HIPAA COW BUSINESS ASSOCIATE AGREEMENT TEMPLATE 
September 27, 2002HIPAA COW BA Agreement Template1INTRODUCINGTHE HIPAA COW BUSINESS ASSOCIATE AGREEMENT TEMPLATECarol RubinCo-Chair, HIPAA Privacy TaskforceSeptember 27, 2002HIPAA COW BA Agreement Template2CREATION OF HIPAA COW BAC TEMPLATEDrafted by Contracting Workgroup of the HIPAA COW Privacy Taskforce over many monthsMembers:•Janice Ahlstrom--BORN•Sue Bevsek--Covenant Health Care•Wendy Bergh--Group Health Cooperative•Tracey Klein--Reinhart Boerner Von Deuren SC•Nancy LeMarbre—ProHealth Care•Roger Rego--Beaver Dam Community Hospital•Carol Rubin--WEA Trust Had a variety of different BA templates to consider, including DHHS model Wanted to add value by injecting our pragmatic insight of how a variety of BA relationships actually functionBiggest issues should be referenced in footnotesDozens of smaller decisions embodied in the provisionsMust be customized and reviewed by your attorneySeptember 27, 2002HIPAA COW BA Agreement Template3BAC FORMATSAddendumSections to incorporate into a brand new contractStand-alone HIPAA Privacy Agreement?September 27, 2002HIPAA COW BA Agreement Template4LESSONS LEARNEDDo not just insert provisions from the HIPAA statute or regulationsMinimize HIPAA definitions; do not need to define:•Covered Entity•Business Associate•Designated Record SetWhere a definition is essential to contract, reword or combine definitions to make it intelligible to BAAs much as possible, exclude all references to federal code which:•Could frighten unsophisticated BA’s•Force them to secure legal advice where they otherwise wouldn’t need toBAC should help educate BAs, not force them to secure legal advice to understand totality of HIPAA lawSeptember 27, 2002HIPAA COW BA Agreement Template5ISSUES/CHALLENGESUse of PHISecurity IssuesRelationship of BAC and TPAReporting of Unauthorized DisclosuresAccounting of DisclosuresTerm and TerminationPlus othersSeptember 27, 2002HIPAA COW BA Agreement Template6USE OF PHIHow to harmonize:•The general prohibition on BA’s use•The BA use expressly permitted by contract, and •The use for BA’s “proper management and administration, or . . . . legal responsibilities. . .”See Provisions 2, 3, and 4September 27, 2002HIPAA COW BA Agreement Template7HOW TO ADDRESS SECURITY ISSUES WHEN THE SECURITY RULE IS NOT FINALImpose general security obligation to safeguard PHI on BA, Provision 5If CE wants to review BA’s security safeguards, see Footnote 4Plus, Provision 7 references conformance with more specific HIPAA security requirements once those regulations are effective if this BA receives PHI in electronic formSeptember 27, 2002HIPAA COW BA Agreement Template8RELATIONSHIP OF BAC AND TRADING PARTNER AGREEMENTProvision 8: We inserted a very minimal TPA provision, to use if desiredAnother HIPPA COW EDI taskforce is working on a TPADelete if BA does not conduct any Standard Transaction for youYes, a BA and a TPA, and a Chain of Trust agreement can be combinedBut many Trading Partner relationships will not have an underlying BAC, for example, between a provider and a payer where provider only submits claimsSeptember 27, 2002HIPAA COW BA Agreement Template9REPORTING OF UNAUTHORIZED DISCLOSURES OR MISUSESee Provision 11Establish and spell out the procedure now, not after the misuseHelpful if all CEs used the same or similar procedureSeptember 27, 2002HIPAA COW BA Agreement Template10BA’s TRACKING AND ACCOUNTING OF DISCLOSURES: PROVISION 13Many legal concepts to fit into one provision, many of which might not be relevant to a particular BAMay appear intimidating to a BAExceptions at subsection (b) very significant, might eliminate all or most of the obligations of subsection (a)September 27, 2002HIPAA COW BA Agreement Template11TERM AND TERMINATION: PROVISION 15 AND FOOTNOTE 12CD’s unilateral right to terminate will trouble BAs, but is legally requiredProvision 15 is as explicit and non-threatening as possibleAdded requirements of notice, reasonableness, good faith, and material breach, none of which are expressly referenced in HIPAA regulations (greatest expansion on HIPAA requirements)September 27, 2002HIPAA COW BA Agreement Template12MISCELLANEOUS:PROVISIONS 17 AND FOOTNOTES 14-17Indemnification Automatic amendment (lifted from DHSS model)Response to subpoenasOwnership of data and informationSeptember 27, 2002HIPAA COW BA Agreement Template13DISCUSSION/QUESTIONS?