This tutorial about business associate contracts is the eighteenth of 24 lessons. HIPAA requires covered entities (CEs) and business associates (BAs) to sign contracts to specify how "protected health information" (PHI) is to be managed by the respective parties. BA contracts are governed by privacy rule sections 164.502(e) and 164.504(e), and security rule sections 164.308(b) and 164.314. This website is specifically designed for small entities in California. Each tutorial is narrated by Carol Mack, RN, attorney at law.