hipaa-baa-management

Installation
SKILL.md

HIPAA Business Associate Agreement Management — §164.502(e), §164.504(e)

Overview

The HIPAA Privacy and Security Rules require covered entities to obtain satisfactory assurances from business associates that they will appropriately safeguard PHI. These assurances are documented through Business Associate Agreements (BAAs). The HITECH Act of 2009 and the 2013 Omnibus Rule fundamentally changed the BA landscape by making business associates directly liable for HIPAA Security Rule compliance and certain Privacy Rule provisions, and by extending the BAA chain to subcontractors. A BAA is not merely a contractual formality — it is a regulatory requirement, and failure to execute a BAA when required is itself a HIPAA violation subject to enforcement.

Who Is a Business Associate — §160.103

Definition

A business associate is a person or entity that:

  1. On behalf of a covered entity or another business associate, creates, receives, maintains, or transmits PHI for a function or activity regulated by the HIPAA Administrative Simplification rules, including claims processing, data analysis, utilization review, quality assurance, billing, benefit management, practice management, and repricing; OR
  2. Provides legal, actuarial, accounting, consulting, data aggregation, management, administrative, accreditation, or financial services to or for a covered entity where the provision of the service involves the disclosure of PHI

Who Is NOT a Business Associate

Installs
22
GitHub Stars
239
First Seen
May 26, 2026
hipaa-baa-management — mukul975/privacy-data-protection-skills