Business associate agreements
The agreement describes permitted and required uses and disclosures and the safeguards and responsibilities that apply.
HHS guidance →SmartMBX does not treat a marketing form, public chatbot or ordinary email as a place for patient information.
When SmartMBX acts as a business associate for work involving PHI, the parties first define permitted work, access, safeguards and responsibilities in a written agreement.
Business contact and workflow information only. No patient identifiers.
Identify the service, systems, people, minimum necessary access and data flow.
Put the applicable service agreement and BAA in place before protected data moves.
Use the agreed administrative, physical and technical safeguards, access controls and audit process.
HHS explains that covered entities and business associates are subject to HIPAA requirements based on their role, and that a covered entity engaging a business associate for work involving PHI needs a written business associate contract or arrangement. HHS also describes the Security Rule as requiring reasonable and appropriate administrative, physical and technical safeguards for ePHI.
The agreement describes permitted and required uses and disclosures and the safeguards and responsibilities that apply.
HHS guidance →Access and use should be limited to what is reasonably necessary for the intended purpose, subject to applicable exceptions and the actual relationship.
HHS guidance →This page is an operating summary, not a legal opinion or certification. The HIPAA Rules, signed agreements and qualified legal/security guidance control.