A Business Associate Agreement is a HIPAA safeguard that is required if a third-party entity or person like a vendor or contractor will receive or have access to Protected Health Information (PHI) while performing work on behalf of UC Davis Health (UCDH). However, not every third-party that receives, handles, or has access to UCDH PHI is required to complete this agreement; the necessity is determined by the specific nature of the relationship and the data being handled. For example, there are some cases where a BAA is not required and an alternative agreement like a Data Use Agreement (DUA) or Data Security Agreement (DSA) may instead be required to protect the data.
When a Business Associate Agreement (BAA) is Required
A BAA is generally required if any data is handled by:
- The person or entity is outside of the University of California (UC).
- The outside person or entity is receiving, maintaining, transmitting, or creating PHI on behalf of UCDH.
- The outside person or entity is a healthcare provider receiving, maintaining, transmitting, or creating PHI for treatment purposes, but does not meet any specific exceptions listed below.
When a Business Associate Agreement (BAA) is NOT Required
A BAA is generally not required if any of the following scenarios are met:
- The person or entity is a member of the UC workforce. (Note: Memorandum of Understanding (MOU) or other agreement may instead be required)
- The outside person or entity is not receiving, maintaining, transmitting, or creating PHI on behalf of UCDH.
- The outside person or entity is a healthcare provider and receives, maintains, transmits, or creates PHI, but also meets the specific exceptions listed below.
Specific Exceptions
Even if PHI is involved, a BAA is not generally required if the data is:
- De-identified.
- For payment purposes:
- Included in claims sent to a health plan.
- Included in payments to a healthcare provider.
- Included in funds transferred to certain financial institutions.
- Going to a Health Oversight Agency as part of federal or state programs.
- Sent in response to law enforcement/subpoenas, or legal reporting requirements.
Questions
Please contact the Privacy Compliance Team by calling 916-734-8808 or emailing privacyprogram@health.ucdavis.edu.