Free HIPAA policy template · v1.0 · Applies to covered entities & business associates · Companion: Procedures →
Adopting this document means committing to these HIPAA controls, the 45 CFR §164 requirements it helps satisfy, by area:
Common threats (NIST SP 800-30 classes) that the controls behind this document defend against:
Exploits: Missing BAA; weak vendor controls · 164.308(b) / 164.502(e) BA Contracts
Template. Replace every
[bracketed]item with your organization's specifics. A name in[Title Case]is your organization, a role, or a person; a phrase in[lower case]is a category of tool. Substitute the actual product you use (e.g.,[compliance tracking system]→ your chosen tool). Have this reviewed by counsel or your compliance advisor before adoption.
This Policy establishes how [Organization] selects, contracts with, and oversees the third-party vendors and service providers it relies on, and, where those vendors create, receive, maintain, or transmit protected health information (PHI/ePHI) on its behalf, how it obtains and documents the satisfactory assurances the HIPAA Rules require through a Business Associate Agreement (BAA). It ensures that vendor relationships introduce only measured, managed risk; that PHI is protected throughout the relationship lifecycle; and that subcontractor obligations flow down the chain. It satisfies the HIPAA Security Rule organizational requirements at 45 CFR §§ 164.308(b)(1) and 164.314(a), the Privacy Rule business-associate requirements at §§ 164.502(e) and 164.504(e), and the group-health-plan requirement at § 164.314(b).
See where your organization stands on the controls this template cites.
Join UsThis Policy applies to all third-party vendors, service providers, contractors, and other external parties that [Organization] engages in the course of business (including any party that accesses, stores, processes, or transmits [Organization] or customer data, and any business associate that handles PHI on [Organization]'s behalf) and to the subcontractors those parties use. It applies to all workforce members (employees, contractors, interns, and volunteers) who own, manage, or evaluate a vendor relationship, and it governs the relationship from initial need through due diligence, contracting, ongoing oversight, and termination. Vendor onboarding screening, access provisioning and revocation, encryption of data shared with vendors, and breach handling are governed by the Workforce Security, Training & Sanctions Policy, Access Control Policy, Data Security & Encryption Policy, and Breach Notification Policy respectively; this Policy addresses vendor selection, BAAs, and oversight.
[Organization] maintains a documented program for managing third-party relationships and the risk they pose to operations, data, and reputation. The program includes:
A Business Owner, a workforce member who identifies the need and manages the relationship, is assigned to every vendor, and a member of leadership authorizes the engagement. The program operates across the full lifecycle: need identification → risk assessment and due diligence → contracting → ongoing monitoring → issue management → termination. (164.308(b)(1))
[Organization] executes a written Business Associate Agreement (BAA) before disclosing PHI to, or allowing PHI to be created/received/maintained/transmitted by, any vendor that performs a function or service on its behalf involving PHI. A BAA is required when, for example, a vendor:
[cloud infrastructure provider] or [cloud productivity & storage suite] holding PHI);[Organization] creates or maintains PHI;A BAA is not required for: a true conduit that only transports PHI without routine access (e.g., a postal/courier service or an ISP moving encrypted traffic); a vendor that genuinely has no access to PHI; a member of [Organization]'s own workforce; or another covered entity for treatment purposes. When it is unclear whether a vendor is a business associate, the [Privacy Officer] makes and documents the determination, defaulting to executing a BAA where access to PHI is reasonably possible. Disclosing PHI to a business associate without a BAA in place is prohibited. (164.502(e)(1), 164.308(b)(1))
The BAA is the written satisfactory assurance that the business associate will appropriately safeguard PHI. Every [Organization] BAA must require the business associate to, at minimum:
[Organization]'s behalf (164.314(a)(2)(i)(A));[Organization] (164.504(e)(2)(i));[Organization] without unreasonable delay: [Organization] requires notice within [without unreasonable delay and no later than 5 calendar days] of discovery (and immediately for an incident involving suspected unauthorized disclosure of PHI), with the detail needed to meet [Organization]'s own breach-assessment obligations (164.314(a)(2)(i)(C), 164.504(e)(2)(ii)(C));[Organization] if the business associate violates a material term (164.314(a)(2)(i)(D), 164.504(e)(2)(iii)).[Organization] uses an approved BAA template (referenced in the companion Vendor & Business Associate Management Procedures); a vendor's own BAA is acceptable only after review against this checklist. Before execution and at renewal, a member of leadership (in coordination with the [Privacy Officer] and [Security Official]) reviews BAAs and all critical/high-risk vendor contracts to confirm the required terms are present. (164.308(b)(1), 164.314(a)(1), 164.314(a)(2)(i), 164.504(e)(2))
