A hospital is partnering with a third-party analytics firm to process patient data for population health studies.
The firm will have access to a large dataset containing electronic Protected Health Information (ePHI).
Which of the following is the MOST critical document to have in place before any data is shared?