1Permitted Uses and Disclosures
The BAA should define permitted service-related uses of PHI, required legal disclosures, data aggregation if applicable, and restrictions on unauthorized uses.
2Safeguards and Reporting
The BAA should address appropriate safeguards, Security Rule compliance, reporting of breaches and security incidents, mitigation, access requests, amendments, accountings, and government access.
3Subcontractors
Subcontractors that create, receive, maintain, or transmit PHI must agree to applicable restrictions and safeguards.
4Termination and Data Handling
The BAA should describe termination rights and the return, destruction, or continued protection of PHI when return or destruction is infeasible.
5 Request a BAA
Contact SBAR Alerts to request the current BAA for review or to discuss BAA requirements for your facility.
Contact Us to Request a BAA