Business Associate Agreements
Procedure for Executing a SOM HIPAA Business Associate Agreement Do you contract with vendors who may have access or be exposed to Patient Health Information (PHI) while completing their work for you? If so, the vendor should sign a Business Associate Agreement (BAA) prior to performing any work. How do you go about getting a BAA executed for School of Medicine vendors? Contact Kelly_Merrell@med.unc.edu or 919-843-7925 to begin the process described in this article. When SOM departments enter into agreements with outside vendors involving the vendor’s access or exposure to information considered to be PHI, pursuant to the Health Information Privacy and Portability Act (HIPAA), a BAA is required. The SOM is the Covered Entity (custodian of the information) and the Business Associate is the vendor (providing services to the SOM). When the SOM acts as the Business Associate, the HIPAA Coordinator requests that the SOM standard template be used, and facilitates the same process as below. Persons involved in the process of executing BAAs on behalf of the SOM may include:
The SOM Privacy Officer and HIPAA Coordinator review all SOM requests for BAAs. If it is determined that a BAA is required when the SOM acts as Covered Entity, the HIPAA Coordinator:
|

