Business Associate Contracts - Compliance, v1.0

Specifies requirements for contents of the business associate contract between a covered entity and its business associate(s). A business associate would not be in compliance if aware a subcontractor violated its contract obligations and did not fix them.
To support the assessment of these requirements, the assessor should upload all or part of the business associate contract or agreement in question or other policy and procedure documents, and provide section references with the text that support the assessor's determination.

Assessment Step

1
Business Associate Subcontractor Compliance (BusinessAssociateSubcontractorCompliance)
Does the business associate have policies and procedures that if the business associate knew of a pattern of activity or practice of a subcontractor that constituted a material breach or violation of the subcontractor's obligation under the business associate contract or other arrangement, unless the business associate took reasonable steps to cure the breach or end the violation, as applicable, and, if such steps were unsuccessful, terminated the contract or arrangement, if feasible?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
The Business Associate Contract describes the relationship between the covered entity and its business associate (or other subcontractors) with respect to handling of PHI and other matters.

Conformance Criteria (1)

Enforce Compliance
The business associate must have policies and procedures that if the business associate knew of a pattern of activity or practice of a subcontractor that constituted a material breach or violation of the subcontractor's obligation under the business associate contract or other arrangement, unless the business associate took reasonable steps to cure the breach or end the violation, as applicable, and, if such steps were unsuccessful, to terminated the contract or arrangement, if feasible.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.504(e)(1)(iii)