What three notifications from the Covered Entity trigger compliance requirements for the Healthsource Chiropractic Business Associate regarding PHI?
Healthsource_Chiropractic Franchise · 2025 FDDAnswer from 2025 FDD Document
-
- Requirements of Covered Entity to Inform Business Associate. Business Associate shall only be required to comply with the respective limitation, restriction or changes and/or revocation if Covered Entity notifies Business Associate of (1) any limitation in the notice of privacy practices, (2) any restriction on the use of disclosure of PHI that Covered Entity has agreed to or is required to abide by, and (3) any changes in, or revocation of, the permission by an individual to use or disclose his or her PHI.
Source: Item 23 — Receipts (FDD pages 77–282)
What This Means (2025 FDD)
According to the 2025 Healthsource Chiropractic FDD, the Business Associate (HealthSource Chiropractic, LLC) must comply with specific limitations, restrictions, or changes only when the Covered Entity (the franchisee) provides notification of certain events. These notifications are critical for maintaining HIPAA compliance.
The three specific notifications that trigger compliance requirements for the Healthsource Chiropractic Business Associate are: (1) any limitation in the notice of privacy practices, (2) any restriction on the use of disclosure of PHI that the Covered Entity has agreed to or is required to abide by, and (3) any changes in, or revocation of, the permission by an individual to use or disclose his or her PHI.
This means that the Healthsource Chiropractic franchisee must promptly inform HealthSource Chiropractic, LLC of any changes to patient privacy practices, restrictions on PHI use, or revocations of permission to use or disclose PHI. Failure to do so could result in non-compliance with HIPAA regulations, potentially leading to penalties or termination of the franchise agreement. It is the franchisee's responsibility to keep the Business Associate informed of these changes to ensure both parties remain compliant with HIPAA.