HIPAA Compliance FAQ for Covered Entities and Business Associates
Answers to common HIPAA questions about risk assessments, BAAs, written policies, staff training, and incident reporting — for both covered entities and business associates.
Common HIPAA Questions from Healthcare Practices and Their Vendors
Whether you run a small clinic, dental office, behavioral health practice, or a company that handles protected health information on behalf of a healthcare provider, the same HIPAA regulations apply. The questions below address the areas where covered entities and business associates most often have gaps: Security Risk Assessments, written policies and procedures, workforce training, Business Associate Agreements, and incident reporting.
Who is this page for? Covered entities include healthcare providers, health plans, and healthcare clearinghouses. Business associates are companies or individuals that create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity — such as IT vendors, billing services, cloud storage providers, and shredding companies.
HIPAA Compliance Questions and Answers
Learn More About HIPAA Compliance
Have a HIPAA Question We Did Not Cover?
Book a free 30-minute intro call. We will review your situation and point you in the right direction — whether you are a covered entity or a business associate.
Book Your Free HIPAA Compliance Review