Scanning and capture
HIPAA Business Associate Agreement
We sign BAAs.
Keep patient documents in Ademero with the agreement HIPAA requires. Request a copy of our Business Associate Agreement to review with your team.
01What a BAA is
The contract HIPAA requires of every vendor that touches PHI.
A Business Associate Agreement (BAA) is a legally binding contract required under HIPAA. When a covered entity engages a business associate to perform functions involving the use or disclosure of protected health information (PHI), a BAA is mandatory. It sets the legal framework for handling patient data under federal privacy and security standards.
Healthcare providers, health plans and clearinghouses must have a BAA with any vendor, processor or service provider that handles PHI. The HITECH Act extended direct liability to business associates for breaches, which makes the BAA more important than ever.
Request one if you use Ademero to:
- Store, process or transmit patient health information
- Manage documents that contain PHI
- Run healthcare workflows involving protected data
- Meet HIPAA requirements for business associate relationships
02What a BAA addresses
What HIPAA expects, and the controls that help.
Our agreement sets out its own terms; request a copy to read them in full. As general background, HHS guidance describes the topics a business associate agreement covers, and our products include controls that help you protect patient documents.
Topics a BAA covers under HIPAA
Permitted uses and disclosures
How the business associate may use and disclose PHI.
Safeguards
That the business associate protects PHI as the HIPAA Security Rule requires.
Reporting
Reporting uses or disclosures the agreement does not allow, including breaches.
Subcontractors
That subcontractors who handle PHI agree to the same restrictions.
Individual rights
Helping the covered entity respond to requests for access and amendment.
End of the relationship
What happens to PHI when the agreement ends.
Controls in the software
Permissions
Role-based access so the right people see each document.
Audit trail
A record of who viewed, changed or shared each document.
Retention and legal holds
Keep records for as long as your policies require.
Sign-in controls
Active Directory, SAML single sign-on and authenticator-app MFA in Content Central.
The federal rules behind BAAs
- HIPAA Privacy Rule
Restrictions on use and disclosure of PHI.
- HIPAA Security Rule
Requirements for protecting electronic PHI (ePHI).
- Breach Notification Rule
Requirements for notifying individuals of breaches.
- HITECH Act and Omnibus Rule
Direct liability for business associates and the later amendments.
03Request
Request your BAA.
04Questions
BAA basics.
When do I need a BAA?
You need a BAA with any vendor or service provider that will have access to protected health information (PHI). That includes document management systems, cloud storage, email services and any technology platform that processes healthcare data. If a vendor touches patient data in any form, a BAA is required.
Does Ademero sign BAAs?
Yes. Request a copy with the form on this page and review it with your own team and counsel.
What terms does the BAA include?
The terms are set out in the agreement itself. Request a copy to review them, and send any questions to support@ademero.com.
We need changes to the agreement. Who do we talk to?
Note them in the request form or email support@ademero.com, and we can discuss them with you.
Which Ademero products are used for patient documents?
Healthcare teams can use CapturePoint 6 to scan and read patient paperwork on their own PCs, Content Central to manage patient documents in the cloud or on their own servers, and Nucleus One for team projects, forms and client portals. Ask us which fits your setup.
05Built for healthcare documents
Software that helps you meet HIPAA.
Document management
Content Central
Team projects and client portals
Nucleus One
Fortune 500 companies and government agencies run on Ademero. Their security, IT and legal teams review us every year and keep renewing.