News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach

A customer is asking us to sign a BAA

If you handle their patient data, you need one. Review it carefully before signing.

  1. 1

    Determine if you qualify as a Business Associate

    If your product or service involves creating, receiving, maintaining, or transmitting protected health information on behalf of a covered entity, you are a Business Associate and must sign a BAA.

  2. 2

    Review the BAA they have sent

    Check for: what PHI you are permitted to use, breach notification timelines, subcontractor requirements, and termination provisions. Have legal counsel review if it is your first BAA.

  3. 3

    Negotiate terms if needed

    BAAs are negotiable. If their breach notification requirement is 24 hours and you cannot operationally meet that, negotiate for a longer timeline.

  4. 4

    Sign and file the BAA

    Keep a copy of every signed BAA. HIPAA requires you to retain BAAs for 6 years. Store them somewhere secure and searchable.

Important

Use our free BAA Generator to create your own compliant BAA template, or to understand what a BAA you have received should contain.

Related

Not legal advice. Follow your organization's policies and consult counsel for legal questions.