Every covered entity that uses business associates is required to obtain assurances that their business associates treat patient data the way you and HHS require them to.
How do I monitor my business associates' HIPAA compliance?
Monitor business associate HIPAA compliance by auditing or requiring documented security procedures, prioritizing your highest risk associates first, and reevaluating everyone annually.
- Personally audit each business associate or require documented security procedures from them.
- Start with your highest risk business associates, then move to medium risk ones.
- Track each business associate's progress to confirm they maintain an approved compliance level.
- Reevaluate every business associate's plan and vulnerabilities every year.
- A signed BAA alone isn't enough; a breach still damages patient trust and your organization.
*This article was taken from our HIPAA Guide. For more information on this topic, download our free HIPAA Guide.
“Sharing patient data with a business associate can lead to a large data breach.”
Every covered entity that uses business associates is required to obtain assurances that their business associates treat patient data the way you and HHS require them to. Whether you choose to personally audit each business associate or require documented data security procedures, take the initiative to secure the future of your organization and the safety of patient data.
As your business associates progress towards compliance, track their success to ensure an approved level of compliance. As the riskiest business associates reach compliance, begin to reach out toward medium-risk business associates to start this process with them. Don’t forget to reevaluate every business associate’s plan and associated vulnerabilities each year.
Remember, sharing data with a business associate can lead to a large breach of your patient data. However, most people I speak with tell me, “I have BAAs in place, so I don’t need to worry. Even if they do end up getting breached, we have airtight agreements removing our liability.”
It’s not just about who’s the responsible party. When patient data is lost or stolen, your patients (and your organization) could experience serious repercussions. Losing community trust can be devastating for your organization.




