Problem
The American Recovery and Reinvestment Act (ARRA) has increased the risk for a person or organization that is a HIPAA business associate. Before HIPAA. business associates operated under contract law with the covered entity, but now under ARRA, they are operating under a federal law. How do these changes make it risker to be a business associate? Are the HIPAA Security Rule requirements cumbersome for business associates? How?