HIPAA checklist for business associates
Most checklists aimed at business associates are a covered entity’s checklist with the word swapped. That is safe advice and bad information: OCR can act against you directly for a specific, short, enumerated set of obligations — and not for most of the Privacy Rule. Knowing which is which decides where your effort goes.
No email required, no download gate. Last reviewed .
The ten things OCR can pursue you for directly
HITECH made business associates directly liable for parts of the HIPAA Rules, and OCR’s 2013 final rule identified which parts. OCR publishes the resulting list and states that its enforcement authority over business associates extends only to these. Each line below carries the citation from that guidance so you can check it against the regulation rather than against us.
- 01
Cooperating with OCR
Providing records and compliance reports, cooperating with complaint investigations and compliance reviews, and permitting access to information — including protected health information — relevant to determining compliance.
45 CFR 160.310, 164.502(a)(4)(i)
- 02
Not retaliating
Against anyone who files a complaint, participates in an investigation or enforcement process, or opposes an unlawful act or practice.
45 CFR 160.316
- 03
The whole Security Rule
Not a subset. The administrative, physical and technical safeguards, the organizational requirements and the documentation requirements all apply to you directly, in your own environment.
45 CFR 164.306, 164.308, 164.310, 164.312, 164.314, 164.316
- 04
Breach notification upward
Notifying the covered entity — or the business associate above you — when a breach of unsecured protected health information is discovered.
45 CFR 164.410, 164.412
- 05
Impermissible uses and disclosures
Using or disclosing protected health information other than as your agreement permits or the rules require.
45 CFR 164.502(a)(3)
- 06
Providing an electronic copy on request
Failing to give an electronic copy of ePHI to whoever your agreement names — the covered entity, or the individual or their designee — to satisfy an individual's right of access.
45 CFR 164.502(a)(4)(ii)
- 07
Minimum necessary
Making reasonable efforts to limit protected health information to the minimum necessary for the intended purpose of a use, disclosure or request.
45 CFR 164.502(b)
- 08
Accounting of disclosures
Providing one in the circumstances where it is required of you.
HITECH Act 13405(c)(3), 42 USC 17935(c)(3)
- 09
Agreements with your own subcontractors
Entering into business associate agreements with subcontractors that create or receive protected health information on your behalf, and complying with the implementation specifications for those agreements.
45 CFR 164.502(e)(1)(ii), 164.504(e)(5)
- 10
Acting on a subcontractor's breach of its agreement
Taking reasonable steps to cure a known pattern of activity that materially breaches a subcontractor's obligations — and terminating the arrangement if that fails and termination is feasible.
45 CFR 164.504(e)(1)(iii)
Your agreement is the other half, and it is not smaller
Everything in the Privacy Rule that is not on that list still reaches you — through your business associate agreement, as a contractual obligation to your client rather than a regulatory one to OCR. The practical difference is who comes after you and how. A regulator brings an investigation and possibly a penalty; a client brings a terminated contract, an indemnity claim, and a reference you will need for the next deal. Neither is the cheaper problem, and the client one arrives far more often.
1. Establish that you are one, and for whom
Plenty of business associates do not know they are one. If you create, receive, maintain or transmit protected health information to perform a function on behalf of a covered entity, you are — and “maintain” alone is enough, which is what catches hosting providers and IT firms.
Write down the determination that you are a business associate, and why
Evidence: A dated note of the reasoning, revisited when services change
160.103
List every covered entity and business associate you act for
Evidence: A client register with the executed agreement for each
Identify which of your own systems hold or reach client data
Evidence: A systems inventory covering tooling and staff devices, not just the product
2. Run the Security Rule for yourself
This is the largest of your direct obligations and the one most commonly deferred to clients. Your clients' assessments cover their environments. Nobody else is assessing yours.
Conduct and document a risk analysis of your own environment
Evidence: A dated analysis covering every system on your inventory
164.308(a)(1)(ii)(A)
Implement measures sufficient to reduce the risks you found
Evidence: A remediation log with owners, dates and closing evidence
164.308(a)(1)(ii)(B)
Designate a security official
Evidence: A named person in writing
164.308(a)(2)
Train your workforce and keep per-person records
Evidence: Completion dates and certificates, per employee and contractor
164.308(a)(5)
Document addressable specifications you did not implement, and what you did instead
Evidence: A written decision per specification
164.306(d)
Perform the periodic evaluation, and after material change
Evidence: A dated evaluation record naming what changed since last time
164.308(a)(8)
3. Handle the chain beneath you
Two of the ten direct-liability items are about subcontractors, which tells you how seriously this is taken. Your obligations flow down, and knowing about a subcontractor's material breach without acting is itself a violation.
