Title 42 › Chapter CHAPTER 156— - HEALTH INFORMATION TECHNOLOGY › Subchapter SUBCHAPTER III— - PRIVACY › Part Part A— - Improved Privacy Provisions and Security Provisions › § 17931
Business associates must follow the security rules in 45 C.F.R. 164.308, 164.310, 164.312, and 164.316 just like covered entities. Other security requirements that apply to covered entities must be put into the contract between the covered entity and the business associate. If a business associate breaks these security rules, sections 1320d–5 and 1320d–6 apply to the business associate the same as to a covered entity. Starting one year after February 17, 2009, and every year after, the Secretary of Health and Human Services must consult stakeholders and publish guidance on the best technical safeguards to meet these rules. The guidance must include standards developed under section 300jj–12(b)(2)(B)(vi) as added by section 13101, as they stood the day before February 17, 2009.
Full Legal Text
The Public Health and Welfare — Source: USLM XML via OLRC
Legislative History
Reference
Citation
42 U.S.C. § 17931
Title 42 — The Public Health and Welfare
Last Updated
Apr 6, 2026
Release point: 119-73