In 2013, under the authority granted by the HITECH Act, OCR issued a final rule that, among other things, identified provisions of the HIPAA Rules that apply directly to business associates and for which business associates are directly liable.
“As part of the department’s effort to fully protect patients’ health information and their rights under HIPAA, OCR has issued this important new fact sheet clearly explaining a business associate’s liability,” OCR Director Roger Severino said in a statement.
There are 10 provisions for which OCR has the authority to take enforcement action against a business associate. The provisions are detailed on the fact sheet, linked below.
VIEW FACT SHEET
In 2013, under the authority granted by the HITECH Act, OCR issued a final rule that, among other things, identified provisions of the HIPAA Rules that apply directly to business associates and for which business associates are directly liable.
“As part of the department’s effort to fully protect patients’ health information and their rights under HIPAA, OCR has issued this important new fact sheet clearly explaining a business associate’s liability,” OCR Director Roger Severino said in a statement.
There are 10 provisions for which OCR has the authority to take enforcement action against a business associate. The provisions are detailed on the fact sheet, linked below.
VIEW FACT SHEET