Regulated Customer Contract Checker
Regimes · HIPAA

The HIPAA Security Rule (45 CFR Part 164, Subpart C)

Reaches every agreement with a covered entity in the United States (hospitals and health systems, health plans, clinics, pharmacies) under which the supplier handles electronic protected health information: the business associate contract of 164.308(b)(1) and (b)(3), its required provisions in 164.314(a)(2)(i) (Security Rule duties, subcontractor flow-down, incident and breach reporting, termination), and the subcontractor terms of 164.308(b)(2) and 164.314(a)(2)(iii).

On the register, tick "HIPAA Security Rule" (every regime is ticked by default) and these rows attach where the customer's sector and country reach it. Source framework: HIPAA Security Rule.

What it expects, term by term

BAA164.308(b)(1) · 164.308(b)(3) · 164.314(a)(1) · 164.314(a)(2)(i)Where the row names health or personal data the supplier handles
subcontractors164.308(b)(2) · 164.314(a)(2)(iii)Where the supplier handles personal data
breach clock164.314(a)(2)(i) · 164.308(a)(6)(ii)Where the supplier handles health or personal data

The business associate contract

A covered entity may let a business associate handle electronic protected health information only after written satisfactory assurances. 164.314(a)(2)(i) sets what that contract provides: Security Rule duties, subcontractor flow-down, reporting of security incidents including breaches, and termination. A US health customer's row with no BAA shown raises its own finding.

The clauses, quoted

7

Clause text from The Art of Service standards library at compliance.theartofservice.com, read against the held text of each standard and cited to its clause: our close statement of each clause, not the instrument verbatim. Where the UK text is held only as a summary, the EU GDPR article of the same number is quoted and the page says so.

HIPAA 164.308(a)(6)(ii) Response and Reporting (Required)

Identify and respond to suspected or known incidents, mitigate harmful effects, and document incidents and their outcomes. NIST recommends linkage to HIPAA Breach Notification Rule timelines.

Evidence an auditor accepts: Incident ticket log; Post-incident reports; Breach risk assessments per 164.402
Where it usually falls short: Incident closure without root cause
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Evidence an auditor accepts: BA inventory; Executed BAAs; Vendor risk assessments
Where it usually falls short: BA inventory incomplete
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(2) Subcontractor Arrangements

A business associate may permit a business associate that is a subcontractor to create, receive, maintain, or transmit electronic protected health information on its behalf only if the business associate obtains satisfactory assurances, in accordance with 164.314(a), that the subcontractor will appropriately safeguard the information.

Evidence an auditor accepts: Inventory of subcontractors that create, receive, maintain or transmit electronic protected health information on the business associate's behalf; Executed written agreements with each subcontractor containing the satisfactory assurances required; Evidence the assurances obtained are equivalent to those the business associate provided to the covered entity
Where it usually falls short: Assurances obtained from the immediate subcontractor while its own downstream subcontractors handling the same data are unaddressed
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.308(b)(3) Written Contract or Other Arrangement

Document the satisfactory assurances required by paragraph (b)(1) of this section through a written contract or other arrangement with the business associate that meets the applicable requirements of 164.314(a).

Evidence an auditor accepts: Standard BAA template aligned to 164.314(a); Executed BAAs stored in contract repository; Alternative arrangement documentation where BA is a government entity
Where it usually falls short: BAAs missing required Security Rule clauses
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)

The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.

Evidence an auditor accepts: BAA template addressing all required 164.314(a)(2) elements; Government arrangement documentation where applicable; Special arrangement records (group health plan, plan sponsor)
Where it usually falls short: Older BAAs missing post-Omnibus requirements
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(i) Business Associate Contract Required Provisions

The contract between a covered entity and a business associate must provide that the business associate will comply with the applicable Security Rule requirements, ensure subcontractors comply, report security incidents including breaches, and authorize termination by the covered entity if the business associate violates a material term.

Evidence an auditor accepts: BAA template with required clauses traceable to 164.314(a)(2)(i); Incident reporting requirements and SLAs; Subcontractor flow-down clause
Where it usually falls short: Incident reporting SLA missing or longer than reasonable
HIPAA Security Rule in The Art of Service standards library
HIPAA 164.314(a)(2)(iii) Business Associate Contracts with Subcontractors

The requirements of paragraph (a)(2)(i) of this section apply to the contract or other arrangement between a business associate and a subcontractor required by 164.308(b)(4) in the same manner as such requirements apply to contracts or other arrangements between a covered entity and business associate.

Evidence an auditor accepts: Subcontractor BAA template aligned to 164.314(a)(2)(i); Executed subcontractor BAAs; Subcontractor inventory with ePHI scope
Where it usually falls short: Subcontractor inventory incomplete
HIPAA Security Rule in The Art of Service standards library

See what it expects of your list

Paste the list of customer agreements and every row this regime reaches carries these terms, ticked or open. Eight agreements free, no account.

Check my contract list