yourstate.us
48 CFR 839.105-70

839.105-70 Business Associate Agreements, information technology-related contracts and privacy.

United States · 48 CFR — Federal Acquisition Regulations System · Status: effective

Get this as JSONEmbed this
Cite this
Citation
48 CFR 839.105-70, 839.105-70 Business Associate Agreements, information technology-related contracts and privacy, United States, version 1 as recorded 2026-07-09, yourstate.us, https://yourstate.us/provision/247498
Permanent ID
ys:prov:247498@1
SHA-256
24c47d7b6bc8e87bd0ac52926fed8b333910598ce9c9d4837c77ddc3703b6249

The hash is SHA-256 of this version's text, with every run of whitespace collapsed to a single space and the ends trimmed. The ID always leads back here, and checking it says whether the text you cited is still the current version.

Full text

In accordance with 824.103-70, contracting officers and contracting officer representatives (CORs) shall ensure that contractors, their employees, subcontractors, and third-parties under the contract complete Business Associate Agreements for— (a) Information technology or information technology-related service contracts subject to the Health Insurance Portability and Accountability Act of 1996 (HIPAA) where HIPAA PHI is created, received, maintained, or transmitted, or that will be stored, generated, accessed, exchanged, processed, or utilized in order to perform certain health care operations activities or functions on behalf of the Veterans Health Administration (VHA) as a covered entity (see 802.101 for the definition of information technology-related contracts); or (b) Contractors supporting other VA organizations which support VHA in this regard and which would therefore require Business Associate Agreements in accordance with 824.103-70.

Legislative history

This is a federal regulation, adopted through agency rulemaking under the Administrative Procedure Act — not enacted by a recorded vote of Congress.