Get certified in HIPAA for Leaders for just $49.95.
To view this video please enable JavaScript, and consider upgrading to a web browser that supports HTML5 video
So now let’s talk about a business associate agreement. A business associate agreement is a required contract between a covered entity and a business associate who creates, receives, maintains, or transmits PHI or ePHI to perform a service for the covered entity. A BAA document will contain details on how each entity will be responsible in handling PHI. This includes required compliance training, risk assessment, financial liabilities, and responsibilities if and when a data breach occurs. A BAA is required and holds accountable the business associate to handle PHI and ePHI securely. Business associates are also required to have a risk assessment, HIPAA compliance training, policies and procedures compiled in a book of evidence.
In this lesson, we'll go over what a Business Associate Agreement (BAA) is, when it is required, what key provisions must be included in the contract, and the specific compliance obligations required for business associates.
A Business Associate Agreement is a mandatory contract between a covered entity and a business associate who creates, receives, maintains, or transmits Protected Health Information (PHI) or electronic PHI (ePHI) to perform a service on behalf of the covered entity.
A BAA explicitly details how both entities are legally responsible for handling sensitive patient information, including protocols for:
Pro Tip: Enforcing Legal Accountability: A signed BAA is legally required and holds business associates directly accountable under federal law to handle all PHI and ePHI safely and securely.
In addition to signing a BAA, business associates are legally required to establish and maintain their own comprehensive compliance programs, which must include: