vaulytica

BAA — Business Associate to Subcontractor (HIPAA) review

Business-associate to subcontractor BAA under HIPAA. Checks cover 45 CFR § 164.504(e) required clauses, § 164.314(a) Security Rule flow-down, § 164.410 breach notification, plus HHS-guidance posture rules — with an emphasis on flow-down (the subcontractor must comply with the same terms the upstream BAA imposes on the business associate, per 45 CFR § 164.502(e)(1)(ii) and § 164.504(e)(5)).

Review your document — free → See a sample report

What it checks

Permitted uses and disclosures of PHI

BAA must establish the permitted and required uses and disclosures of PHI by the business associate.

Critical · BAA-001

Use limited to permitted purposes

Business associate may not use PHI for any purpose other than as permitted by the BAA or required by law.

Critical · BAA-002

Appropriate safeguards clause

BAA must require BA to use appropriate safeguards, including Security Rule administrative, physical, and technical safeguards.

Critical · BAA-003

Report improper uses or disclosures

BAA must require BA to report to the covered entity any use or disclosure not provided for by the contract.

Critical · BAA-004

Subcontractor flow-down

BA must ensure subcontractors that handle PHI agree in writing to the same restrictions and conditions.

Critical · BAA-005

Access to PHI (164.524)

BAA must require BA to make PHI available in a Designated Record Set to satisfy 45 CFR 164.524.

Critical · BAA-006

Amendment of PHI (164.526)

BAA must require BA to make PHI available for amendment to satisfy 45 CFR 164.526.

Critical · BAA-007

Accounting of disclosures (164.528)

BAA must require BA to maintain and make available the information required to provide an accounting of disclosures.

Critical · BAA-008

Books and records available to HHS Secretary

BAA must require BA to make its internal practices, books, and records available to HHS for compliance review.

Critical · BAA-009

Return or destruction at termination

BA must, at termination, return or destroy all PHI received from, or created on behalf of, the covered entity.

Critical · BAA-010

Termination right for material breach

Covered entity must have the right to terminate the BAA for material breach by the business associate.

Critical · BAA-011

Authorization to terminate if cure infeasible

BAA should authorize termination when cure of a material breach is not feasible.

Warning · BAA-012

Security Rule compliance required

BAA must require BA to comply, where applicable, with the Security Rule with respect to ePHI.

Critical · BAA-013

Administrative safeguards referenced

BAA should reference administrative safeguards required by the Security Rule.

Warning · BAA-014

Physical safeguards referenced

BAA should reference physical safeguards required by the Security Rule.

Warning · BAA-015

Technical safeguards referenced

BAA should reference technical safeguards required by the Security Rule.

Warning · BAA-016

Security incident reporting

BAA must require BA to report security incidents to the covered entity.

Critical · BAA-017

Subcontractor flow-down for Security Rule

BA must ensure subcontractors handling ePHI agree to the Security Rule restrictions.

Critical · BAA-018

Breach notification clause present

BAA must require BA to notify the covered entity of a breach of unsecured PHI.

Critical · BAA-019

Breach notification looser than 60 days

Flags breach-notice timing that exceeds the 60-day outer bound or shifts the trigger to a later event.

Critical · BAA-020

Breach trigger is 'discovery'

Breach-notification timing should be measured from 'discovery,' not a stricter post-discovery event.

Warning · BAA-021

'Without unreasonable delay' language present

BAA should include 'without unreasonable delay' to match HIPAA's inner timing bound.

Warning · BAA-022

Security Incident narrowed to 'successful' access

Flags clauses that limit 'Security Incident' to only successful unauthorized accesses — a narrowing OCR has criticized.

Warning · BAA-023

Return-or-destruction lacks definite outer bound

Flags return-or-destruction language that is open-ended ('as soon as practicable', 'commercially reasonable').

Warning · BAA-024

Indemnity cap impairing HIPAA remedies

Flags liability caps that limit damages below the covered entity's potential HIPAA penalty exposure.

Warning · BAA-025

Covered entity audit rights preserved

BAA should preserve the covered entity's right to audit BA's HIPAA compliance.

Warning · BAA-026

Covered entity indemnifies BA for HIPAA violations

Flags clauses where the covered entity indemnifies the business associate for HIPAA violations — a common vendor overreach.

Warning · BAA-027

PHI / ePHI defined or cross-referenced

BAA should define PHI/ePHI or cross-reference the HIPAA definition.

Warning · BAA-028

Minimum-necessary standard referenced

BAA should reference HIPAA's minimum-necessary standard.

Warning · BAA-029

Mitigation obligation

BAA should require BA to mitigate harmful effects of any improper use or disclosure.

Critical · BAA-030

Workforce training requirement

BAA should require BA's workforce members handling PHI to be trained on its obligations.

Warning · BAA-031

Encryption or NIST safeguards referenced

BAA should reference encryption / NIST-style safeguards for ePHI at rest and in transit.

Warning · BAA-032

Risk assessment requirement

BAA should require BA to conduct periodic risk assessments per § 164.308(a)(1).

Warning · BAA-033

Sanctions policy / personnel discipline

BAA should reference BA's sanctions policy for workforce members who violate HIPAA/BAA.

Warning · BAA-034

Subprocessor / vendor disclosure

BAA should require BA to disclose subprocessors / downstream vendors that handle PHI.

Warning · BAA-035

Signed by authorized representative

BAA should be signed by an authorized representative of each party (satisfactory assurances).

Critical · BAA-036

Effective date present

BAA should state an effective date.

Warning · BAA-037

Term / duration clause present

BAA should specify its term.

Warning · BAA-038

Governing law specified

BAA should specify the governing law.

Warning · BAA-039

Notice clause present

BAA should specify how formal notices (including breach notices) are delivered.

Warning · BAA-040

PHI referenced in document

BAA should explicitly reference PHI or ePHI; absence likely means the wrong template.

Critical · BAA-041

Choice-of-law overrides federal HIPAA

Flags clauses that purport to make state law control over HIPAA — preempted but indicates poor drafting.

Warning · BAA-042

Survival of HIPAA obligations after termination

BAA should state that HIPAA-related obligations survive termination.

Warning · BAA-043

Definitions track current HIPAA terminology

BAA should track current HIPAA / HITECH terminology (Breach, Unsecured PHI, Covered Entity, Business Associate).

Warning · BAA-044

Covered entity / business associate roles named

BAA should clearly identify which party is the Covered Entity and which is the Business Associate.

Critical · BAA-045

Every run also applies 109 general checks that belong to any agreement: structure, parties and signatures, defined terms, cross-references, dates, amounts, and one-sided terms.

Sources

Often reviewed with

How it works

  1. Open vaulytica.com — no account, nothing to install.
  2. Drop your PDF or DOCX. The document type is detected and only the checks that belong to it run, inside your browser tab.
  3. Get a Word report in which every finding quotes the clause and cites the rule and source behind it — one of 1,825 checks across 268 document types.
Review your document — free →

More healthcare documents

Every document type →