actually address the risk. HHS guidance is emphatic that this is not a one-time exercise; the analysis needs to be refreshed whenever you adopt new technology, change vendors, expand operations, or face new threat types.7U.S. Department of Health and Human Services. Guidance on Risk Analysis

Findings must be formally documented and used to drive updates to your risk management plan. Incomplete or outdated risk analyses are among the most common findings in OCR enforcement actions. If an investigator asks how you chose your safeguards and you cannot point to a written analysis, the audit gets much harder.

Know the Difference Between Required and Addressable

Throughout the Security Rule, each implementation specification is labeled either “required” or “addressable.” Required means you must implement it. Addressable does not mean optional. If a specification is addressable, you must assess whether it is a reasonable and appropriate safeguard for your environment.8U.S. Department of Health and Human Services. What Is the Difference Between Addressable and Required Implementation Specifications

If it is reasonable and appropriate, you implement it. If it is not, because of your size, technology, or cost constraints, you document why and implement an equivalent alternative that achieves the same protective purpose. Skipping an addressable specification without written justification is treated the same as ignoring a required one.8U.S. Department of Health and Human Services. What Is the Difference Between Addressable and Required Implementation Specifications Every decision, whether you implement, substitute, or decline with justification, needs to be documented. That documentation is exactly what OCR asks to see.

Administrative Safeguards

Administrative safeguards make up the largest part of the Security Rule and focus on human processes rather than technology. The starting point is a security management process: written policies and procedures to prevent, detect, contain, and correct security violations.9eCFR. 45 CFR 164.308 – Administrative Safeguards From there the requirements branch out.

  • Assign a designated security official responsible for developing and implementing your policies. This cannot be a shared, undefined responsibility.
  • Train every workforce member with access to electronic health information on your security policies and procedures. Training is ongoing, not a one-time onboarding event, and needs to cover current threats like phishing and social engineering.
  • Manage access so that employees can only reach the data their roles require.
  • Adopt a sanction policy that applies appropriate discipline to workforce members who violate your security policies.9eCFR. 45 CFR 164.308 – Administrative Safeguards

The Privacy Rule adds a parallel obligation: the minimum necessary standard. When your team uses or discloses health information, they should access only the smallest amount needed to complete the task. This applies to routine uses, role-based access decisions, and disclosures to outside parties.10U.S. Department of Health and Human Services. Understanding the HIPAA Privacy Rule Minimum Necessary Standard Exceptions exist for treatment disclosures, disclosures to the individual who is the subject of the data, and uses required by law.

Physical Safeguards

Physical safeguards protect the buildings, rooms, and equipment where electronic health information lives. Facility access controls are the core requirement: policies and procedures that limit physical access to your systems while still letting authorized personnel work.11eCFR. 45 CFR 164.310 – Physical Safeguards In practice this looks like badge readers, locked server rooms, visitor logs, and cameras at entry points.

Workstation use and security standards require rules about how and where workstations are used, and a physical environment that prevents unauthorized viewing of screens. In open offices, screen positioning and privacy filters matter. Device and media controls require procedures governing how hardware and electronic media containing health information are received, moved, removed, and disposed of.11eCFR. 45 CFR 164.310 – Physical Safeguards

Technical Safeguards

Technical safeguards govern the technology that protects electronic health information and controls access to it. Five standards apply.12eCFR. 45 CFR 164.312 – Technical Safeguards

  • Access control. Systems holding health information must have technical mechanisms restricting access to authorized users. Unique user identification and emergency access procedures are required specifications; automatic logoff and encryption are addressable.
  • Audit controls. Deploy mechanisms that record and examine activity in systems containing health information. These logs create the electronic trail investigators review after an incident.
  • Integrity controls. Policies and procedures must protect electronic health information from unauthorized alteration or destruction.
  • Authentication. You need procedures to verify that any person or system requesting access is who it claims to be.
  • Transmission security. Technical measures must guard against unauthorized access to health information moving over a network.12eCFR. 45 CFR 164.312 – Technical Safeguards

Unique user identification deserves emphasis. When every action ties back to a specific person, you can investigate incidents, enforce accountability, and show regulators exactly who did what. Shared logins destroy that trail and remain one of the most common audit findings.

Encryption and the Breach Notification Safe Harbor

Encryption provides one of the most valuable protections in the entire framework. The Breach Notification Rule applies only to “unsecured” protected health information, meaning data that has not been rendered unusable, unreadable, or indecipherable to unauthorized persons.13eCFR. 45 CFR 164.402 – Definitions If you encrypt electronic health information using processes consistent with NIST standards and the keys have not been compromised, the data is considered secured. A laptop stolen from a car, a server hit by an intruder: if the data was properly encrypted, no breach notification is required.

HHS guidance specifies that valid encryption for data at rest must be consistent with NIST Special Publication 800-111, and encryption for data in motion must comply with NIST standards for TLS, IPsec VPNs, or SSL VPNs. Encryption keys must be stored separately from the data they protect.14U.S. Department of Health and Human Services. Guidance to Render Unsecured Protected Health Information Unusable, Unreadable, or Indecipherable to Unauthorized Individuals Given the cost of breach notification, encryption is one of the highest-return investments you can make.

Breach Notification Duties

When a breach of unsecured health information occurs, your obligation is specific: notify the affected covered entity without unreasonable delay and no later than 60 calendar days after discovery.15eCFR. 45 CFR 164.410 – Notification by a Business Associate The clock starts the day any employee, officer, or agent of your organization knew about the breach, or would have known through reasonable diligence, not the day you finished confirming it.

