Business Associate Liability: What Vendors Owe You
Your billing vendor calls on a Tuesday. Ransomware hit their claims-scrubbing server eleven days ago, and roughly 4,200 of your patients are in the affected data set. Your first question should not be "are we in trouble?" It should be "what does our agreement say the notification deadline is, and did they blow it?" Under HIPAA, business associate liability is direct — the Office for Civil Rights can penalize that vendor on its own — but that fact does not remove your practice from the equation. It just means two organizations are now on the hook for different pieces of the same incident.
This article maps those pieces: which obligations your vendor owes HHS directly, which obligations stay with you no matter what the contract says, and what documentation an OCR investigator will ask for if the incident lands on the breach portal.
Direct Business Associate Liability Started in 2013, Not 1996
Before the HITECH Act and the 2013 Omnibus Rule, a business associate's only exposure was contractual. If your transcription service leaked records, OCR came after you, and you sued the vendor for breach of contract. That structure is gone.
Today a business associate is directly liable to HHS for a defined set of HIPAA provisions and can be assessed civil money penalties without any covered entity involvement. OCR reached its first settlement directly with a business associate in 2016 — a company providing management services to nursing facilities, resolved for $650,000 after a stolen unencrypted iPhone. Since then, business associates have appeared regularly in OCR's enforcement list, including large IT service organizations serving hospital systems.
The practical upshot for your practice: your vendor now has its own regulatory skin in the game, which gives you leverage in negotiation. It also means a vendor telling you "HIPAA doesn't really apply to us, we just host the data" is telling you something false and disqualifying.
The Ten Obligations Your Vendor Owes HHS Directly
Short answer for the person searching this at 4 p.m.: HHS lists ten categories where business associates face direct liability. A business associate can be penalized by OCR for:
- Failing to provide HHS with records and compliance reports, or refusing to cooperate with an investigation or compliance review.
- Retaliating against anyone who files a complaint, participates in an investigation, or objects to an unlawful practice.
- Failing to comply with the Security Rule — risk analysis, risk management, and the administrative, physical, and technical safeguards.
- Failing to notify the covered entity (or upstream business associate) of a breach of unsecured PHI.
- Impermissible uses and disclosures of protected health information.
- Failing to release electronic PHI to the covered entity, the individual, or the individual's designee when the BAA assigns that duty to the vendor.
- Failing to limit PHI to the minimum necessary for the purpose.
- Failing to provide an accounting of disclosures.
- Failing to execute business associate agreements with its own subcontractors that handle PHI.
- Failing to take reasonable steps to fix a subcontractor's material breach of its agreement.
HHS publishes this list in its fact sheet on direct liability of business associates. Print it and attach it to your vendor review checklist.
What Your Vendor Is Not Directly Liable For
Equally important: business associates are not directly liable for failing to distribute a Notice of Privacy Practices, for failing to designate a privacy official, or for responding to individual requests for amendment or restriction. Those are yours. A patient who calls your vendor asking to amend a record has called the wrong organization, and your BAA should route that request back to you in writing.
Where Your Practice Stays on the Hook Regardless
Direct business associate liability is additive, not substitutive. Three failure modes keep your practice exposed.
1. No Agreement at All
Disclosing PHI to a business associate without a signed BAA in place is your violation, not the vendor's. OCR has settled multiple cases on exactly this fact pattern — including a Florida physician group that shared patient data with a billing company before any agreement existed, and a pediatric practice that used an offsite records storage company for years without paper. These settlements were not about a breach. They were about the missing contract.
If you are staring at a vendor list with gaps, close them before anything else. You can generate a signature-ready business associate agreement through a six-step wizard and export it as PDF or DOCX — one-time purchase, no subscription — which is faster than routing a redline through counsel for a low-risk vendor and considerably faster than explaining the gap to an investigator.
2. Agency Liability
Under 45 CFR 160.402(c), a covered entity is liable for the acts of its business associate when that business associate acts as its agent under federal common law. The test is control: if you direct how the vendor performs the work — not just what deliverable you want — the vendor may be your agent, and its violation becomes your violation.
A staffing agency whose coders sit in your office, use your systems, and follow your supervisor's instructions looks like an agent. A cloud archive vendor operating on its own terms of service and its own schedule generally does not. The BAA language matters here. Contracts that reserve broad instruction rights to the covered entity increase agency risk.
