Showmenu

Business Associate Agreement | Compliance and Privacy Services | UC Davis Health

Business Associate Agreement

A Business Associate Agreement is a HIPAA safeguard that is required if a third-party entity or person like a vendor or contractor will receive or have access to Protected Health Information (PHI) while performing work on behalf of UC Davis Health (UCDH). However, not every third-party that receives, handles, or has access to UCDH PHI is required to complete this agreement; the necessity is determined by the specific nature of the relationship and the data being handled. For example, there are  some cases where a BAA is not required and an alternative agreement like a Data Use Agreement (DUA) or Data Security  Agreement (DSA) may instead be required to protect the data. 

When a Business Associate Agreement (BAA) is Required

A BAA is generally required if any data is handled by:

  • The person or entity is outside of the University of California (UC).
  • The outside person or entity is receiving, maintaining, transmitting, or creating PHI on behalf of UCDH.
  • The outside person or entity is a healthcare provider receiving, maintaining, transmitting, or creating PHI for treatment purposes, but does not meet any specific exceptions listed below.

When a Business Associate Agreement (BAA) is NOT Required

A BAA is generally not required if any of the following scenarios are met:

  • The person or entity is a member of the UC workforce. (Note: Memorandum of Understanding (MOU) or other agreement may instead be required)
  • The outside person or entity is not receiving, maintaining, transmitting, or creating PHI on behalf of UCDH.
  • The outside person or entity is a healthcare provider and receives, maintains, transmits, or creates PHI, but also meets the specific exceptions listed below.

Specific Exceptions

Even if PHI is involved, a BAA is not generally required if the data is:

  • De-identified.
  • For payment purposes:
    • Included in claims sent to a health plan.
    • Included in payments to a healthcare provider.
    • Included in funds transferred to certain financial institutions.
  • Going to a Health Oversight Agency as part of federal or state programs.
  • Sent in response to law enforcement/subpoenas, or legal reporting requirements.

Questions

Please contact the Privacy Compliance Team by calling 916-734-8808 or emailing privacyprogram@health.ucdavis.edu