Sign agreements with every subcontractor that touches client data
Evidence: Executed agreements with the required implementation specifications
164.502(e)(1)(ii), 164.504(e)(5)
Maintain a subprocessor list you can hand to a client who asks
Evidence: A current list, dated, naming what each one does
Act on a subcontractor's material breach, and terminate if cure fails
Evidence: A written record of the steps taken and the outcome
164.504(e)(1)(iii)
Screen subcontractors against the federal exclusion lists
Evidence: Dated screening results, refreshed monthly
42 USC 1320a-7, 42 CFR 1001.1901
4. Be ready to notify, upward and fast
Your breach obligation runs to the covered entity, not to individuals or to HHS — but the clock it starts is theirs, and a late notification from you makes them late. This is the obligation whose failure is most visible to the client paying you.
Define what a security incident is and how staff report one
Evidence: A written procedure people have been shown
164.308(a)(6)
Assess every incident against the four factors and record the outcome
Evidence: An incident log including the ones assessed as not reportable, with reasoning
164.402, 164.414(b)
Notify the covered entity without unreasonable delay after discovery
Evidence: A dated notification record, with the discovery date recorded
164.410, 164.412
5. Keep the evidence, and be able to hand it over
Two audiences ask for the same pack: OCR, whose access you are directly liable for permitting, and clients, who ask far more often. Building it once for both is the only version of this that is not done twice.
Retain documentation for six years from creation or last effect, whichever is later
Evidence: Version history rather than overwritten files
164.316(b)(2)(i)
Be able to produce records and compliance reports to the Secretary
Evidence: An export you have actually run, not a folder you believe in
160.310, 164.502(a)(4)(i)
Have a current answer ready for client security questionnaires
Evidence: A dated evidence pack: analysis, policies, training, agreements
Built for the party in the middle.
Run your own assessment, keep policies and training current, hold the agreements in both directions, screen your subcontractors monthly, and export the dated pack when a client asks — which they will. 14 days free, no credit card, no sales call.
Common questions
- What is a business associate responsible for under HIPAA?
- OCR has authority to take enforcement action against business associates only for a specific enumerated set of obligations — ten of them, listed on this page. The largest is the whole Security Rule, which applies to a business associate directly and in its own environment. The rest cover cooperating with OCR, not retaliating, breach notification to the covered entity, impermissible uses and disclosures, providing electronic copies, minimum necessary, accounting of disclosures, and two obligations about subcontractors.
- Are business associates liable for the whole Privacy Rule?
- No, and this is the distinction most checklists get wrong. Business associates are directly liable for the specific Privacy Rule provisions OCR enumerates — impermissible uses and disclosures, minimum necessary, electronic copies, accounting, and the subcontractor requirements — not for the Privacy Rule generally. OCR gives its own worked example of the boundary: it cannot enforce the reasonable, cost-based fee limitation at 45 CFR 164.524(c)(4) against a business associate, because HITECH did not apply that provision to them; only the covered entity can be pursued for it. Everything else in the Privacy Rule reaches you through your agreement, which makes it a contractual obligation to your client rather than a regulatory one to OCR — still enforceable, just by a different party in a different forum.
- Does a business associate need its own risk analysis?
- Yes. The Security Rule applies to you directly, and 45 CFR 164.308(a)(1)(ii)(A) asks for an accurate and thorough assessment of the risks to all electronic protected health information you hold. Running assessments for your clients does not discharge it — those cover their systems. Yours covers your infrastructure, your tooling, your staff devices and anything your subcontractors reach.
- Do business associates report breaches to HHS?
- Generally no — your notification runs to the covered entity, or to the business associate above you if you are a subcontractor, under 45 CFR 164.410. The covered entity then notifies individuals, HHS and, where the numbers require it, the media. The exception is where your agreement makes you the party that notifies on the covered entity's behalf, which some agreements do. Either way the timing matters more than the routing: the covered entity's own 60-day clock is affected by when you tell them.
- What happens if a business associate has no BAA with a client?
- The covered entity has made an impermissible disclosure by giving you the data without satisfactory assurances, and it is their violation. You are not off the hook: your direct obligations — the Security Rule, breach notification, impermissible uses and disclosures — attach because of what you do with protected health information, not because of what you signed. The missing agreement removes a protection; it does not remove a duty.
Billing or RCM company? The version written for you →
Informational only, based on the published text of 45 CFR Parts 160 and 164, the HITECH Act, and OCR’s published guidance on the direct liability of business associates, read on August 13, 2026. This is not legal advice — what your own agreement obliges you to do is a question about that contract. No organization or product can be “HIPAA certified” — no such designation exists. See our editorial standards.
Keep reading
- Answering a security questionnaireWhat they are really asking for, and what to send.
- Trust Packet exportOne dated pack answering the whole request.
- For healthcare software vendorsStop rebuilding the same answers for every deal.
- For billing and RCM companiesYou are a business associate. Sooner or later someone asks.
- HIPAA billing softwareWhat to require of a billing vendor, and why some billing companies are covered entities.
- Questionnaire answer starterFill-in-the-blank answers to the twelve questions every form asks.
Looking for the software rather than the explanation? Trust Packet export.