FAQ

HIPAA Compliance FAQ for Covered Entities and Business Associates

Answers to common HIPAA questions about risk assessments, BAAs, written policies, staff training, and incident reporting — for both covered entities and business associates.

Common HIPAA Questions from Healthcare Practices and Their Vendors

Whether you run a small clinic, dental office, behavioral health practice, or a company that handles protected health information on behalf of a healthcare provider, the same HIPAA regulations apply. The questions below address the areas where covered entities and business associates most often have gaps: Security Risk Assessments, written policies and procedures, workforce training, Business Associate Agreements, and incident reporting.

Who is this page for? Covered entities include healthcare providers, health plans, and healthcare clearinghouses. Business associates are companies or individuals that create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity — such as IT vendors, billing services, cloud storage providers, and shredding companies.

HIPAA Compliance Questions and Answers

For Covered Entities
One Guy Consulting offers full-scope HIPAA help for small practices and business associates, including a Security Risk Assessment, gap analysis and remediation plans, custom policies and procedures, staff training with tracking, site and IT audits, vendor and BAA management, incident handling, and audit-readiness support. Everything is included in one flat annual rate with no per-user fees.
If your clinic has no HIPAA risk assessment or written policies yet, start with a Security Risk Analysis now: identify where PHI is stored and transmitted, list your vendors and devices, document the main risks, then put the required policies and procedures in writing and assign someone responsible for security. The Security Risk Analysis is required under 45 CFR §164.308(a)(1)(ii)(A), and written policies are required under §164.316(a). These two steps form the foundation of every HIPAA compliance program.
A Security Risk Assessment (SRA) is a documented evaluation of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI) held by your organization. It is required under 45 CFR §164.308(a)(1)(ii)(A) for every covered entity and business associate. The assessment must identify where ePHI is created, received, maintained, or transmitted, evaluate current security measures, determine the likelihood and impact of potential threats, and assign risk levels to each identified vulnerability. It is not a one-time task — it should be reviewed and updated regularly or whenever significant changes occur in your environment.
Yes. The HIPAA Security Rule at 45 CFR §164.308(a)(5)(i) requires covered entities and business associates to implement a security awareness and training program for all workforce members, including management. The Privacy Rule at §164.530(b) separately requires training on the organization's privacy policies and procedures. Training must be provided to each new workforce member within a reasonable time after joining, and again whenever policies or procedures change in a way that affects their duties. Organizations should document all training sessions and retain records for at least six years per §164.530(j).
Under 45 CFR §164.502(e), a covered entity may not disclose protected health information to a business associate or allow a business associate to create, receive, maintain, or transmit PHI on its behalf unless there is a written Business Associate Agreement (BAA) in place. Operating without BAAs for vendors that handle PHI is a compliance gap that has been cited in OCR enforcement actions. If a breach occurs through an uncontracted vendor, the covered entity may face additional scrutiny for failing to have the required agreement. The BAA must specify the permitted uses and disclosures of PHI, require the business associate to implement appropriate safeguards, and require breach notification.
For Business Associates
Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for compliance with many provisions of the HIPAA Security Rule and parts of the Privacy Rule. Under 45 CFR §164.502(e) and §164.308(b), business associates must implement administrative, physical, and technical safeguards to protect ePHI, conduct their own Security Risk Assessment under §164.308(a)(1)(ii)(A), develop and maintain written policies and procedures per §164.316(a), train their workforce per §164.308(a)(5)(i), report security incidents and breaches to the covered entity per §164.314(a)(2)(i)(C), and enter into BAAs with any subcontractors that access PHI. Business associates face the same civil and criminal penalties as covered entities for HIPAA violations.
Yes. Under 45 CFR §164.308(a)(1), every business associate must conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI it holds. This is the same requirement that applies to covered entities. A business associate cannot rely on the covered entity's risk assessment to satisfy this obligation — the assessment must evaluate the business associate's own systems, workflows, workforce, and physical environment. It should be reviewed and updated when the business associate's operations, technology, or threat landscape changes.
Under 45 CFR §164.410, a business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and no later than 60 days after discovery. The notification must include the identities of individuals affected (if known), a description of the types of information involved, a description of what happened and what the business associate is doing in response, and any steps individuals should take to protect themselves. Separately, under §164.404, the covered entity is then responsible for notifying the affected individuals. Business associates should have a written incident response plan, train their workforce to recognize and report potential breaches, and maintain logs of all security incidents whether or not they rise to the level of a reportable breach.

Learn More About HIPAA Compliance

Have a HIPAA Question We Did Not Cover?

Book a free 30-minute intro call. We will review your situation and point you in the right direction — whether you are a covered entity or a business associate.

Book Your Free HIPAA Compliance Review