A BAA Spells Out Permitted Use, “Appropriate Safeguards”
The HIPAA Privacy Rule of 2003 first defined covered entities and business associates, describing the latter as those that do work on behalf of a covered entity that involves the use or disclosure of PHI. The 2013 HIPAA Omnibus Rule offered additional clarification, generally defining business associates as those that create, receive, maintain, transmit or store PHI on behalf of a covered entity.
The Department of Health and Human Services has indicated that a BAA must describe permitted and required uses of PHI, prohibit further disclosure beyond those use cases, require “appropriate safeguards” to prevent use or disclosure beyond what the BAA specifies and require reporting of any disclosure of PHI the contract doesn’t account for.
What those “appropriate safeguards” should be often remains in the eye of the beholder. HIPAA itself is meant to be technology-neutral and doesn’t explicitly spell them out. (This is understandable in part because the authors of HIPAA had no way to anticipate how technology would evolve in the decades that followed the law’s signing.)
The HIPAA Security Rule offers some clues, indicating that covered entities and business associates must “implement a series of administrative, physical, and technical safeguards to ensure the confidentiality, integrity, and availability” of electronic PHI. According to HHS, this means ensuring data confidentiality, integrity and availability while protecting against data security threats, “reasonably anticipated” impermissible data disclosure, and noncompliant employee behavior.
Cuffe says proper data classification and data lifecycle management are an important part of this process. Along with outlining what safeguards a business partner puts in place at each stage of this lifecycle, it’s important for covered entities to define who, when and why users and systems get to use the data.
“Organizations need to set boundaries about who can access what,” he says. “You need to establish clear guidelines for technical and employee enablement. Whether it’s PHI or important corporate data, you need to make sure it’s not leaked.”
Click the banner below to power employee productivity with AI.
