Security and privacy
The Business Associate Agreement, explained
What HIPAA requires every Business Associate Agreement (BAA) to say, in plain words, with the rule behind each line.
| Term | In plain words | Rule |
|---|---|---|
| Permitted uses | The business associate uses and shares patient information only as the BAA allows or the law requires. The BAA cannot allow anything the practice could not do itself, apart from the business associate's own management and administration and combining data for the practice's operations. | 45 CFR 164.504(e)(2)(i) and (ii)(A)1 |
| Safeguards | It protects the information with appropriate safeguards and follows the HIPAA Security Rule for electronic records. | 45 CFR 164.504(e)(2)(ii)(B)1; 164.314(a)(2)(i)(A)2 |
| Reporting | It tells the practice about any use or disclosure the BAA does not allow, any security incident, and any breach of unsecured patient information. | 45 CFR 164.504(e)(2)(ii)(C)1; 164.314(a)(2)(i)(C)2 |
| Vendors | Every vendor it uses that handles the information agrees to the same restrictions, in writing. | 45 CFR 164.504(e)(2)(ii)(D)1; 164.314(a)(2)(i)(B)2 |
| Patients' rights | It makes the information available so the practice can answer patients who ask to see or correct their records, or ask who their information was shared with. | 45 CFR 164.504(e)(2)(ii)(E) to (G)1 |
| The practice's own duties | It follows the Privacy Rule when it does a task that is the practice's own obligation. | 45 CFR 164.504(e)(2)(ii)(H)1 |
| Access for HHS | It opens its books and records about the information to HHS. | 45 CFR 164.504(e)(2)(ii)(I)1 |
| At the end | It returns or destroys all of the information and keeps no copies. If that is not feasible, it keeps protecting what is left and uses it only for the reason it could not be returned or destroyed. | 45 CFR 164.504(e)(2)(ii)(J)1 |
| Ending the agreement | The practice can end the agreement if the business associate breaks a material term. | 45 CFR 164.504(e)(2)(iii)1 |
HHS publishes sample BAA provisions and says they are only sample language; the parties can add stricter terms, such as a shorter window to report a breach.3
Why it works this way
A billing service is a business associate
A billing service that handles patient information for a practice is a HIPAA business associate.4
HHS can enforce many duties against us directly
HHS can enforce many HIPAA duties against a business associate directly, not only through the BAA.6
A BAA is not a certification
There is no official HIPAA certification. HHS does not issue one and does not recognize private ones.7
At the end, data is returned or destroyed
When the BAA ends, a business associate must return or destroy the practice's patient information and keep no copies; if that is not feasible, it must keep protecting it.1
Next question: who are you?
A new company, and what is true today.