Business associate agreement
This document is a Business Associate Agreement (BAA) template designed to help covered entities and business associates comply with HIPAA regulations. It outlines the responsibilities and obligations of each party regarding the protection of Protected Health Information (PHI). The template covers essential clauses such as the definition of PHI, permitted uses and disclosures, safeguards, reportin
- Personalized with your details
- Word & PDF
- Legally compliant
- Reviewed by professionals
Business Associate Agreement Template: Ensure HIPAA Compliance
A Business Associate Agreement (BAA) is a critical document mandated by the Health Insurance Portability and Accountability Act (HIPAA). It is a legally binding contract between a covered entity and a business associate that outlines how Protected Health Information (PHI) will be protected. Using a well-structured template is the first step toward ensuring compliance and safeguarding sensitive data.
What is a Business Associate Agreement (BAA)?
The purpose of a business associate agreement is to ensure that any third-party vendor or contractor that handles, processes, or has access to PHI on behalf of a covered entity agrees to protect that information in accordance with HIPAA rules. This contract establishes the permitted uses and disclosures of PHI and details the safeguards the business associate must implement. It is not merely a formality but a foundational component of a covered entity's HIPAA compliance program.
Who needs a Business Associate Agreement?
A BAA is required whenever a covered entity (like a healthcare provider, health plan, or healthcare clearinghouse) engages the services of a business associate. Identifying who needs a Business Associate Agreement is essential. Common examples of business associates include:
- Medical billing companies and transcription services.
- Cloud storage providers hosting PHI.
- IT consultants and managed service providers with access to systems containing PHI.
- Legal, accounting, and consulting firms that may handle PHI in the course of their work.
- Third-party administrators and pharmacy benefit managers.
Essentially, any external person or entity that performs activities or services involving the use or disclosure of PHI for a covered entity is likely a business associate and requires a BAA.
Key components of a BAA template
A robust Business Associate Agreement template should address all necessary elements to create a HIPAA compliant business associate agreement. Key sections include:
- Definitions: Clearly defines terms like "Protected Health Information (PHI)," "Breach," and "Business Associate."
- Permitted Uses and Disclosures: Specifies exactly how the business associate may use or disclose PHI, typically limited to performing its services for the covered entity or as required by law.
- Safeguards: Obligates the business associate to implement appropriate administrative, physical, and technical safeguards to protect PHI, mirroring HIPAA's Security Rule requirements.
- Reporting: Requires the business associate to report any security incident, use or disclosure not permitted by the agreement, or breach of unsecured PHI to the covered entity.
- Subcontractors: Stipulates that if the business associate hires subcontractors who will handle PHI, those subcontractors must also agree to the same protections through a written agreement.
- Access to Information: Details the business associate's obligation to provide access to PHI for individuals (to support the covered entity's obligation under HIPAA's Privacy Rule) and for audits by the Department of Health and Human Services (HHS).
- Term and Termination: Defines the agreement's duration and the process for termination, including the requirement to return or destroy all PHI upon termination.
How to fill out a BAA template
Using a Business Associate Agreement template effectively requires careful attention. Follow these general steps:
- Identify the Parties: Accurately insert the legal names and addresses of the Covered Entity and the Business Associate.
- Define the Services: Clearly describe the services the business associate is providing. This context is crucial for defining the scope of permitted PHI use.
- Review and Customize Clauses: While a template provides a standard framework, certain clauses may need tailoring. Pay close attention to the indemnification, liability, and insurance sections.
- Specify Addresses for Notices: Ensure the addresses for sending formal notices, especially breach notifications, are correct and reliable.
- Execution: The agreement must be signed by authorized representatives of both parties. Retain fully executed copies for your records.
HIPAA compliance requirements for BAAs
Yes, business associates have to comply with HIPAA directly. The HITECH Act made business associates directly liable for compliance with certain HIPAA provisions. A BAA does not just pass liability; it contractually obligates the business associate to protect PHI. The Office for Civil Rights (OCR) can audit both covered entities and business associates and impose penalties for non-compliance, which can include significant fines. The BAA is the primary evidence of this contractual relationship and the agreed-upon safeguards.
Common mistakes to avoid in a BAA
Understanding common BAA mistakes can prevent costly errors. Key pitfalls include:
- Failing to Execute a BAA: Operating without a signed agreement is a direct HIPAA violation.
- Using an Outdated Template: Templates must reflect current laws, including updates from the HITECH Act and the Omnibus Rule.
- Overly Broad Permissions: The template should narrowly define how PHI can be used, tied directly to the services provided.
- Neglecting Subcontractor Provisions: Not ensuring that downstream subcontractors are bound by a BAA can create a major compliance gap.
- Vague Safeguard Language: The agreement should require "appropriate" safeguards as defined by HIPAA, not just "reasonable" efforts.
Difference between BAA and NDA
It's important to understand the difference between a BAA and NDA. A Non-Disclosure Agreement (NDA) is a general confidentiality contract used to protect proprietary or sensitive business information. A BAA is a specific, federally mandated agreement for protecting health information (PHI) under HIPAA. While both concern confidentiality, a BAA includes specific regulatory requirements, breach notification protocols, individual rights provisions, and audit rights for HHS that a standard NDA does not cover. A BAA is required for PHI; an NDA is insufficient on its own.
Download your free Business Associate Agreement template today!
