انتقل إلى المحتوى الرئيسي
DocumentMS

Glossary

Business associate agreement

Also called: BAA

A business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf. It allocates responsibility for safeguards, for breach reporting, and for the uses that are permitted at all.

Business associate agreement explained

Who needs one

Any vendor that handles protected health information for a covered entity, which includes document management, hosting, backup and support providers. It is a legal requirement rather than a negotiating position, and a vendor unwilling to execute one cannot lawfully be used for PHI.

What it must address

Permitted uses and disclosures, a commitment to safeguards under the Security Rule, reporting of unauthorised use or disclosure, flow-down obligations to subcontractors, availability of records to the Department of Health and Human Services, and return or destruction of PHI at termination.

Subcontractor flow-down

The obligations extend down the chain. A business associate that engages a sub-processor must bind it to equivalent terms, which is why a published sub-processor list matters as much here as under the GDPR — the covered entity carries accountability for parties it never contracted with.

Breach reporting timing

The agreement should state a specific period rather than relying on "without unreasonable delay", because the covered entity's own 60-day notification clock under HITECH runs from discovery and it cannot start on time if the vendor reports late.

Why hesitation is informative

A vendor that treats a BAA as an unusual request has probably not handled regulated health data before. That is not disqualifying, but it changes what the security review should examine.

FAQ

Business associate agreement: common questions

Does a BAA replace a data processing addendum?

No — they cover different regimes and are usually both required where an organisation handles both PHI and personal data of EU or UK residents. They can be executed as separate addenda to one agreement.

Is a BAA needed if data is encrypted?

Yes. Encryption affects breach notification analysis; it does not remove business associate status, because the vendor still maintains the information.

جلسة من ثلاثين دقيقة مع مهندس حلول، على بنية مجلدات وسلسلة اعتماد تشبه ما لديك — لا بيئة عرض عامة.