A Business Associate is a person or organization, other than an employee of a covered entity, who performs functions or provides services related to creating, receiving, maintaining, or transmitting PHI on behalf of your organization.
A written contract with your Business Associate must:
-
Detail the uses and disclosures of PHI the Business Associate may make
-
Require that the Business Associate safeguard PHI
Make sure your Business Associate Agreements (BAAs) require compliance with HIPAA and HITECH Breach Notification requirements.
Tools and Resources for Step 9
The HHS website offers sample Business Associate Agreement provisions