Healthcare Breaches

Healthcare Data Breach: Allocating Fault Between Covered Entities and Business Associates

When protected health information is exposed through a vendor's systems, determining who bears what share of legal and financial responsibility requires careful analysis of contract, regulation, and practical control.

Law & Forensics LLCSeptember 7, 20268 min read

The Core Problem in Every HIPAA Breach Dispute

When a vendor entrusted with protected health information suffers a security failure, two parties immediately find themselves in a dispute that is simultaneously regulatory, contractual, and reputational: the covered entity that collected and is ultimately accountable for patient data, and the business associate whose systems, personnel, or processes were the proximate site of the breach. Each side carries genuine exposure, and neither can simply assign the entirety of blame to the other by pointing at the Business Associate Agreement. The dynamics of a healthcare data breach dispute are therefore more layered than most commercial technology disputes.

At the center of every such dispute sits the Business Associate Agreement, or BAA — the contractually mandated instrument under HIPAA that allocates permitted uses, required safeguards, and, critically, response obligations between the parties. Practitioners who approach vendor data breach mediation without a precise understanding of what the BAA does and does not resolve will find themselves unprepared for the arguments that emerge. The BAA is not a liability waiver; it is a floor of obligations, and the question of whether either party met that floor is almost always contested on multiple dimensions.

A HIPAA breach dispute rarely resolves on a single theory. The covered entity may contend that the business associate's failure to implement required technical safeguards caused the breach and that indemnification under the BAA follows automatically. The business associate may counter that the covered entity's own configuration choices, inadequate scoping of the engagement, or delay in issuing incident-response instructions contributed materially to the harm. Both arguments can be simultaneously valid, which is exactly why structured, confidential resolution through a neutral is often more efficient than adversarial litigation.

In plain terms

When a vendor loses patient data, both the healthcare organization and the vendor are legally on the hook — and they usually disagree about how much each owes. The contract between them (a BAA) sets some rules, but it rarely resolves everything.

The BAA is not a liability waiver; it is a floor of obligations, and whether either party met that floor is almost always contested on multiple dimensions.

What the Business Associate Agreement Actually Governs — and What It Leaves Open

A Business Associate Agreement must, at minimum, specify the permitted uses of protected health information, require the business associate to implement safeguards equivalent to those the covered entity itself must maintain under the Security Rule, and obligate the business associate to report any breach or security incident to the covered entity within a defined timeframe. These are regulatory minimums. The commercial terms layered on top — indemnification caps, consequential-damages waivers, duty-to-defend provisions, choice of law — are purely contractual and vary enormously across healthcare vendor relationships.

The gap between regulatory minimum and commercial reality is where most disputes live. A business associate may have complied with every technical safeguard enumerated in the BAA and still experienced a breach because threat actors exploited a zero-day vulnerability that neither party anticipated. In that posture, the business associate will argue that it satisfied its contractual obligations and that the covered entity cannot seek indemnification for an unforeseeable risk the BAA did not specifically address. The covered entity will counter that the Security Rule's requirement of 'reasonable and appropriate' safeguards is not satisfied merely by checking enumerated boxes, and that the business associate's failure to conduct adequate risk analysis contributed to the exposure.

Indemnification provisions in BAAs are frequently drafted with limitations that become fiercely contested when actual breach costs arrive. Caps tied to annual contract value may bear no rational relationship to notification costs, regulatory exposure, or harm suffered by individuals whose protected health information was compromised. When those caps are reached quickly — as they often are in large healthcare data breach events — the covered entity must decide whether to pursue the business associate beyond the cap, and the business associate must decide how aggressively to assert that the cap is the exclusive remedy. Both of those decisions benefit from a candid neutral assessment before litigation costs compound the underlying loss.

In plain terms

The BAA sets minimum rules, but the real money fight is in the commercial terms layered on top — indemnification caps, damage waivers, and who pays defense costs. Those commercial terms almost never match the real costs of a breach.

The gap between regulatory minimum and commercial reality is where most disputes live.

Control, Configuration, and the Shared-Fault Problem

One of the most practically significant questions in any business associate liability dispute is the degree to which the covered entity exercised operational control over the environment where the breach occurred. If a covered entity specifies the architecture, maintains administrative credentials, or retains the right to audit and direct the business associate's security controls, it has implicitly assumed a share of the risk that attaches to those controls. This is not a theoretical concern — it arises routinely in cloud-based electronic health record deployments, revenue cycle management arrangements, and managed security services where the boundary between the covered entity's obligations and the business associate's obligations is deliberately blurred by commercial convenience.

Configuration errors are a particularly fertile source of shared-fault arguments. If the business associate administered the environment but the covered entity controlled the user access provisioning, an over-permissioned account that enabled lateral movement by an attacker implicates both parties. The business associate will note that it could not restrict access it was not authorized to touch; the covered entity will note that it relied on the business associate's recommendations. Untangling these contributions requires a forensic timeline developed by a neutral technical expert — ideally one operating under a framework that preserves the confidentiality of findings while still giving both sides enough factual grounding to negotiate meaningfully.

