A customer is asking us to sign a BAA
If you handle their patient data, you need one. Review it carefully before signing.
- 1
Determine if you qualify as a Business Associate
If your product or service involves creating, receiving, maintaining, or transmitting protected health information on behalf of a covered entity — you are a Business Associate and must sign a BAA.
- 2
Review the BAA they have sent
Check for: what PHI you are permitted to use, breach notification timelines, subcontractor requirements, and termination provisions. Have legal counsel review if it is your first BAA.
- 3
Negotiate terms if needed
BAAs are negotiable. If their breach notification requirement is 24 hours and you cannot operationally meet that, negotiate for a longer timeline.
- 4
Sign and file the BAA
Keep a copy of every signed BAA. HIPAA requires you to retain BAAs for 6 years. Store them somewhere secure and searchable.
Important
Use our free BAA Generator to create your own compliant BAA template, or to understand what a BAA you have received should contain.
Related
Not legal advice. Follow your organization's policies and consult counsel for legal questions.