Skip to main content
OCR Can Fine You for Your Business Associate's MistakesRegulatory Framework
5 min readFor Privacy Officers

OCR Can Fine You for Your Business Associate's Mistakes

You've signed Business Associate Agreements with every vendor who touches Protected Health Information (PHI). Your contracts include all the required HIPAA language. You're covered, right?

Not even close.

Under 45 CFR § 160.402 (the Common Agency Provision), the Office for Civil Rights (OCR) can hold you liable for HIPAA violations your Business Associates commit. That cloud storage vendor who misconfigured access controls? Your liability. The billing company that left a laptop unencrypted? Your penalty. The provision applies agency law to healthcare compliance: when someone acts on your behalf, their failures become yours.

This guide walks you through building a compliance program that actually manages Business Associate risk, not just documents it.

What You Need Before Starting

Access and authority:

  • Admin access to your vendor management system or contract repository
  • Authority to request documentation from Business Associates
  • Budget approval for compliance tools (SaaS monitoring, audit logs)

Documentation you'll need:

  • Current inventory of all Business Associates (every vendor, contractor, or agent who creates, receives, maintains, or transmits PHI on your behalf)
  • Executed Business Associate Agreements for each relationship
  • Your organization's HIPAA Security Rule risk analysis (required under 45 CFR § 164.308(a)(1)(ii)(A))
  • List of systems where Business Associates have access to PHI

Team involvement:

  • Privacy Official (you'll need their sign-off on monitoring protocols)
  • IT security lead (for technical validation steps)
  • Procurement or legal (to enforce contract amendments)

Step-by-Step Implementation

Step 1: Map Your Actual Agency Relationships

Don't rely on your contract list. Map every entity that handles PHI in practice.

Start with obvious Business Associates: EHR vendors, billing companies, cloud hosting providers, transcription services. Then identify the hidden ones: IT support contractors who remote into systems, shredding companies, email security providers, patient portal platforms.

For each relationship, document:

  • What PHI they access (ePHI in databases, paper records, email)
  • How they access it (API, SFTP, direct system login, physical pickup)
  • Scope of their authority (create, read, update, delete, transmit)

Use a spreadsheet with columns: Vendor Name | PHI Type | Access Method | BAA Signed (Y/N) | Last Security Assessment Date | Risk Tier (Critical/High/Medium/Low).

Mark any vendor without a signed BAA as Critical and halt their PHI access immediately. Operating without a BAA is direct liability.

Step 2: Implement Continuous Compliance Verification

A signed BAA creates a legal obligation. It doesn't create actual security.

Build a quarterly verification process for high-risk Business Associates (those with database access, those storing ePHI, those handling large volumes):

Request and review:

  • Current SOC 2 Type II report or HITRUST CSF certification
  • Breach incident log (even if no reportable breaches occurred)
  • Evidence of workforce HIPAA training completion
  • Encryption status for data at rest and in transit
  • Access log samples showing who accessed your PHI and when

If a Business Associate refuses to provide documentation, that's a red flag. The Common Agency Provision creates liability by association when you know about non-compliance and don't act. Document your request, escalate to your legal team, and consider contract termination clauses.

For critical vendors (those whose failure would trigger Breach Notification Rule obligations), conduct annual on-site or virtual audits:

  • Review their access control configurations
  • Verify segregation of customer data
  • Test their incident response procedures with a tabletop exercise
  • Confirm backup and disaster recovery processes

Step 3: Automate Monitoring Where Possible

Manual oversight doesn't scale. Implement technical controls that alert you to Business Associate activity:

API and system access: If your Business Associate connects via API, enable logging at your end. Most EHR and data platforms support audit logs showing:

  • Which Business Associate accounts accessed PHI
  • What records they viewed or modified
  • When access occurred
  • Whether access was authorized under your BAA scope

Set up alerts for unusual patterns: access outside business hours, bulk downloads, access to records unrelated to the Business Associate's function.

Subcontractor disclosure: Require Business Associates to notify you within 5 business days when they engage a subcontractor who will access PHI. Your BAA should mandate this, but enforce it with a tracking system. Each subcontractor creates another layer of agency liability.

Step 4: Document Your Due Diligence

The Common Agency Provision makes you liable for violations you knew about and failed to address. Your defense is a documented compliance program.

Maintain a compliance file for each Business Associate containing:

  • Signed BAA with date
  • Security documentation (certs, SOC reports, attestations)
  • Audit reports and findings
  • Correspondence regarding compliance issues
  • Remediation plans for identified gaps
  • Termination criteria if compliance isn't achieved

If OCR investigates a breach involving your Business Associate, this file demonstrates you met your oversight obligations under 45 CFR § 160.402.

Validation: How to Verify It Works

Quarterly spot checks: Select three Business Associates at random each quarter. Request access logs for the past 90 days. Verify:

  • All access was authorized under the BAA scope
  • No PHI was accessed for unauthorized purposes
  • Logs are complete and tamper-evident

Annual BAA audit: Review every Business Associate Agreement against current HIPAA requirements. The HIPAA Omnibus Rule updated BAA requirements in 2013; many organizations still operate under pre-Omnibus agreements. Your BAA must address:

  • Subcontractor requirements
  • Breach notification timelines
  • Access, amendment, and accounting of disclosures
  • Return or destruction of PHI at contract termination

Incident response test: Run a tabletop exercise simulating a Business Associate breach. Can your team:

  • Identify which Business Associate was involved?
  • Locate the current BAA and contact information?
  • Determine whether the breach meets the Breach Notification Rule threshold?
  • Execute notification within the required timelines?

If you can't complete these steps in under 2 hours, your oversight program has gaps.

Maintenance and Ongoing Tasks

Monthly:

  • Review new vendor requests and flag any that will access PHI
  • Update your Business Associate inventory with new relationships
  • Check for BAA expirations (many auto-renew, but security requirements should be reviewed annually)

Quarterly:

  • Verify compliance documentation from high-risk Business Associates
  • Review access logs and investigate anomalies
  • Update risk tiers based on recent security incidents or vendor changes

Annually:

  • Conduct full Business Associate risk assessment
  • Update BAA templates to reflect regulatory changes
  • Provide Business Associate compliance training to procurement and IT teams
  • Test incident response procedures with key vendors

When a Business Associate fails to comply: Document the issue, issue a written notice requiring remediation within 30 days, and escalate to legal if they don't respond. The Common Agency Provision creates liability when you know about violations and don't act. Your options are: get them compliant or terminate the relationship.

The Common Agency Provision isn't theoretical. It's the mechanism OCR uses to hold you accountable for every vendor, contractor, and agent who touches PHI on your behalf. A compliance program that stops at signing contracts leaves you exposed. Build systems that verify, monitor, and enforce Business Associate obligations continuously.

You Might Also Like