Business Associate Contracts - Covered Entity Compliance, v1.0

Specifies requirements for contents of the business associate contract between a covered entity and its business associate(s). A covered entity would not be in compliance if aware the business associate violated its contract obligations and did not remedy them.
To support the assessment of these requirements, the assessor should upload all or part of the business associate contract or agreement in question, and provide section references with the text that support the assessor's determination.

Assessment Step

1
Business Associate Compliance Enforcement (BusinessAssociateComplianceEnforcement)
Does the covered entity have policies and procedures to terminate the business associate contract if the covered entity knew of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate's obligation under the contract or other arrangement, unless the covered entity took reasonable steps to cure the breach or end the violation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
The Business Associate Contract describes the relationship between the covered entity and its business associate (or other subcontractors) with respect to handling of PHI and other matters.

Conformance Criteria (1)

Enforce Compliance
The covered entity must have policies and procedures to terminate the business associate contract if the covered entity knew of unaddressed violations of the contract by the business associate.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.504(e)(1)(ii)