Skip to main content
U.S. flag

An official website of the United States government

Return to Search

FAQ 390 Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?

This is guidance regarding business associates providing a Notice of Privacy Practices on their websites

Final

Issued by: Office for Civil Rights (OCR)

Does the HIPAA Privacy Rule require a business associate to create a notice of privacy practices?

Answer:

No. However, a covered entity must ensure through its contract with the business associate that the business associate's uses and disclosures of protected health information and other actions are consistent with the covered entity's privacy policies, as stated in covered entity's notice. Also, a covered entity may use a business associate to distribute its notice to individuals.

HHS is committed to making its websites and documents accessible to the widest possible audience, including individuals with disabilities. We are in the process of retroactively making some documents accessible. If you need assistance accessing an accessible version of this document, please reach out to the guidance@hhs.gov.

DISCLAIMER: The contents of this database lack the force and effect of law, except as authorized by law (including Medicare Advantage Rate Announcements and Advance Notices) or as specifically incorporated into a contract. The Department may not cite, use, or rely on any guidance that is not posted on the guidance repository, except to establish historical facts.