S02 - Attachment 3 - Business Associate Profile Questionnaire Fillable.pdf
PDF 381 KB Posted
- Attached to
- DA10--Evidence Based Practice [EBP] Research Tool [VA-25-00010231] Federal contract opportunity
- Solicitation number
- 36C77625Q0105
About this file
The document is a Business Associate Profile Questionnaire for a vendor seeking to work with the Veterans Health Administration (VHA). The comprehensive five-page form requires detailed information about a company's handling of Protected Health Information (PHI), including data access, storage, transmission, destruction, and privacy/security practices. Key areas of inquiry include the number of employees with PHI access, methods of electronic and hard copy data handling, subcontractor agreements, potential data breaches, and compliance with HIPAA regulations. The questionnaire is designed to assess a potential business associate's capability to securely manage sensitive veteran healthcare information while maintaining appropriate privacy and security protocols.
View the file
Other files for this federal contract opportunity
| File | Type | Posted |
|---|---|---|
| Attachment 01_PWS_EBP Research Tool_FINAL_V2.pdf | ||
| 36C77625Q0105 0001.docx | DOCX document | |
| S02 - Attachment 4 - Addendum A - Section 508 Accesibility Standards.docx | DOCX document | |
| S02 - Attachment 2 - Complete Site Listing 12.17.2024.xlsx | XLSX spreadsheet | |
| S02 - Attachment 1 - PWS_EBP Research Tool_FINAL.docx | DOCX document | |
| 36C77625Q0105_1.docx | DOCX document |
On GovTribe
Work with this file on GovTribe
- Download the original file
- Contacts named in this file
- Similar government files
- Ask GovTribe AI about this file
Text version
Business Associate Profile Questionnaire
IMPORTANT NOTE: THIS QUESTIONNAIRE ASKS QUESTIONS CONCERNING THE RELATIONSHIP BETWEEN YOUR COMPANY AND THE VETERANS HEALTH ADMINISTRATION (VHA) AND THE PRIVACY AND SECURITY OF VHA DATA REQUIRED BY YOUR COMPANY. WE REQUEST THAT THE APPROPRIATE COMPANY OFFICIALS WITH KNOWLEDGE OF PRIVACY AND SECURITY CONTROLS ASSIST WITH COMPLETING, SIGNING AND DATING THIS
QUESTIONNAIRE.
1. Company Name & Address:
2. Is your company a health care provider as defined by the HIPAA Regulations at 45 CFR §160.103?
☐ Yes ☐ No
3. Does your company act as a member of VHA workforce as defined by the HIPAA Regulations at
45 CFR §160.103?
4. Does the function or activity of your company meet the definition of treatment under the HIPAA Privacy Rule at 45 CFR § 164.501?
☐ Yes ☐ No
If you answered “Yes” to Question 2-4, please disregard the remaining questions and submit form. If you answered “No” to either Question 2, 3, or 4, continue to Question 5.
5. A VHA Business Associate creates, receives, maintains, stores, or transmits Protected Health
Information (PHI) (patient identifiers such as name, social security number and address or any other of the 18 data elements outlined in the HIPAA Privacy Rule) to perform a function or activity on VHA’s behalf. Define in your own words, the function or activity your company provides on VHA’s behalf. (Include all services currently being provided regardless of whether they are covered under the National Business Associate Agreement (BAA) with VHA) https://www.law.cornell.edu/cfr/text/45/160.103 https://www.law.cornell.edu/cfr/text/45/160.103 https://www.law.cornell.edu/cfr/text/45/164.501
6. Does your company’s function or activity involve the use or disclosure of VHA’s PHI or do you access, store, create, receive, maintain or transmit VHA PHI?
☐ Yes ☐ No
If you answered “No” to Question 6, please disregard the remaining questions and submit form.
If you answered “Yes” to Question 6, complete the following questions before submitting the form.
7. Please provide contact information for your company official (Privacy Officer, Information Security Officer, Compliance Officer, etc.) that VHA should contact regarding the BAA relationship.
8. Include the names of all VHA Program Offices, VA Medical Centers or VISNs that receive the services identif ied in Question 5 above. (If more than 10, insert the number)
9. Does your company have any contracts/underlying agreements with VHA, relating to this BAA, which will be expiring within the next year?
