April 1, 2026 · Ken Armstrong
Auditors ask about business associate contracts early, because the answer tells them how the rest of the program is likely to look. The requirement is 45 CFR 164.314(a)(2)(i).
45 CFR 164.314(a)(2)(i) governs business associate contracts. The operative text is not reproduced here: read it at the source linked below, because the conditions in it are the requirement and a summary of a conditional rule is not a safe substitute for the rule.
This is a required implementation specification. 45 CFR 164.306(d)(2) gives no documented-alternative route: you implement it, or you have a finding.
In an assessment, 45 CFR 164.314(a)(2)(i) is not one question. It resolves into several, and each one is really asking for a different artifact:
Ownership usually sits with the security official, though the evidence is often produced by someone else, which is where the trail breaks. A control that works but has no owner tends to stop working the month the person who quietly maintained it changes roles.
Every covered entity and every business associate, at any size. 45 CFR 164.306(b) allows flexibility of approach, so a two-provider practice and a hospital system may implement this differently and both comply. What flexibility does not allow is skipping the decision: the smaller the organization, the more the written reasoning carries the weight, because there is no scale of operation to make the control self-evident.
The sequence below is the order that produces evidence as a by-product rather than as a separate documentation exercise:
The same evidence answers more than one framework. The questions behind 45 CFR 164.314(a)(2)(i) also map to NIST CSF GV.SC-05; ISO 27001 A.5.20; SOC 2 CC9.2; NIST 800-53 MP-6, SA-4, SA-9; CIS v8 15.4, 15.7; HITRUST 09.e. That matters for scoping: if you are working toward SOC 2 or an ISO certification alongside HIPAA, this control is one piece of work and several answers, provided the artifact is written once and referenced rather than rewritten per framework.
For this requirement the artifact types that satisfy it are agreement and record. The distinction matters more than it looks: a policy states what you intend to do, a procedure states how, and a record proves it happened on a date. Auditors ask for all three, and a practice that has written the first two often has nothing for the third.
Date every artifact and keep the superseded versions. 45 CFR 164.316(b)(2)(i) requires documentation be retained for six years from the date of its creation or the date when it last was in effect, whichever is later, so a policy you replaced two years ago is still part of the record.
This requirement carries critical weight in an assessment, which means a gap here tends to surface as a high finding rather than an observation. The usual cause is drift: the control was implemented once, the environment changed, and nothing re-checked it. A dated review on a fixed cadence is cheaper than the remediation.
The practical test for 45 CFR 164.314(a)(2)(i) is whether someone unfamiliar with your organization could read your documentation and tell what you do, who does it, and when it last happened. If they can, the requirement is met. If they need you in the room to explain it, it is not.