Compliance · Healthcare vendors

HITECH Act of 2009 and Business Associate Agreements

The Health Information Technology for Economic and Clinical Health (HITECH) Act strengthened HIPAA. Its biggest change for shredding: the companies healthcare providers hire to handle patient information became directly liable under HIPAA, and the relationship has to be documented in a Business Associate Agreement.

What changed

  • Business associates are on the hook. A shredding company, billing service, IT vendor or records-storage firm that touches PHI must comply with HIPAA's Security Rule and can be fined directly.
  • Breach notification. If PHI is exposed — including paper found in a dumpster — patients must be notified, HHS must be notified, and breaches affecting 500 or more people are posted publicly and often reported to the media.
  • Higher penalties. HITECH created the tiered penalty structure HHS uses today and gave state attorneys general the power to bring HIPAA actions.

What a Business Associate Agreement does

A BAA is a written contract between a healthcare provider and a vendor that handles PHI. It spells out what the vendor may do with the information, requires appropriate safeguards, and requires the vendor to report any breach. Regulators have fined practices simply for lacking one — in the FileFax case, a small pediatric practice paid $31,000 because it had no BAA with its records vendor.

Why on-site shredding fits

The less time a vendor holds your PHI, the smaller the risk. With on-site destruction, the vendor's custody of your records lasts minutes, in your parking lot, in your view. There is no storage facility, no transport, and no waiting queue where a breach could occur.

This page is a plain-English summary for business owners, not legal advice. Talk to your attorney or compliance officer about how the law applies to you.

Call (567) 202-2660 Get a Quote