The North Carolina Healthcare Information and Communications Alliance has released a revised model of its Business Associate Agreement that reflects changes in the HIPAA privacy and security rules under the HITECH Act within the American Recovery and Reinvestment Act.

Under HITECH, business associates are treated as covered entities for all provisions of the security rule and parts of the privacy rule. They also must notify covered entities of beaches of protected health information and face higher penalties for noncompliance with the rules.

Attorneys from NCHICA's legal workgroup revised the business associate agreement, which is available for free at Other free materials available to help covered entities in communicating with business associates include: a Notice to Covered Entities Under HIPAA Regarding New Requirements under the ARRA HITECH Act, a Template for Business Associate Alert and New Breach Notification Requirements, and a Summary of Selected ARRA and HITECH Act Provisions Related to Business Associates.

--Joseph Goedert

Register or login for access to this item and much more

All Health Data Management content is archived after seven days.

Community members receive:
  • All recent and archived articles
  • Conference offers and updates
  • A full menu of enewsletter options
  • Web seminars, white papers, ebooks

Don't have an account? Register for Free Unlimited Access