
{"id":2378,"date":"2013-04-05T00:00:00","date_gmt":"2013-04-05T00:00:00","guid":{"rendered":"http:\/\/otava.test\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/"},"modified":"2013-04-05T00:00:00","modified_gmt":"2013-04-05T00:00:00","slug":"hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates","status":"publish","type":"post","link":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/","title":{"rendered":"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates"},"content":{"rendered":"<p id=\"internal-source-marker_0.5400900581630548\" dir=\"ltr\">Of the HIPAA data breaches reported in 2013 so far, nearly 40 percent have involved a business associate. A look at the overall percentage of business associate involvement with data breaches dating back to 2009 reveals that almost 30 percent played a role in the reported cases.<\/p>\n<p dir=\"ltr\">Clearly, the U.S. Dept. of Health and Human Services (HHS) has attempted to address the chronic issue by widening the HIPAA penalty net to include business associates and subcontractors this year, with the drop of the final omnibus rules that went into effect March 26 (with 180 days to be in compliance).<\/p>\n<p dir=\"ltr\">While business associates may have a new vested interest as they can be investigated and penalized directly by the Office for Civil Rights (OCR), covered entities also need to pay closer attention to their vendor contracts and security practices as they can be held liable for business associate and subcontractors as well.<\/p>\n<p dir=\"ltr\">Business associates of covered entities can no longer be overlooked &#8211; for every healthcare organization that touches protected health information (PHI), each vendor must undergo scrutiny of their <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">physical<\/a>, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">administrative<\/a> and <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/technical-security\">technical security<\/a>. When it comes to <a href=\"https:\/\/otavawebsite.wpengine.com\/compliance-security\/hipaa-compliant-cloud\/\">HIPAA hosting<\/a> providers, the three tiers of security involve:<\/p>\n<ul>\n<li dir=\"ltr\">\n<p dir=\"ltr\"><strong>Physical Security<\/strong> &#8211; Physical security adds one layer of security your data center should have in place to not only meet compliance standards, but to keep unauthorized users from accessing physical servers.<\/p>\n<\/li>\n<li dir=\"ltr\">\n<p dir=\"ltr\"><img loading=\"lazy\" decoding=\"async\" class=\"alignright\" title=\"HIPAA Administrative Security\" src=\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png\" alt=\"HIPAA Administrative Security\" width=\"216\" height=\"216\" \/><strong>Administrative Security<\/strong> &#8211; Administrative security includes the <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">audits<\/a>, <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/administrative-security\/policies\">policies<\/a>, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">staff training<\/a>, and, for HIPAA-specific requirements, <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">business associate training<\/a>. Equally important as ensuring the physical and technical security of your data environment, administrative security addresses the business-facing concerns of partnering with a third-party hosting provider.<\/p>\n<\/li>\n<\/ul>\n<ul>\n<li dir=\"ltr\">\n<p dir=\"ltr\"><strong>Technical Security<\/strong> &#8211; Secure hosting solutions require a multi-layered approach with the use of several different security tools. Not only do these tools help your company meet various compliance standards, but they also strengthen the security framework of your systems and minimize your overall risk of data loss. From <a href=\"https:\/\/www.onlinetech.com\/secure-hosting\/technical-security\/file-integrity-monitoring-fim\">file integrity monitoring<\/a> (FIM) to <a href=\"https:\/\/otavawebsite.wpengine.com\/solutions\/cloud-security\/\">web application firewalls<\/a> (WAF), protect your systems from unauthorized access.<\/p>\n<\/li>\n<\/ul>\n<p><strong>Just \u2018HIPAA-Friendly\u2019 or Actually \u2018HIPAA Compliant\u2019?<\/strong><br \/>\nOne example of a repeat business associate offender of HIPAA breaches is a case reported in January &#8211; a small web design company out of Boston, ClearPoint Design, was responsible for a breach that affected 15,000 individuals at three different healthcare organizations.<\/p>\n<p dir=\"ltr\">As the vendor contracted to host, maintain and monitor an online intake form for patients to request services, ClearPoint leased a dedicated server from Hosting.com to support the system. The Hosting.com server was hacked by an individual that modified the code on the website and diverted unencrypted payment data to a Gmail account. The hacker had gained administrative rights to the server housing PHI.