decisionhealth Newsletters, Part B News - 2013 Issue 2 (February)
HIPAA ‘mega-rule’ adds EHR vendors, storage facilities to business associate list
Subscribe or sign in to view the full article.
Article Overview
This article is a compliance-focused overview of HHS’ HIPAA mega-rule and its impact on business associate relationships. It is aimed at providers, practice managers, compliance staff, and attorneys who manage vendor contracts, business associate agreements, and breach-response obligations. The discussion covers the expanded business associate definition, contract updates, subcontractor oversight, and related timing considerations under HIPAA and the broader final-rule package.
Why This Topic Matters
Organizations that handle protected health information need to understand which vendors, storage companies, and subcontractors may now fall within HIPAA obligations. The article helps readers identify contract and compliance areas that may need attention to reduce exposure when a business associate is involved in a privacy or security incident.
Article Sections
-
Rule overview and expanded business associate definition
Introduces the HHS mega-rule and explains the broader compliance context for entities that use, store, maintain, or transmit protected health information. It summarizes the types of organizations newly affected by the updated framework.
-
Contract review and compliance timing
Discusses the need to review existing vendor and service agreements and the timing considerations tied to updated business associate arrangements. It also notes the role of subcontractors under the revised requirements.
-
What you should do now
Outlines general next steps for organizations managing business associate relationships. The section focuses on communication, contract renewal review, responsibility allocation, and breach-notification planning.
What You Will Learn
- How the HIPAA mega-rule changed the business associate landscape
- Which types of vendor and service relationships may be affected
- Why existing contracts may need to be reviewed or updated
- What general compliance areas organizations should evaluate with business associates and subcontractors
- How breach-response coordination fits into vendor oversight
Who Should Read This
- Healthcare providers
- Practice managers
- Compliance officers
- Health care attorneys
- Vendor management teams
- Privacy and security staff
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com