Business Associate Agreements

What Is a Business Associate

Under HIPAA, a business associate is a person or entity that performs functions or activities on behalf of a covered entity involving the use or disclosure of protected health information, such as a billing company, a cloud storage vendor, a transcription service, or a release of information vendor. Business associates are directly liable for certain HIPAA compliance obligations, not merely through their contractual relationship with the covered entity.

Purpose of the Business Associate Agreement

A Business Associate Agreement, or BAA, is a written contract required whenever a covered entity shares protected health information with a business associate. The BAA establishes the permitted and required uses of PHI and obligates the business associate to implement appropriate safeguards to protect the information.

Required BAA Provisions

  • Description of permitted and required uses and disclosures of PHI
  • Prohibition on using or disclosing PHI beyond what the agreement permits or law requires
  • Requirement to implement appropriate administrative, physical, and technical safeguards
  • Obligation to report breaches and security incidents to the covered entity
  • Requirement that any subcontractors agree to the same restrictions
  • Provision for return or destruction of PHI upon contract termination
  • Right for the covered entity to terminate the contract if the business associate materially violates its terms

Breach Responsibilities

If a business associate experiences a breach of unsecured PHI, it must notify the covered entity without unreasonable delay, and no later than 60 days after discovery. The covered entity generally retains ultimate responsibility for notifying affected individuals and HHS, though the BAA may delegate certain notification tasks to the business associate depending on the terms negotiated.

Subcontractor Requirements

Business associates that engage subcontractors to handle PHI on their behalf must enter into a subcontractor business associate agreement imposing the same restrictions and requirements found in the original BAA. This creates a chain of accountability extending HIPAA obligations through multiple layers of vendor relationships.

Termination Clauses

BAAs must specify that the covered entity may terminate the contract if it becomes aware of a pattern of activity or practice constituting a material breach of the business associate's obligations, unless reasonable steps to cure the breach are unsuccessful.

Ongoing Monitoring

Covered entities should maintain an inventory of all business associates, track BAA execution and renewal dates, and periodically assess business associate compliance, particularly for vendors handling large volumes of sensitive data or providing critical infrastructure services.

Ready to Start Studying?

Access 500+ flashcards, 30 mini exams, and 7 full-length practice exams.

Get Started Free

RHIApractice is not affiliated with or endorsed by AHIMA or Pearson VUE.