Under HIPAA, a billing company processes claims for several clinics — is it a business associate, and what must its business associate contracts contain?
answer
- on behalf of a covered entity
- billing is a listed function
- subcontractors are BAs too
- assurances flow one link at a time
- 164.314(a)(2)(i)
basics
~20 sYes. Under 45 CFR 160.103 a firm handling PHI on a covered entity's behalf for billing or claims processing is a business associate. Each clinic needs a written contract under 164.308(b) and 164.314(a), and the billing company needs one with each subcontractor.
solid answer
~40 sUnder the definition in `45 CFR 160.103`, a **business associate** creates, receives, maintains or transmits PHI **on behalf of** a covered entity, other than as its workforce, for a regulated function - and the text lists **claims processing** and **billing**. So the billing company is a business associate of each clinic. Under `164.308(b)(1)` each clinic may let it handle ePHI only after obtaining **satisfactory assurances**, documented in a written contract (`164.308(b)(3)`). `164.314(a)(2)(i)` requires the contract to make the business associate comply with the Security Rule, bind its **subcontractors** through their own contracts, and **report security incidents**, including breaches of unsecured PHI under `164.410`. The clinics do not contract with the billing company's subcontractors; the billing company does. Business associates are also directly bound by the Security Rule (`164.302`).
go deeper
Recall the difference between a covered entity and a business associate, and that billing and claims processing are listed business associate functions.
Explain the three contract terms in 164.314(a)(2)(i) and how satisfactory assurances chain from covered entity to business associate to subcontractor.
Show how you would map every party that touches PHI, decide who owes a contract to whom, and set incident and breach reporting terms that fit the 164.410 clock.
Weigh how far to push security obligations down a vendor chain by contract versus relying on each business associate's own direct duties.
## Who is who under HIPAA HIPAA's Administrative Simplification rules apply to two kinds of party, both defined in **45 CFR 160.103**: - A **covered entity** is a health plan, a health care clearinghouse, or a health care provider who transmits health information electronically in connection with a covered transaction. The clinics are covered entities. - A **business associate** is a person who, on behalf of a covered entity and other than as a member of its workforce, creates, receives, maintains or transmits PHI for a regulated function or activity. The definition names examples including **claims processing or administration, data analysis, utilization review, quality assurance, billing, benefit management, practice management and repricing**. It also covers legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation and financial services that involve disclosure of PHI. The definition then adds three points that matter for a billing company: 1. A **subcontractor** that creates, receives, maintains or transmits PHI on behalf of a business associate is itself a business associate. 2. A covered entity **may be a business associate** of another covered entity. 3. Some parties are excluded, for example a health care provider receiving PHI from a covered entity for the individual's **treatment**. One edge case: a billing service that converts health information from nonstandard formats into standard transactions also meets the definition of a **health care clearinghouse**, which is a covered entity in its own right. ## What the Security Rule requires The Security Rule applies to business associates directly: `164.302` says a covered entity **or business associate** must comply with the subpart. The contract does not create the obligation; it documents assurances and allocates duties. | Provision | What it says | |---|---| | `164.308(b)(1)` | A covered entity may permit a business associate to handle ePHI on its behalf only after obtaining satisfactory assurances under `164.314(a)`. It need not obtain them from a business associate that is a subcontractor. | | `164.308(b)(2)` | A business associate may permit a subcontractor to handle ePHI only after obtaining the same kind of assurances. | | `164.308(b)(3)` | The assurances are documented through a written contract or other arrangement (Required). | | `164.314(a)(2)(i)` | The contract must provide that the business associate will comply with the subpart, ensure its subcontractors agree to comply through compliant contracts, and report security incidents, including breaches of unsecured PHI as required by `164.410`. | | `164.314(a)(2)(iii)` | The same terms apply between a business associate and its subcontractor. | Further contract terms about permitted uses and disclosures come from the Privacy Rule, which the `164.314(a)(2)(ii)` "other arrangements" path also cross-references. ## Applying it to the billing company - **One contract per clinic.** Each clinic is a separate covered entity and must document its own assurances with the billing company. - **Downstream contracts are the billing company's job.** If it stores claims data with a hosting provider or passes accounts to a collections firm that receives PHI, those are subcontractors and therefore business associates; the billing company must obtain their assurances. The clinics are not required to obtain assurances from them. - **Breach reporting flows upward.** Under `164.410`, a business associate that discovers a breach of unsecured PHI must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery, identifying each affected individual where possible. The clinic then owns notification to individuals. - **Its own Security Rule programme.** As a business associate, the billing company needs its own risk analysis, safeguards and documentation; the contract does not shift those duties back to the clinics. ## Scoping the contracts Before drafting anything, list every party that creates, receives, maintains or transmits PHI for the billing company: hosting, backup, printing and mailing of statements, collections, and any analytics provider. Each of these is a candidate subcontractor. For each, record whether PHI actually reaches it, which clinic's data it touches, and whether a compliant written contract is in place. That inventory is what makes the contract chain auditable. ## Common mistakes - Assuming a vendor that "only stores" data is not a business associate. The definition covers anyone who **maintains** PHI on the covered entity's behalf. - Believing the clinic must sign with every downstream party. - Treating a business associate contract as the source of the business associate's obligations, when `164.302` binds it directly. A strong answer applies the definition, names the three required contract terms from `164.314(a)(2)(i)`, and explains how assurances chain from one link to the next.
- The billing company stores claims data with a hosting provider. Does each clinic need a contract with that provider?No. The hosting provider is the billing company's subcontractor and so a business associate. Under `164.308(b)(1)` and `(b)(2)`, the billing company obtains its assurances; a covered entity need not obtain them from a subcontractor.
- If the billing company discovers a breach, who notifies patients?Under `164.410` the business associate notifies the covered entity, no later than 60 calendar days after discovery, with the affected individuals' identities where possible. The covered entity then carries the duty to notify individuals under `164.404`.
- Can a covered entity also be a business associate?Yes. The `160.103` definition says a covered entity may be a business associate of another covered entity when it performs a regulated function on that entity's behalf.
saying these in an interview costs you the question
- Says a vendor that only stores PHI cannot be a business associate
- Believes each clinic must sign contracts with every downstream subcontractor
- Thinks business associates are bound only by contract, not by the Security Rule
- Treats a provider receiving PHI for treatment as a business associate
- Assumes one master contract with the billing company covers all the clinics