Step 9: Update or execute Business Associate Agreements (BAAs)


A Business Associate is a person or organization, other than an employee of a covered entity, who performs functions or provides services related to creating, receiving, maintaining, or transmitting PHI on behalf of your organization.

 

A written contract with your Business Associate must:

  • Detail the uses and disclosures of PHI the Business Associate may make

  • Require that the Business Associate safeguard PHI

 

Make sure your Business Associate Agreements (BAAs) require compliance with HIPAA and HITECH Breach Notification requirements.

 

Tools and Resources for Step 9


The HHS website offers sample Business Associate Agreement provisions

BAA Samples

Upcoming Webinars

[add_eventon_list hide_month_headers="no" hide_empty_months="yes" event_order="ASC" number_of_months="3" ]

New Social Media Course

MyHIPAA Guide is offering a new social media course that will help you protect your organization from potential privacy violations that result from social media

Read More »

Upcoming Events

10 Steps to Compliance