Security and privacy

The Business Associate Agreement, explained

What HIPAA requires every Business Associate Agreement (BAA) to say, in plain words, with the rule behind each line.

TABLE 1.What every BAA must say
TermIn plain wordsRule
Permitted usesThe business associate uses and shares patient information only as the BAA allows or the law requires. The BAA cannot allow anything the practice could not do itself, apart from the business associate's own management and administration and combining data for the practice's operations.45 CFR 164.504(e)(2)(i) and (ii)(A)1
SafeguardsIt protects the information with appropriate safeguards and follows the HIPAA Security Rule for electronic records.45 CFR 164.504(e)(2)(ii)(B)1; 164.314(a)(2)(i)(A)2
ReportingIt tells the practice about any use or disclosure the BAA does not allow, any security incident, and any breach of unsecured patient information.45 CFR 164.504(e)(2)(ii)(C)1; 164.314(a)(2)(i)(C)2
VendorsEvery vendor it uses that handles the information agrees to the same restrictions, in writing.45 CFR 164.504(e)(2)(ii)(D)1; 164.314(a)(2)(i)(B)2
Patients' rightsIt makes the information available so the practice can answer patients who ask to see or correct their records, or ask who their information was shared with.45 CFR 164.504(e)(2)(ii)(E) to (G)1
The practice's own dutiesIt follows the Privacy Rule when it does a task that is the practice's own obligation.45 CFR 164.504(e)(2)(ii)(H)1
Access for HHSIt opens its books and records about the information to HHS.45 CFR 164.504(e)(2)(ii)(I)1
At the endIt returns or destroys all of the information and keeps no copies. If that is not feasible, it keeps protecting what is left and uses it only for the reason it could not be returned or destroyed.45 CFR 164.504(e)(2)(ii)(J)1
Ending the agreementThe practice can end the agreement if the business associate breaks a material term.45 CFR 164.504(e)(2)(iii)1

HHS publishes sample BAA provisions and says they are only sample language; the parties can add stricter terms, such as a shorter window to report a breach.3

Why it works this way

  1. A billing service is a business associate

    A billing service that handles patient information for a practice is a HIPAA business associate.4

  2. The BAA comes before any patient data

    A practice may share patient information with a business associate only after a written BAA is in place.51

  3. Our vendors sign the same terms; you do not sign with them

    You do not sign with a business associate's vendors; the business associate must have a written BAA with each vendor that handles patient information.51

  4. HHS can enforce many duties against us directly

    HHS can enforce many HIPAA duties against a business associate directly, not only through the BAA.6

  5. A BAA is not a certification

    There is no official HIPAA certification. HHS does not issue one and does not recognize private ones.7

  6. At the end, data is returned or destroyed

    When the BAA ends, a business associate must return or destroy the practice's patient information and keep no copies; if that is not feasible, it must keep protecting it.1

Next question: who are you?

A new company, and what is true today.