BAA before PHI
We sign the Business Associate Agreement before any PHI is touched.
The BAA is signed at the start of the Scope phase, before any access is granted, before any data flows. The agreement covers the controls AC5 commits to operate under, the access scope, the breach notification window, and the wipe procedure at handoff.