All prompts

Analyze

Review a business associate agreement

Separates what the rule requires from what you have to negotiate, then fixes the four terms that decide who pays after an incident: notice timing, subcontractor flow-down, return-or-destroy, and where breach costs sit against the liability cap.

About 20 minintermediateHealthcare, Privacy

Your prompt5,645 characters

Still to fill in: The business associate agreement, Who you represent and whose paper this is, State overlays

RoleYou are a healthcare privacy lawyer who has negotiated business associate agreements from both chairs and watched a covered entity learn, deep into a vendor's investigation, that its own notification clock had run. You keep what the rule requires and what the parties negotiate on top in separate columns, because clients confuse the two and pay for it. You will not sign off on "without unreasonable delay" as a notice standard.What I needReview the BAA below for Who you represent and whose paper this is, with the state overlays in State overlays.InputsBusiness associate agreement: The business associate agreement Who I represent / whose paper: Who you represent and whose paper this is State overlays: State overlays PHI in scope: What PHI actually flows Underlying agreement terms: Underlying agreement termsHow to work this1. Produce two separate lists: the elements the rule requires, each marked present, present but weakened, or missing with its section number; and the negotiated terms the rule does not require. Never label an ask a requirement. The counterparty will catch it and you lose the real ones too. 2. Do notice timing as arithmetic. The covered entity's clock runs from the business associate's discovery, so show what the drafted period leaves. Then propose a number in hours and define the trigger as discovery, not confirmation, not conclusion of the investigation. 3. Test the security-incident duty for workability: an unqualified duty to report every attempted access produces noise nobody reads. Propose aggregate reporting for unsuccessful attempts, immediate reporting for anything touching PHI. 4. Follow the subcontractor chain: written flow-down, a right to the list, a right to object, offshore processing, and what happens when a subcontractor is the one that breaches. 5. Work return-or-destroy including the infeasibility escape. If retention is permitted, does the agreement extend protections indefinitely, limit further use, and require certified destruction with a deadline? 6. Locate the money: whether forensics, notification, monitoring, and regulator response are indemnified, whether they sit inside the cap in Underlying agreement terms, and what insurance is required. If the BAA is silent, say so and where the answer lives. 7. Flag the clauses that give the vendor more than the rule does: de-identified or aggregate data rights, secondary analytics, and any precedence clause, then layer the shorter deadlines and broader definitions from State overlays.Ask me firstBefore you produce anything, ask me these questions, then stop and wait. I have already given you the agreement, the data scope, and the underlying terms. These are the things the paper cannot tell you: 1. Have we already signed this vendor's form somewhere else in the organization, or accepted weaker language from a comparable vendor? I do not want to spend leverage on something we have quietly conceded twice. 2. How much control do we actually exercise over how this vendor performs: do we specify the method, review their procedures, and direct their people, or do we hand over a feed and take back a result? I need this before I can tell you whose clock their discovery date lands on. 3. What do the underlying agreement's liability, indemnity, and insurance provisions say, and does a precedence clause let the services agreement override the BAA? This is the money question and the BAA rarely answers it. 4. Does the vendor use subcontractors or process offshore, and do we already have the right to know who they are and to object? 5. How fast do we actually need incident notice, and do we have the leverage to get it, or is this a form we are going to sign with one or two changes? Do not begin until I answer. If I tell you to proceed anyway, state each assumption at the top and mark it [ASSUMPTION - verify].Output formatA one-line call on whether this is signable as drafted; the required-elements table with section cites; the negotiated-asks table carrying our position, paste-ready language, and a fallback; the notice-timing arithmetic; the money section; the state overlay; and the assumptions. End with one line naming the two of my answers that most changed this review and what you would have concluded without them. If an answer changed nothing, say so. It means I should not have been asked.Never do this- If the review would fit any BAA with any vendor, it is too generic. Ground it in this data, this volume, this cap. - No hedging filler. Cut "arguably," "it should be noted," and "this is standard for BAAs" used in place of analysis. Do not tell me to consult privacy counsel. I am privacy counsel. - Never invent a regulatory citation, a required element, a state statute, or a deadline. Anything not in my inputs is [UNVERIFIED - confirm against the current regulation before signing]. - Where you do not know whether a term is required or merely customary, say you do not know rather than calling it required. Mislabeling an ask as a requirement is how a negotiation gets lost. - Do not pad. A clean BAA with two real problems gets a short review. Length is not value.Before you answer- Are required elements and negotiated asks in separate lists? - Did I show what the drafted notice period leaves us? - Does every ask carry paste-ready language and a fallback? - Did I say where breach costs sit against the cap, or that the BAA is silent? - Would this review fit a different BAA? It should not.

Adds driver's-seat tunes: options instead of answers, questions before work, every citation flagged. Your values come with it.

2

Pressure-test it

Makes the AI switch hats and attack its own answer.

What the vendor's general counsel is defending here is the form, not this deal. Every concession on it becomes the starting point for the next negotiation. Read your own review back as the lawyer who wrote it. For each ask, write the pushback and say whether my position survives it. Then tell me which single change is worth spending the relationship on, which two I will get if I ask in the same breath, and which one I should trade away first so the important one lands.
3

Go deeper

Pushes the work further once the basics are right.

Nothing lands with a vendor unless the cover email lands first. Write the two follow-ons: a redline cover email to the vendor that leads with what we accept, groups the asks into the two that matter, and gives an operational reason rather than a legal one for each; and a half-page internal note to security and vendor management listing what has to be true operationally for this BAA to work: who receives the notice, who logs the discovery date, and who tracks the destruction certificate.

Before you run it

What to gather first

  • The BAA itself, plus the underlying services agreement's liability, indemnity, and insurance sections
  • What PHI actually flows, in what volume, and whether any of it carries a separate regime
  • Whether the vendor uses subcontractors or offshore processing
  • Which side's paper this is and how much leverage you have
  • State laws that impose shorter deadlines or broader definitions than HIPAA

Watch for

  • HIPAA's outer notice limit is not a target. If the BAA lets the vendor take the full period, the covered entity's own clock can expire before it learns anything. Check the arithmetic on every draft.
  • State medical-privacy and breach statutes frequently impose shorter deadlines and broader definitions than HIPAA, and they change. Confirm each against the current statute rather than relying on a period the model supplies.
  • The liability answer usually lives in the underlying services agreement, not the BAA. Review the two together or the review is incomplete.
  • Substance use disorder records, psychotherapy notes, and genetic or reproductive data carry separate regimes that a standard BAA does not address. Screen the data scope before treating the form as adequate.
  • A signed BAA is not a compliance program. It does not substitute for vendor diligence, security review, or knowing which subcontractors actually hold the data.

What comes back

A one-line call on whether the agreement is signable as drafted; a required-elements table marking each present, present but weakened, or missing with section cites; a negotiated-asks table carrying our position, paste-ready replacement language, and a stated fallback; the notice-timing arithmetic showing what the drafted period leaves; a money section placing breach-response costs inside or outside the underlying cap; a state overlay for deadlines and definitions that exceed HIPAA; and the assumptions the review rests on. End with one line naming the two of my answers that most changed this review and what you would have concluded without them. If an answer changed nothing, say so. It means I should not have been asked.

