A hospital contracts with a third-party cloud storage provider to archive its electronic health records (EHR). The provider guarantees the data will be encrypted at rest. Under HIPAA, what is the most critical document the hospital must have in place with this vendor before transferring any Protected Health Information (PHI)?
-
A
Service Level Agreement (SLA)
-
B
Business Associate Agreement (BAA)
-
C
Non-Disclosure Agreement (NDA)
-
D
Data Use Agreement (DUA)