THIRD PARTYCURRENT
U.S. federal regulation

HIPAA Security Rule and business-associate requirements

The Security Rule requires covered entities and business associates to protect electronic protected health information with administrative, physical, and technical safeguards. Organizational requirements include written business-associate arrangements, satisfactory assurances, flow-down obligations to subcontractors, incident reporting, and required documentation.

What the authority establishes

The Security Rule requires covered entities and business associates to protect electronic protected health information with administrative, physical, and technical safeguards. Organizational requirements include written business-associate arrangements, satisfactory assurances, flow-down obligations to subcontractors, incident reporting, and required documentation.

Healthcare buyers must know which vendors create, receive, maintain, or transmit ePHI; document business-associate agreements; obtain safeguards and incident commitments; manage subcontractor flow-down; and retain evidence. The rule creates durable requirements for inventory, data-access scoping, contract controls, risk analysis, incident response, and offboarding.

The record is written for operational interpretation, not legal advice. Applicability depends on entity type, jurisdiction, relationship, service, data, criticality, contractual commitments, and later authority guidance.

Who should read it

The primary audiences named in this review are health plans, clearinghouses, and covered healthcare providers, healthcare business associates and their subcontractors, health-system privacy, security, compliance, procurement, and legal teams, healthcare technology and services vendors. Those roles may divide responsibility differently, but the operating record should still show scope, accountable ownership, evidence, review, exceptions, and the final decision.

Third-party lifecycle implications

Scope And Relationship Classification

Teams should determine what this authority expects at the scope and relationship classification stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Risk Analysis

Teams should determine what this authority expects at the risk analysis stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Contracting

Teams should determine what this authority expects at the contracting stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Safeguard Verification

Teams should determine what this authority expects at the safeguard verification stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Incident Management

Teams should determine what this authority expects at the incident management stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Subcontractor Oversight

Teams should determine what this authority expects at the subcontractor oversight stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Termination And Data Disposition

Teams should determine what this authority expects at the termination and data disposition stage, which function owns the judgment, what evidence must be retained, and what later change would reopen the record.

Capabilities that may support the work

These links identify relevant operating capabilities; they do not state that any product creates compliance.

Intake And Inventory

establishing an accountable record of relationships, products, owners, and critical services. Buyers should test the workflow against their own scope and evidence requirements.

Inherent Risk Tiering

using relationship context to determine proportional diligence and review. Buyers should test the workflow against their own scope and evidence requirements.

Due Diligence And Assessments

collecting and reviewing evidence before and during a relationship. Buyers should test the workflow against their own scope and evidence requirements.

Evidence Collection

preserving source material, responses, and reviewer context. Buyers should test the workflow against their own scope and evidence requirements.

Continuous Monitoring

bringing material external and internal change into an owned response workflow. Buyers should test the workflow against their own scope and evidence requirements.

Issue Remediation

assigning findings, deadlines, exceptions, and closure evidence. Buyers should test the workflow against their own scope and evidence requirements.

Fourth-Party Visibility

identifying and explaining important downstream dependencies. Buyers should test the workflow against their own scope and evidence requirements.

Regulatory Mapping

connecting program records to obligations and examination needs. Buyers should test the workflow against their own scope and evidence requirements.

Reporting

turning program activity into operator, executive, and board-ready information. Buyers should test the workflow against their own scope and evidence requirements.

Offboarding

closing access, data, evidence, and residual obligations when a relationship ends. Buyers should test the workflow against their own scope and evidence requirements.

What software cannot decide

Software can structure records, route work, preserve evidence, surface change, and support reporting. It cannot determine legal applicability, set risk appetite, negotiate accountable contract terms, validate every external claim, accept residual risk, or make management responsible for an outcome. Those remain organizational decisions.

Primary authority: HIPAA Security Rule.

Editorial boundary: Third Party Current summarizes the authority for market research. Readers should consult the official text and qualified counsel or specialists for applicability.