S02 - Attachment 3 - Business Associate Profile Questionnaire Fillable.pdf

PDF 381 KB Posted

Attached to
DA10--Evidence Based Practice [EBP] Research Tool [VA-25-00010231] Federal contract opportunity
Solicitation number
36C77625Q0105
Issued by
Department of Veterans Affairs Technology Acquisition Center Austin

About this file

The document is a Business Associate Profile Questionnaire for a vendor seeking to work with the Veterans Health Administration (VHA). The comprehensive five-page form requires detailed information about a company's handling of Protected Health Information (PHI), including data access, storage, transmission, destruction, and privacy/security practices. Key areas of inquiry include the number of employees with PHI access, methods of electronic and hard copy data handling, subcontractor agreements, potential data breaches, and compliance with HIPAA regulations. The questionnaire is designed to assess a potential business associate's capability to securely manage sensitive veteran healthcare information while maintaining appropriate privacy and security protocols.

View the file

Other files for this federal contract opportunity

Other files attached to DA10--Evidence Based Practice [EBP] Research Tool [VA-25-00010231], newest first.
File Type Posted
Attachment 01_PWS_EBP Research Tool_FINAL_V2.pdf PDF
36C77625Q0105 0001.docx DOCX document
S02 - Attachment 4 - Addendum A - Section 508 Accesibility Standards.docx DOCX document
S02 - Attachment 2 - Complete Site Listing 12.17.2024.xlsx XLSX spreadsheet
S02 - Attachment 1 - PWS_EBP Research Tool_FINAL.docx DOCX document
36C77625Q0105_1.docx DOCX document

On GovTribe

Work with this file on GovTribe

  • Download the original file
  • Contacts named in this file
  • Similar government files
  • Ask GovTribe AI about this file

Text version

Business Associate Profile Questionnaire

IMPORTANT NOTE: THIS QUESTIONNAIRE ASKS QUESTIONS CONCERNING THE RELATIONSHIP BETWEEN YOUR COMPANY AND THE VETERANS HEALTH ADMINISTRATION (VHA) AND THE PRIVACY AND SECURITY OF VHA DATA REQUIRED BY YOUR COMPANY. WE REQUEST THAT THE APPROPRIATE COMPANY OFFICIALS WITH KNOWLEDGE OF PRIVACY AND SECURITY CONTROLS ASSIST WITH COMPLETING, SIGNING AND DATING THIS

QUESTIONNAIRE.

1. Company Name & Address:

2. Is your company a health care provider as defined by the HIPAA Regulations at 45 CFR §160.103?

☐ Yes ☐ No

3. Does your company act as a member of VHA workforce as defined by the HIPAA Regulations at

45 CFR §160.103?

4. Does the function or activity of your company meet the definition of treatment under the HIPAA Privacy Rule at 45 CFR § 164.501?

☐ Yes ☐ No

If you answered “Yes” to Question 2-4, please disregard the remaining questions and submit form. If you answered “No” to either Question 2, 3, or 4, continue to Question 5.

5. A VHA Business Associate creates, receives, maintains, stores, or transmits Protected Health

Information (PHI) (patient identifiers such as name, social security number and address or any other of the 18 data elements outlined in the HIPAA Privacy Rule) to perform a function or activity on VHA’s behalf. Define in your own words, the function or activity your company provides on VHA’s behalf. (Include all services currently being provided regardless of whether they are covered under the National Business Associate Agreement (BAA) with VHA) https://www.law.cornell.edu/cfr/text/45/160.103 https://www.law.cornell.edu/cfr/text/45/160.103 https://www.law.cornell.edu/cfr/text/45/164.501

6. Does your company’s function or activity involve the use or disclosure of VHA’s PHI or do you access, store, create, receive, maintain or transmit VHA PHI?

☐ Yes ☐ No

If you answered “No” to Question 6, please disregard the remaining questions and submit form.

If you answered “Yes” to Question 6, complete the following questions before submitting the form.

7. Please provide contact information for your company official (Privacy Officer, Information Security Officer, Compliance Officer, etc.) that VHA should contact regarding the BAA relationship.