The work-product doctrine and attorney-client privilege both bear on how that forensic work is commissioned and used. If the business associate's incident-response investigation is conducted without the involvement of counsel, its findings may be discoverable in subsequent litigation, and those findings may be used by the covered entity to establish the business associate's fault. Conversely, if both parties jointly commission a neutral forensic expert through mediation, the findings can be structured to inform settlement discussions without creating a weapon for one side to use against the other. This architecture of protected neutral analysis is one of the most underappreciated advantages of resolving these disputes through vendor data breach mediation.

In plain terms

When both parties had some control over the breached system, responsibility gets shared. Who configured what, who had credentials, and who made security decisions all matter — and a neutral technical expert is usually needed to sort it out fairly.

Notification Obligations, Timing, and the Delay Dispute

HIPAA's breach notification framework imposes obligations on both covered entities and business associates, and the sequencing of those obligations creates its own category of inter-party dispute. The business associate is required to notify the covered entity of a breach — or a security incident that may constitute a breach — within a contractually specified period that cannot exceed sixty calendar days from discovery. The covered entity then bears the obligation to notify affected individuals, the Secretary, and, in some cases, prominent media outlets, within sixty days of the covered entity's own discovery.

What 'discovery' means in this context is contested with surprising frequency. A business associate that detected anomalous network activity but did not classify the event as a breach until its forensic investigation was complete will argue that its notification clock did not begin until the classification decision. The covered entity, having learned of the anomalous activity informally before the formal notification, may argue that its own clock was already running — and that the business associate's investigation timeline improperly extended it. These competing discovery dates translate directly into arguments about which party caused a notification delay and which party therefore bears regulatory exposure.

Notification delay disputes are among the most difficult to resolve bilaterally because each party's position is partly defensive. Acknowledgment that notification should have occurred earlier is an admission that bears on both regulatory and civil exposure. A structured mediation process, operating under Federal Rule of Evidence 408, provides the confidential space in which both parties can acknowledge timeline facts candidly, explore what a good-faith investigation actually required, and reach a shared account of events that serves as the foundation for a negotiated allocation — rather than a foundation for further litigation.

In plain terms

HIPAA has strict deadlines for telling patients about a breach. When those deadlines are missed, the two parties usually disagree about whose fault the delay was — and that fight has real regulatory consequences for both.

Acknowledgment that notification should have occurred earlier is an admission that bears on both regulatory and civil exposure.

Expert Evidence and the Standards-of-Care Problem

Disputes about whether a business associate implemented 'reasonable and appropriate' safeguards are, at bottom, disputes about standards of care — and those disputes require expert testimony to resolve. Under the framework established by Federal Rule of Evidence 702 and the reliability standards associated with Daubert v. Merrell Dow Pharmaceuticals, an expert opining that a business associate's security controls fell below industry norms must ground that opinion in a reliable methodology, not simply professional intuition or experience alone.

The practical difficulty in healthcare data breach disputes is that standards of care for information security are not codified with the precision of, say, clinical practice guidelines. They are assembled from regulatory guidance, industry frameworks, and the evolving practice of peer organizations — none of which are static or universally agreed upon. A business associate that implemented controls consistent with one widely recognized framework may have neglected controls emphasized by another. A covered entity that failed to audit the business associate's implementation may have satisfied its own BAA obligations on paper while effectively abandoning the oversight function that gives the BAA meaning. Expert witnesses on both sides will narrate these tensions in ways that favor their retaining party, and a neutral forensic expert appointed through mediation can provide a more balanced reference point for evaluating those narratives.

The admissibility and reliability of expert opinions also intersects with the authentication requirements of Federal Rule of Evidence 901 when the evidence underlying the opinion consists of logs, packet captures, or system artifacts. The integrity of digital evidence — its chain of custody, its completeness, and the accuracy of the tools used to analyze it — is routinely challenged when a party believes the forensic record disadvantages it. A neutral's role in assessing those challenges before they become courtroom battles saves both parties from a costly and unpredictable detour.

In plain terms

To prove who fell short on security, both sides need experts. Courts require those experts to use sound methods, not just opinions — and experts hired by each side often reach opposite conclusions. A neutral expert helps cut through that.

Structuring a Mediated Resolution: From Impasse to Durable Agreement

The structural challenge in mediating a HIPAA breach dispute between a covered entity and its business associate is that the parties are not simply adversaries — they are, or recently were, commercial partners with ongoing contractual obligations, shared regulatory exposure, and, in many cases, a continuing need for the underlying services. A mediated resolution that destroys the relationship without adequately compensating either party for its concessions is not durable. Conversely, a resolution that papers over genuine fault findings without calibrating the allocation to actual responsibility is not fair.

