Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?
No. However, a covered entity must ensure through its contract with the business associate that the business associate’s uses and disclosures of protected health information and other actions are consistent with the covered entity’s privacy policies, as stated in covered entity’s notice. Also, a covered entity may use a business associate to distribute its notice to individuals.
Related Questions
- Under the HIPAA Privacy Rule, may a covered entity contract with a business associate to create a limited data set the same way it can use a business associate to create de-identified data?
- Does the HIPAA Privacy Rule require a business associate to provide individuals with access to their PHI or an accounting of disclosures, or an opportunity to amend PHI?
- Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?