<\/p>\n<p dir=\"ltr\">Hosting.com\u2019s website states they are \u2018HIPAA Business Associate Agreement friendly\u2019 and claims they can create a solution to help organizations meet HIPAA compliant requirements. However, they do not mention if they have undergone an independent HIPAA audit of their own facilities, and there is no word if their organization meets the physical, administrative or technical security requirements of HIPAA.<\/p>\n<p dir=\"ltr\">Case in point &#8211; to avoid being a statistic on the HHS Wall of Shame, covered entities must do a deep dive into their HIPAA hosting provider\u2019s audit reports. Check that they\u2019ve been audited to the latest <a href=\"https:\/\/www.onlinetech.com\/compliant-hosting\/hipaa-compliant-hosting\/resources\/hipaa-glossary-of-terms#OCRprotocol\">OCR HIPAA Audit Program Protocol<\/a>. Ask them which particular IT services can help them meet HIPAA compliant security standards. Ask about their documented policies and procedures, and ensure their employees are trained. Finally, review their business associate agreement (BAA) carefully, and never partner with a hosting provider that won\u2019t sign one.<\/p>\n<p>References:<br \/>\n<a href=\"https:\/\/www.cfpsych.org\/HIPAA-Breach-Letter.pdf\">Child &amp; Family Psychological Services, Inc. HIPAA Breach Letter<\/a> (PDF)<br \/>\n<a href=\"https:\/\/www.hosting.com\/managed-services\/security--compliance\/compliance\">Hosting.com: Compliance<\/a><br \/>\n<a href=\"https:\/\/www.hhs.gov\/ocr\/privacy\/hipaa\/administrative\/breachnotificationrule\/postedbreaches.html\">HHS: Breaches Affecting 500 or More Individuals<\/a><br \/>\n<a href=\"https:\/\/www.databreachtoday.com\/blogs\/small-firms-big-hipaa-troubles-p-1412\">Small Firms, Big HIPAA Troubles?<\/a><\/p>\n<p>Related Articles:<br \/>\n<em><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/hipaa-breach-lessons-learned-store-phi-in-hipaa-compliant-data-centers-not-locally\/\">HIPAA Breach Lessons Learned: Store PHI in HIPAA Compliant Data Centers; Not Locally<\/a><\/em><br \/>\nWhile no records were broken when it comes to number of health records disclosed per data breach, the top HIPAA breaches of last year still come with some hard lessons learned about technical and physical security. Learn from their mistakes \u2026 <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/hipaa-breach-lessons-learned-store-phi-in-hipaa-compliant-data-centers-not-locally\/\">Continue reading \u2192<\/a><\/p>\n<p><em><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/interview-hipaa-rules-effective-starting-today-is-your-hipaa-hosting-provider-prepared\/\">Interview: HIPAA Rules Effective Starting Today \u2013 Is Your HIPAA Hosting Provider Prepared?<\/a><\/em><br \/>\nThe Web Host Industry Review (WHIR) recently featured a Q&amp;A with Online Tech\u2019s Director of Healthcare Vertical discussing the recent regulations that take effect today, March 26. The new HIPAA rules affect HIPAA hosting providers, as they are considered business \u2026 <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/interview-hipaa-rules-effective-starting-today-is-your-hipaa-hosting-provider-prepared\/\">Continue reading \u2192<\/a><\/p>\n<p><em><a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/hipaa-in-a-hitech-world-hipaa-violations-on-the-rise-according-to-director-of-ocr\/\">HIPAA in a HITECH World: HIPAA Violations on the Rise, According to Director of OCR<\/a><\/em><br \/>\nLeon Rodriguez, Director Office for Civil Rights, U.S. Department of Health and Human Services shared unexpected insights from early analysis of breach statistics and the audit pilot at the American Healthcare Lawyers Association conference, HIPAA in a HITECH World, along \u2026 <a href=\"https:\/\/otavawebsite.wpengine.com\/blog\/hipaa-in-a-hitech-world-hipaa-violations-on-the-rise-according-to-director-of-ocr\/\">Continue reading \u2192<\/a><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Of the HIPAA data breaches reported in 2013 so far, nearly 40 percent have involved a business associate. A look at the overall percentage of business associate involvement with data breaches dating back to 2009 reveals that almost 30 percent played a role in the reported cases. Clearly, the U.S. Dept. of Health and Human Services (HHS) has attempted to address the chronic issue by widening the HIPAA penalty net to include business associates and subcontractors this year, with the drop of the final omnibus rules that went into effect March 26 (with 180 days to be in compliance). While business associates may have a new vested interest as they can be investigated and penalized directly by the Office for Civil Rights (OCR), covered entities also need to pay closer attention to their vendor contracts and security practices as they can be held liable for business associate and subcontractors as well. Business associates of covered entities can no longer be overlooked &#8211; for every healthcare organization that touches protected health information (PHI), each vendor must undergo scrutiny of their physical, administrative and technical security. When it comes to HIPAA hosting providers, the three tiers of security involve: Physical Security &#8211;&#8230;<\/p>\n","protected":false},"author":3,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"_acf_changed":false,"footnotes":""},"categories":[1],"tags":[],"other_category":[],"class_list":["post-2378","post","type-post","status-publish","format-standard","hentry","category-uncategorized"],"acf":[],"yoast_head":"<!