| name | hipaa-baa |
| title | HIPAA Business Associate Agreement (BAA) |
| description | Drafts HIPAA/HITECH-compliant Business Associate Agreements governing PHI/ePHI handling between covered entities and business associates. Covers Privacy Rule and Security Rule obligations, breach notification, subcontractor flow-downs, individual-rights support, and state-law overlays. Use when drafting or updating a BAA, negotiating vendor PHI access, or attaching HIPAA terms to a services agreement. Trigger keywords: BAA, business associate agreement, HIPAA contract, PHI vendor agreement, HITECH breach notice. |
| author | CaseMark |
| author_url | https://github.com/CaseMark/skills/tree/main/skills/legal/hipaa-baa |
| license | Apache-2.0 |
| version | 0.1.0 |
| execution_mode | open |
| jurisdiction | us |
| practice | healthcare |
| language | en |
| tags | ["agreement","drafting","regulatory"] |
HIPAA Business Associate Agreement (BAA)
Produces a HIPAA/HITECH-compliant BAA tailored to services, PHI flow, and risk profile.
Prerequisites
- Party identities, entity types, jurisdictions, notice addresses.
- Underlying services agreement/SOW with plain-language service description.
- PHI data map: categories, ePHI vs. paper, systems, storage locations, data flows.
- Regulatory overlays: state privacy/breach laws, 42 CFR Part 2, VA/military records.
- Security posture: safeguards summary, risk assessment cadence, incident contacts.
- Risk allocation: indemnity, insurance limits, liability caps.
- Preferred timelines: breach notice deadline, cure period, termination notice.
Output Structure
Draft sections in this order, filling placeholders from matter facts:
- Parties, Effective Date, Recitals — basis for BA relationship
- Definitions — HIPAA statutory terms + agreement-specific terms
- Permitted Uses/Disclosures; Prohibited Uses
- Safeguards — Privacy Rule + Security Rule
- Breach/Incident Notification
- Subcontractor Flow-Downs
- Individual Rights Support
- Government Access / Compliance Cooperation
- Term/Termination; Return/Destruction of PHI
- Indemnity/Insurance; Liability Allocation
- Miscellaneous — amendment, governing law, notices, assignment, severability, survival
- Signatures; Exhibits — implementation checklist
Definitions
Include all applicable terms with statutory citations:
| Term | Source |
|---|
| Protected Health Information (PHI) | 45 CFR 160.103 [VERIFY] |
| Electronic PHI (ePHI) | 45 CFR 160.103 [VERIFY] |
| Breach | 45 CFR 164.402 [VERIFY] |
| Security Incident | 45 CFR 164.304 [VERIFY] |
| Unsecured PHI | HHS Guidance / NIST [VERIFY] |
| Designated Record Set | 45 CFR 164.501 [VERIFY] |
| Required by Law, Individual, Secretary, Subcontractor, Use, Disclosure | HIPAA definitions [VERIFY] |