Reviewing your BAA
Reviewing a business associate agreement (BAA) involves ensuring the agreement continues to comply with the Health Insurance Portability and...
2 min read
Tshedimoso Makhene
Jan 22, 2025 5:01:49 AM
The covered entity is responsible for ensuring that a business associate agreement (BAA) is in place with any business associate who has access to protected health information (PHI).
While both the covered entity and the business associate share responsibility for HIPAA compliance, the primary responsibility for ensuring that a BAA is in place rests with the covered entity. Here’s a breakdown of the responsibilities:
According to the HHS, “If a covered entity engages a business associate to help it carry out its health care activities and functions, the covered entity must have a written business associate contract or other arrangement with the business associate that establishes specifically what the business associate has been engaged to do and requires the business associate to comply with the Rules’ requirements to protect the privacy and security of protected health information.” This puts the onus on the covered entity to ensure a BAA is in place before any PHI is shared with a business associate.
The responsibilities of the covered entity involve:
While the covered entity holds the primary responsibility, business associates also have a significant role to play:
Read also: Can you be a covered entity and a business associate?
Here are some best practices for covered entities to ensure effective management of BAAs:
See also: HIPAA Compliant Email: The Definitive Guide
If a covered entity shares PHI with a business associate without a BAA, they may face HIPAA violation penalties. The covered entity and business associate may be liable for compliance violations, including substantial fines and reputational damage.
A BAA includes the following details:
It’s good practice for covered entities to review their BAAs annually or whenever there are changes to services, regulations, or business associates. Regular reviews ensure ongoing compliance and that the BAA remains aligned with current laws and practices.
Reviewing a business associate agreement (BAA) involves ensuring the agreement continues to comply with the Health Insurance Portability and...
Subcontractors are considered business associates under HIPAA when they directly handle, manage, or can access protected health information (PHI) as...
Terminating a business associate agreement (BAA) means ending the legal contract between a covered entity and a business associate. This action...