HIPAA: Business Associate Reports a Breach — Your Response

Essential response procedures when a vendor/business associate reports a data breach

Immediate Action Required

Response Timeline

First 24 Hours

  • Document the BA's breach notification
  • Verify BAA is in place with the BA
  • Review the BAA for breach notification requirements
  • Request detailed written disclosure from BA
  • Ask BA for: date of breach, affected patients, type of data, scope of access
  • Determine which of your patients were affected
  • Assess the 60-day notification deadline
  • Notify your compliance officer and legal counsel

First 2-3 Days

  • Conduct detailed review of BA's breach disclosure
  • Request evidence of BA's incident investigation
  • Ask BA what remedial measures they have taken
  • Determine if BA is reporting to HHS/OCR
  • Request forensic investigation report from BA
  • Assess the scope of affected patient data
  • Begin preparation of patient notification
  • Determine OCR reporting requirements

First 7 Days

  • Complete breach assessment based on BA's disclosure
  • Verify BA's remediation steps are appropriate
  • Decide on BA relationship continuity vs. termination
  • Finalize patient notification messaging
  • Determine if media notification is required (500+ affected)
  • Prepare OCR notification if required
  • Schedule breach notification mailings

First 30 Days

  • Send patient breach notifications (within 60-day deadline)
  • File OCR breach notification if required
  • Provide media notification if required (500+ affected)
  • Monitor for BA's OCR notification
  • Conduct vendor audit assessment
  • Determine BA relationship status (continue, terminate, remediate)
  • Document all responses and actions

60+ Days

  • Submit OCR notification if required
  • If terminating: request return or destruction of all PHI
  • If continuing: implement additional oversight controls
  • Conduct security audit of BA's practices
  • Update vendor risk assessment procedures
  • Enhance contract language for future BAs
  • Retain documentation for investigations

Business Associate Agreement Review

Your BAA should address breach notification requirements:

Breach Information Required from BA

Demand the following information from your business associate:

Your Notification Obligations

As the covered entity, you remain responsible for patient notification:

Vendor Assessment and Remediation

Evaluate whether to continue the relationship:

Vendor Termination Process

If you decide to terminate the relationship:

Frequently Asked Questions

Am I responsible for my BA's breach?
Yes, you are liable for breaches of your patient data by your business associates. You must have a Business Associate Agreement in place, and you are responsible for notifying patients even if the BA caused the breach. HIPAA holds covered entities responsible for BA compliance.
What should I require from my BA regarding the breach?
Require detailed written disclosure of the breach, including the timeline, affected patient data, forensic investigation results, remedial measures being taken, and evidence that they are reporting to HHS OCR. Conduct an audit of their controls and incident response procedures.
Can I terminate the relationship with my BA?
Yes, you can and should consider termination depending on breach severity. Review your BAA for termination clauses. Ensure the BA returns or destroys all patient data. Plan transition to a new vendor with better security controls in place.
What is my notification timeline?
You must notify affected patients within 60 days of discovery of the breach, even if the BA caused it. The 60-day clock starts from when you became aware of the breach. This may require expedited action if you were notified late by your BA.

Strengthen Your Vendor Management

A comprehensive security risk analysis includes assessment of business associate controls and compliance.

Get Your Security Analysis