- videocam Live Webinar with Live Q&A
- calendar_month September 15, 2026 @ 1:00 PM ET/10:00 AM PT
- signal_cellular_alt Intermediate
- card_travel Health
- schedule 90 minutes
Risk Allocation in Business Associate Agreements: Structuring Indemnification Provisions and Beyond
Welcome to BARBRI, the trusted global leader in legal education. Continue to access the same expert-led Strafford CLE and CPE webinars you know and value. Plus, explore professional skills courses and more.
About the Course
Introduction
This CLE webinar will guide healthcare counsel in better understanding and negotiating risk allocation provisions in business associate agreements (BAAs). The panel will examine cybersecurity, privacy, regulatory, and third-party liability risks facing healthcare organizations and their business associates. The panel will offer best practices for evaluating, drafting, and negotiating indemnification and other contractual provisions designed to address traditional and emerging risks associated with data security breaches and cybersecurity events, including new threats and vulnerabilities associated with artificial intelligence (AI).
Description
Many covered entities and business associates consider indemnification critical. Business associates are directly liable under HIPAA, and covered entities view indemnification provisions as additional protection. Business associates, as well as covered entities, use them to allocate or mitigate their risk.
Not all BAAs contain indemnification provisions and, when included, these clauses vary and can generate heavy negotiation. Often, however, parties (particularly business associates) enter into BAAs without recognizing the significance and potential variations of indemnification terms.
Before deciding whether to include or exclude indemnification provisions and their scope, healthcare counsel should weigh various considerations. For example, will such a provision adversely impact insurance coverage, limit liability, or unfairly shift costs? When designing indemnification provisions, counsel should consider the consequences of state law, whether a court will interpret a unilateral provision as reciprocal, how the provisions interact with the terms of the underlying contract, and whether the provisions incorporate appropriate controls if breach notification issues arise.
Listen as our authoritative panel of healthcare attorneys discusses whether and when to include indemnification provisions in BAAs, variations in the scope of indemnification, and the factors counsel should consider when making those determinations from both the covered entity and the business associate (e.g., vendor) perspectives. The panel will also cover model training and other risks to protected health information in the AI environment and offer alternatives and best practices for negotiating and structuring these provisions.
Presented By
Mr. Hindman focuses his practice on healthcare regulatory, data privacy, cybersecurity, corporate, and transactional matters. He represents physicians and other healthcare providers and organizations in structuring group practices, joint ventures, ambulatory surgery centers, provider networks, and physician / hospital affiliations, as well as arrangements to provide professional and ancillary services, telehealth, chronic care management, remote patient monitoring, and physician in-office dispensing. Mr. Hindman also assists healthcare providers and businesses with potential compliance challenges, including compliance with the Stark physician self-referral law, federal and state anti-kickback laws, and corporate practice and fee-splitting restrictions.
Ms. Leopard is a veteran health IT attorney at the intersection of healthcare, technology, and innovation. For over 25 years, she has guided healthcare providers, payors, and innovators through complex regulations, designing technology and data-sharing solutions that safeguard patients, data, technology assets, and intellectual property while mitigating privacy and security risks. Ms. Leopard helps clients leverage technology for innovative applications across the AI life cycle to transform regulated healthcare data into scalable, responsible AI solutions. She offers strategic guidance on enterprise governance and risk management, contracting and procurement, regulatory and product counsel, data rights, interoperability, and government enforcement. Ms. Leopard holds MIT Sloan’s AI in Health Care certificate, which covers AI assurance, risk stratification, transparency, and bias mitigation from concept to deployment. Her decade in hospital leadership provides valuable operational insight, and an early internship at the U.S. Justice Department shaped her regulatory counsel. Ms. Leopard has dedicated her career to health law, serving as secretary and board member of the American Health Law Association and chairing its Health IT Practice Group.
Mr. Scott counsels small and large entities, including merchants, medical providers, financial institutions, and educational institutions on the identification, evaluation, and management of first- and third-party data privacy and cybersecurity risks. He advises on data privacy, cybersecurity breach response, and payment card industry standards and investigations. Mr. Scott has handled hundreds of breaches, often reducing public and regulatory scrutiny and protecting clients’ reputations. His practice also includes advising clients on compliance with state, federal, and international laws and regulations. In addition to his data privacy and cybersecurity experience, Mr. Scott served as a judicial law clerk for the Chief Judge of the U.S. Court of Appeals for the Armed Forces. He also participated in the investigation and prosecution of financial fraud in the handling of government contracts for the Special Inspector General for Iraq Reconstruction in coordination with the Department of Justice. After serving in the U.S. Marine Corps for 27 years, Mr. Scott retired as a colonel.
-
This 90-minute webinar is eligible in most states for 1.5 CLE credits.
-
Live Online
On Demand
Date + Time
- event
Tuesday, September 15, 2026
- schedule
1:00 PM ET/10:00 AM PT
I. Risk allocation: key considerations in a BAA for covered entities and business associates
II. Best practices for negotiating and structuring indemnification provisions
III. Addressing risks, including regulatory enforcement, class action exposure, and emerging technologies such as AI
The panel will review these and other high priority issues:
- What factors should counsel consider when allocating risk for a BAA?
- What approaches should counsel use to protect a client's interests when drafting and negotiating an indemnification provision and other risk shifting provisions?
- What are some best practices for counsel when structuring BAA risk allocation provisions to address liability exposure and emerging technologies?
Unlimited access to premium CLE courses:
- Annual access
- Available live and on-demand
- Best for attorneys and legal professionals
Unlimited access to premium CPE courses.:
- Annual access
- Available live and on-demand
- Best for CPAs and tax professionals
Unlimited access to premium CLE, CPE, Professional Skills and Practice-Ready courses.:
- Annual access
- Available live and on-demand
- Best for legal, accounting, and tax professionals
Unlimited access to Professional Skills and Practice-Ready courses:
- Annual access
- Available on-demand
- Best for new attorneys
Related Courses
Fair Market Value and Commercial Reasonableness in Hospital and Physician Transactions: Complying With Anti-Kickback and Self-Referral Laws
Wednesday, September 2, 2026
1:00 PM ET/10:00 AM PT
Recommended Resources
Navigating Modern Legal Challenges: A Comprehensive Guide
- Business & Professional Skills
- Career Advancement