The chain of satisfactory assurances must extend to every subcontractor that handles PHI downstream of a business associate. [Organization] requires, through its BAAs, that each business associate obtain a compliant BAA with any subcontractor before disclosing PHI to it, and that those downstream agreements impose protections at least as stringent as those [Organization] imposes on the business associate. The obligation flows down the full chain. A subcontractor is itself a business associate and must in turn bind its own subcontractors. [Organization] may request evidence that downstream BAAs exist as part of due diligence (§5) and ongoing oversight (§6). (164.308(b)(1), 164.314(a)(2)(i)(B), 164.502(e)(1)(ii))
Before [Organization] engages a vendor, the Business Owner conducts due diligence scaled to the vendor's risk. A risk assessment produces a rating, high / medium / low (critical vendors are those whose failure would halt operations or that handle sensitive/confidential data), based on factors including the vendor's expertise, experience, and reputation; the nature and necessity of the service; whether the vendor will access PHI or other sensitive/confidential data; and the vendor's own security posture. The rating determines the depth of due diligence and the cadence of ongoing oversight. Due diligence evaluates the vendor's control environment and may include reviewing independent attestations (e.g., SOC 2 reports), security questionnaires, certifications, penetration-test summaries, and the vendor's policies. Leadership reviews and approves all high-risk and critical vendors before contracting; results are documented and retained. (164.308(b)(1))
[Organization] monitors business associates and critical vendors throughout the relationship and is responsible for managing the risk of the services they provide. Monitoring is risk-based:
A re-assessment is also triggered by significant changes: a change in the scope of data the vendor handles, a major change to the vendor's product/service, a merger or acquisition, or a security incident. If [Organization] becomes aware of a pattern of activity or practice of a business associate that constitutes a material breach or violation of the BAA, it must take reasonable steps to cure the breach or end the violation; if unsuccessful, it must terminate the agreement, or if termination is not feasible, report the problem to HHS (164.504(e)(1)(ii)). Issues identified through monitoring are assessed, prioritized, assigned an owner, and tracked to resolution. (164.308(b)(1), 164.504(e)(1)(ii))
PHI is disclosed to a business associate only as permitted by the BAA and only the minimum necessary to accomplish the contracted purpose. The BAA specifies the permitted uses and disclosures of PHI by the business associate; uses or disclosures beyond those terms are prohibited. A business associate may use or disclose PHI for its own proper management and administration or to carry out its legal responsibilities only if the BAA so permits and the required assurances/breach-reporting conditions are met. [Organization] does not rely on a vendor's verbal assurances in place of the written agreement. (164.502(e), 164.504(e)(2)(i))
Where [Organization] sponsors or administers a group health plan and ePHI is shared with the plan sponsor, the plan documents must be amended to require the plan sponsor to:
These plan-document provisions are in addition to any BAA required for vendors to the plan. (If [Organization] does not sponsor or administer a group health plan, mark this section N/A and document why.) (164.314(b))
When a vendor relationship ends, [Organization] minimizes operational impact and protects its data. The Business Owner completes a vendor off-boarding checklist covering, as applicable: return or secure destruction of [Organization] and customer data (including ePHI per the BAA's termination terms), removal of the vendor's access to systems and facilities (per the Access Control Policy), and any transition plan. Where a business associate cannot feasibly return or destroy PHI at termination, [Organization] requires that the BAA's protections continue to apply to the retained PHI and that further use/disclosure be limited to the purposes that make return/destruction infeasible. Additional steps may apply for critical or high-risk vendors based on their risk assessment. (164.308(b)(1), 164.504(e)(2)(ii)(J))
[Privacy Officer]: owns this Policy; determines whether a vendor is a business associate; oversees the BAA program and the vendor/BAA inventory; coordinates HHS-reportable situations with counsel.[Security Official]: reviews vendor security posture and BAA security terms; incorporates vendor risk into the risk register; supports incident handling involving vendors.[Organization]'s security and privacy requirements, bind their subcontractors, and report incidents promptly.Vendor & Business Associate Management Procedures · Security & Privacy Program Policy · Access Control Policy · Workforce Security, Training & Sanctions Policy · Data Security & Encryption Policy · Security Incident Response Policy · Breach Notification Policy.
| Citation | Requirement | Addressed in |
|---|---|---|
| 164.308(b)(1) | Business Associate Contracts: satisfactory assurances (Security Rule) | §1, §2, §3, §4, §5, §6, §9 |
| 164.502(e) | Business Associate Contracts (Privacy Rule) | §2, §4, §7 |
| 164.504(e) | Business Associate Contracts: content & other requirements (Privacy Rule) | §3, §6, §7, §9 |
| 164.314(a)(1) | Business Associate Contracts (Organizational / Security Rule) | §3 |
| 164.314(a)(2) | BA Contract Content / Other Arrangements | §3, §4 |
| 164.314(b) | Requirements for Group Health Plans | §8 |
Reviewed at least annually by the [Privacy Officer] (with the [Security Official]) and after any significant change to the vendor population or the ePHI environment. v1.0.