Does a Business Associate (an agent) need to report a breach to HHS or should it be reported to the carrier (a covered entity) and the covered entity report to HHS?
Business Associates are required by law to report breaches to HHS. The agent/agency may also have contractual commitments to report the breach to the carrier. Some carriers will provide guidance on whether the event is a breach and will assist the agent in the breach compliance process. In the end the Business Associate who is responsible for a breach must make sure the breach is properly reported to HHS, that the required notification of clients occurs, and pay all fines and serve time if the breach is determined to be a felony. All BAs need to know the law and the correct steps to follow if there is a breach since under HITECH, they are fully regulated by HHS like covered entities.