
Use this original Arca BAA template as a starting point when a company may create, receive, maintain, or transmit protected health information on behalf of a covered entity.
The template should be tailored to the actual services, data flows, security controls, breach timelines, and subcontractor model before use.
What is inside
Permitted uses and disclosures
Safeguards
Breach notification
Subcontractors
Return or destruction of PHI
Individual rights support
These resources are starting points, not legal advice. Review every template and recommendation against your facts, policies, and applicable law before use.