HIPAA Privacy and Security for Business Associates
45 min! Run Time
Employees
only
of Completion
What you'll learn
Description
This foundational course prepares business associate staff to meet their HIPAA obligations when handling protected health information.
What this course covers:
- Who qualifies as a business associate and how a Business Associate Agreement (BAA) applies
- Proper use and disclosure of protected health information (PHI) and individual rights of access
- Organizational and personal security best practices
- Breach notification requirements and HIPAA penalties and enforcement
- The 2024 HHS Final Rule strengthening PHI protections for reproductive health care
Ideal for frontline supervisors, workers, trainees, and volunteers at billing companies, transcription and consulting services, accounting firms, and subcontractors that operate as business associates.
Table of Contents
1. Introduction
2. HIPAA Basics
3. Using and Disclosing PHI
4. Individuals’ Rights of Access to PHI
5. Securing PHI
6. Breach Notification Rules
7. Enforcement
System Requirements
See System Requirements in the Coggno Knowledge Base
Author
HIPAA Privacy and Security for Business Associates
Frequently Asked Questions
The course defines this directly, along with how a Business Associate Agreement establishes what your organisation may do with a covered entity's PHI.
The contract governing your handling of a covered entity's protected health information. It sets terms you are bound by in addition to HIPAA itself.
Yes. It assumes no prior HIPAA training and prepares business associate staff to meet their obligations from the beginning.
The obligations differ. Business associates operate under agreements defining permitted uses, and their permitted disclosures are narrower.
Any staff member handling PHI on a client's behalf — often including technical and administrative roles that never see a patient.
The course provides a comprehensive foundation for understanding and complying with the HIPAA Privacy and Security Rules, with a specific focus on the unique responsibilities of business associates operating under a Business Associate Agreement (BAA). Learners will explore the proper use and disclosure of protected health information (PHI), individual rights of access to PHI, organizational and personal security best practices, breach notification requirements, and HIPAA penalty and enforcement provisions. Upon completion, employees will have the working knowledge needed to handle patient information appropriately and support their organization's compliance obligations under HIPAA.
This course has been updated to reflect the 2024 HHS Final Rule, which strengthens PHI protections related to reproductive health care. Following the Supreme Court's decision in Dobbs v. Jackson Women's Health Organization, HHS modified the Privacy Rule to limit the circumstances under which PHI related to reproductive health care may be used or disclosed for non-healthcare purposes — an update that applies equally to business associates handling such information.