Business Associate Agreement Under HIPPA:  Your Clients Are Protected; Are You?

Robert Haney • September 27, 2018

Representing healthcare clients is a very involved and complex task for any attorney to handle. This is especially true from a compliance perspective. The Health Insurance Portability & Accountability Act of 1996 (“ HIPAA ”) provides the requirements for the privacy and security rules regulating protected health information (“ PHI ”) of individuals and entities. Additionally, the HIPAA Privacy Rule and Security Rule (the “ Rule ”) set forth the rules for enforcing HIPAA violations and handling notifications involving any breach involving PHI (a “ Breach ”). Individuals and organizations required to comply with the Rule are called “Covered Entities.” However, the application of HIPAA does not stop at Covered Entities. HIPAA also applies to the business associates of Covered Entities, a role that is occupied by many attorneys representing Covered Entities.

What is a Business Associate?

On January 25, 2013, the final changes to the Rule were published. Under the Rule, a “business associate” of a Covered Entity can be held directly liable under HIPAA for a Breach. The Rule provides for three types of business associates working with or on behalf of Covered Entities: (1) business associate subcontractors; (2) entities routinely transmitting and accessing PHI; and (3) personal health record vendors.

Generally speaking, attorneys representing Covered Entities or business associates are business associate subcontractors if, in representing a Covered Entity or business associate, the attorney requires access to PHI in order to do their work for their client. If an attorney is a business associate, then a written Business Associate Agreement with their client is required.

Why Should I Enter Into A Business Associate Agreement?

The Rule requires business associates to enter into a written Business Associate Agreement that implements reasonable and appropriate policies in order to comply with the Rule and any Breaches thereunder. Failure to implement a written Business Associate Agreement can result in substantial fines and penalties. Amongst other things, Attorneys who are business associates can be held directly liable under the Rule, just as a Covered Entity would, for Breaches and violations of the Rule.

What is Required Under a Business Associate Agreement?

In order to avoid or reduce the chance of incurring liability for a Breach or other violation of the Rule the acts listed above, it is important to have a detailed and effective Business Associate Agreement. The template for a Business Associate Agreement should begin by incorporating the following requirements set forth under the Rule:

1)Establish the business associate’s permitted and required uses of PHI by setting forth how and when the business associate will use the PHI;

2)Provide that the business associate will only disclose PHI other than is set forth in the Business Associate Agreement or is required by law;

3)Implement appropriate safeguards to prevent the unauthorized use or disclosure of PHI;

4)Implement the requirements of the HIPAA Security Rule regarding electronic PHI;

5)Establish the situations and circumstances under which the business associate must disclose PHI to a requesting party;

6)Require the business associate to comply with all applicable requirements to the extent that the business associate is carrying out an obligation under the Rule on behalf of the covered entity;

7)Require the business associate’s internal practices, books and records in relation to the use and disclosure of PHI to be made available to the U.S. Department of Health & Human Services so that determinations regarding compliance with the Rule can be made;

8)To the extent practicable, require the business associate to return or destroy all PHI at the termination of the Business Associate Agreement;

9)Provide that any subcontractors, as defined by the Rule, business associate will engage with require the business associate to ensure that any subcontractors it may engage on its behalf that will have access to protected health information agree to the same restrictions and conditions that apply to the business associate with respect to such information; and

10)Provide for a termination of the Business Associate Agreement if the business associate violates a material term of the Agreement.

How will a Business Associate Agreement Reduce Attorney Liability?

While no Business Associate Agreement can eliminate an attorney’s liability under the Rule, it can greatly assist the attorney in limiting their liability to the extent possible.

First, while a Business Associate Agreement cannot change the statutory timeframes for providing notice or curing a Breach under the Rule, an attorney can give themselves as much leeway as possible with respect to how and when it must provide notice or cure a Breach by allowing themselves as much time as is permitted under the Rule.

Second, the Business Associate Agreement can provide greater clarity to the parties in detailing what a Breach is and when a Breach a occurs. This will help both parties reduce the probability of a Breach, recognize when a Breach occurs, and address either party’s failure to comply with the notice and cure provisions of the Rule.

Third, the Business Associate Agreement can provide essential guidance in handling a Breach by clearly stating each party’s responsibilities in the event of a Breach and the best and most efficient way to cure a Breach. Having definite and delegated plans of action for each party will provide security to each party in handling a Breach.

Finally, in addition to entering in to a Business Associate Agreement, it is also important to remember take a step back, evaluate your practice and determine the best way to become HIPAA and Rule compliant. This can be done by assessing your current level of compliance with HIPAA, projecting potential future compliance needs as your practice changes or grows and a developing plan of action to address any gaps you may discover or anticipate.

