Title 42 › Chapter 156— HEALTH INFORMATION TECHNOLOGY › Subchapter III— PRIVACY › Part A— Improved Privacy Provisions and Security Provisions › § 17931
Make the security rules in 45 C.F.R. 164.308, 164.310, 164.312, and 164.316 apply to a business associate the same way they apply to a covered entity. Any other security requirements that apply to covered entities must also apply to business associates and must be included in the contract between them. If a business associate breaks those security rules, the penalty rules in sections 1320d–5 and 1320d–6 apply to that business associate the same as to a covered entity. Starting the first year after February 17, 2009, and every year after, the HHS Secretary must consult stakeholders and issue guidance on technical safeguards, including standards under section 300jj–12(b)(2)(B)(vi) (added by section 13101), as they were in effect before February 17, 2009.
Full Legal Text
The Public Health and Welfare — Source: USLM XML via OLRC
Legislative History
Reference
Citation
42 U.S.C. § 17931
Title 42 — The Public Health and Welfare
Last Updated
Apr 5, 2026
Release point: 119-73not60