BAA — Business Associate to Subcontractor (HIPAA) review
Business-associate to subcontractor BAA under HIPAA. Checks cover 45 CFR § 164.504(e) required clauses, § 164.314(a) Security Rule flow-down, § 164.410 breach notification, plus HHS-guidance posture rules — with an emphasis on flow-down (the subcontractor must comply with the same terms the upstream BAA imposes on the business associate, per 45 CFR § 164.502(e)(1)(ii) and § 164.504(e)(5)).
Review your document — free → See a sample report- 45 document-specific checks
- + 109 general checks
- Nothing uploaded
- Free forever (MIT)
What it checks
Permitted uses and disclosures of PHI
BAA must establish the permitted and required uses and disclosures of PHI by the business associate.
Critical · BAA-001
Use limited to permitted purposes
Business associate may not use PHI for any purpose other than as permitted by the BAA or required by law.
Critical · BAA-002
Appropriate safeguards clause
BAA must require BA to use appropriate safeguards, including Security Rule administrative, physical, and technical safeguards.
Critical · BAA-003
Report improper uses or disclosures
BAA must require BA to report to the covered entity any use or disclosure not provided for by the contract.
Critical · BAA-004
Subcontractor flow-down
BA must ensure subcontractors that handle PHI agree in writing to the same restrictions and conditions.
Critical · BAA-005
Access to PHI (164.524)
BAA must require BA to make PHI available in a Designated Record Set to satisfy 45 CFR 164.524.
Critical · BAA-006
Amendment of PHI (164.526)
BAA must require BA to make PHI available for amendment to satisfy 45 CFR 164.526.
Critical · BAA-007
Accounting of disclosures (164.528)
BAA must require BA to maintain and make available the information required to provide an accounting of disclosures.
Critical · BAA-008
Books and records available to HHS Secretary
BAA must require BA to make its internal practices, books, and records available to HHS for compliance review.
Critical · BAA-009
Return or destruction at termination
BA must, at termination, return or destroy all PHI received from, or created on behalf of, the covered entity.
Critical · BAA-010
Termination right for material breach
Covered entity must have the right to terminate the BAA for material breach by the business associate.
Critical · BAA-011
Authorization to terminate if cure infeasible
BAA should authorize termination when cure of a material breach is not feasible.
Warning · BAA-012
Security Rule compliance required
BAA must require BA to comply, where applicable, with the Security Rule with respect to ePHI.
Critical · BAA-013
Administrative safeguards referenced
BAA should reference administrative safeguards required by the Security Rule.
Warning · BAA-014
Physical safeguards referenced
BAA should reference physical safeguards required by the Security Rule.
Warning · BAA-015
Technical safeguards referenced
BAA should reference technical safeguards required by the Security Rule.
Warning · BAA-016
Security incident reporting
BAA must require BA to report security incidents to the covered entity.
Critical · BAA-017
Subcontractor flow-down for Security Rule
BA must ensure subcontractors handling ePHI agree to the Security Rule restrictions.
Critical · BAA-018
Breach notification clause present
BAA must require BA to notify the covered entity of a breach of unsecured PHI.
Critical · BAA-019
Breach notification looser than 60 days
Flags breach-notice timing that exceeds the 60-day outer bound or shifts the trigger to a later event.
Critical · BAA-020
Breach trigger is 'discovery'
Breach-notification timing should be measured from 'discovery,' not a stricter post-discovery event.
Warning · BAA-021
'Without unreasonable delay' language present
BAA should include 'without unreasonable delay' to match HIPAA's inner timing bound.
Warning · BAA-022
Security Incident narrowed to 'successful' access
Flags clauses that limit 'Security Incident' to only successful unauthorized accesses — a narrowing OCR has criticized.
Warning · BAA-023
Return-or-destruction lacks definite outer bound
Flags return-or-destruction language that is open-ended ('as soon as practicable', 'commercially reasonable').
Warning · BAA-024
Indemnity cap impairing HIPAA remedies
Flags liability caps that limit damages below the covered entity's potential HIPAA penalty exposure.
Warning · BAA-025
Covered entity audit rights preserved
BAA should preserve the covered entity's right to audit BA's HIPAA compliance.
Warning · BAA-026
Covered entity indemnifies BA for HIPAA violations
Flags clauses where the covered entity indemnifies the business associate for HIPAA violations — a common vendor overreach.
Warning · BAA-027
PHI / ePHI defined or cross-referenced
BAA should define PHI/ePHI or cross-reference the HIPAA definition.
Warning · BAA-028
Minimum-necessary standard referenced
BAA should reference HIPAA's minimum-necessary standard.
Warning · BAA-029
Mitigation obligation
BAA should require BA to mitigate harmful effects of any improper use or disclosure.
Critical · BAA-030
Workforce training requirement
BAA should require BA's workforce members handling PHI to be trained on its obligations.
Warning · BAA-031
Encryption or NIST safeguards referenced
BAA should reference encryption / NIST-style safeguards for ePHI at rest and in transit.
Warning · BAA-032
Risk assessment requirement
BAA should require BA to conduct periodic risk assessments per § 164.308(a)(1).
Warning · BAA-033
Sanctions policy / personnel discipline
BAA should reference BA's sanctions policy for workforce members who violate HIPAA/BAA.
Warning · BAA-034
Subprocessor / vendor disclosure
BAA should require BA to disclose subprocessors / downstream vendors that handle PHI.
Warning · BAA-035
Signed by authorized representative
BAA should be signed by an authorized representative of each party (satisfactory assurances).
Critical · BAA-036
Effective date present
BAA should state an effective date.
Warning · BAA-037
Term / duration clause present
BAA should specify its term.
Warning · BAA-038
Governing law specified
BAA should specify the governing law.
Warning · BAA-039
Notice clause present
BAA should specify how formal notices (including breach notices) are delivered.
Warning · BAA-040
PHI referenced in document
BAA should explicitly reference PHI or ePHI; absence likely means the wrong template.
Critical · BAA-041
Choice-of-law overrides federal HIPAA
Flags clauses that purport to make state law control over HIPAA — preempted but indicates poor drafting.
Warning · BAA-042
Survival of HIPAA obligations after termination
BAA should state that HIPAA-related obligations survive termination.
Warning · BAA-043
Definitions track current HIPAA terminology
BAA should track current HIPAA / HITECH terminology (Breach, Unsecured PHI, Covered Entity, Business Associate).
Warning · BAA-044
Covered entity / business associate roles named
BAA should clearly identify which party is the Covered Entity and which is the Business Associate.
Critical · BAA-045
Every run also applies 109 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.
Sources
Often reviewed with
How it works
- Open vaulytica.com — no account, nothing to install.
- Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
- Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
More healthcare documents
- Business Associate Agreement (HIPAA)
- Clinical Trial Agreement
- HIPAA Notice of Privacy Practices
- Informed Consent (Research / Clinical)
- Medical Director Agreement
- Notice of Privacy Practices Acknowledgment
- Payer / Provider Participation Agreement
- Patient Authorization for Release of PHI
- Physician Employment Agreement
- Telehealth Informed Consent