OCR Releases Sample Business Associate Agreement Provisions

The Department of Health and Human Services, Office for Civil Rights (OCR) has posted on its website sample business associate agreement provisions to help covered entities and business associates comply with the new business associate agreement requirements under the final HIPAA Omnibus Rule.

The HIPAA Omnibus Rule modified the minimum required contents of business associate agreements. In addition to previously required provisions, business associate agreements must now include provisions that require business associates to:

comply with the HIPAA Security Rule requirements;

report any security breach to the covered entity;

enter into a business associate agreement with any subcontractor that receives the covered entity's protected health information (“PHI”); and

comply with the provisions of the HIPAA Privacy Rule applicable to any obligation which the covered entity delegates to the business associate, such as the obligation to provide an individual with access to his or her PHI.

As we noted in our HIPAA Omnibus reference chart, the HIPAA Omnibus Rule expanded the definition ofbusiness associate to include subcontractors. This change means that covered entities must obtain satisfactory assurances in the form of business associate agreements from their business associates, and that business associates must do the same with regard to subcontractors who...

To continue reading

Request your trial

VLEX uses login cookies to provide you with a better browsing experience. If you click on 'Accept' or continue browsing this site we consider that you accept our cookie policy. ACCEPT