Problem
The American Recovery and Reinvestment Act (ARRA) has increased the risk for a person or organization that is a HIPAA business associate. Before HIPAA. business associates operated under contract law with the covered entity, but now under ARRA, they are operating under a federal law.  How do these changes make it risker to be a business associate?  Are the HIPAA Security Rule requirements cumbersome for business associates? How?