This online page is an overview, not an executed BAA. A binding BAA must identify the parties, effective date, signatures, and negotiated terms.
1Permitted Uses and Disclosures
The BAA should define permitted service-related uses of PHI, required legal disclosures, data aggregation if applicable, and restrictions on unauthorized uses.
2Safeguards and Reporting
The BAA should address appropriate safeguards, Security Rule compliance, reporting of breaches and security incidents, mitigation, access requests, amendments, accountings, and government access.
3Subcontractors
Subcontractors that create, receive, maintain, or transmit PHI must agree to applicable restrictions and safeguards.
4Termination and Data Handling
The BAA should describe termination rights and the return, destruction, or continued protection of PHI when return or destruction is infeasible.
5Request a BAA
@
Email support@sbaralerts.com to request the current BAA for review.