Find & Ask Federal › this rule

45 CFR 164.314 — HIPAA Security Rule: Organizational requirements

FederalregulationU.S. Department of Health and Human Services (HHS), Office for Civil Rights· effective 2005-04-20

What this rule requires your agency to do

  • 1The group health plan's documents must be amended to require the plan sponsor to implement administrative, physical, and technical safeguards; ensure adequate separation is supported by security measures; ensure agents implement reasonable safeguards; and report security incidents to the plan (§ 164.314(b)(2)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)
  • 2A business associate contract must require the business associate to ensure that any subcontractors that handle electronic PHI agree to comply with the applicable Security Rule requirements via a compliant contract or arrangement (§ 164.314(a)(2)(i)(B)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)
  • 3The requirements for business associate contracts apply in the same manner to contracts or arrangements between a business associate and a subcontractor (§ 164.314(a)(2)(iii)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)
  • 4A group health plan (except in the narrow disclosure situations noted) must ensure its plan documents require the plan sponsor to reasonably and appropriately safeguard electronic PHI (§ 164.314(b)(1)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)
  • 5A covered entity's business associate contract or other arrangement required by § 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (ii), or (iii), as applicable (§ 164.314(a)(1)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)
  • 6A business associate contract must require the business associate to report to the covered entity any security incident of which it becomes aware, including breaches of unsecured PHI under § 164.410 (§ 164.314(a)(2)(i)(C)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)
  • 7A business associate contract must require the business associate to comply with the applicable requirements of the Security Rule subpart (§ 164.314(a)(2)(i)(A)).(45 CFR 164.314 — HIPAA Security Rule: Organizational requirements)

Applies to: cross-cutting

Sets the organizational requirements under the HIPAA Security Rule for business associate contracts (or other arrangements) and for group health plans. It requires that business associate contracts obligate the business associate to comply with the Security Rule, ensure subcontractor compliance, and report security incidents; and that group health plan documents require plan sponsors to safeguard electronic PHI.

Regulatory information, not legal advice — always confirm against the cited official source. Verification reduces error; it does not certify compliance.