Your notification to the covered entity must identify each affected individual, to the extent you can determine, and provide the information the covered entity will need to fulfill its own notification duties: what happened, the types of information involved, recommendations for affected individuals, and the steps being taken to investigate and mitigate harm.15eCFR. 45 CFR 164.410 – Notification by a Business Associate

The covered entity carries the obligation to notify individuals and HHS. For breaches affecting 500 or more people, the covered entity must also notify a prominent media outlet in the affected jurisdiction, and HHS must be notified immediately. Smaller breaches are logged and reported to HHS within 60 days after the end of the calendar year.16eCFR. 45 CFR Part 164 Subpart D – Notification in the Case of Breach of Unsecured Protected Health Information You need to know these thresholds because the scope of the breach determines how urgently the covered entity needs your cooperation.

Contingency and Disaster Recovery Planning

The Security Rule requires a contingency plan for emergencies that could damage systems containing electronic health information: fires, natural disasters, ransomware, hardware failures. Three implementation specifications are required, not addressable, which means every business associate must have them.9eCFR. 45 CFR 164.308 – Administrative Safeguards

  • Data backup plan. Procedures to create and maintain retrievable exact copies of electronic health information. Backups need to be regular, tested, and stored so they survive the disaster you are planning for.
  • Disaster recovery plan. Procedures to restore any loss of data. This goes beyond backups and addresses how you get systems operational after a major disruption.
  • Emergency mode operation plan. Procedures to keep critical business processes running during and immediately after an emergency, focused on protecting health information while normal systems are down.

Testing and revision of these plans is an addressable specification. In practice, nearly every organization should be testing. A disaster recovery plan that has never been tested is a plan that probably will not work.

Manage Your Subcontractors

If you use subcontractors that access protected health information in any way, whether IT vendors, shredding companies, cloud platforms, or consultants, you must have a written agreement with each one imposing the same restrictions and requirements that apply to you.17eCFR. 45 CFR 164.502 – Uses and Disclosures of Protected Health Information: General Rules The regulation specifically requires subcontractors to comply with the Security Rule by entering into a contract that meets the same organizational requirements as your agreement with the covered entity.4eCFR. 45 CFR 164.314 – Organizational Requirements

The chain extends indefinitely. If your subcontractor uses its own subcontractor to process health information, that downstream entity also needs an agreement. The regulatory definition of business associate explicitly includes subcontractors that create, receive, maintain, or transmit protected health information on behalf of another business associate.2eCFR. 45 CFR 160.103 – Definitions You are responsible for vetting each vendor’s compliance posture before sharing patient data, and you bear liability if a subcontractor causes a breach without a proper agreement in place.

Destroy Data the Right Way

How you destroy health information matters, and doing it carelessly can itself constitute a violation. HHS does not mandate one destruction method but requires the data to be rendered essentially unreadable, indecipherable, and unable to be reconstructed.18U.S. Department of Health and Human Services. Frequently Asked Questions About the Disposal of Protected Health Information

For paper records, acceptable methods include shredding, burning, pulping, or pulverizing. Simply tossing files into a dumpster without rendering them unreadable is explicitly prohibited, even if the dumpster sits behind your building. For electronic media, HHS points to three approaches: clearing (overwriting with non-sensitive data), purging (degaussing or other techniques that make recovery infeasible), and physical destruction such as shredding, melting, or incinerating the media.18U.S. Department of Health and Human Services. Frequently Asked Questions About the Disposal of Protected Health Information HHS recommends NIST Special Publication 800-88 for selecting the right method for different storage media.

If you use a disposal vendor, that vendor is itself a business associate and needs its own written agreement. After destruction, retain documentation, such as a destruction certification or written attestation, to confirm proper disposal. When a covered entity asks for proof that you destroyed their data after the contract ended, this is the document they expect to see.

Documentation and Six-Year Retention

A theme runs through every section of this checklist: documentation. The Security Rule requires business associates to maintain written records of their policies, procedures, actions, activities, and assessments, and to retain them for six years from the date they were created or the date they were last in effect, whichever is later.19eCFR. 45 CFR 164.316 – Policies and Procedures and Documentation Requirements

Keep your written security policies, risk analysis documentation, training logs, sanction records, Business Associate Agreements (including expired ones), breach investigation files, and records of every decision you made about addressable implementation specifications. These records prove to OCR that you took compliance seriously and protect you in litigation by showing you had reasonable safeguards in place. Letting documentation lapse, or discarding old policies before the six-year window closes, can turn a defensible audit into an expensive one.

What Noncompliance Costs

Civil penalties are structured in four tiers based on the violator’s level of awareness and whether the problem was corrected. As of 2026, the inflation-adjusted amounts are:20Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

  • Tier 1, did not know: $145 to $73,011 per violation, annual cap of $2,190,294 for identical violations.
  • Tier 2, reasonable cause: $1,461 to $73,011 per violation, same annual cap.
  • Tier 3, willful neglect corrected within 30 days: $14,602 to $73,011 per violation, same annual cap.
  • Tier 4, willful neglect not corrected: $73,011 to $2,190,294 per violation, annual cap also at $2,190,294.20Federal Register. Annual Civil Monetary Penalties Inflation Adjustment

Those are per-violation figures. A single breach exposing thousands of records can involve thousands of individual violations, and the total escalates quickly.

Criminal liability applies to anyone who knowingly obtains or discloses protected health information in violation of the rules. The tiers run from up to $50,000 and one year in prison for a knowing violation, up to $100,000 and five years for a violation under false pretenses, and up to $250,000 and ten years for violations committed with intent to sell the information or use it for personal gain.21Office of the Law Revision Counsel. 42 USC 1320d-6 – Wrongful Disclosure of Individually Identifiable Health Information Criminal cases are referred to the Department of Justice and target individuals, not just organizations. An employee who steals patient records for personal use faces personal criminal exposure regardless of how good the employer’s policies were.