A surgery center runs on a schedule that cannot slip. Patients arrive fasting, surgeons arrive with a block of time, anesthesia arrives with a plan, and the chart has to be complete before the first incision. Then, some Tuesday, the practice management system will not open and there is a ransom note on the screen. The cases still on the board are the least of it.
That scenario is not hypothetical. OCR (the HHS Office for Civil Rights) settled a HIPAA ransomware investigation with Syracuse ASC on July 23, 2025. Thirteen years earlier, on April 13, 2012, HHS settled with Phoenix Cardiac Surgery for lack of HIPAA safeguards. Surgical practices have been on the enforcement list for as long as there has been a list.
This guide covers why HIPAA applies to an ASC, what P.H.I. (Protected Health Information) looks like in a surgery center, the violations that recur in this setting, how to build the program, which vendors need a B.A.A. (Business Associate Agreement), and what the proposed Security Rule update would change.
HIPAA Compliance for Ambulatory Surgery Centers: Why the Rules Apply
45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." An ASC that bills a payer electronically, checks eligibility online, or receives electronic prior authorizations meets the test, and there is no exception for size or ownership. A physician-owned single-specialty center is as covered as a hospital-affiliated one.
Two things make the ASC setting different from a medical office. First, the chart is dense by federal design. The Medicare condition for coverage at 42 CFR 416.47(b) requires every ASC medical record to include patient identification, "significant medical history and results of physical examination," pre-operative diagnostic studies, "findings and techniques of the operation, including a pathologist's report on all tissues removed during surgery," allergies and abnormal drug reactions, "entries related to anesthesia administration," documented informed consent, and a discharge diagnosis. That list is the minimum. Every item on it is PHI.
Second, several covered entities share that chart. The operating surgeon's practice is one covered entity. The anesthesia group is another. The ASC itself is a third. 160.103 defines an organized health care arrangement to include "a clinically integrated care setting in which individuals typically receive health care from more than one health care provider," which describes a surgery center exactly. That designation lets the participants issue a joint Notice of Privacy Practices under 164.520(d) and share PHI with each other for the arrangement's treatment, payment, and health care operations. It does not merge their compliance obligations; each entity still owns its own risk analysis, policies, and workforce training.
What PHI Looks Like in a Surgery Center
- The pre-admission packet. History and physical from the surgeon, labs, EKG, imaging, medication list, and the pre-op phone screening notes, often collected by fax and phone days before the case.
- The operative record. Consent forms, the anesthesia record, intra-op nursing notes, implant logs with device serial numbers, specimen labels, and the op note.
- The schedule. The daily case board, which in many centers is a whiteboard in a corridor listing patient names, procedures, and surgeons.
- Pathology and lab traffic. Specimens and requisitions to outside labs, results coming back by fax or portal.
- Escort and family information. The name and phone number of the person driving the patient home, and whatever the recovery nurse tells them.
- Post-op follow-up calls. Voicemails, call logs, and patient satisfaction surveys.
- Billing. Facility claims with procedure codes, implant charges, and the anesthesia group's separate claim.
Common HIPAA Violations in ASCs
Ransomware with no downtime plan. The Security Rule treats availability as a security property: 164.306(a)(1) requires covered entities to "ensure the confidentiality, integrity, and availability of all electronic protected health information." A center that cannot pull a chart, verify an implant, or document anesthesia because its systems are encrypted by an attacker is out of compliance and out of business for the day. 164.308(a)(7) requires a contingency plan whose data backup, disaster recovery, and emergency mode operation components are all Required. The first 72 hours guide covers the response.
The case board in the hallway. 164.530(c)(1) requires "appropriate administrative, technical, and physical safeguards to protect the privacy of protected health information." A whiteboard with full names and procedures, visible from the family waiting area, fails that standard. Initials and case numbers on the public-facing board, full names only on the OR-side screen, is the usual fix.
Waiting-room updates. 164.510(b) permits disclosure to a family member or other person involved in the patient's care of PHI "directly relevant to such person's involvement," when the patient has had a chance to agree or object. Telling the driver that the patient is in recovery and can leave in an hour fits. Reading the pathology result to the driver does not. Train recovery staff on where the line is.
Surgeons' offices with a login to the ASC system. Convenient and common, and only compliant if 164.308(a)(4) access authorization is documented, each user has a unique ID under 164.312(a)(2)(i), and the ASC terminates access when a surgeon leaves the medical staff, per 164.308(a)(3)(ii)(C).
Device representatives in the OR. A rep observing a case sees PHI. That is a disclosure question for the center's consent process and policies rather than a BAA question, unless the rep's company also receives records. Have counsel review the arrangement, and put it in writing.
Pre-op calls to the wrong number, and detailed voicemails. The pre-op call script should confirm identity before discussing fasting instructions and the procedure, and a voicemail should carry the callback number and nothing clinical.
Building the Program
Designate the officials for the ASC itself. 164.308(a)(2) requires a security official and 164.530(a)(1) requires a privacy official. The medical director is not automatically either. In a small center the administrator or the director of nursing typically holds both, in writing.
Run the risk analysis on the center's own systems. 164.308(a)(1)(ii)(A) requires an "accurate and thorough" assessment of risks to ePHI (electronic P.H.I.). For an ASC, the list includes the practice management and EHR system, the anesthesia record application, the implant and inventory system, the pathology portal, the fax server, the phone system's voicemail, and the backup. The risk assessment guide covers the method.
Write the downtime procedure and test it. Paper anesthesia records, paper consents, a printed case list each morning, and a rule for how downtime documents get scanned back in. 164.308(a)(7)(ii)(D) makes testing Addressable, which means a center that skips the annual tabletop must document why. The contingency plan guide covers all five components.