☐ Yes ☐ No
If you answered “Yes” to question 9, please identify the contract/underlying agreement and the date it expires: (If more than 2, use the additional space at bottom of form)
Agreement Title:
Expiration Date:
Agreement Title:
Expiration Date:
10. Does your company access, create, receive, maintain, store, or transmit VHA PHI? (Select all that apply)
☐ Access ☐ Create ☐ Receive ☐ Maintain ☐ Store ☐ Transmit
10a. What is the number of your employees with access to VHA data?
Number of employees: ☐ 1-10 ☐ 11-25 ☐ 26-50 ☐ 51-100 ☐ Over 100 ☐ Over 500
11. Does your company access, create, receive, maintain, store, or transmit VHA PHI outside of a VHA facility? (Including PHI that has been disclosed to your company by VHA)
☐ Yes ☐ No (If you answered “No”, please skip to question 12.)
11a. What is the number of employees with access to VHA data outside a VHA facility?
Number of employees: ☐ 1-10 ☐ 11-25 ☐ 26-50 ☐ 51-100 ☐ Over 100 ☐ Over 500
11b. What is the number of location(s) where employees access VHA data outside of a VHA facility?
(Including PHI that has been disclosed to your company by VHA)
Number of locations: ☐ 1 ☐ 2-5 ☐ Over 5
11c. What is the location(s) where employees create, access, store or maintain VHA data outside of a VHA facility?
Location (Address, City, State, Zip Code, Country)
12. How is VHA PHI accessed? (Select all that Apply)
12a. Electronic Means of Access:
☐ VPN ☐ CAG ☐ Interconnection ☐ Direct Access to VHA ☐ Other ________________
12b. What is your hard copy means of accessing VHA PHI? (Select all that Apply) ☐ File ☐ Other Media (Films, Tissues, Photographs, Paper Documents) ☐ N/A
12c. What PHI is created by your company for VHA on VHA's behalf? (Select all that Apply) ☐ Electronic ☐ Hardcopy ☐ N/A
13. How many VHA records on individuals (PHI per individual) does your company create, access, receive, store, transmit, or maintain?
Number of Records: ☐ 0 ☐ 1-100 ☐ 100-1000 ☐ 1000-10,000 ☐ Over 10,000
14. Does your company use VHA PHI for purposes other than those specific to the functions or activities for which you are a Business Associate with VHA? (e.g., state reporting required of your company, litigation defense, etc.)
14a. If you answered yes, please list the purposes for which VHA data is being disclosed by your company outside the purposes under the BAA.
15. Does your company make disclosures of VHA PHI to other individuals or entities in its provision of specific services or activities to VHA, including disclosures to subcontractors for them to provide a portion of the service?
16. Does your company engage subcontractors in services provided to VHA under your BAA?
☐ Yes ☐ No (If you answered “No”, please skip to question 17.)
16a. Do you have a specific, documented chain-of-custody agreement that requires the subcontractor to meet the requirements set forth in your BAA with VHA?
☐ Yes ☐ No
16b. Do you have subcontractors who provide services to VHA that are outside of the jurisdiction of the laws of the United States?
16c. Do you have HIPAA mandated subcontractor Business Associate Agreements with your subcontractors who provide a portion of your services to VHA?
NOTE: If your company doesn’t have appropriate subcontractor Business Associate Agreements in place, this requirement must be satisfied to adhere to HIPAA and VA requirements.
17. Does your company destroy VHA PHI on VHA's behalf? (Including PHI that has been disclosed to your company by VHA)
☐ Yes ☐ No ☐ Return to VHA ☐ Retain for regulatory purposes ☐ Other (explain)_____________________________________________________
17a. If you answered “Yes” to question 17, does your company follow VHA’s records control schedule (RCS) for destruction of these records as outlined in RCS 10-1?
18. Does your company have direct contact with VHA patients?
19. Has your company entered into other BAAs on a local/regional/VISN level with VHA?
20. Does your company receive requests from third-parties for VHA data to be disclosed by you or created by you for purposes other than defined in the BAA?
21. Has your company ever been involved in an incident (as defined in the BAA) involving VHA PHI?
☐ Yes ☐ No (If answered “No”, skip to question 22.)
21a. How many incidents has your company had since completing the last questionnaire?
Number of Breaches: ☐ 1-5 ☐ 6-10 ☐ 11-20 ☐ Over 20 ☐ Over 50
21b. How many Veterans were affected?
