Evaluate compliance with HIPAA Business Associate Agreement requirements for vendors and service providers handling Protected Health Information (PHI)
§164.502(e): BAA required before PHI can be disclosed to business associate
Permitted uses, safeguards, subcontractor requirements, reporting, termination
BAAs must reflect current HIPAA requirements and services provided
§164.504(e)(2)(i): Limited to purposes specified in BAA
§164.504(e)(2)(i): Prohibited uses and disclosures
§164.514(d): Only minimum PHI necessary for intended purpose
§164.308-164.312: HIPAA Security Rule applies to business associates
Safe harbor: AES 256-bit encryption for data at rest, TLS 1.2+ in transit
§164.308(a)(1)(ii)(A): Risk analysis required at least annually
§164.308(a)(5): Training on HIPAA and PHI handling procedures
§164.504(e)(2)(ii): Subcontractor BAAs required
Subcontractors must agree to same restrictions and conditions
Document subcontractor chain and BAA status
§164.410: Business associate must notify covered entity of breaches
Incident response plan for detecting, investigating, and reporting breaches
Four-factor risk assessment per §164.402 breach definition
§164.524: Individuals have right to access their PHI
§164.526: Individuals have right to amend their PHI
§164.528: Accounting of certain disclosures required for 6 years
§164.504(e)(2)(ii)(I): Return or destruction of PHI at termination
Please answer all required questions to see your results