Business Associate Contracts - Security Safeguards, v1.0

Specifies requirements for contents of the business associate contract between a covered entity and its business associate(s). The contract must provide that the business associate will use safeguards to prevent unauthorized use or disclosure of e-PHI.
To support the assessment of these requirements, the assessor should upload all or part of the business associate contract or agreement in question, and provide section references with the text that support the assessor's determination.

Assessment Step

1
Business Associate Uses of PHI (BusinessAssociateUsesofPHI)
Does the covered entity have and enforce a business associate contract to use appropriate safeguards and comply, where applicable, with subpart C (45 CFR Section 164.300-399, i.e., Security Standards) of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract?
Artifact
A1
Provide evidence (e.g. organizational policies, procedures, compliance/assessment reports, etc.) that support the assessor's response to this assessment step.
The Business Associate Contract describes the relationship between the covered entity and its business associate (or other subcontractors) with respect to handling of PHI and other matters.

Conformance Criteria (1)

Use Safeguards
The covered entity must have a business associate contract to use appropriate safeguards and comply, where applicable, with subpart C (45 CFR Section 164.300-399, i.e., Security Standards) of this part with respect to electronic protected health information, to prevent use or disclosure of the information other than as provided for by its contract.
Citation
HIPAA-Privacy-Rule
45 CFR Section 164.504(e)(2)(ii)(B)