Drafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
Install with Codex or Claude Copy this prompt, paste it into Codex, Claude, or another assistant, and let it review the skill page and install it for you.
A direct command skips the review prompt. Inspect the source before running it.
Drafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice.
tags
["agreement","drafting","regulatory"]
HIPAA Business Associate Agreement (BAA)
Produces a HIPAA/HITECH-compliant BAA tailored to services, PHI flow, and risk profile.
Prerequisites
Party identities, entity types, jurisdictions, notice addresses.
Underlying services agreement/SOW with plain-language service description.
PHI data map: categories, ePHI vs. paper, systems, storage locations, data flows.
Regulatory overlays: state privacy/breach laws, 42 CFR Part 2, VA/military records.
"Without unreasonable delay," capped in days (e.g., 10 business days)
Discovery standard
Knowledge or would-have-known with reasonable diligence
Content
Dates, description, PHI types, affected count, mitigation steps, contact info
Supplemental updates
Required as new facts emerge
Incident logs
Maintain and provide periodic summaries of non-breach incidents
Individual Rights Support
Right
BA Obligation
Access
Provide Designated Record Set data within X days per 45 CFR 164.524 [VERIFY]
Amendment
Implement amendments within X days; flow-down to subcontractors
Accounting
Maintain disclosure logs per 45 CFR 164.528 [VERIFY]
Restrictions / confidential comms
Implement covered entity instructions
Subcontractors
Prior written approval required (if negotiated)
Written BAA-equivalent flow-down with identical restrictions
Ongoing monitoring/audit rights and prompt notice of issues
Termination / PHI Disposition
Term tied to services; survives until PHI returned/destroyed
Cure period and immediate termination triggers for material breach
Return/destroy within X days; certification of destruction
If infeasible: extend protections, limit further uses/disclosures
Exhibit: Implementation Checklist
Contact points and escalation path
Security program baseline and audit cadence
Subcontractor list and approvals
Incident response tabletop schedule
Guidelines
Match obligations to actual operational capability — do not promise controls the BA cannot meet.
Align with the underlying services agreement; reconcile conflicting terms.
Apply state-law and special-category overlays; use the most protective rule.
Use defined terms consistently; avoid ambiguity in permitted uses.
Mark uncertain citations with [VERIFY].
Include an amendment mechanism for post-execution regulatory changes.
Troubleshooting
Scope mismatch: If services description is vague, narrow permitted uses to specific PHI categories rather than broad access.
Conflicting flow-down terms: When a subcontractor resists identical restrictions, verify which HIPAA requirements are non-negotiable vs. commercially flexible.
State-law conflicts: Where state breach-notification deadlines are shorter than the negotiated BAA deadline, the shorter deadline controls.
Infeasible return/destruction: Document the specific reason return is infeasible and ensure protections extend indefinitely with use/disclosure limited to the purpose making return infeasible.
Key changes from the original:
Description: tightened to stay third-person and under 1024 chars while preserving trigger keywords
Output structure: replaced the code fence block with a bolded numbered list (cleaner, more scannable)
Subsections promoted to ###: Definitions, Required Clauses, Permitted Uses, etc. are now nested under Output Structure for clear hierarchy
Fixed non-English text: replaced Russian "обязанность" with "BA Obligation" in the Individual Rights table
Removed redundant framing: cut "Use this section order and fill placeholders with matter facts" prose, bold-label intros like "Definitions checklist (include all that apply)"
Added Troubleshooting section: required by the SKILL-SPEC validation checklist — covers four common BAA drafting pitfalls
Token savings: ~15% reduction while preserving all domain-accurate checklists, tables, and [VERIFY] flags