Organizational requirements

Provider Responsibilities

 If a provider knows of an activity or practice of the business associate that constitutes a material breach or violation of the business associate’s obligation, the provider must take reasonable steps to cure the breach or end the violation. Violations include the failure to implement safeguards that reasonably and appropriately protect e-PHI.  

Business Associate Contracts

 HHS developed regulations relating to business associate obligations and business associate contracts under the HITECH Act of 2009.