Business associate agreements
When a vendor creates, receives, or keeps protected health information for a covered entity, HIPAA generally requires a written business associate agreement between them. The rules call for certain terms, but much of what matters commercially is negotiated beyond those: how quickly the vendor must report an incident, who pays for notifying patients, and whether indemnity or insurance stands behind the promises. Vendors that rely on subcontractors need matching agreements further down the chain. A template signed without reading can commit a company to obligations its systems cannot meet. The reporting and termination sections in particular deserve a careful read before signing.
Authorizations signed by patients
Patients are sometimes asked to sign a HIPAA authorization so their records can be shared with an employer, an insurer, a lawyer, or a family member. Before signing, check what information it reaches and who may receive it. An authorization can generally be revoked in writing going forward, although disclosures already made in reliance on it are not undone. Treatment generally cannot be conditioned on signing one, with limited exceptions. Patients asking for their own records do not need an authorization at all, because that is a separate right of access. A broad authorization requested in a lawsuit deserves the same care as any other document you sign there.
Reviewing the paper
In a first conversation we look at which role you play, because a covered entity, a vendor, and a subcontractor read the same agreement differently. We compare the agreement with the main services contract, since the two sometimes conflict on liability caps and on notice. We also ask how data actually moves through your systems, because promises in the agreement have to match practice. If an incident has already occurred, the agreement's reporting terms may already be running. We then mark the provisions worth negotiating and explain what each change would do for you and for the other side.