Skip to main content
Category: Uses and Disclosures

Satisfactory Assurances

Simply put

Satisfactory assurances are documented commitments a covered entity must obtain before it uses or discloses protected health information (PHI) in certain situations, confirming that the recipient will handle the information appropriately. For example, when responding to a subpoena or discovery request, a covered entity generally must receive satisfactory assurances that reasonable steps were taken to notify the patient or to obtain a protective order. Similarly, before a business associate handles PHI on the covered entity's behalf, the covered entity must obtain satisfactory assurances that the associate will safeguard the information.

Formal definition

Under the HIPAA Privacy Rule, 'satisfactory assurances' is a term of art referring to documented commitments a covered entity must obtain before certain permitted uses or disclosures of PHI. In the business associate context, the satisfactory assurances that a business associate will appropriately safeguard PHI must generally be documented through a written contract or other written agreement (commonly a business associate agreement). In the litigation context, a covered entity that is not a party to the litigation may disclose PHI in response to a subpoena or discovery request only upon receiving satisfactory assurances that reasonable efforts were made either to notify the individual of the request or to secure a qualified protective order. This term applies to PHI in all forms under the Privacy Rule and is distinct from the Security Rule's ePHI-specific safeguard requirements. Note that the specific procedural conditions constituting satisfactory assurances differ by context; practitioners should confirm the applicable requirements against the current regulatory text, and note that state law may impose additional or stricter notification requirements.

Why it matters

Satisfactory assurances function as a gatekeeping requirement under the HIPAA Privacy Rule, ensuring that PHI is not released or handed off without documented protections in place. In the business associate context, these assurances are the mechanism by which a covered entity extends privacy and safeguarding obligations to the vendors and partners that handle PHI on its behalf. Without obtaining and documenting them, a covered entity may be disclosing PHI in a manner the Privacy Rule does not permit, exposing itself to enforcement action by HHS OCR.

The requirement is especially significant in litigation, where a covered entity that is not a party to a lawsuit may feel pressure to comply quickly with a subpoena or discovery request. The Privacy Rule generally prohibits such disclosures unless the covered entity first receives satisfactory assurances that reasonable efforts were made either to notify the individual whose information is sought or to secure a qualified protective order. This protects patients from having their health information swept into legal proceedings without notice or safeguards.

Because the specific conditions that constitute satisfactory assurances differ by context, and because state law may impose additional or stricter notification requirements, this term is a frequent source of confusion and compliance risk. Treating a subpoena as automatically sufficient authority to disclose, or engaging a vendor without a written agreement, are common missteps that the satisfactory assurances requirement is designed to prevent.

Who it's relevant to

Privacy Officers
Privacy officers are responsible for ensuring that satisfactory assurances are obtained and documented before PHI is disclosed in the situations the Privacy Rule requires them, including business associate arrangements and responses to subpoenas or discovery requests. They typically develop policies and internal tools to verify that the appropriate assurances exist before any disclosure proceeds.
Legal and Compliance Teams
Legal and compliance staff evaluate subpoenas and discovery requests to determine whether satisfactory assurances (such as evidence that the individual was notified or that a qualified protective order was sought) have been provided before responding. They should also confirm whether state law imposes additional or stricter notification requirements beyond HIPAA.
Vendor and Contract Managers
Those who onboard and manage vendors handling PHI must ensure that satisfactory assurances are captured through a written contract or other written agreement, typically a business associate agreement, before the business associate begins handling PHI on the covered entity's behalf.
Business Associates
Business associates provide satisfactory assurances by entering into a written agreement committing to appropriately safeguard PHI. Understanding this requirement helps them recognize the documented obligations they take on when handling PHI on behalf of a covered entity.

Inside Satisfactory Assurances

Written Contract or Arrangement Requirement
Satisfactory assurances must generally be documented in a written contract or other written arrangement, most commonly a business associate agreement (BAA), between a covered entity and its business associate, or between a business associate and its subcontractor.
Permitted Uses and Disclosures
The arrangement typically specifies the permitted and required uses and disclosures of protected health information (PHI) by the business associate, limiting how the PHI may be handled consistent with the Privacy Rule.
Safeguard Obligations
The business associate agrees to implement appropriate safeguards to protect PHI, including, for electronic PHI (ePHI), the administrative, physical, and technical safeguards addressed by the Security Rule.
Flow-Down to Subcontractors
Satisfactory assurances generally must flow through to subcontractors that create, receive, maintain, or transmit PHI on behalf of a business associate, so that comparable obligations attach down the chain of relationships.
Reporting and Breach Notification Provisions
The arrangement typically requires the business associate to report security incidents and breaches, or uses and disclosures not permitted by the agreement, to the covered entity, supporting obligations under the Breach Notification Rule.
Termination and Return/Destruction of PHI
Arrangements commonly address termination for material breach and the return or destruction of PHI at the end of the relationship where feasible.

Common questions

Answers to the questions practitioners most commonly ask about Satisfactory Assurances.

