Step by step

Business Associate Decision Tree

This decision tree will help you determine if an entity is a “business associate” and requires a BAA.

1

Step 1

Does the entity provide services on behalf of DPH? 

 

  • No.  The entity is not a business associate.  
  • Yes. Go to Step 2. 
Show more
2

Step 2

Will the entity create, receive, maintain, or transmit protected health information (PHI) on behalf of DPH? 

  • No.  The entity is not a business associate. 
  • Yes. Go to Step 3. 
Show more
3

Step 3

Is it an individual healthcare provider who is receiving PHI for the purpose of treating an individual? 

  • No.  Go to Step 4. 
  • Yes. The entity is not a business associate. 
Show more
4

Step 4

Does the entity perform a service for DPH involving PHI (e.g., healthcare operations or payment functions)?


OR


Does the entity provide legal, accounting, consulting, data aggregation, management, administrative, or other similar services for DPH?


OR


Does the entity provide data transmission services with respect to PHI and the entity requires access to the PHI on a routine basis (i.e., the entity is not merely the conduit for the PHI)?
 

  • Yes. Go to Step 5.
  • No.  The entity is not a business associate.
Show more
5

Step 5

The entity is a business associate and requires a business associate agreement before DPH can share any PHI with the entity.  

Show more

Last updated April 18, 2023