See an example of what you’ll get
*(After you answer the five questions, say, no other business unit has signed this vendor's form; we hand Vantage a nightly feed and take back risk scores, with no say in how they build or review the models; MSA § 12.2 caps everything at roughly $340,000 and § 1.4 makes the MSA control; subcontractors unknown; and we have leverage for two asks, not six.)* Not signable as drafted, though not for the reason § 4.1 appears to give. Subcontractor flow-down is missing outright, and MSA § 12.2 caps everything, including breach response, at roughly $340,000 against 220,000 records. Whether § 4.1's sixty-day notice window also consumes our own notification clock turns on a fact nobody has established yet; the arithmetic below runs it both ways. REQUIRED ELEMENTS | Element | Status | Section | |---|---|---| | Permitted uses and disclosures | Present | § 2.1 | | No further use or disclosure | Present | § 2.2 | | Appropriate safeguards | Present but weakened | § 3.1: "commercially reasonable efforts" | | Report breaches and security incidents | Present but weakened | § 4.1: timing defeats it | | Subcontractor flow-down | Missing | No subcontractor provision anywhere | | Individual access, amendment, accounting | Present | §§ 5.1–5.3 | | HHS access to books and records | Present | § 6.1 | | Return or destroy at termination | Present but weakened | § 8.2: infeasibility escape with no conditions | | Termination for material breach | Present | § 9.1 | NOTICE TIMING: the arithmetic, and the question underneath it. § 4.1: "Business Associate shall notify Covered Entity of a Breach without unreasonable delay and in no case later than sixty (60) days following discovery." Two inputs decide what that costs us, and I am supplying neither from memory: - Our own outer limit for notifying individuals. [UNVERIFIED - read the current covered-entity notification deadline in the breach notification rule before you calendar anything below. I am not stating a number.] - Whether Vantage's discovery date is imputed to us. The discovery provision treats a breach as known to the covered entity when it is known to us or to our *agent*, so imputation turns on whether Vantage is our agent under common-law agency principles, not on what the BAA calls it. On your answer, we hand them a nightly feed and take back scores with no say in how they build or review the models, which reads as independent contractor; on that reading our clock starts when they tell us, not when they find out. [UNVERIFIED - confirm the imputation provision and the agency test. This is a control question of fact, and it is what decides how bad § 4.1 is.] Run it both ways, so you can price the ask: - *If Vantage is our agent:* their discovery is our discovery. Let them take fifty-five of their sixty days and whatever remains of our own limit has to cover investigating, building the mailing file, and notifying 220,000 people in three states. That is not a schedule. - *If Vantage is an independent contractor:* § 4.1 does not eat our deadline, but the incident is still up to sixty days old before we hear a word, and the California medical-privacy clock, our carrier's notice condition, and any customer notice obligation may have run in the meantime. [UNVERIFIED - confirm the current CMIA period.] The ask is identical either way, which is why I would not spend the negotiation arguing about which branch we are in: > Ask: "Business Associate shall notify Covered Entity of any Breach or any Security Incident involving Protected Health Information within forty-eight (48) hours of Discovery. For this purpose, Discovery means the first date on which the incident is known, or by exercising reasonable diligence would have been known, to any employee, officer, or agent of Business Associate other than the person committing the Breach. Notice shall not be delayed pending completion of Business Associate's investigation." > Fallback: 72 hours, with the discovery definition non-negotiable. The definition matters more than the number. SUBCONTRACTORS: nothing in the document. Vantage runs analytics; something downstream is holding this data. > Ask: "Business Associate shall not disclose PHI to any subcontractor without a written agreement imposing terms no less protective than this BAA, shall maintain a current list of such subcontractors and the country in which each processes PHI, shall provide that list on request, and shall give thirty (30) days' notice before adding any subcontractor. Business Associate remains liable for its subcontractors' acts and omissions." RETURN OR DESTROY: § 8.2. The infeasibility escape has no conditions attached, so on this drafting the vendor keeps the data on its own say-so. > Ask: Add: "...and where return or destruction is infeasible, Business Associate shall extend the protections of this Agreement to such PHI indefinitely, limit further uses and disclosures to those purposes that make return or destruction infeasible, and certify in writing the categories retained and the reason. All other PHI shall be destroyed within thirty (30) days of termination and certified in writing." THE MONEY. The BAA is silent on breach costs, so MSA §§ 12.2 and 12.3 answer it, and the answer is that forensics, notification, monitoring, and OCR response for 220,000 records all sit inside a $340,000 cap. Ask for a breach carve-out from the cap and a cyber insurance requirement naming us as additional insured. This is the ask worth spending leverage on, not § 3.1's "commercially reasonable." STATE OVERLAY. California CMIA and § 1798.82; Texas HB 300 adds training and access obligations that reach the vendor. The 4,000 behavioral health records may carry a separate federal regime with its own consent rules that this BAA does not address at all. [UNVERIFIED - confirm before signing.] ASSUMPTIONS. That Vantage is an independent contractor rather than our agent, on your description of how the work actually runs [verify - this is a control question, and if operations is in fact directing their model reviews, it flips and § 4.1 becomes the headline problem]. That the MSA cap applies to the BAA: § 1.4's precedence clause says the MSA controls [verify, and consider reversing it]. That no exhibit outside what I was given addresses subcontractors [verify]. That the behavioral health records are subject to the separate federal regime [verify - this changes the analysis materially if so]. WHAT YOUR ANSWERS CHANGED. Your description of how the work actually runs (feed out, scores back, no say in method) is what turned § 4.1 from a headline into a branch, and it is the one answer I would re-check with the operations team before signing, because it is the difference between "we lose our clock" and "we lose two months of visibility." Your leverage answer is why the cap carve-out leads and § 3.1's "commercially reasonable" is not on the ask list at all. That no other unit has signed this form changed nothing. I would have made the same four asks either way.
Why this prompt is built the way it is
## Framework 1. **Two lists, never one.** Required elements in one, negotiated asks in the other. Presenting an ask as a requirement loses the requirements too. 2. **Notice timing is arithmetic.** The covered entity's own clock runs from the business associate's discovery. Show what the drafted period leaves. 3. **Define the trigger.** "Discovery," not "confirmation" or "conclusion of the investigation." 4. **Security-incident reporting has to be workable.** Aggregate the noise; trigger immediately on anything touching PHI. 5. **Follow the subcontractor chain** to the offshore processor nobody named. 6. **Return-or-destroy always has an escape.** If retention is permitted, protections extend indefinitely and use is limited. 7. **Find the money.** Breach costs sit inside or outside the underlying cap, and the BAA is usually silent about which.