Speak to an Attorney

Related Posts
By Jordan Uditsky February 25, 2026
Why TODAY Is The Time To Prepare Your Practice – and Yourself - For an Uncertain Tomorrow
By Jordan Uditsky February 4, 2026
Bogus ADA Claims Regarding Dental Practice Websites Are Rampant. Your Lawyer Can Help You Tell the Difference Between a Real Problem and a Real Shakedown. Over 25 years have passed since the Americans with Disabilities Act (ADA) quite literally reshaped the landscape for people with disabilities. From building entrances to parking lots to restrooms to elevators, from hiring and employment opportunities to restaurants, stores, and websites, disabled Americans have far greater access to the same facilities, services, and opportunities as everyone else. Harassment at Best, Extortion at Worst For all the good it has accomplished, however, the ADA has also been abused by opportunistic individuals and attorneys who have used the law in bad faith to shake down small businesses, including dental practices, for alleged violations that have not actually caused any harm or infringed upon any rights afforded by the act. These self-appointed ADA compliance "testers" have filed thousands of nuisance ADA suits that have cost American businesses millions of dollars. According to one analysis, ADA lawsuits have increased by 320% since 2013, with over 4,000 suits filed in 2024 alone. Many plaintiff's law firms file hundreds of cookie-cutter ADA lawsuits each year. One person can visit multiple businesses or websites in a single day solely to identify even the slightest accessibility transgressions in order to generate claims. While these suits can focus on any number of alleged ADA shortcomings, those relating to website accessibility (discussed in detail in this earlier post ) filed by a handful of law firms and serial plaintiffs have earned the scorn of small businesses and practices across the country. That's because these "testers" and the lawyers who represent them specifically target small businesses, as they typically have limited means to defend themselves, may not be able to discern between legitimate and bogus claims, and often see a quick payoff as the path of least resistance. Here’s how the shakedown typically goes down: A plaintiff or their attorney sends the practice a demand letter in which they claim that the practice’s website is inaccessible to people with disabilities (e.g., missing image alt text, inaccessible forms, incompatible with screen readers). They cite a violation of Title III of the ADA. They make a demand for a cash settlement, often ranging from $2,500 to $25,000, alongside a request for accessibility fixes. The business/practice cuts a check in exchange for a release of any ADA claims by that plaintiff related to the website. The business/practice may then receive more demand letters, often from the same firm, on behalf of other plaintiffs who make the same claim, and the extortion continues. Don’t Act Impulsively – Do This Instead All this is not to say that dental practice owners should consider all such claims and demands to be frivolous or ignore their ADA obligations relating to their website. To be sure, a meritorious ADA lawsuit can indeed expose a practice to significant financial and reputational damage. Before reflexively giving in to an ADA demand letter and settling a supposed claim, practice owners should take the following steps: · Don't Panic, But Don't Ignore It. As noted, a demand letter with legalese and ominous language doesn’t mean that you’ve done anything wrong or actually violated the law. While your immediate reaction may include fear, confusion, or anger, don’t act impulsively. By the same token, don’t assume it is a bogus threat; crumble up the letter and throw it in the recycling. Deadlines in these letters are real, and failing to respond appropriately to a viable claim could lead to litigation. · Contact Your Attorney Immediately. This is not a DIY situation. Before responding to the letter or contacting the sender, consult with an attorney experienced in ADA compliance and website accessibility issues. Your lawyer can evaluate the demand letter or complaint, the validity of the claim, and the law firm behind it before formulating an appropriate response. Testers send many cookie-cutter letters that may contain boilerplate allegations of deficiencies that do not actually exist. · Evaluate Your Actual Compliance. Work with your attorney and website accessibility experts to have your website assessed against the Web Content Accessibility Guidelines (WCAG) , which courts often reference in ADA website cases. Understanding your site's actual accessibility helps inform whether settlement, remediation, or another approach makes sense and whether you need to take additional steps to avoid future claims. Keep in mind that this isn't just about legal compliance—it's good business. An accessible website serves all patients better and demonstrates your commitment to inclusivity. If you have questions about your business's ADA obligations and how to protect it from accessibility complaints, please call Grogan, Hesse & Uditsky at (630) 833-5533 or contact us online to arrange for your free initial consultation. At Grogan Hesse & Uditsky, P.C., we focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you. Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices. This blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.
Show More
By Jordan Uditsky February 25, 2026
Why TODAY Is The Time To Prepare Your Practice – and Yourself - For an Uncertain Tomorrow
By Jordan Uditsky February 4, 2026