Settle the notice question. Either the ASC issues its own Notice of Privacy Practices and each surgeon's office issues its own, or the participants adopt a joint notice under 164.520(d) that "describes with reasonable specificity the covered entities" it covers. Whichever route, the ASC as a direct treatment provider must give the notice no later than the first service delivery and make a good faith effort to get a signed acknowledgment, per 164.520(c)(2). The NPP guide lists the required content.
Apply minimum necessary to the shared chart. 164.502(b) requires reasonable efforts to limit PHI "to the minimum necessary to accomplish the intended purpose." That standard does not apply to disclosures to a provider for treatment, so the surgeon and the anesthesiologist see the full chart. It does apply to the billing company, the implant vendor's invoice, and the survey vendor.
Train for the floor. 164.530(b)(1) requires training for "all members of its workforce," and 164.308(a)(5) requires security awareness training for the workforce "including management." Recovery nurses, schedulers, and the front desk need scenarios, not slides: the driver who asks too much, the surgeon's office that asks for a different patient's records, the pre-op call that reaches the wrong person.
Vendor BAA Checklist for Surgery Centers
160.103 defines a business associate as a person who "creates, receives, maintains, or transmits" PHI on behalf of a covered entity, and separately lists "accreditation" among the services that make a vendor a business associate when PHI is disclosed to it. 164.308(b) requires a written contract before the vendor touches ePHI. The same definition excludes disclosures to a health care provider for treatment, which is why the pathology lab and the anesthesia group are not business associates.
| Vendor or partner | BAA required? | Note |
|---|---|---|
| Practice management, EHR, and anesthesia record software | Yes | Hosted, or on-premises with remote support |
| Billing and coding company | Yes | Billing is named in the definition |
| Accreditation organization | Yes | Accreditation is named in the definition when records are disclosed for the survey |
| Transcription and dictation | Yes | Op notes are PHI in draft form too |
| Patient satisfaction survey vendor | Yes | Receives names, dates of service, and procedures |
| Collection agency | Yes | Collection activities are payment activities under 164.501 |
| IT managed service provider and cloud backup | Yes | Administrative access is access |
| Shredding and offsite record storage | Yes | They maintain and destroy PHI for you |
| Answering service | Yes | Post-op messages are PHI |
| Pathology lab | No | A health care provider receiving PHI for treatment |
| Operating surgeons and anesthesia group | No | Separate covered entities in the same arrangement; treatment disclosures |
| Medical waste hauler, sterile supply | No | No PHI changes hands |
Keep one register with signature dates and renewal dates. The BAA guide lists the terms 164.504(e)(2) requires.
The Proposed Security Rule Update
HHS published a proposed Security Rule overhaul in January 2025. It is not final, OCR is not enforcing it, and none of it is required today. As proposed, it would require encryption of ePHI at rest and in transit, multifactor authentication, a written asset inventory and network map, automated vulnerability scanning at least every six months, penetration testing at least every 12 months, and procedures to restore critical systems within 72 hours. The 72-hour restoration idea is the one that should get an ASC administrator's attention, because it is roughly the standard a surgery center already has to meet to keep its schedule. Planning for it now, under the current contingency plan requirement, is the practical move. The Security Rule delay article tracks the timeline.
---
FAQ
Is an ambulatory surgery center a covered entity under HIPAA?
Yes, if it transmits any health information electronically in connection with a standard transaction such as a facility claim or an eligibility check. 45 CFR 160.103 sets the test, and ownership structure and size do not change the answer.
Do the surgeons and the ASC each need their own Notice of Privacy Practices?
Either each covered entity issues its own notice, or the ASC, the surgeons, and the anesthesia group, as an organized health care arrangement, adopt a joint notice under 164.520(d). The joint notice must name the entities it covers and state that they share PHI for the arrangement's treatment, payment, and operations.
Does the anesthesia group need a business associate agreement with the ASC?
No. The anesthesia group is a health care provider receiving PHI for treatment, which the business associate definition in 160.103 excludes. It is a separate covered entity with its own HIPAA obligations.
Can the recovery nurse tell the patient's driver how the surgery went?
164.510(b) permits disclosure to a person involved in the patient's care of the PHI directly relevant to that involvement, when the patient has had an opportunity to agree or object. Discharge logistics fit that rule. Clinical findings should wait for the patient, unless the patient has agreed otherwise.
Is the 72-hour system restoration requirement already in force?
No. It is part of the Security Rule update HHS proposed in January 2025, which has not been finalized. The rule in force today is 164.308(a)(7), which requires a contingency plan with a data backup plan, a disaster recovery plan, and an emergency mode operation plan, without a stated restoration deadline.
Conclusion
An ASC's HIPAA program has to account for every surgeon, anesthesia provider, and vendor who touches the chart, and it has to survive the day the servers are locked. One Guy Consulting's Full-Scope plan covers the risk analysis, the policies, the notice and B.A.A. register, and workforce training, with consulting time to test the downtime plan. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: covered entity, business associate, organized health care arrangement)
- 42 CFR 416.47 (ASC condition for coverage: medical records)
- 45 CFR 164.308 (administrative safeguards)
- 45 CFR 164.312 (technical safeguards)
- 45 CFR 164.502 (uses and disclosures: general rules, minimum necessary)
- 45 CFR 164.510 (disclosures to persons involved in care)
- 45 CFR 164.520 (notice of privacy practices, joint notice)
- 45 CFR 164.530 (administrative requirements: safeguards, training)
- HHS OCR resolution agreements and civil money penalties
- HIPAA Security Rule NPRM, 90 FR 898 (January 6, 2025)
Related Reading