Covered Entity Contract With Business Associate, v1.0
Specifies the requirement that a covered entity obtain satisfactory assurances, in accordance with Section 164.314(a), that the business associate will appropriately safeguard the information.
To support the assessment of these requirements, the assessor should upload all or part of the business associate contract in question, and provide section references with the text that support the assessor's determination.
Assessment Step
1
Business Assocate Handles e-PHI (BusinessAssocateHandlese-PHI)
Does the covered entity permit a business associate to create, receive, maintain, or transmit electronic protected health information on the covered entity's behalf only if the covered entity obtains satisfactory assurances, in accordance with Section 164.314(a), that the business associate will appropriately safeguard the information. A covered entity is not required to obtain such satisfactory assurances from a business associate that is a subcontractor.
Artifact
A1
The assessor must provide evidence of the satisfactory assurances required by paragraph (b)(1) through the covered entity's written contract or other arrangement with the business associate that meets the applicable requirements of Section 164.314(a).
|
A covered entity or business associate must perform these requirements in accordance with Section 164.306 (Security standards: General rules).
Conformance Criteria (1)
PHI Safeguarded Appropriately
A covered entity may permit a business associate to create, receive, maintain, or transmit electronic protected health information on the covered entity's behalf only if the covered entity obtains satisfactory assurances, in accordance with Section 164.314(a) (Business Associate Contract Requirements), that the business associate will appropriately safeguard the information. A covered entity is not required to obtain such satisfactory assurances from a business associate that is a subcontractor.
Citations
HIPAA-Security-Rule
45 CFR Section 164.308(b)(1)
HIPAA-Security-Rule
45 CFR Section 164.306
|