The HIPAA Security Rule (45 CFR Part 164, Subpart C)
Reaches every agreement with a covered entity in the United States (hospitals and health systems, health plans, clinics, pharmacies) under which the supplier handles electronic protected health information: the business associate contract of 164.308(b)(1) and (b)(3), its required provisions in 164.314(a)(2)(i) (Security Rule duties, subcontractor flow-down, incident and breach reporting, termination), and the subcontractor terms of 164.308(b)(2) and 164.314(a)(2)(iii).
On the register, tick "HIPAA Security Rule" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: HIPAA Security Rule.
What it expects, term by term
| BAA | 164.308(b)(1) · 164.308(b)(3) · 164.314(a)(1) · 164.314(a)(2)(i)Where the row names health or personal data the supplier handles |
|---|---|
| subcontractors | 164.308(b)(2) · 164.314(a)(2)(iii)Where the supplier handles personal data |
| breach clock | 164.314(a)(2)(i) · 164.308(a)(6)(ii)Where the supplier handles health or personal data |
The business associate contract
A covered entity may let a business associate handle electronic protected health information only after written satisfactory assurances. 164.314(a)(2)(i) sets what that contract provides: Security Rule duties, subcontractor flow-down, reporting of security incidents including breaches, and termination. A US health customer's row with no BAA shown raises its own finding.
The clauses, quoted
7Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.
HIPAA 164.308(a)(6)(ii) Response and Reporting (Required)Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.
Where it usually falls short: Incident closure without root cause
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.
Where it usually falls short: BA inventory incomplete
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(2) Subcontractor ArrangementsA business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with 164.314(a), that the subcontractor will appropriately safeguard the information.
Where it usually falls short: Assurances obtained from the immediate subcontractor while its own downstream subcontractors handling the same data are unaddressed
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(3) Written Contract or Other ArrangementDocument the satisfactory assurances required by paragraph (b)(1) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of 164.314(a).
Where it usually falls short: BAAs missing required Security Rule clauses
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.
Where it usually falls short: Older BAAs missing post-Omnibus requirements
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(i) Business Associate Contract Required ProvisionsThe contract between a covered entity and a business associate must provide that the business associate will comply with the applicable Security Rule requirements, ensure subcontractors comply, report security incidents including breaches, and authorize termination by the covered entity if the business associate violates a material term.
Where it usually falls short: Incident reporting SLA missing or longer than reasonable
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(iii) Business Associate Contracts with SubcontractorsThe requirements of paragraph (a)(2)(i) of this section apply to the contract or other arrangement between a business associate and a subcontractor required by 164.308(b)(4) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate.
Where it usually falls short: Subcontractor inventory incomplete
HIPAA Security Rule in The Art of Service standards library
See what it expects of your list
Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.
Check my contract list