Understanding the Compliance Challenge
Your business associate just informed you they're hiring a freelance developer to build a patient portal feature. Your privacy officer wants to know if the existing Business Associate Agreement (BAA) covers this arrangement. Your IT director is asking who's responsible for vetting the contractor's security setup. And your compliance officer just forwarded an email asking whether the freelancer needs their own HIPAA training.
These questions are common. They're coming from covered entities and business associates who've realized that subcontractors, especially independent contractors in software development, create a compliance gap that most BAAs don't address. The short answer: your existing BAA doesn't extend to the subcontractor, and yes, you're still responsible if they cause a breach.
Here's what you need to know.
Q1: Do We Need a Separate Agreement for Every Subcontractor Who Handles PHI?
Yes. When your business associate shares Protected Health Information (PHI) with a subcontractor, that transfer requires a Business Associate Subcontractor Agreement (BASA). Your BAA with the business associate doesn't automatically cover downstream relationships.
Think of it this way: the BAA transfers responsibility from you to your business associate. When that business associate hands PHI to a third party, they need a parallel mechanism to transfer and document compliance obligations. Without a BASA, there's no contractual obligation binding the subcontractor to HIPAA requirements.
This applies whether the subcontractor is a solo freelancer working from home or a 50-person development shop. If PHI flows to them, you need a BASA in place before that transfer happens.
Q2: Who Ensures the Developer's Environment is HIPAA-Compliant?
The subcontractor is responsible for their own compliance, but you can't ignore it.
You can't dictate exactly how a freelancer works unless you employ them directly. The IRS has clear guidance on this: if you control the method and means, they're an employee, not a contractor. So you can't simply hand a freelance developer a security policy and tell them to follow it.
What you can do: require evidence of compliance as a condition of the BASA. Ask for documentation of their development environment security controls. Request copies of their policies and procedures. Some covered entities and business associates go further, offering to provide HIPAA training or conducting a security assessment for the subcontractor to ensure baseline protections are in place.
Ultimately, the subcontractor must establish and maintain their own HIPAA compliance program. If they can't document secure coding practices, access controls in their dev environment, or how they vet third-party code libraries, don't sign the BASA.
Q3: If the Subcontractor Makes a Mistake, Who Gets Fined?
You do. Under the Common Agency Provision, a business associate's breach becomes the covered entity's breach. That liability doesn't stop at your business associate; it extends through the subcontractor chain.
For example, if your business associate hires a developer who uses an unsecured cloud instance to test code with production PHI and that instance gets compromised, the breach notification obligation falls on you, the covered entity. The Office for Civil Rights (OCR) will evaluate your due diligence in selecting and overseeing your business associate, and your business associate's due diligence in selecting and overseeing the subcontractor.
This is why you can't treat BASAs as a formality. The agreement doesn't eliminate your risk; it's supposed to document how that risk is being managed at every level.
Q4: What Should Be in a BASA?
The same core elements you'd expect in a BAA, tailored to the subcontractor's specific role:
- Permitted uses and disclosures of PHI
- Safeguard requirements (administrative, physical, and technical)
- Breach notification obligations, including timelines
- Subcontractor's agreement to make their records available for OCR audits
- Return or destruction of PHI at contract termination
- Prohibition on further disclosure without authorization
For software developers specifically, add requirements around the development environment: how they'll handle PHI in testing, whether they're allowed to use production data (generally, don't allow this), secure coding standards, and how they vet any open-source libraries or third-party code they incorporate.
Don't copy-paste your standard BAA template. A graphic designer handling PHI for marketing materials has different risk factors than a developer building an API that queries your EHR.
Q5: How Do We Audit a Solo Freelancer's HIPAA Compliance?
Conduct the same due diligence you'd conduct for any business associate, scaled to the engagement.
Start with a questionnaire. Ask about their training (have they completed HIPAA training, and when?), their technical safeguards (encryption at rest and in transit, access controls, logging), and their policies (incident response, workforce security, device and media controls). Request documentation.
For developers, dig into the development environment specifically. Where do they work? What devices do they use? How is PHI segregated from non-PHI projects? What's their process for code review? How do they ensure that any third-party code they pull in doesn't introduce vulnerabilities?
If they can't answer these questions with specifics, they're not ready to handle PHI. A freelancer who's serious about healthcare work will have invested in their own compliance infrastructure, training, documented policies, and a security setup they can defend in an audit.
Q6: Can We Prohibit Our Business Associates from Using Subcontractors?
You can try, but it's not realistic for most engagements, especially in software development.
Modern software projects rely on specialized expertise. Your business associate might need a database architect for two weeks, a front-end developer for a sprint, or a security consultant to conduct penetration testing. Prohibiting subcontractors entirely means you're limiting your business associate's ability to deliver quality work.
The better approach: require prior written approval for any subcontractor arrangement. Your BAA should include a clause stating that the business associate must notify you before engaging a subcontractor, provide details about the subcontractor's role and access to PHI, and obtain your consent. This gives you the chance to evaluate the risk and ensure a BASA is in place before PHI starts flowing.
Some covered entities maintain an approved subcontractor list. If your business associate wants to use someone not on the list, they submit a request with supporting documentation, and your compliance team evaluates it.
Taking Action
If you're a business associate managing subcontractor relationships, start by auditing your current agreements. Identify any subcontractors who've had access to PHI without a BASA in place, and remediate those gaps immediately.
If you're a covered entity, add subcontractor oversight to your business associate audit process. During your annual or biennial reviews, ask your business associates for a list of all subcontractors who've accessed PHI in the past year, verify that BASAs are in place, and spot-check the subcontractors' compliance documentation.
For subcontractors, especially independent developers, treat HIPAA compliance as a professional credential. Document your policies, complete training, and be ready to demonstrate your security controls. The healthcare market rewards contractors who can prove they're not a liability.
The chain of responsibility for PHI doesn't end at your business associate. Make sure every link can hold the weight.



