HIPAA: Business Associate Reports a Breach — Your Response
Essential response procedures when a vendor/business associate reports a data breach
Immediate Action Required
- Document the breach notification from your BA
- Verify a valid Business Associate Agreement (BAA) exists
- Request detailed breach disclosure from the BA
- Identify which of your patient records were affected
- Assess the timeline for your patient notification obligations
- Activate incident response team
- Notify legal counsel immediately
Response Timeline
First 24 Hours
- Document the BA's breach notification
- Verify BAA is in place with the BA
- Review the BAA for breach notification requirements
- Request detailed written disclosure from BA
- Ask BA for: date of breach, affected patients, type of data, scope of access
- Determine which of your patients were affected
- Assess the 60-day notification deadline
- Notify your compliance officer and legal counsel
First 2-3 Days
- Conduct detailed review of BA's breach disclosure
- Request evidence of BA's incident investigation
- Ask BA what remedial measures they have taken
- Determine if BA is reporting to HHS/OCR
- Request forensic investigation report from BA
- Assess the scope of affected patient data
- Begin preparation of patient notification
- Determine OCR reporting requirements
First 7 Days
- Complete breach assessment based on BA's disclosure
- Verify BA's remediation steps are appropriate
- Decide on BA relationship continuity vs. termination
- Finalize patient notification messaging
- Determine if media notification is required (500+ affected)
- Prepare OCR notification if required
- Schedule breach notification mailings
First 30 Days
- Send patient breach notifications (within 60-day deadline)
- File OCR breach notification if required
- Provide media notification if required (500+ affected)
- Monitor for BA's OCR notification
- Conduct vendor audit assessment
- Determine BA relationship status (continue, terminate, remediate)
- Document all responses and actions
60+ Days
- Submit OCR notification if required
- If terminating: request return or destruction of all PHI
- If continuing: implement additional oversight controls
- Conduct security audit of BA's practices
- Update vendor risk assessment procedures
- Enhance contract language for future BAs
- Retain documentation for investigations
Business Associate Agreement Review
Your BAA should address breach notification requirements:
- Breach notification clause: Requires BA to notify you of breaches without unreasonable delay
- Investigation requirements: BA must conduct investigation and provide detailed findings
- Remediation obligations: BA must implement corrective actions
- Cooperation: BA must cooperate with your investigation and OCR inquiries
- Liability: Clarify liability allocation and insurance requirements
- Termination rights: Your right to terminate if breach occurs
- Data return: BA must return or destroy PHI upon termination
Breach Information Required from BA
Demand the following information from your business associate:
- Breach date: When the breach occurred
- Discovery date: When breach was discovered
- Patient count: Number of affected patients
- Data elements: Specific information that was compromised (names, MRN, SSN, etc.)
- Investigation results: How breach occurred and forensic findings
- Access evidence: Whether data was actually accessed or just exposed
- Remediation: What steps BA is taking to prevent recurrence
- BA's notification: Whether BA is notifying HHS/OCR and timeline
Your Notification Obligations
As the covered entity, you remain responsible for patient notification:
- You must notify affected patients within 60 days of discovery
- This timeline starts from when you became aware of the breach
- Your notification responsibility exists even though BA caused the breach
- Notify media if 500+ residents in a jurisdiction are affected
- You must report to HHS/OCR (or BA must and you should verify)
- Include details about what BA caused the breach and measures taken
- Offer credit monitoring if financial information was exposed
Vendor Assessment and Remediation
Evaluate whether to continue the relationship:
- Breach severity: Was this a minor incident or serious lapse?
- BA's response: Was BA's incident response appropriate and timely?
- Security posture: Request audit results or risk assessment
- Remediation plan: Does BA have credible corrective action plan?
- Insurance: Does BA have cyber liability insurance?
- Compliance track record: Is this BA's first breach or recurring?
- Alternatives: Consider moving to different vendors with better security
- Contract amendments: Require enhanced protections in revised BAA
Vendor Termination Process
If you decide to terminate the relationship:
- Review BAA termination clauses
- Provide written notice of termination with specific timeframe
- Require BA to return all patient data in specified format
- Require BA to certify destruction of all remaining data
- Request copies of BA's certifications of destruction
- Plan transition to new vendor
- Ensure continuity of business operations during transition
- Conduct final audit of BA's compliance before separation
Frequently Asked Questions
Am I responsible for my BA's breach?
Yes, you are liable for breaches of your patient data by your business associates. You must have a Business Associate Agreement in place, and you are responsible for notifying patients even if the BA caused the breach. HIPAA holds covered entities responsible for BA compliance.
What should I require from my BA regarding the breach?
Require detailed written disclosure of the breach, including the timeline, affected patient data, forensic investigation results, remedial measures being taken, and evidence that they are reporting to HHS OCR. Conduct an audit of their controls and incident response procedures.
Can I terminate the relationship with my BA?
Yes, you can and should consider termination depending on breach severity. Review your BAA for termination clauses. Ensure the BA returns or destroys all patient data. Plan transition to a new vendor with better security controls in place.
What is my notification timeline?
You must notify affected patients within 60 days of discovery of the breach, even if the BA caused it. The 60-day clock starts from when you became aware of the breach. This may require expedited action if you were notified late by your BA.
Strengthen Your Vendor Management
A comprehensive security risk analysis includes assessment of business associate controls and compliance.
Get Your Security Analysis