8. Include the names of all VHA Program Offices, VA Medical Centers or VISNs that receive the services identif ied in Question 5 above. (If more than 10, insert the number)

9. Does your company have any contracts/underlying agreements with VHA, relating to this BAA, which will be expiring within the next year?

☐ Yes ☐ No

If you answered “Yes” to question 9, please identify the contract/underlying agreement and the date it expires: (If more than 2, use the additional space at bottom of form)

Agreement Title:

Expiration Date:

Agreement Title:

Expiration Date:

10. Does your company access, create, receive, maintain, store, or transmit VHA PHI? (Select all that apply)

☐ Access ☐ Create ☐ Receive ☐ Maintain ☐ Store ☐ Transmit

10a. What is the number of your employees with access to VHA data?

Number of employees: ☐ 1-10 ☐ 11-25 ☐ 26-50 ☐ 51-100 ☐ Over 100 ☐ Over 500

11. Does your company access, create, receive, maintain, store, or transmit VHA PHI outside of a VHA facility? (Including PHI that has been disclosed to your company by VHA)

☐ Yes ☐ No (If you answered “No”, please skip to question 12.)

11a. What is the number of employees with access to VHA data outside a VHA facility?

Number of employees: ☐ 1-10 ☐ 11-25 ☐ 26-50 ☐ 51-100 ☐ Over 100 ☐ Over 500

11b. What is the number of location(s) where employees access VHA data outside of a VHA facility?

(Including PHI that has been disclosed to your company by VHA)

Number of locations: ☐ 1 ☐ 2-5 ☐ Over 5

11c. What is the location(s) where employees create, access, store or maintain VHA data outside of a VHA facility?

Location (Address, City, State, Zip Code, Country)

12. How is VHA PHI accessed? (Select all that Apply)

12a. Electronic Means of Access:

☐ VPN ☐ CAG ☐ Interconnection ☐ Direct Access to VHA ☐ Other ________________

12b. What is your hard copy means of accessing VHA PHI? (Select all that Apply) ☐ File ☐ Other Media (Films, Tissues, Photographs, Paper Documents) ☐ N/A

12c. What PHI is created by your company for VHA on VHA's behalf? (Select all that Apply) ☐ Electronic ☐ Hardcopy ☐ N/A

13. How many VHA records on individuals (PHI per individual) does your company create, access, receive, store, transmit, or maintain?

Number of Records: ☐ 0 ☐ 1-100 ☐ 100-1000 ☐ 1000-10,000 ☐ Over 10,000

14. Does your company use VHA PHI for purposes other than those specific to the functions or activities for which you are a Business Associate with VHA? (e.g., state reporting required of your company, litigation defense, etc.)

14a. If you answered yes, please list the purposes for which VHA data is being disclosed by your company outside the purposes under the BAA.

15. Does your company make disclosures of VHA PHI to other individuals or entities in its provision of specific services or activities to VHA, including disclosures to subcontractors for them to provide a portion of the service?

16. Does your company engage subcontractors in services provided to VHA under your BAA?

☐ Yes ☐ No (If you answered “No”, please skip to question 17.)

16a. Do you have a specific, documented chain-of-custody agreement that requires the subcontractor to meet the requirements set forth in your BAA with VHA?

☐ Yes ☐ No

16b. Do you have subcontractors who provide services to VHA that are outside of the jurisdiction of the laws of the United States?

16c. Do you have HIPAA mandated subcontractor Business Associate Agreements with your subcontractors who provide a portion of your services to VHA?

NOTE: If your company doesn’t have appropriate subcontractor Business Associate Agreements in place, this requirement must be satisfied to adhere to HIPAA and VA requirements.

17. Does your company destroy VHA PHI on VHA's behalf? (Including PHI that has been disclosed to your company by VHA)

☐ Yes ☐ No ☐ Return to VHA ☐ Retain for regulatory purposes ☐ Other (explain)_____________________________________________________

17a. If you answered “Yes” to question 17, does your company follow VHA’s records control schedule (RCS) for destruction of these records as outlined in RCS 10-1?

18. Does your company have direct contact with VHA patients?

19. Has your company entered into other BAAs on a local/regional/VISN level with VHA?

20. Does your company receive requests from third-parties for VHA data to be disclosed by you or created by you for purposes other than defined in the BAA?

