Business Associate Contracts - Privacy Rule Compliance, v1.0

Specifies requirements for contents of the business associate contract between a covered entity and its business associate(s). The business associate must carry out a covered entity's obligations and comply with regulations during such performance.
To support the assessment of these requirements, the assessor should upload all or part of the business associate contract or agreement in question, and provide section references with the text that support the assessor's determination.

Assessment Step

1
Business Associate Uses of PHI (BusinessAssociateUsesofPHI)
To the extent the business associate is to carry out a covered entity's obligation under subpart E (45 CFR Section 164.500-599, Privacy Rule), does the covered entity have and enforce a business associate contract to comply with the requirements of this subpart that apply to the covered entity in the performance of such obligation?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
The Business Associate Contract describes the relationship between the covered entity and its business associate (or other subcontractors) with respect to handling of PHI and other matters.

Conformance Criteria (1)

Comply with Privacy Rule
To the extent the business associate is to carry out a covered entity's obligation under subpart E (45 CFR Section 164.500-599, Privacy Rule), the covered entity must have a business associate contract to comply with the requirements of this subpart that apply to the covered entity in the performance of such obligation.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.504(e)(2)(ii)(H)