Department of Health and Human Services Wants to Help You Keep Your HIPAA Business Associates In Line


In last month’s Cyber-Awareness Monthly Update, the Office for Civil Rights (OCR) of the US Department of Health and Human Services (HHS) asked “Is Your Business Associate Prepared for a Security Incident?

The OCR, which is tasked with, among other things, ensuring equal access to certain health and human services and protecting the privacy and security of health information, noted growing concerns by covered entities under the Health Insurance Portability and Accountability Act (HIPAA) regarding security breaches of their business associates. In particular, the OCR explained that “[d]espite the requirements of HIPAA, not only do a large percentage of covered entities believe they will not be notified of security breaches or cyberattacks by their business associates, they also think it is difficult to manage security incidents involving business associates and impossible to determine if data safeguards and security policies and procedures at their business associates are adequate to respond effectively to a data breach.”

In response to these concerns, the OCR advised covered entities to consider the following for their contracts with business associates:

In addition, remember to ensure that the above concepts “flow down” into the contracts between the business associate and any subcontractors who may provide services for the covered entity.


Copyright © 2025 by Morgan, Lewis & Bockius LLP. All Rights Reserved.
National Law Review, Volume VI, Number 168