NIST SP 800-66
Business Associate Agreements

NIST SP 800-66 NISTSP66-4: Business Associate Agreements (BAAs) and Third-Party ePHI Governance

Manage Business Associate relationships per HIPAA Security Rule 45 CFR 164.308(b) and HIPAA Privacy Rule 45 CFR 164.502(e). Obtain satisfactory assurances per a written contract or other arrangement (a Business Associate Agreement - BAA) that the business associate will appropriately safeguard ePHI per 45 CFR 164.314(a). The BAA must require the business associate to (a) not use or further disclose ePHI other than as permitted or required by the contract or law, (b) use appropriate safeguards to prevent use or disclosure not provided for by the contract, (c) report any use or disclosure not provided for by the contract of which the business associate becomes aware, (d) ensure any subcontractor that creates + receives + maintains + transmits ePHI on behalf of the business associate agrees to the same restrictions and conditions, (e) make ePHI available to the covered entity for access + amendment + accounting + as required by 45 CFR 164.504(e)(2), (f) make internal practices + books + records available to HHS for compliance review, (g) at termination return or destroy all ePHI received from or maintained on behalf of the covered entity. Maintain BAA inventory + risk assessment per BA + ongoing oversight + breach notification chain.

Maintained by Gerard BlokdykVerified against the published standard Control text last updated

Query this from an agent

The graph holds this control, the 0 it maps to, and the evidence behind each claim, over MCP and REST.