Securing a compliant agreement shouldn't be a barrier. We offer a comprehensive, free Business Associate Agreement template designed to address the key components and common pitfalls discussed. This template provides a solid foundation to protect your organization and the sensitive health information you handle. You can download it as an editable Business Associate Agreement Word document or a ready-to-use Business Associate Agreement PDF to streamline your compliance process. Ensure your partnerships are built on a foundation of security and regulatory adherence.
Definitions
Protected Health Information (PHI) shall have the meaning given to such term under the Health Insurance Portability and Accountability Act of 1996, as amended, and its implementing regulations (collectively, HIPAA), including, but not limited to, the Privacy Rule and the Security Rule.
Business Associate shall have the meaning given to such term under HIPAA, and for purposes of this Agreement, refers to __________.
Covered Entity shall have the meaning given to such term under HIPAA, and for purposes of this Agreement, refers to __________.
Breach shall have the meaning given to such term under HIPAA.
Security Incident shall have the meaning given to such term under HIPAA.
Purpose of Agreement
This Business Associate Agreement (the "Agreement") is entered into to establish the terms under which the Business Associate will protect the confidentiality, integrity, and availability of Protected Health Information (PHI) in connection with the services it provides to the Covered Entity. The purpose is to ensure compliance with HIPAA and to define the permitted and required uses and disclosures of PHI.
Permitted Uses and Disclosures of PHI
The Business Associate may use or disclose PHI only as necessary to perform the services specified as: __________. Such uses and disclosures are limited to the minimum necessary to accomplish the intended purpose. The Business Associate may also use or disclose PHI as required by law. Any other use or disclosure not expressly permitted herein or required by law is prohibited.
Obligations to Implement Safeguards
The Business Associate shall implement appropriate administrative, physical, and technical safeguards that reasonably and appropriately protect the confidentiality, integrity, and availability of the PHI it creates, receives, maintains, or transmits on behalf of the Covered Entity. These safeguards shall be designed to prevent any use or disclosure of PHI not provided for by this Agreement.
Reporting of Improper Uses or Disclosures
The Business Associate shall report to the Covered Entity any use or disclosure of PHI not provided for by this Agreement of which it becomes aware. The Business Associate shall also report any Security Incident of which it becomes aware.
Breach Notification
Subcontractor Obligations
Access to PHI
Upon request by the Covered Entity, the Business Associate shall provide the Covered Entity with access to PHI in a Designated Record Set held by the Business Associate. The Business Associate shall also make such PHI available for inspection and copying, as necessary to fulfill the Covered Entity's obligations under HIPAA.
Amendment of PHI
Upon request by the Covered Entity, the Business Associate shall make any amendment(s) to PHI in a Designated Record Set that the Covered Entity directs or agrees to pursuant to HIPAA. The Business Associate shall incorporate any such amendments into the PHI as required by HIPAA.
Accounting of Disclosures
The Business Associate shall make available to the Covered Entity the information required to provide an accounting of disclosures of PHI, as required by HIPAA. Upon the Covered Entity's request, the Business Associate shall provide such accounting to the Covered Entity.
Termination
This Agreement may be terminated by the Covered Entity for cause upon written notice to the Business Associate if the Covered Entity determines the Business Associate has violated a material term of this Agreement. The Agreement may also be terminated by either party for convenience upon mutual written agreement or as otherwise specified herein.
Return or Destruction of PHI Upon Termination
Upon termination of this Agreement for any reason, the Business Associate shall, if feasible, return or destroy all PHI received from, or created or received by the Business Associate on behalf of, the Covered Entity. This obligation extends to PHI in the possession of subcontractors. If return or destruction is not feasible, the Business Associate shall extend the protections of this Agreement to the PHI and limit further uses and disclosures to those purposes that make the return or destruction infeasible.
__________
No Legal Relationship
The parties are independent contractors. Nothing in this Agreement is intended to create, nor shall it be deemed to create, a partnership, joint venture, or agency relationship between the Covered Entity and the Business Associate.
Indemnification
Governing Law and Jurisdiction
This Agreement shall be governed by and construed in accordance with the laws of the State of __________, without regard to its conflict of laws principles. Any legal action or proceeding arising under this Agreement will be brought exclusively in the federal or state courts located in __________, and the parties hereby consent to the personal jurisdiction and venue therein.
Entire Agreement
This Agreement constitutes the entire agreement between the parties concerning the subject matter hereof and supersedes all prior and contemporaneous agreements and understandings, whether written or oral. This Agreement may be amended only by a written instrument signed by both parties.
Severability
If any provision of this Agreement is held by a court of competent jurisdiction to be invalid, illegal, or unenforceable, the remainder of this Agreement will remain in full force and effect, and such provision shall be deemed modified to the minimum extent necessary to make it valid, legal, and enforceable.
Notices
All notices required or permitted under this Agreement shall be in writing and shall be deemed given when delivered personally, sent by certified or registered mail (return receipt requested), or sent by a recognized overnight courier service, to the addresses of the respective contact persons listed below, or to such other address as a party may specify by notice.
Confidentiality
The Business Associate agrees to hold in strict confidence and not to use or disclose, except as permitted or required by this Agreement or by law, any PHI or other confidential information of the Covered Entity. This obligation shall survive the termination of this Agreement.
IN WITNESS WHEREOF, the parties have executed this Business Associate Agreement.
In __________, on __________.
THE COVERED ENTITY
Fdo.: __________
THE BUSINESS ASSOCIATE
Fdo.: __________