Bogus ADA Claims Regarding Dental Practice Websites Are Rampant. Your Lawyer Can Help You Tell the Difference Between a Real Problem and a Real Shakedown. Over 25 years have passed since the Americans with Disabilities Act (ADA) quite literally reshaped the landscape for people with disabilities. From building entrances to parking lots to restrooms to elevators, from hiring and employment opportunities to restaurants, stores, and websites, disabled Americans have far greater access to the same facilities, services, and opportunities as everyone else. Harassment at Best, Extortion at Worst For all the good it has accomplished, however, the ADA has also been abused by opportunistic individuals and attorneys who have used the law in bad faith to shake down small businesses, including dental practices, for alleged violations that have not actually caused any harm or infringed upon any rights afforded by the act. These self-appointed ADA compliance "testers" have filed thousands of nuisance ADA suits that have cost American businesses millions of dollars. According to one analysis, ADA lawsuits have increased by 320% since 2013, with over 4,000 suits filed in 2024 alone. Many plaintiff's law firms file hundreds of cookie-cutter ADA lawsuits each year. One person can visit multiple businesses or websites in a single day solely to identify even the slightest accessibility transgressions in order to generate claims. While these suits can focus on any number of alleged ADA shortcomings, those relating to website accessibility (discussed in detail in this earlier post ) filed by a handful of law firms and serial plaintiffs have earned the scorn of small businesses and practices across the country. That's because these "testers" and the lawyers who represent them specifically target small businesses, as they typically have limited means to defend themselves, may not be able to discern between legitimate and bogus claims, and often see a quick payoff as the path of least resistance. Here’s how the shakedown typically goes down: A plaintiff or their attorney sends the practice a demand letter in which they claim that the practice’s website is inaccessible to people with disabilities (e.g., missing image alt text, inaccessible forms, incompatible with screen readers). They cite a violation of Title III of the ADA. They make a demand for a cash settlement, often ranging from $2,500 to $25,000, alongside a request for accessibility fixes. The business/practice cuts a check in exchange for a release of any ADA claims by that plaintiff related to the website. The business/practice may then receive more demand letters, often from the same firm, on behalf of other plaintiffs who make the same claim, and the extortion continues. Don’t Act Impulsively – Do This Instead All this is not to say that dental practice owners should consider all such claims and demands to be frivolous or ignore their ADA obligations relating to their website. To be sure, a meritorious ADA lawsuit can indeed expose a practice to significant financial and reputational damage. Before reflexively giving in to an ADA demand letter and settling a supposed claim, practice owners should take the following steps: · Don't Panic, But Don't Ignore It. As noted, a demand letter with legalese and ominous language doesn’t mean that you’ve done anything wrong or actually violated the law. While your immediate reaction may include fear, confusion, or anger, don’t act impulsively. By the same token, don’t assume it is a bogus threat; crumble up the letter and throw it in the recycling. Deadlines in these letters are real, and failing to respond appropriately to a viable claim could lead to litigation. · Contact Your Attorney Immediately. This is not a DIY situation. Before responding to the letter or contacting the sender, consult with an attorney experienced in ADA compliance and website accessibility issues. Your lawyer can evaluate the demand letter or complaint, the validity of the claim, and the law firm behind it before formulating an appropriate response. Testers send many cookie-cutter letters that may contain boilerplate allegations of deficiencies that do not actually exist. · Evaluate Your Actual Compliance. Work with your attorney and website accessibility experts to have your website assessed against the Web Content Accessibility Guidelines (WCAG) , which courts often reference in ADA website cases. Understanding your site's actual accessibility helps inform whether settlement, remediation, or another approach makes sense and whether you need to take additional steps to avoid future claims. Keep in mind that this isn't just about legal compliance—it's good business. An accessible website serves all patients better and demonstrates your commitment to inclusivity. If you have questions about your business's ADA obligations and how to protect it from accessibility complaints, please call Grogan, Hesse & Uditsky at (630) 833-5533 or contact us online to arrange for your free initial consultation. At Grogan Hesse & Uditsky, P.C., we focus a substantial part of our practice on providing exceptional legal services for dentists and dental practices, as well as orthodontists, periodontists, endodontists, pediatric dentists, and oral surgeons. We bring unique insights and deep commitment to protecting the interests of dental professionals and their practices and welcome the opportunity to work with you. Jordan Uditsky, an accomplished businessman and seasoned attorney, combines his experience as a legal counselor and successful entrepreneur to advise dentists and other business owners in the Chicago area. Jordan grew up in a dental family, with his father, grandfather, and sister each owning their own dental practices. This blend of legal, business, and personal experience provides Jordan with unique insight into his clients’ needs, concerns, and goals.
Show More