Free HIPAA policy template · v1.0 · Applies to business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Missing BAA; weak vendor controls · 164.308(b) / 164.502(e) BA Contracts
Template. Replace every
[bracketed]item with your organization's specifics. This Policy is for a Business Associate that uses subcontractors to help handle PHI. Have it reviewed by counsel before adoption.
This Policy establishes how [Organization], as a Business Associate, engages and oversees subcontractors that create, receive, maintain, or transmit protected health information (PHI) on its behalf, so that the protections [Organization] owes its covered-entity customers flow down unbroken. It satisfies 45 CFR §§ 164.502(e)(1)(ii), 164.308(b)(2)–(3), and 164.504(e)(2)(ii).
This Policy applies to every subcontractor, downstream vendor, or agent of [Organization] that may access PHI [Organization] handles under any Business Associate Agreement (BAA), and to the workforce members who select and manage them.
[Organization] does not permit a subcontractor to create, receive, maintain, or transmit PHI on its behalf until the subcontractor has provided , through an executed BAA, that it will appropriately safeguard that PHI. No PHI is disclosed to, and no access is granted to, a prospective subcontractor before the BAA is signed.
See where your organization stands on the controls this template cites.
Join UsEach subcontractor BAA imposes terms at least as protective as those [Organization] owes the covered entity, including: use and disclosure limited to what the agreement permits or law requires; the HIPAA Security Rule safeguards for ePHI; a duty to bind its own subcontractors on the same terms; reporting of security incidents and breaches to [Organization] within a defined timeframe; assistance with individual-rights requests; and return or destruction of PHI at termination.
[Organization] maintains a register of all subcontractors that handle PHI (the PHI involved, the BAA effective and renewal dates, and the assigned owner) and performs risk-appropriate due diligence before onboarding (e.g., security questionnaire, [SOC 2] report, or equivalent).
[Organization] reviews each PHI-handling subcontractor at least [annually] and on any material change (new data flows, an incident, a change of control). A subcontractor that materially breaches its BAA is remediated or terminated, and PHI is returned or destroyed.
On termination of a subcontractor relationship, [Organization] ensures the subcontractor returns or securely destroys all PHI it holds, capturing a return/destruction certificate; where infeasible, the BAA's protections continue for the retained PHI and further use is restricted.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.502(e)(1)(ii) | Subcontractor satisfactory assurances | §1 |
| 164.308(b)(2) | Written contract / arrangement | §1, §3, §4 |
| 164.308(b)(3) | Business associate contracts (flow-down) | §2 |
| 164.504(e)(2)(ii) | Business associate contract required terms | §2, §5 |
Reviewed at least annually by the [Privacy Official] and after any change to [Organization]'s subcontractor relationships. v1.0.