Mediations in this space tend to organize around four workstreams: establishing a factual account of the breach and its causes; assessing what the BAA actually requires of each party in the circumstances that obtained; valuing the components of loss, including notification costs, regulatory exposure, and harm to individuals; and negotiating the allocation of those losses against the backdrop of the factual and legal analysis. Federal Rule of Civil Procedure 26 governs the exchange of expert materials in litigation, but in mediation the parties can agree on a more targeted and efficient disclosure protocol that gives the neutral sufficient factual grounding without full litigation-style discovery.

Where the business associate dispute is embedded in broader class or multi-claimant litigation, the court may appoint a special master under Federal Rule of Civil Procedure 53 to manage discovery and assist with settlement proceedings. In that posture, the neutral serves a dual function — managing the information flow between parties and providing assessments that help the court evaluate proposed resolutions. Standing alone, a pre-litigation mediation of a covered entity and business associate dispute can achieve a resolution far more efficiently, and the confidentiality protections of Federal Rule of Evidence 408 mean that positions taken in mediation do not become admissions in subsequent proceedings if negotiations break down.

In plain terms

A good mediated resolution covers four things: what actually happened, what the contract required, what the losses actually were, and how to split them fairly. Getting there is faster and cheaper than litigation, and what's said in mediation stays there.

A resolution that papers over genuine fault findings without calibrating the allocation to actual responsibility is not fair.

Frequently asked

Can a covered entity seek indemnification from a business associate even if the BAA has a liability cap?
The BAA's liability cap governs what is recoverable under the contract, but a covered entity may assert claims outside the contract — in tort or under other legal theories — that are not subject to the contractual cap. Whether those extra-contractual claims survive depends on the governing law, the scope of the cap provision, and whether the parties intended it as an exclusive remedy. This is a frequently litigated point in healthcare data breach disputes, and it is often a central issue in mediation because each side's willingness to settle depends heavily on the realistic ceiling of extra-contractual exposure.
What happens if the business associate discovers the breach but delays notifying the covered entity?
A business associate that delays notification beyond the period specified in the BAA — and in any event beyond the HIPAA regulatory maximum — has breached both its contractual and regulatory obligations. The covered entity may assert that the delay caused it to incur additional notification costs, miss its own regulatory deadlines, or suffer reputational harm that earlier action would have mitigated. The business associate will typically defend on the grounds that its investigation timeline was reasonable and that notification before the investigation was complete would have been premature and potentially misleading. Both positions have merit in specific factual contexts, which is why a neutral assessment of the actual investigation timeline is so valuable.
Is the forensic investigation report protected from disclosure in a HIPAA breach dispute?
The protection of forensic investigation reports depends on how the investigation was commissioned and conducted. If counsel directed the investigation for purposes of providing legal advice or litigation preparation, the work-product doctrine and attorney-client privilege under Upjohn Co. v. United States and the principles of Hickman v. Taylor may protect the report from compelled disclosure. If the investigation was conducted primarily for regulatory compliance or business purposes, those protections are much weaker. Parties who want to protect the investigation record should structure the engagement through counsel from the outset, before the investigation begins.
How does vendor data breach mediation differ from ordinary commercial mediation in this context?
Healthcare data breach mediation between a covered entity and a business associate differs from ordinary commercial mediation in several respects. The regulatory overlay of HIPAA means that certain obligations cannot be waived or modified by private agreement — a mediated resolution that purports to excuse conduct that independently violates regulatory requirements does not eliminate regulatory exposure. Additionally, the technical complexity of the underlying facts typically requires a mediator or neutral with sufficient forensic literacy to assess the competing expert narratives. Finally, the ongoing commercial relationship between the parties, and the possibility of future breach events, means that a durable resolution often includes prospective remediation commitments, not just…
Can protected health information be shared with the neutral during mediation without violating HIPAA?
HIPAA's Privacy Rule recognizes several pathways for disclosing protected health information without individual authorization, including disclosures required by law and disclosures for judicial and administrative proceedings. A mediation convened under court order or a formal dispute resolution agreement will typically qualify under one or more of these pathways. Even in private pre-litigation mediation, the parties can structure their data-sharing arrangements to minimize the amount of identifiable information the neutral actually receives — using de-identified records, aggregate counts, or representative samples — while still giving the neutral sufficient factual grounding to provide useful assessments.

Analysis is based on publicly available regulatory frameworks and professional standards; no client matters or confidential proceedings are referenced.

Bring the dispute before the scales.

A confidential scoping call and conflicts check follow — without obligation.

This piece concerns vendor and supply-chain breach allocation mediation. Read how these matters are handled, or send yours directly.

The Breach Docket

Keep reading the docket

The Breach Docket collects recent data-breach decisions and notable settlements, read the way a neutral reads them. Free, every other week.

No advertising. Unsubscribe in one click.