Business Associate Agreement Advanced Provisions

The Purpose of a Business Associate Agreement

A business associate agreement, or BAA, is a written contract required between a covered entity and any business associate that creates, receives, maintains, or transmits PHI on the covered entity's behalf. The BAA establishes the permitted and required uses and disclosures of PHI and imposes HIPAA obligations directly on the business associate.

Required Provisions

  • A description of the permitted and required uses of PHI by the business associate
  • A prohibition on further use or disclosure other than as permitted by the contract or required by law
  • A requirement to implement appropriate safeguards to prevent unauthorized use or disclosure
  • A requirement to report breaches, security incidents, and any unauthorized use or disclosure to the covered entity
  • A requirement that subcontractors agree to the same restrictions and conditions
  • A requirement to make PHI available to satisfy patient access and amendment rights
  • A requirement to return or destroy PHI at contract termination when feasible

Advanced Provisions Worth Studying

Beyond the baseline required elements, sophisticated BAAs often address indemnification for breaches caused by the business associate, cyber liability insurance requirements, audit rights allowing the covered entity to assess the business associate's security controls, and specific breach notification timelines that may be shorter than the HIPAA default to give the covered entity adequate time to meet its own regulatory deadlines.

Subcontractor Chains

When a business associate engages a subcontractor that will also handle PHI, HIPAA requires that subcontractor to sign an agreement with terms at least as restrictive as those in the original BAA. This creates a chain of agreements that must be tracked, since liability can extend through multiple tiers of subcontracting relationships.

Direct Liability of Business Associates

Since the HITECH Act, business associates are directly liable for certain HIPAA violations, including impermissible uses and disclosures, failure to provide breach notification to the covered entity, and failure to comply with the Security Rule. This direct liability means OCR can investigate and penalize business associates independently of the covered entity.

Common Exam Traps

  1. Assuming a BAA is optional for entities that only incidentally encounter PHI, when in fact the determining factor is whether PHI is created, received, maintained, or transmitted on the covered entity's behalf
  2. Forgetting that subcontractors of business associates are themselves considered business associates
  3. Overlooking that a missing or outdated BAA is itself a common OCR enforcement finding

Key Takeaway

RHIA candidates should be comfortable identifying both the required BAA provisions and the practical risk-management terms sophisticated organizations add, along with understanding how direct liability extends through subcontractor chains.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.