Business Associate Contract Requirements, v1.0

Specifies that a health care related organization's contract must provide that the business associate will comply with the applicable requirements of this subpart (Section 164.300-399).

Assessment Steps (3)

1
Comply with this Subpart (ComplywiththisSubpart)
Does the covered entity's contract provide that the business associate will comply with the applicable requirements of this subpart (Section 164.300-399)?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
2
Subcontractor Contract (SubcontractorContract)
Does the covered entity's contract provide that the business associate will, in accordance with Section 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit electronic protected health information on behalf of the business associate agree to comply with the applicable requirements of this subpart (Section 164.300-399) by entering into a contract or other arrangement that complies with this section?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
3
Security Incident Reporting (SecurityIncidentReporting)
Does the covered entity's contract provide that the business associate will report to the covered entity any security incident of which it becomes aware, including breaches of unsecured protected health information as required by Section 164.410?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.

Conformance Criteria (3)

Comply with this Subpart
The covered entity's contract must provide that the business associate will comply with the applicable requirements of this subpart (Section 164.300-399).
Citation
HIPAA-Security-Rule
45 CFR Section 164.314(a)(2)(i)(A)
Enter into Contract
The covered entity's contract must provide that the business associate will, in accordance with Section 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit electronic protected health information on behalf of the business associate agree to comply with the applicable requirements of this subpart (Section 164.300-399) by entering into a contract or other arrangement that complies with this section.
Citation
HIPAA-Security-Rule
45 CFR Section 164.314(a)(2)(i)(B)
Report Security Incident
The covered entity's contract must provide that the business associate will report to the covered entity any security incident of which it becomes aware, including breaches of unsecured protected health information as required by Section 164.410.
Citation
HIPAA-Security-Rule
45 CFR Section 164.314(a)(2)(i)(C)