Business Associate Agreements
Health care organizations regularly share protected health information with vendors, consultants, technology companies, billing companies, management organizations, and other third parties. When a third party creates, receives, maintains, or transmits protected health information on behalf of a HIPAA-covered entity, the relationship may require a Business Associate Agreement, commonly referred to as a BAA.
A Business Associate Agreement is not simply a confidentiality agreement. It is a HIPAA-required contract that establishes how protected health information may be used and disclosed, what safeguards must be maintained, how security incidents and breaches must be reported, and what happens to protected health information when the business relationship ends.
G2Z Law Group assists physicians, medical practices, health care organizations, technology companies, management companies, and other businesses with Business Associate Agreement drafting, review, negotiation, and HIPAA compliance.
What Is a Business Associate Agreement?
Under HIPAA, a business associate is generally a person or organization that performs certain functions or provides services for a covered entity involving access to protected health information, or PHI.
Business associates may include organizations providing services such as:
billing and claims administration;
practice management;
legal, accounting, or consulting services involving PHI;
data storage and cloud services;
electronic health record or software services;
health care analytics;
utilization review;
quality assurance;
administrative support; and
other services requiring access to patient information.
A business associate may also have its own subcontractors. If a subcontractor creates, receives, maintains, or transmits PHI on behalf of the business associate, HIPAA generally requires the business associate to enter into an appropriate BAA with that subcontractor as well. HHS recently reiterated that these downstream subcontractors are themselves treated as business associates for HIPAA purposes.
When Is a Business Associate Agreement Required?
A BAA is generally required when a covered entity allows a business associate to create, receive, maintain, or transmit protected health information in connection with services performed for the covered entity.
The agreement helps define and limit the business associate’s permitted uses and disclosures of PHI and requires the business associate to comply with applicable HIPAA obligations.
Not every vendor relationship requires a BAA. For example, whether a particular service provider is a business associate depends upon the nature of the services being performed and the provider’s relationship to PHI.
Determining whether a BAA is necessary should therefore begin with the underlying business relationship rather than simply whether a vendor happens to encounter patient information.
What Must a Business Associate Agreement Include?
HIPAA requires a BAA to contain certain substantive provisions.
According to HHS guidance, the agreement generally must:
identify permitted and required uses and disclosures of PHI;
prohibit uses or disclosures that are not permitted by the agreement or required by law;
require appropriate safeguards to protect PHI;
require compliance with applicable HIPAA Security Rule requirements for electronic PHI;
require reporting of unauthorized uses, disclosures, and breaches;
address access, amendment, and accounting obligations where applicable;
require cooperation with HHS compliance investigations;
require appropriate protections for subcontractors;
address return or destruction of PHI at termination where feasible; and
allow termination when the business associate materially violates the agreement.
These requirements reflect the HIPAA Privacy, Security, and Breach Notification Rules and should be tailored to the services actually being performed.
Why Should a BAA Be Customized?
HHS provides sample Business Associate Agreement provisions, but the federal government expressly states that its sample language is guidance rather than a mandatory contract form.
HHS also cautions that its sample provisions address HIPAA requirements only and may not include all provisions necessary to create a complete contract under applicable state law. The language may therefore need to be modified to reflect the parties’ actual business relationship.
A properly drafted BAA may need to address issues beyond the minimum regulatory requirements, including:
breach notification deadlines;
investigation and cooperation obligations;
allocation of breach-response costs;
cybersecurity standards;
cyber liability insurance;
indemnification;
subcontractor responsibilities;
data ownership;
de-identification and data use;
audit rights;
return or destruction of data;
limitation of liability; and
survival of privacy and security obligations after termination.
For technology vendors and software companies, the BAA may also need to address cloud hosting, third-party infrastructure, artificial intelligence tools, data analytics, and other downstream services that may create additional privacy and security concerns.
What Are a Business Associate’s Direct HIPAA Responsibilities?
Business associates are not protected from liability simply because their responsibilities arise through a contract with a covered entity.
Under HIPAA, business associates can be directly liable for certain violations of the Privacy, Security, and Breach Notification Rules. HHS explains that business associates may face direct liability for unauthorized uses or disclosures of PHI and for failures to safeguard electronic PHI as required by the Security Rule.
Business associates must also ensure that applicable subcontractors agree to appropriate HIPAA restrictions before PHI is disclosed to them.
For this reason, companies serving the health care industry should evaluate their HIPAA responsibilities before signing a customer’s standard BAA.
What Happens When a Business Associate Experiences a Breach?
A BAA should establish procedures for reporting unauthorized uses or disclosures of PHI and breaches of unsecured protected health information.
Federal regulations establish breach-notification obligations, but the contract can impose additional requirements regarding timing, investigation, documentation, cooperation, and responsibility for notifications.
HHS specifically notes that parties may choose to impose a reporting period that is shorter than the outside regulatory deadline and may address whether the business associate will assist with notifications to affected individuals, HHS, or the media.
Clearly defining these responsibilities before a security incident occurs can reduce uncertainty and disputes during a breach response.
Can a Covered Entity Use the HHS Sample BAA?
Yes. HHS publishes sample Business Associate Agreement provisions that covered entities and business associates may use as a starting point.
However, HHS emphasizes that use of its sample provisions is not required for HIPAA compliance and that the language may be modified to reflect the particular business relationship. The agency also warns that the sample may not address all contractual requirements imposed by state law.
Organizations can review the federal government's sample here:
HHS Sample Business Associate Agreement Provisions
HHS also publishes a downloadable model Business Associate Agreement.
What Can G2Z Law Group Do for My Health Care Business?
G2Z Law Group assists health care providers, medical practices, technology companies, vendors, management organizations, and other businesses with Business Associate Agreements and HIPAA compliance.
Our attorneys can help determine whether a BAA is required, draft and review Business Associate Agreements, negotiate privacy and security provisions, evaluate subcontractor relationships, address breach-notification obligations, and identify contractual risks relating to PHI.
We also assist business associates that receive BAAs from hospitals, medical groups, and other customers in evaluating whether the agreement imposes obligations beyond those required by HIPAA.
A properly structured Business Associate Agreement can help establish clear responsibilities between the parties, protect patient information, and reduce uncertainty when privacy, security, or breach issues arise.
Contact us.
Please review the disclaimer below before sending us an email.
info@g2zlaw..com
(202) 656-8387
1250 Connecticut Ave. NW, Suite 700
Washington, DC 20036
Disclaimer: Completing and submitting the above electronic form does not establish an attorney-client relationship with us. Our Law Firm cannot agree to represent you until we determine there would be no conflict of interest an notify you that you are a client. Any information sent to the Law Firm via this website before we have agreed to represent you will not be treated as confidential. Information submitted to the Law Firm before we agree to represent you will not bar the Law Firm from representing or continuing to represent someone whose interests are adverse to yours in connection with your case.
Copyright 2020, G2Z Law Group, PLLC