HHS · OCR

HIPAA Business Associate Compliance

Evaluate compliance with HIPAA Business Associate Agreement requirements for vendors and service providers handling Protected Health Information (PHI)

At a glance

Short name
HIPAA BAA
Issuing / stewarding body
HHS, OCR
Jurisdiction
US
Also known as / related labels
45 CFR 164 Subpart C · HITECH Act

What this entry covers

Evaluate compliance with HIPAA Business Associate Agreement requirements for vendors and service providers handling Protected Health Information (PHI)

MyRHC indexes this framework so practitioners, auditors, and automated agents can find the authoritative primary sources in one place. This page is a navigation aid — it is not legal advice and is not a substitute for the official text.

Official documentation

How to use this index entry

  1. Open the official link above (or the agency home if the deep link drifts).
  2. Confirm edition / revision date against your program scope.
  3. Map applicability by sector and jurisdiction listed in the metadata.
  4. Follow related frameworks only after checking their own official sources.

Disclaimers

  • MyRHC does not host proprietary standards text (ISO, some industry bodies).
  • Where standards are paywalled, we link to the publisher’s catalog page.
  • Always verify current requirements with counsel and the issuing authority.
Index only — not legal advice. MyRHC does not certify compliance. Confirm current requirements with the issuing authority and qualified counsel. Proprietary standards text remains with its publisher.