164.314(a)(1) Organizational Requirements

Business Associate Contracts or Other Arrangements

High Risk Moderate Medium

A covered entity may permit a business associate to create, receive, maintain, or transmit ePHI on the covered entity's behalf only if the covered entity obtains satisfactory assurances that the business associate will appropriately safeguard the information.

Implementation Guidance

A covered entity may permit a business associate to create, receive, maintain or transmit ePHI on its behalf only with satisfactory assurances, documented in a written contract, that the business associate will appropriately safeguard the information. The organisational requirement at 164.314(a)(1) sets what that contract must contain; 164.308(b)(1) requires the assurances themselves.

The agreement must require the business associate to:
• Comply with the Security Rule's administrative, physical and technical safeguards
• Ensure that any subcontractor creating, receiving, maintaining or transmitting ePHI on its behalf agrees to equivalent restrictions, through a downstream agreement
• Report security incidents, including breaches of unsecured PHI, to the covered entity
• Make its practices available to HHS for compliance review
• Return or destroy PHI at termination where feasible, and extend protections where it is not

Operating the requirement in practice:
- Identify business associates by function, not by label. A vendor with incidental, unavoidable access — a cloud host, a managed service provider, an offshore transcription service — is a business associate. Conduit exceptions are narrow and often misapplied
- Maintain a register with counterparty, service, ePHI involved, agreement dates, expiry and renewal owner
- Execute the agreement before any ePHI moves, not after go-live
- Set breach reporting timelines in the contract rather than relying on the regulatory default, which can consume most of your own 60-day window
- Assess the risk each business associate presents proportionate to the data they hold; a signature is assurance, not verification
- Track subcontractors where they materially hold your data
- Review agreements on renewal, on material service change, and when regulation changes
- Ensure termination triggers return or destruction, and obtain confirmation

Business associates are directly liable for Security Rule compliance and have been the subject of OCR enforcement in their own right.

Required Documentation

• Business associate management policy and procedure
• Register of all business associates, with service, ePHI involved and access route
• Executed business associate agreements, with effective and expiry dates
• Evidence that the agreement predates any ePHI disclosure
• Subcontractor arrangements where a business associate uses downstream providers
• Risk assessment or due diligence records per business associate, proportionate to risk
• Breach and incident notification terms, including agreed timelines
• Renewal tracking and review records
• Termination records showing return or destruction of PHI, with confirmation received
• Records of incidents reported by business associates and the response taken

Best Practices

• Keep a single register of business associates with named owners and automated expiry alerts
• Classify by function and data access rather than by vendor category or self-description
• Require breach notification well inside the regulatory default, so your own 60-day clock is protected
• Scale due diligence to risk: request SOC 2 Type 2 or HITRUST evidence from vendors holding large volumes of ePHI
• Make agreement execution a gate in procurement, before any data moves
• Reassess vendors periodically rather than only at onboarding
• Record subcontractor chains where your data materially sits downstream
• Build termination obligations into the contract and hold the confirmation of destruction
• Treat cloud infrastructure providers as business associates where they maintain ePHI, even encrypted

Common Violations

• No agreement in place with a vendor that clearly handles ePHI
• Agreement signed after the service went live and data had already moved
• Cloud and IT providers wrongly excluded on a mistaken reading of the conduit exception
• Agreements missing required terms, particularly subcontractor flow-down and incident reporting
• Breach notification left at the regulatory default, leaving no time for the covered entity to act
• No register, so nobody knows how many business associates exist
• Agreements lapsed and never renewed, with the relationship continuing regardless
• Due diligence limited to collecting a signature, with no assessment of actual safeguards
• No evidence of PHI return or destruction after termination
• Subcontractor chains entirely untracked

Testing Procedures

• Reconcile the business associate register against accounts payable and the vendor list to find unregistered relationships
• Confirm a signed agreement exists for every counterparty with access to ePHI
• Check that agreement effective dates precede the start of ePHI disclosure
• Review agreement text for each required element, including subcontractor flow-down and incident reporting
• Sample cloud and IT vendors specifically, since these are most often misclassified as outside scope
• Confirm breach notification timelines are contractually specified rather than left to default
• Review due diligence evidence and test whether it is proportionate to the data held
• Confirm expiring agreements are tracked and renewed before lapse
• Sample terminated relationships and confirm PHI return or destruction was obtained in writing
• Trace a business-associate-reported incident through to your own documented response

Implementation Resources

Download expert-developed templates and checklists to implement this control:

Quick Facts

Control ID 164.314(a)(1)
Category Organizational Requirements
Risk Level High
Difficulty Moderate
Est. Cost Medium
Timeframe 2-4 months
Last Updated Sep 3, 2026

Need Help Implementing This Control?

Our certified HIPAA experts can help you implement this control correctly and efficiently.