Security Questionnaire Mapper

Health information and business associate terms: the clause the question tests

Whether the supplier will take on business associate duties for health information.

How the customer usually asks it

example

"Will you sign a business associate agreement for the protected health information we share?"

Read this question

Anchor clauses

1 framework
FrameworkAnchor clause
HIPAA Security Rule (45 CFR 164)164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard) · 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)

Every framework that anchors this family is listed here; a register shows the ones ticked for the customer.

Evidence expected

The business associate agreement terms the supplier will sign, and the safeguards that apply to protected health information in the service.

The clauses, with what an assessor asks for

HIPAA 164.308(b)(1) Business Associate Contracts and Other Arrangements (Standard)

A covered entity may permit a business associate to handle ePHI only after obtaining satisfactory assurances via written contract. NIST recommends due diligence, security questionnaires, and ongoing monitoring of BAs.

Evidence an assessor expects: BA inventory; Executed BAAs; Vendor risk assessments; Ongoing monitoring records
Where answers usually fall short: BA inventory incomplete; BAAs missing for cloud vendors
Source: HIPAA Security Rule (45 CFR 164)
HIPAA 164.314(a)(1) Business Associate Contracts or Other Arrangements (Standard)

The contract or other arrangement required by 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.

Evidence an assessor expects: BAA template addressing all required 164.314(a)(2) elements; Government arrangement documentation where applicable; Special arrangement records (group health plan, plan sponsor); Subcontractor BAAs flowing down requirements; Legal review records for BAAs
Where answers usually fall short: Older BAAs missing post-Omnibus requirements; Government arrangements undocumented
Source: HIPAA Security Rule (45 CFR 164)
No ISO 27001 clause anchors this family, so with ISO 27001 held the register marks the question "beyond your certificate". That is a fact about where the clause sits, not about the controls you run.

Other families in privacy and data subject rights