A covered entity hires a third-party data analytics firm to process patient data for a quality improvement study.
The analytics firm then hires a cloud storage provider to host the data.
According to HIPAA, what is the minimum requirement for Business Associate Agreements (BAAs) in this scenario?