Business Associate Agreement
Business Associate Agreement (BAA)
If your organization may disclose PHI to PDPM Audit Group for PowerChart90 or related audit services, a BAA should be in place before that disclosure. Marketing language alone is not a BAA.
Effective date: August 17, 2026 · Last updated: August 17, 2026
Policy: Prefer fully de-identified or synthetic charts for evaluation. Upload PHI only after counsel confirms a BAA covers the disclosure and the minimum-necessary standard is met.
1. When a BAA is needed
Under HIPAA, a vendor that creates, receives, maintains, or transmits PHI for a covered entity may be a business associate. Whether a BAA is required for your use depends on facts—including whether data are actually de-identified. That determination belongs to your privacy/compliance counsel.
2. How to execute
- Email audit-defense@pdpmauditgroup.com with subject “BAA request — PowerChart90.”
- Include legal entity name, facility NPI(s), primary privacy contact, and whether you need our form or will provide yours.
- We return a long-form BAA for countersignature. Electronic checkbox acceptance on product pages is a preliminary acknowledgment only and does not replace a countersigned enterprise BAA when counsel requires one.
3. Summary of BA obligations (not the full contract)
- Use and disclose PHI only to provide agreed audit-readiness services
- Apply administrative, physical, and technical safeguards appropriate to the risk
- Ensure subcontractors that handle PHI agree to equivalent restrictions
- Report unauthorized uses/disclosures as required by the BAA and applicable law
- Return or destroy PHI at termination when feasible, subject to legal retention needs
4. Customer responsibilities
- Authorize disclosures and apply minimum necessary
- Train workforce users
- De-identify when possible; avoid SSNs, full addresses, and insurance IDs in pilots
- Do not treat tool output as a substitute for your compliance program