All prompts
Analyze
Review a business associate agreement
Separates what the rule requires from what you have to negotiate, then fixes the four terms that decide who pays after an incident: notice timing, subcontractor flow-down, return-or-destroy, and where breach costs sit against the liability cap.
Your prompt
2
Pressure-test it
3
Go deeper
Before you run it
What to gather first
Watch for
What comes back
See an example of what you’ll get
*(After you answer the five questions, say, no other business unit has signed this vendor's form; we hand Vantage a nightly feed and take back risk scores, with no say in how they build or review the models; MSA § 12.2 caps everything at roughly $340,000 and § 1.4 makes the MSA control; subcontractors unknown; and we have leverage for two asks, not six.)*
Not signable as drafted, though not for the reason § 4.1 appears to give. Subcontractor flow-down is missing outright, and MSA § 12.2 caps everything, including breach response, at roughly $340,000 against 220,000 records. Whether § 4.1's sixty-day notice window also consumes our own notification clock turns on a fact nobody has established yet; the arithmetic below runs it both ways.
REQUIRED ELEMENTS
| Element | Status | Section |
|---|---|---|
| Permitted uses and disclosures | Present | § 2.1 |
| No further use or disclosure | Present | § 2.2 |
| Appropriate safeguards | Present but weakened | § 3.1: "commercially reasonable efforts" |
| Report breaches and security incidents | Present but weakened | § 4.1: timing defeats it |
| Subcontractor flow-down | Missing | No subcontractor provision anywhere |
| Individual access, amendment, accounting | Present | §§ 5.1–5.3 |
| HHS access to books and records | Present | § 6.1 |
| Return or destroy at termination | Present but weakened | § 8.2: infeasibility escape with no conditions |
| Termination for material breach | Present | § 9.1 |
NOTICE TIMING: the arithmetic, and the question underneath it. § 4.1: "Business Associate shall notify Covered Entity of a Breach without unreasonable delay and in no case later than sixty (60) days following discovery."
Two inputs decide what that costs us, and I am supplying neither from memory:
- Our own outer limit for notifying individuals. [UNVERIFIED - read the current covered-entity notification deadline in the breach notification rule before you calendar anything below. I am not stating a number.]
- Whether Vantage's discovery date is imputed to us. The discovery provision treats a breach as known to the covered entity when it is known to us or to our *agent*, so imputation turns on whether Vantage is our agent under common-law agency principles, not on what the BAA calls it. On your answer, we hand them a nightly feed and take back scores with no say in how they build or review the models, which reads as independent contractor; on that reading our clock starts when they tell us, not when they find out. [UNVERIFIED - confirm the imputation provision and the agency test. This is a control question of fact, and it is what decides how bad § 4.1 is.]
Run it both ways, so you can price the ask:
- *If Vantage is our agent:* their discovery is our discovery. Let them take fifty-five of their sixty days and whatever remains of our own limit has to cover investigating, building the mailing file, and notifying 220,000 people in three states. That is not a schedule.
- *If Vantage is an independent contractor:* § 4.1 does not eat our deadline, but the incident is still up to sixty days old before we hear a word, and the California medical-privacy clock, our carrier's notice condition, and any customer notice obligation may have run in the meantime. [UNVERIFIED - confirm the current CMIA period.]
The ask is identical either way, which is why I would not spend the negotiation arguing about which branch we are in:
> Ask: "Business Associate shall notify Covered Entity of any Breach or any Security Incident involving Protected Health Information within forty-eight (48) hours of Discovery. For this purpose, Discovery means the first date on which the incident is known, or by exercising reasonable diligence would have been known, to any employee, officer, or agent of Business Associate other than the person committing the Breach. Notice shall not be delayed pending completion of Business Associate's investigation."
> Fallback: 72 hours, with the discovery definition non-negotiable. The definition matters more than the number.
SUBCONTRACTORS: nothing in the document. Vantage runs analytics; something downstream is holding this data.
> Ask: "Business Associate shall not disclose PHI to any subcontractor without a written agreement imposing terms no less protective than this BAA, shall maintain a current list of such subcontractors and the country in which each processes PHI, shall provide that list on request, and shall give thirty (30) days' notice before adding any subcontractor. Business Associate remains liable for its subcontractors' acts and omissions."
RETURN OR DESTROY: § 8.2. The infeasibility escape has no conditions attached, so on this drafting the vendor keeps the data on its own say-so.
> Ask: Add: "...and where return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to such PHI indefinitely, limit further uses and disclosures to those purposes that make return or destruction infeasible, and certify in writing the categories retained and the reason. All other PHI shall be destroyed within thirty (30) days of termination and certified in writing."
THE MONEY. The BAA is silent on breach costs, so MSA §§ 12.2 and 12.3 answer it, and the answer is that forensics, notification, monitoring, and OCR response for 220,000 records all sit inside a $340,000 cap. Ask for a breach carve-out from the cap and a cyber insurance requirement naming us as additional insured. This is the ask worth spending leverage on, not § 3.1's "commercially reasonable."
STATE OVERLAY. California CMIA and § 1798.82; Texas HB 300 adds training and access obligations that reach the vendor. The 4,000 behavioral health records may carry a separate federal regime with its own consent rules that this BAA does not address at all. [UNVERIFIED - confirm before signing.]
ASSUMPTIONS. That Vantage is an independent contractor rather than our agent, on your description of how the work actually runs [verify - this is a control question, and if operations is in fact directing their model reviews, it flips and § 4.1 becomes the headline problem]. That the MSA cap applies to the BAA: § 1.4's precedence clause says the MSA controls [verify, and consider reversing it]. That no exhibit outside what I was given addresses subcontractors [verify]. That the behavioral health records are subject to the separate federal regime [verify - this changes the analysis materially if so].
WHAT YOUR ANSWERS CHANGED. Your description of how the work actually runs (feed out, scores back, no say in method) is what turned § 4.1 from a headline into a branch, and it is the one answer I would re-check with the operations team before signing, because it is the difference between "we lose our clock" and "we lose two months of visibility." Your leverage answer is why the cap carve-out leads and § 3.1's "commercially reasonable" is not on the ask list at all. That no other unit has signed this form changed nothing. I would have made the same four asks either way.
Why this prompt is built the way it is
## Framework
1. **Two lists, never one.** Required elements in one, negotiated asks in the other. Presenting an ask as a requirement loses the requirements too.
2. **Notice timing is arithmetic.** The covered entity's own clock runs from the business associate's discovery. Show what the drafted period leaves.
3. **Define the trigger.** "Discovery," not "confirmation" or "conclusion of the investigation."
4. **Security-incident reporting has to be workable.** Aggregate the noise; trigger immediately on anything touching PHI.
5. **Follow the subcontractor chain** to the offshore processor nobody named.
6. **Return-or-destroy always has an escape.** If retention is permitted, protections extend indefinitely and use is limited.
7. **Find the money.** Breach costs sit inside or outside the underlying cap, and the BAA is usually silent about which.