Organizational requirements., 45 CFR 164.314


Summary

Standard: Business associate contracts or other arrangements. The contract or other arrangement required by § 164.308(b)(3) must meet the requirements of paragraph (a)(2)(i), (a)(2)(ii), or (a)(2)(iii) of this section, as applicable.
Implementation specifications (Required).
Business associate contracts. The contract must provide that the business associate will—
Comply with the applicable requirements of this subpart;
In accordance with § 164.308(b)(2), ensure that any subcontractors that create, receive, maintain, or transmit electronic protected health information on behalf of the business associate agree to comply with the applicable requirements of this subpart by entering into a contract or other arrangement that complies with this section; and
Report to the covered entity any security incident of which it becomes aware, including breaches of unsecured protected health information as required by § 164.410.
Other arrangements. The covered ...