Business Associate Agreements are a HIPAA requirement, but their value depends on how they are written, maintained, and enforced. Too often, healthcare organizations execute a BAA and move on, only to find during an audit or incident that their agreements are incomplete, outdated, or impossible to locate.
In this webinar, Medcurity and Malek + Malek attorney Hannah Kimball review the full BAA lifecycle, from what a strong agreement includes to how organizations can build a management process that holds up when it matters most.
In this session, you will learn:
- Why BAAs matter beyond regulatory compliance
- Where healthcare organizations most commonly fall short, including limitations of liability provisions, vendor oversight gaps, and risks tied to the use of de-identified data
- How to structure, track, and manage BAAs across the full vendor relationship
Frequently Asked Questions (FAQs)
What is a Business Associate Agreement?
A Business Associate Agreement is a HIPAA-required contract between a healthcare organization and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It defines each party’s responsibilities for protecting that data.
Who is speaking at the webinar?
Hannah Kimball, Healthcare and Municipal Attorney at Malek + Malek, and Jordan Scherich, Senior Business Analyst at Medcurity, will lead the session. Hannah brings a background in healthcare regulatory compliance and HIPAA from her time at Pullman Regional Hospital before becoming an attorney. Jordan works with healthcare organizations nationwide on HIPAA Security Risk Analyses and compliance.
What will I learn from this webinar?
Attendees will learn why BAAs matter beyond compliance, where organizations most commonly fall short (limitation of liability provisions, vendor oversight, de-identified data risks), and how to structure, track, and manage BAAs across vendor relationships.
Who should attend this webinar?
Healthcare organizations, compliance officers, and practice or operations leaders responsible for vendor agreements and HIPAA compliance.