Does obtaining satisfactory assurances mean the covered entity is no longer responsible for how the business associate handles PHI?
No. Obtaining satisfactory assurances does not transfer or eliminate the covered entity's own compliance obligations. Satisfactory assurances are the covered entity's mechanism for permitting a business associate to create, receive, maintain, or transmit PHI on its behalf, but the covered entity generally remains accountable for its own conduct under the Privacy Rule and Security Rule. In addition, a covered entity may face liability where it knew of a pattern of activity or practice by the business associate that constituted a material breach of the agreement and failed to take reasonable steps to address it. Readers should verify the specific obligations and liability provisions against the current regulatory text.
Is a signed business associate agreement by itself enough to establish that satisfactory assurances have been met?
Not necessarily in a functional sense. A written contract or other arrangement is the required documentation vehicle for satisfactory assurances, and the agreement must contain the elements specified in the applicable rules. However, the assurance is that the business associate will appropriately safeguard the information; a document that exists on paper but does not reflect or support actual safeguarding practices does not fulfill the underlying purpose. The written agreement is the required form the assurances take, not a substitute for the substantive protections the arrangement is meant to secure. Confirm the required contract elements against the current regulation.
How does a covered entity document satisfactory assurances in practice?
In most cases, satisfactory assurances are documented through a written contract or other written arrangement that meets the requirements specified in the applicable rules. When both parties are government entities, other permissible arrangements such as a memorandum of understanding may satisfy the requirement in certain circumstances. The documentation should be retained consistent with applicable recordkeeping requirements. Readers should verify the acceptable forms of documentation and retention periods against the current regulatory text.
What should a covered entity do if it learns a business associate has breached the terms of the arrangement?
Generally, if a covered entity becomes aware of a pattern of activity or practice by the business associate that constitutes a material breach or violation of the arrangement, it must take reasonable steps to cure the breach or end the violation. If such steps are unsuccessful, terminating the arrangement is the expected course, and if termination is not feasible, reporting the problem to the appropriate authority may be required. The specific steps and their sequence should be confirmed against the current regulatory text.
Do satisfactory assurances need to flow down to subcontractors that handle PHI?
Yes. A business associate that engages a subcontractor to create, receive, maintain, or transmit PHI on its behalf is generally required to obtain satisfactory assurances from that subcontractor, typically through a written agreement containing the applicable elements. This flow-down is how obligations attach through the chain of defined relationships rather than to every vendor generally. The precise requirements applicable to subcontractor arrangements should be verified against the current regulation.
How do satisfactory assurances relate to a HITRUST CSF certification held by a business associate?
They are distinct. Satisfactory assurances are a HIPAA construct documented through the required written agreement between the parties. A business associate's HITRUST CSF certification is issued by a private organization and may serve as one input a covered entity considers when evaluating a business associate, but it is not a legal substitute for obtaining satisfactory assurances and does not by itself establish HIPAA compliance. The written agreement meeting the applicable requirements remains necessary. Confirm any reliance placed on third-party certifications against current guidance and the current HITRUST CSF version.

Common misconceptions

Obtaining satisfactory assurances makes the covered entity responsible only for its own conduct and fully insulates it from any liability for the business associate's actions.
Satisfactory assurances are a required mechanism to establish and document obligations, but they do not by themselves guarantee compliance or prevent all breaches. Liability considerations depend on the facts, and a covered entity that knows of a pattern of activity or practice constituting a material breach by a business associate generally has obligations to act. Readers should verify specific obligations against the current regulatory text.
A signed business associate agreement means the vendor is HIPAA compliant and no further oversight is needed.
A written agreement documents commitments but does not establish that safeguards are actually in place or effective. It is not a certification of compliance. Ongoing due diligence is generally advisable, and a vendor's HITRUST CSF certification, while informative, is a private-sector assurance that does not by itself establish HIPAA compliance.
Satisfactory assurances only concern electronic PHI and the Security Rule.
The concept spans the Privacy Rule, which covers PHI in all forms including oral and paper, as well as the Security Rule for ePHI. The scope of the assurances should reflect the forms of PHI involved, not just electronic data.

Best practices

Execute a written business associate agreement before allowing a business associate or subcontractor to create, receive, maintain, or transmit PHI, and ensure comparable obligations flow down to subcontractors.
Tailor the permitted uses and disclosures, safeguard obligations, and reporting requirements in each arrangement to the actual PHI involved, including whether it is electronic, oral, or paper.
Do not rely on the signed agreement alone; perform ongoing due diligence and periodic review of the business associate's safeguards and practices rather than treating the BAA as proof of compliance.
Include clear breach and security incident reporting provisions and defined timelines so obligations under the Breach Notification Rule can be met, verifying current requirements against the applicable regulatory text.
Address termination for material breach and the return or destruction of PHI upon termination where feasible.
Treat any third-party assurance such as a HITRUST CSF certification as supplemental information, not as a substitute for the BAA or for independent verification of HIPAA obligations, and check whether state law or HITECH imposes additional requirements.