Covered Entity NameExtract the Covered Entity name...
Business Associate NameExtract the Business Associate name...
Effective DateExtract the BAA effective date. Return in YYYY-MM-...
TermExtract the agreement term or duration...
Services DescriptionExtract the description of services requiring PHI ...
PHI Uses PermittedList permitted uses of PHI by the Business Associa...
PHI Disclosures PermittedList permitted disclosures of PHI...
Minimum NecessaryIs minimum necessary standard referenced? Yes or N...
Safeguards RequiredList required administrative, physical, and techni...
Subcontractor Flow-DownMust the BA ensure subcontractors agree to same re...
Breach Notification TimelineExtract the breach notification timeline (e.g., wi...
Breach Notification MethodExtract the required breach notification method (w...
Security Incident ReportingIs security incident reporting (beyond breaches) r...
Individual Rights SupportList individual rights the BA must support: Access...
Access Request TimelineExtract timeline for BA to provide access to PHI u...
Amendment ObligationsExtract BA obligations regarding PHI amendments...
Accounting of DisclosuresMust BA track disclosures for accounting? Yes or N...
HHS Audit RightsDoes BAA permit HHS access to records for complian...
CE Audit RightsDoes Covered Entity have direct audit rights over ...
Termination for BreachCan CE terminate for material BAA breach? Yes or N...
PHI Return/DestructionExtract requirements for PHI return or destruction...
Destruction CertificationIs destruction certification required? Yes or No...
Survival ProvisionsList obligations that survive termination...
Insurance RequirementsExtract cyber liability or professional liability ...
IndemnificationSummarize indemnification provisions related to HI...
Liability CapExtract any liability cap for HIPAA-related claims...
HITECH ComplianceDoes the BAA reference HITECH Act compliance? Yes ...
State Law ProvisionsExtract any state-specific health privacy law refe...
Governing LawExtract the governing law jurisdiction...
Compliance GapsList any missing required BAA provisions or HIPAA ...