Number of Veterans: ☐ Less than 500 ☐ Over 500
22. Check the appropriate positions assigned within your company:
☐ Privacy Officer ☐ Information Security Officer
☐ Compliance Officer ☐ Records Manager
23. Has your company developed and documented policies and procedures that explain safeguards to prevent use or disclosure of PHI not authorized by the BAA? (Specifically, policies related to Privacy, Security and Records Management)
☐ Yes ☐ No
24. Does your company have any other classification, other than Business Associate or health care provider, as defined under the HIPAA Privacy and Security Rules? (e.g., Covered Entity, Hybrid Entity, etc.)
If you answered yes to this question, please enter the type of classification:
Please use this space for any additional information you would like to provide:
Please obtain signatures for the appropriate company officials below:
Company Representative Date
Privacy/Compliance Officer Date
Information Security Officer Date
For questions concerning this questionnaire please contact the VHA BAA Issues mail group at vhabaaissues@va.gov.
mailto:vhabaaissues@va.gov
| 1 Company Name Address: |
| 2 Is your company a health care provider as defined by the HIPAA Regulations at 45 CFR 160103: Off |
| undefined: Off |
| undefined_2: Off |
| National Business Associate Agreement BAA with VHA: |
| store create receive maintain or transmit VHA PHI: Off |
| Officer Compliance Officer etc that VHA should contact regarding the BAA relationship: |
| identified in Question 5 above If more than 10 insert the number: |
| will be expiring within the next year: Off |
| Agreement Title: |
| Expiration Date: |
| Agreement Title_2: |
| Expiration Date_2: |
| Access: Off |
| Create: Off |
| Receive: Off |
| Maintain: Off |
| Store: Off |
| Transmit: Off |
| 110: Off |
| 1125: Off |
| 2650: Off |
| 51100: Off |
| Over 100: Off |
| Over 500: Off |
| Yes_6: Off |
| No If you answered No please skip to question 12: Off |
| 110_2: Off |
| 1125_2: Off |
| 2650_2: Off |
| 51100_2: Off |
| Over 100_2: Off |
| Over 500_2: Off |
| 1: Off |
| 25: Off |
| Over 5: Off |
| Location Address City State Zip Code Country: |
| Location Address City State Zip Code Country_2: |
| Location Address City State Zip Code Country_3: |
| 12a Electronic Means of Access: Off |
| CAG: Off |
| Interconnection: Off |
| Direct Access to VHA: Off |
| Other: Off |
| undefined_3: |
| File: Off |
| Other Media Films Tissues Photographs Paper Documents: Off |
| NA: Off |
| Electronic: Off |
| Hardcopy: Off |
| NA_2: Off |
| 0: Off |
| 1100: Off |
| 1001000: Off |
| 100010000: Off |
| Over 10000: Off |
| litigation defense etc: Off |
| undefined_4: |
| portion of the service: Off |
| Yes_9: Off |
| No If you answered No please skip to question 17: Off |
| to meet the requirements set forth in your BAA with VHA: Off |
| laws of the United States: Off |
| subcontractors who provide a portion of your services to VHA: Off |
| Yes_13: Off |
| No_11: Off |
| Return to VHA: Off |
| Retain for regulatory purposes: Off |
| undefined_5: Off |
| Other explain: |
| RCS for destruction of these records as outlined in RCS 101: Off |
| 18 Does your company have direct contact with VHA patients: Off |
| 19 Has your company entered into other BAAs on a localregionalVISN level with VHA: Off |
| by you for purposes other than defined in the BAA: Off |
| Yes_18: Off |
| No If answered No skip to question 22: Off |
| 15: Off |
| 610: Off |
| 1120: Off |
| Over 20: Off |
| Over 50: Off |
| Less than 500: Off |
| Over 500_3: Off |
| Privacy Officer: Off |
| Compliance Officer: Off |
| Information Security Officer: Off |
| Records Manager: Off |
| Security and Records Management: Off |
| provider as defined under the HIPAA Privacy and Security Rules eg Covered Entity Hybrid Entity: Off |
| undefined_6: |
| Please use this space for any additional information you would like to provide: |
| Company Representative: |
| Date: |
| PrivacyCompliance Officer: |
| Date_2: |
| Information Security Officer_2: |
| Date_3: |
File details come from the government source that posted it. Updated .