3. Willful Blindness
If you know of a pattern of activity or practice that constitutes a material breach of the BAA and you do nothing, you have violated the rule. "We assumed they were handling it" is not a defense. Documented follow-up — an email, a corrective action request, a termination notice — is.
The 60-Day Clock and Who Starts It
This is where most practices lose time they cannot recover.
Under 45 CFR 164.410, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days from discovery. Discovery means the first day the breach is known, or reasonably should have been known, to any employee or agent of the business associate other than the person who committed it.
Under 45 CFR 164.404, you must notify affected individuals no later than 60 calendar days from your discovery. If your vendor is your agent, their discovery date is imputed to you — the clock started when they knew, not when they called you. If they are an independent contractor, your clock starts when they notify you.
That distinction is the single most valuable thing to negotiate into a BAA. Set a hard vendor notification deadline of 5 to 10 business days from discovery, require notification of security incidents even before breach determination, and require the vendor to supply the individual-level data set, the risk assessment under 164.402, and forensic findings at their cost. A 60-day pass-through leaves you zero days to build a mailing.
Worked Example
Vendor's SOC analyst sees anomalous exfiltration on March 3. Vendor completes forensics March 28 and calls you April 24 — day 52, technically compliant. You now have 8 days to validate the patient list, draft notices, stand up a call center, and, because the count exceeds 500, prepare a media notice and a same-timeline report to HHS. With a 10-day contractual clock, that call happens March 17 and you have six weeks.
The Vendor File an OCR Investigator Will Ask For
When OCR opens an investigation, the data request is predictable. Build the file now, per vendor:
- Executed BAA with signature dates, plus any amendments and the current version in force.
- Classification note: business associate, conduit, or neither — with the one-paragraph reasoning. Your janitorial service and your ISP are not business associates. Your billing company, transcription service, cloud EHR host, shredding company, IT MSP, answering service, and outside counsel handling claims are.
- Due diligence evidence: security questionnaire responses, SOC 2 Type II report or independent assessment, penetration test summary, encryption attestation, subcontractor list.
- Termination and return/destruction records for ended relationships, including certificates of destruction.
- Incident correspondence: every security incident report the vendor sent, with dates.
- Review cadence: dated evidence of annual re-review, signed by whoever owns it.
Assign the owner explicitly. In a practice under 20 staff, this is usually the privacy officer or practice administrator. Above that, split it: contracting owns execution, the security officer owns due diligence, and the privacy officer owns the register. Nobody's job title should be "whoever remembers."
Your own Security Rule risk analysis should treat each business associate as an asset-adjacent risk, not a footnote. NIST SP 800-66 Revision 2 walks through how third-party relationships fold into risk assessment, and it is the most usable free resource for a practice without a security team. If assembling the underlying risk analysis and policy set is the bottleneck, automating the compliance document set gets you to a reviewable draft faster than starting from a blank template.
Liability Runs Downhill to Subcontractors
Your billing vendor's offshore data-entry subcontractor is a business associate too. The chain of agreements must be unbroken from you to the last party touching PHI, and each link is independently liable to HHS.
You do not sign agreements with subcontractors — your vendor does. But you should require, in writing, a current list of subcontractors with PHI access, 30 days' advance notice before adding a new one, and flow-down of terms at least as protective as yours. Ask for the list annually. Vendors that cannot produce one within a week usually cannot produce it at all.
What to Do in the Next 30 Days
- Days 1–5. Pull every vendor from accounts payable for the last 24 months. Mark each: PHI access yes/no.
- Days 6–12. Match each "yes" against your signed agreement folder. Gaps go on a remediation list with names and dates.
- Days 13–20. Execute missing BAAs. Do not let PHI keep flowing while you wait for a redline.
- Days 21–25. Audit breach notification clauses. Anything at 60 days goes into the renewal queue with a 10-day replacement.
- Days 26–30. Request current security documentation from your top five vendors by PHI volume. File the responses — and file the non-responses.
Check the HHS breach portal against your vendor names while you are at it. If a vendor you use appears there, the follow-up email you send today is evidence that you were not willfully blind.
Business associate liability being direct is good news for your practice — it means your vendors have a regulator, not just a contract, holding them accountable. It becomes bad news only when you treat it as permission to stop looking. If your first gap is a missing agreement, build and export the BAA this week and get it signed before the next batch of PHI leaves your building.