Skip to the app
Search
The operating system for desk work that lives in files
Try a sample
Healthcare & Life Sciences · Audits cleared · Hours back · sample run · 62 ms

HIPAA BAA Gap Scanner

3 of 13 required BAA provisions are missing and 1 is weak; breach notice allows 90 days against the 60-day limit. 3 contract risks to negotiate.

Evidence · Agreement, Section 3.4
Business Associate shall use commercially reasonable efforts to ensure that any subcontractors that create, receive, maintain or transmit PHI on behalf of Busin
Working

Section 3.4 is the clause on 'Subcontractors agree to the same restrictions and conditions', but it hedges the duty with 'commercially reasonable efforts'. 45 CFR 164.504(e)(2)(ii)(D); 164.502(e)(1)(ii); 164.314(a)(2)(i)(B) requires: subcontractors agree to the same restrictions and conditions as the business associate, as a firm duty.

Method

1Checked the 13 provisions required by 45 CFR 164.504(e)(2)(i) to (iii) and 164.314(a)(2)(i) (Security Rule contract terms), each by topic patterns plus the elements the regulation requires.

2Present: a sentence on the topic contains every required element with no hedge. Weak: the topic is addressed but an element is missing, or the duty is hedged ('commercially reasonable efforts', 'endeavor', 'to the extent practicable') or overbroad ('any lawful purpose'). Missing: no sentence found.

3
Missing · Need model language
ItemResultCitation
Subcontractors agree to the same restrictions and conditionsWeak45 CFR 164.504(e)(2)(ii)(D); 164.502(e)(1)(ii); 164.314(a)(2)(i)(B)
Amendment of PHIMissing45 CFR 164.504(e)(2)(ii)(F); 164.526
Accounting of disclosuresMissing45 CFR 164.504(e)(2)(ii)(G); 164.528
1 to 3 of 8
Reads

Business associate agreement text

Produces

Provision checklist with missing clauses and model language (Model-language addendum, Provision checklist (CSV), Review results (JSON))

Price

$3,000 / month, 30% to the referring partner

Your files

Read in memory for the session, never stored, never used to train a model.

Not medical, clinical, coding or regulatory advice. A qualified healthcare, coding or regulatory professional must review every result. Privacy and security findings are not legal advice or an audit opinion. Confirm them with privacy counsel or a qualified assessor. Letters, notices and legal analysis are drafts, not legal advice. Have a qualified lawyer review them before they are sent or relied on.