HIPAA Business Associate Agreements: Deadline Approaching

HIPAA Business Associate Agreements: Deadline Approaching

If they have not already done so, the deadline for covered entities and business associates to update their HIPAA business associate agreements to comply with Omnibus Rule requirements is September 22, 2014.

BAA Requirements. HIPAA requires that covered entities and business associates execute contracts (called “business associate agreements” or “BAAs”) which require that business associates comply with certain portions of the HIPAA Privacy, Security and Breach Notification Rules. (45 CFR 164.314(a)), 164.502(e), and 164.504(e)). The HIPAA Omnibus Rule changed BAA requirements. Under the Omnibus Rule, covered entities and business associates must modify their BAAs to require business associates to:

  • comply with the HIPAA Security Rule;
  • execute BAAs with any of their subcontractors that create, receive, maintain, or transmit protected health information on behalf of the business associate;
  • report security incidents, including breaches of unsecured health information; and
  • comply with the Privacy Rule requirements applicable to covered entities if and to the extent the business associate is to carry out a covered entity’s obligations under the Privacy Rule.

(45 CFR 164.314(a) and 164.502(e)). For a checklist of all required BAA terms, click here. The Office for Civil Rights (“OCR”) has also published sample BAA provisions, although the OCR sample may not include additional terms that covered entities or business associates may want to include in their BAAs.

Deadline. Covered entities and business associates were generally required to comply with Omnibus Rule requirements by September 23, 2013; however, the Omnibus Rule extended the deadline for BAA compliance to September 22, 2014 if (i) existing BAAs complied with HIPAA requirements as they existed as of January 25, 2013, and (ii) the BAA was not otherwise renewed or modified between March 26, 2013 and September 22, 2014. (45 CFR 164.532(e)). Thus, all BAAs must comply with the Omnibus Rule requirements by September 22, 2014.

For more information, contact:
Kim Stanger
Holland & Hart LLP
Email: kcstanger@hollandhart.com
Phone: 208-383-3913


Unless you are a current client of Holland & Hart LLP, please do not send any confidential information by email. If you are not a current client and send an email to an individual at Holland & Hart LLP, you acknowledge that we have no obligation to maintain the confidentiality of any information you submit to us, unless we have already agreed to represent you or we later agree to do so. Thus, we may represent a party adverse to you, even if the information you submit to us could be used against you in a matter, and even if you submitted it in a good faith effort to retain us.