Business Associate Contract With Subcontractor, v1.0

Specifies the requirement that a covered entity's business associate obtain satisfactory assurances, in accordance with Section 164.314(a), that the business associate's subcontractor will appropriately safeguard the information.
To support the assessment of these requirements, the assessor should upload all or part of the subcontractor contract in question, and provide section references with the text that support the assessor's determination.

Assessment Step

1
Subcontractor Handles e-PHI (SubcontractorHandlese-PHI)
Does the business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with Section 164.314(a) (Business Associate Contract Requirements), that the subcontractor will appropriately safeguard the information?
Artifact
A1
The assessor must provide evidence of the satisfactory assurances required by paragraph (b)(2) through the business associate's written contract or other arrangement with the subcontractor that meets the applicable requirements of Section 164.314(a).
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).

Conformance Criteria (1)

PHI Safeguarded Appropriately
A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with Section 164.314(a) (Business Associate Contract Requirements), that the subcontractor will appropriately safeguard the information.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(b)(2)
HIPAA-Security-Rule
45 CFR Section 164.306