-- This site is optimized with the Yoast SEO Premium plugin v27.2 (Yoast SEO v27.2) - https:\/\/yoast.com\/product\/yoast-seo-premium-wordpress\/ -->\n<title>HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates | OTAVA<\/title>\n<meta name=\"description\" content=\"The overall percentage of business associate\u00a0involvement with data breaches dating back to 2009 reveals that almost 30% played a role in the reported cases.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\" \/>\n<meta property=\"og:locale\" content=\"en_US\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates\" \/>\n<meta property=\"og:description\" content=\"The overall percentage of business associate\u00a0involvement with data breaches dating back to 2009 reveals that almost 30% played a role in the reported cases.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\" \/>\n<meta property=\"og:site_name\" content=\"OTAVA\" \/>\n<meta property=\"article:published_time\" content=\"2013-04-05T00:00:00+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png\" \/>\n<meta name=\"author\" content=\"Irma Brillantes\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:label1\" content=\"Written by\" \/>\n\t<meta name=\"twitter:data1\" content=\"Irma Brillantes\" \/>\n\t<meta name=\"twitter:label2\" content=\"Est. reading time\" \/>\n\t<meta name=\"twitter:data2\" content=\"4 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"Article\",\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#article\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\"},\"author\":{\"name\":\"Irma Brillantes\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\"},\"headline\":\"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates\",\"datePublished\":\"2013-04-05T00:00:00+00:00\",\"mainEntityOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\"},\"wordCount\":805,\"commentCount\":0,\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png\",\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"CommentAction\",\"name\":\"Comment\",\"target\":[\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#respond\"]}]},{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\",\"url\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\",\"name\":\"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates | OTAVA\",\"isPartOf\":{\"@id\":\"https:\/\/www.otava.com\/#website\"},\"primaryImageOfPage\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage\"},\"thumbnailUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png\",\"datePublished\":\"2013-04-05T00:00:00+00:00\",\"description\":\"The overall percentage of business associate\u00a0involvement with data breaches dating back to 2009 reveals that almost 30% played a role in the reported cases.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#breadcrumb\"},\"inLanguage\":\"en-US\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/\"]}]},{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\/\/www.otava.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.otava.com\/#website\",\"url\":\"https:\/\/www.otava.com\/\",\"name\":\"OTAVA\u00ae\",\"description\":\"\",\"publisher\":{\"@id\":\"https:\/\/www.otava.com\/#organization\"},\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.otava.com\/?s={search_term_string}\"},\"query-input\":{\"@type\":\"PropertyValueSpecification\",\"valueRequired\":true,\"valueName\":\"search_term_string\"}}],\"inLanguage\":\"en-US\"},{\"@type\":\"Organization\",\"@id\":\"https:\/\/www.otava.com\/#organization\",\"name\":\"OTAVA\u00ae\",\"url\":\"https:\/\/www.otava.com\/\",\"logo\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\",\"url\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"contentUrl\":\"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg\",\"caption\":\"OTAVA\u00ae\"},\"image\":{\"@id\":\"https:\/\/www.otava.com\/#\/schema\/logo\/image\/\"}},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263\",\"name\":\"Irma Brillantes\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"en-US\",\"@id\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g\",\"caption\":\"Irma Brillantes\"},\"url\":\"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/\"}]}<\/script>\n<!-- \/ Yoast SEO Premium plugin. -->","yoast_head_json":{"title":"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates | OTAVA","description":"The overall percentage of business associate\u00a0involvement with data breaches dating back to 2009 reveals that almost 30% played a role in the reported cases.