Scope
Who it applies to.
Before HITECH, a vendor that handled protected health information answered mainly to the covered entity that hired it, through contract terms. HITECH made business associates directly liable under federal law, so HHS can pursue the vendor itself and not only its client. The 2013 Omnibus Rule extended that reach downstream: a subcontractor that creates, receives, maintains, or transmits PHI on behalf of a business associate is itself a business associate. Your vendor’s hosting provider, scanning bureau, or AI service is in scope.
- Direct liability for business associates
- HITECH § 13401 applied the Security Rule’s administrative, physical, technical, and documentation standards (45 CFR §§ 164.308, 164.310, 164.312, and 164.316) to business associates in the same manner as to covered entities, and made HIPAA’s civil and criminal penalties apply to them directly. Section 13404 did the same for the Privacy Rule limits on use and disclosure. Compliance stopped being purely a contract question.
- Subcontractors are business associates
- The Omnibus Rule rewrote 45 CFR § 160.103 so that “business associate” includes “a subcontractor that creates, receives, maintains, or transmits protected health information on behalf of the business associate.” A subcontractor is anyone to whom a business associate delegates a function, activity, or service outside its own workforce. The definition is recursive, so it does not stop at the first tier.
- Flow-down agreements at every link
- A covered entity does not contract with its vendor’s subcontractors; the vendor must. Under 45 CFR §§ 164.502(e)(1)(ii) and 164.308(b)(2), a business associate must obtain written satisfactory assurances from each subcontractor before PHI moves. HHS stated the duty repeats “no matter how far ‘down the chain’ the information flows,” leaving you with no direct agreement with many parties actually holding your data.
- Breach notification — the outward duties
- HITECH § 13402 created the first federal breach-notification duty for health information, implemented at 45 CFR §§ 164.400 through 164.414. A covered entity must notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery, notify the Secretary, and notify prominent media outlets when a breach involves more than 500 residents of a state or jurisdiction.
- Breach notification — up the chain
- A business associate that discovers a breach must notify the covered entity without unreasonable delay and no later than 60 calendar days after discovery (45 CFR § 164.410). Discovery is imputed from the first day the breach is known, or would have been known through reasonable diligence, to any employee, officer, or agent other than the person who caused it.
- Presumption of breach
- The Omnibus Rule replaced the 2009 interim rule’s “significant risk of harm” threshold with a presumption. An impermissible use or disclosure is presumed to be a breach unless you demonstrate a low probability that the information was compromised, weighing at least four factors: the nature and extent of the PHI, who received it, whether it was actually acquired or viewed, and how far the risk was mitigated.
The vendor & sub-processor obligation
What it puts on you.
Liability and breach-notification obligations now flow all the way down to subcontractors of business associates. The more third parties touch PHI, the more parties can trigger a reportable breach that lands back on you.
How self-hosting addresses it
Remove the third party, remove the burden.
Removing outside vendors from the data path removes the downstream subcontractors HITECH reaches — shrinking both the breach surface and the notification chain to your own walls.
How FileFerret applies
Search and AI running on hardware inside your own building add no new link to the subcontractor chain the Omnibus Rule reaches, and no outside agent whose discovery of a breach is imputed to you under 45 CFR § 164.404(a)(2). That narrows notification exposure; it does not by itself satisfy HIPAA or HITECH. See how it’s built →
Full, current text is maintained at the official source: HITECH Act (2009) — U.S. HHS.
Enforcement
Who enforces it, and how.
HITECH § 13410 replaced HIPAA’s flat penalty with four culpability tiers, codified at 45 CFR § 160.404: no knowledge; reasonable cause; willful neglect corrected within 30 days; and willful neglect not corrected. Penalties climb with each tier and reach business associates directly. Dollar figures are inflation-adjusted annually and published at 45 CFR part 102, so any amount is current only as of its stated year. HITECH also let state attorneys general sue in federal court for residents (42 U.S.C. § 1320d–5(d)), alongside HHS Office for Civil Rights enforcement.
Common questions
Questions firms ask.
Our firm signed a business associate agreement years ago — isn’t that still enough?
A BAA is still required, but since 2013 it is no longer the only thing binding your vendor. HHS can penalize a business associate directly for Security Rule failures under 45 CFR § 160.404, independent of what your contract says. The practical change is that an older BAA may not describe the full obligation set, and it does not reach your vendor’s subcontractors.
Do we need agreements with our vendor’s subcontractors?
No. 45 CFR § 164.502(e)(1)(i) provides that a covered entity is not required to obtain satisfactory assurances from a business associate that is a subcontractor. That duty sits with your vendor, at each link. The practical catch is visibility: the parties holding your PHI may be several contracts away, and under 45 CFR § 160.402(c) your vendor remains liable for acts of a subcontractor acting as its agent.
If a subcontractor is breached, who notifies the patients?
The covered entity notifies affected individuals (45 CFR § 164.404). A breached subcontractor notifies the business associate that engaged it, which notifies you, each without unreasonable delay and within 60 calendar days of discovery (45 CFR § 164.410). Under § 164.404(a)(2) a breach counts as discovered by you once it is known to any agent of yours, so delay down the chain can erode your own window.