|
|
|
|
|
by athenot
3002 days ago
|
|
That's how it works with HIPAA. Patients interact with Covered Entities, and they can contract out to a third-party and sign a BAA. The third-party is then on the hook because if they fail at protecting data, the Covered Entity gets the sanction. |
|