Glossary of Compliance

Compliance Glossary

Our list of curated compliance glossary offers everything you to know about compliance in one place.

Glossary » HIPAA » HIPAA Agreement

HIPAA Agreement

A HIPAA Business Associate Agreement is a contract between a HIPAA-covered entity (like a healthcare provider) and a business or individual that helps with certain functions involving PHI. It’s essentially a written arrangement that outlines how the PHI is used.

HIPAA requires covered entities to work with business associates who demonstrate the prowess to protect PHI. This must be validated using a contract or an agreement.

Also, the Health and Human Services (HHS) can audit business associates and subcontractors for HIPAA compliance, not just the covered entities. All three levels (covered entities, business associates, and subcontractors) must have a Business Associate Agreement (BAA) to meet HIPAA requirements.

What’s included in the agreement?

The Business Associate/Subcontractor Agreement must spell out several important details, as per HHS guidelines:

  • It describes how PHI can be used by the business associate/subcontractor
  • It ensures that the business associate/subcontractor will only misuse or share PHI within what the contract allows or requires by law
  • It mandates safeguards to prevent improper PHI use or sharing

Once these relationships are identified, you must ensure that third parties safeguard the PHI they handle. A signed agreement documents that the business associate understands and commits to handling PHI securely.

Additional reading

FedRAMP Compliance Of AWS EC2 Instances: Should You Worry?

If you’re using AWS EC2 (Elastic Compute Cloud) for your infrastructure, you might be wondering if you need to do anything to meet the security standards for handling government data. The good news is that your cloud service provider has already taken care of that with FedRAMP (Federal Risk and Authorization Management Program). FedRAMP sets…

NIST Privacy Framework: The Ultimate Guide

TL,DR: The NIST Privacy Framework (January 2020) consists of 3 components: Core (activities for privacy protection), Profiles (current and target privacy states), and Implementation Tiers (levels of risk management rigor) The Core is organized into 5 functions: Identify-P (understanding risks), Govern-P (governance structure), Control-P (data processing management), Communicate-P (stakeholder transparency), and Protect-P (data safeguards) Implementation…

How to Conduct a Gap Analysis for ISO 27001?

TL,DR: ISO 27001 gap analysis compares current security practices against ISO 27001 requirements. It identifies missing policies, controls, evidence, training, access practices, and technology safeguards. The article includes steps, prioritization guidance, common rollout challenges, a checklist, and a template. Implementing the ISO 27001 standard can be daunting for companies of all sizes. Faced with a…

Sprinto: Your growth superpower

Use Sprinto to centralize security compliance management – so nothing
gets in the way of your moving up and winning big.