HIPAA Business Associate Agreement HIPAA Business Associate Agreement

Expand section Summary

This template business associate agreement is for an employer health plan subject to the Health Insurance Portability and Accountability Act (HIPAA),42 U.S.C. §§ 1320d to 1320d-9, and a third-party service provider that will handle protected health information on its behalf (a HIPAA business associate), drafted in accordance with HIPAA requirements. This template includes practical guidance, drafting notes, and alternate and optional clauses. This template covers the specific business associate agreement requirements under HIPAA's Security and Privacy Rules (see 45 C.F.R. §§ 164.314(a) and 164.504(e)), as amended by Health Information Technology for Economic and Clinical Health Act (HITECH). Based in part on the January 2013 sample agreement available at the Department of Health and Human Services website, this template is enhanced to more clearly reflect HITECH compliance. For a full listing of key content covering HIPAA considerations, see HIPAA Resource Kit. For a full listing of related data security & privacy content for first-year associates, see First-Year Associate Resource Kit: Data Security and Privacy. For a full listing of data security content that applies to federal government agencies, see Data Security & Privacy for Government Agencies Resource Kit. For more information on business associate agreements and HIPAA generally, see HIPAA Privacy, Security, Breach Notification, and Other Administrative Simplification Rules. For a business associate policy designed for use by HIPAA covered entities, see HIPAA Business Associate Policy. For other HIPAA-related materials, see HIPAA Resource Kit.

Expand all Drafting Notes Expand all Clauses

Drafting Note to First Paragraph The business associate agreement in the employer-sponsored group health plan context is typically entered into between the employer's group health plan(s) (as covered entity) and a third-party service provider (the business associate) that is creating, maintaining, or disclosing protected health information. The effective date of the business associate agreement must be effective prior to the disclosure or transmission of PHI to the business associate.