Business Associates are now required to do a HIPAA risk assessment and remediate the risk.
**Key compliance actions for the new HIPAA privacy regulations** , Epstein Becker Green, Leah A. Roffman, Pamela D. Tyner and Patricia M. Wagner "In order to meet their responsibilities, business associates are now required to perform risk analyses. Such risk analyses must be accurate and thorough assessments of potential risks and vulnerabilities to the confidentiality, integrity, and availability of the electronic PHI that the business associate creates, receives, maintains, or transmits. The Security Rule also compels corrective actions to minimize any identified risks and vulnerabilities."
Posted May 9, 2013 by Jack Anderson