Before the HITECH Act, the Privacy Rule did not directly govern business associates. However, the HITECH Act makes specific requirements of the Privacy Rule applicable to business associates and creates direct liability for non-compliance by business associates with those requirements.
The HITECH Act creates direct liability for uses and disclosures of PHI by business associates that do not comply with its business associate agreement (BAA) or other arrangement under the Privacy Rule.
Any Privacy Rule limitation on how a covered entity may use or disclose protected health information automatically extends to a business associate.