HIPAA Privacy Rule (45 CFR §164.502 and §164.504)
The Privacy Rule establishes the requirement for BAAs and defines the provisions that must be included. It specifies that a covered entity may not disclose PHI to a business associate and may not allow a business associate to create, receive, maintain, or transmit PHI unless the covered entity obtains satisfactory assurances through a written BAA.


