21. Has your company ever been involved in an incident (as defined in the BAA) involving VHA PHI?

☐ Yes ☐ No (If answered “No”, skip to question 22.)

21a. How many incidents has your company had since completing the last questionnaire?

Number of Breaches: ☐ 1-5 ☐ 6-10 ☐ 11-20 ☐ Over 20 ☐ Over 50

21b. How many Veterans were affected?

Number of Veterans: ☐ Less than 500 ☐ Over 500

22. Check the appropriate positions assigned within your company:

☐ Privacy Officer ☐ Information Security Officer

☐ Compliance Officer ☐ Records Manager

23. Has your company developed and documented policies and procedures that explain safeguards to prevent use or disclosure of PHI not authorized by the BAA? (Specifically, policies related to Privacy, Security and Records Management)

☐ Yes ☐ No

24. Does your company have any other classification, other than Business Associate or health care provider, as defined under the HIPAA Privacy and Security Rules? (e.g., Covered Entity, Hybrid Entity, etc.)

If you answered yes to this question, please enter the type of classification:

Please use this space for any additional information you would like to provide:

Please obtain signatures for the appropriate company officials below:

Company Representative Date

Privacy/Compliance Officer Date

Information Security Officer Date

For questions concerning this questionnaire please contact the VHA BAA Issues mail group at vhabaaissues@va.gov.

mailto:vhabaaissues@va.gov

1 Company Name Address:
2 Is your company a health care provider as defined by the HIPAA Regulations at 45 CFR 160103: Off
undefined: Off
undefined_2: Off
National Business Associate Agreement BAA with VHA:
store create receive maintain or transmit VHA PHI: Off
Officer Compliance Officer etc that VHA should contact regarding the BAA relationship:
identified in Question 5 above If more than 10 insert the number:
will be expiring within the next year: Off
Agreement Title:
Expiration Date:
Agreement Title_2:
Expiration Date_2:
Access: Off
Create: Off
Receive: Off
Maintain: Off
Store: Off
Transmit: Off
110: Off
1125: Off
2650: Off
51100: Off
Over 100: Off
Over 500: Off
Yes_6: Off
No If you answered No please skip to question 12: Off
110_2: Off
1125_2: Off
2650_2: Off
51100_2: Off
Over 100_2: Off
Over 500_2: Off
1: Off
25: Off
Over 5: Off
Location Address City State Zip Code Country:
Location Address City State Zip Code Country_2:
Location Address City State Zip Code Country_3:
12a Electronic Means of Access: Off
CAG: Off
Interconnection: Off
Direct Access to VHA: Off
Other: Off
undefined_3:
File: Off
Other Media Films Tissues Photographs Paper Documents: Off
NA: Off
Electronic: Off
Hardcopy: Off
NA_2: Off
0: Off
1100: Off
1001000: Off
100010000: Off
Over 10000: Off
litigation defense etc: Off
undefined_4:
portion of the service: Off
Yes_9: Off
No If you answered No please skip to question 17: Off
to meet the requirements set forth in your BAA with VHA: Off
laws of the United States: Off
subcontractors who provide a portion of your services to VHA: Off
Yes_13: Off
No_11: Off
Return to VHA: Off
Retain for regulatory purposes: Off
undefined_5: Off
Other explain:
RCS for destruction of these records as outlined in RCS 101: Off
18 Does your company have direct contact with VHA patients: Off
19 Has your company entered into other BAAs on a localregionalVISN level with VHA: Off
by you for purposes other than defined in the BAA: Off
Yes_18: Off
No If answered No skip to question 22: Off
15: Off
610: Off
1120: Off
Over 20: Off
Over 50: Off
Less than 500: Off
Over 500_3: Off
Privacy Officer: Off
Compliance Officer: Off
Information Security Officer: Off
Records Manager: Off
Security and Records Management: Off
provider as defined under the HIPAA Privacy and Security Rules eg Covered Entity Hybrid Entity: Off
undefined_6:
Please use this space for any additional information you would like to provide:
Company Representative:
Date:
PrivacyCompliance Officer:
Date_2:
Information Security Officer_2:
Date_3:

File details come from the government source that posted it. Updated .