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/","og_locale":"en_US","og_type":"article","og_title":"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates","og_description":"The overall percentage of business associate\u00a0involvement with data breaches dating back to 2009 reveals that almost 30% played a role in the reported cases.","og_url":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/","og_site_name":"OTAVA","article_published_time":"2013-04-05T00:00:00+00:00","og_image":[{"url":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png","type":"","width":"","height":""}],"author":"Irma Brillantes","twitter_card":"summary_large_image","twitter_misc":{"Written by":"Irma Brillantes","Est. reading time":"4 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"Article","@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#article","isPartOf":{"@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/"},"author":{"name":"Irma Brillantes","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263"},"headline":"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates","datePublished":"2013-04-05T00:00:00+00:00","mainEntityOfPage":{"@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/"},"wordCount":805,"commentCount":0,"publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"image":{"@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage"},"thumbnailUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png","inLanguage":"en-US","potentialAction":[{"@type":"CommentAction","name":"Comment","target":["https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#respond"]}]},{"@type":"WebPage","@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/","url":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/","name":"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates | OTAVA","isPartOf":{"@id":"https:\/\/www.otava.com\/#website"},"primaryImageOfPage":{"@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage"},"image":{"@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage"},"thumbnailUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png","datePublished":"2013-04-05T00:00:00+00:00","description":"The overall percentage of business associate\u00a0involvement with data breaches dating back to 2009 reveals that almost 30% played a role in the reported cases.","breadcrumb":{"@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#breadcrumb"},"inLanguage":"en-US","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/"]}]},{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#primaryimage","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2019\/04\/business-associate-training.png"},{"@type":"BreadcrumbList","@id":"https:\/\/www.otava.com\/blog\/hhs-wall-of-shame-40-percent-of-2013-hipaa-breaches-involve-business-associates\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Home","item":"https:\/\/www.otava.com\/"},{"@type":"ListItem","position":2,"name":"HHS Wall of Shame: Forty Percent of 2013 HIPAA Breaches Involved Business Associates"}]},{"@type":"WebSite","@id":"https:\/\/www.otava.com\/#website","url":"https:\/\/www.otava.com\/","name":"OTAVA\u00ae","description":"","publisher":{"@id":"https:\/\/www.otava.com\/#organization"},"potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.otava.com\/?s={search_term_string}"},"query-input":{"@type":"PropertyValueSpecification","valueRequired":true,"valueName":"search_term_string"}}],"inLanguage":"en-US"},{"@type":"Organization","@id":"https:\/\/www.otava.com\/#organization","name":"OTAVA\u00ae","url":"https:\/\/www.otava.com\/","logo":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/","url":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","contentUrl":"https:\/\/www.otava.com\/wp-content\/uploads\/2025\/03\/otava-logo.svg","caption":"OTAVA\u00ae"},"image":{"@id":"https:\/\/www.otava.com\/#\/schema\/logo\/image\/"}},{"@type":"Person","@id":"https:\/\/www.otava.com\/#\/schema\/person\/35774075f8f4fcdd4eae80cb72034263","name":"Irma Brillantes","image":{"@type":"ImageObject","inLanguage":"en-US","@id":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","url":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/d5251bebc1699793a698d1a6158603cb3cdc50a095a12357e42d415b3e5546c2?s=96&d=mm&r=g","caption":"Irma Brillantes"},"url":"https:\/\/www.otava.com\/blog\/author\/ibrillantesotava-com\/"}]}},"_links":{"self":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2378","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/users\/3"}],"replies":[{"embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/comments?post=2378"}],"version-history":[{"count":0,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/posts\/2378\/revisions"}],"wp:attachment":[{"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/media?parent=2378"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/categories?post=2378"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/tags?post=2378"},{"taxonomy":"other_category","embeddable":true,"href":"https:\/\/www.otava.com\/wp-json\/wp\/v2\/other_category?post=2378"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}