Comprehensive master services agreement for a healthcare data analytics engagement, with a cover memo explaining key drafting decisions and open items, based on a prior agreement, playbook, and negotiated business terms.
Scanned 9/11/2026
Install to Claude Code
npx -y skills add sunyifeisb-art/legalwork --skill draft-master-services-agreement --agent claude-codeInstalls into .claude/skills of the current project.
Are you the author of Draft Master Services Agreement?
Add the live security badge to your README — it updates automatically with every re-scan.
[](https://www.skillsdirectory.com/skills/sunyifeisb-art-draft-master-services-agreement)More formats (shields.io, HTML) on the badges page.
---
name: draft-master-services-agreement
task_id: intellectual-property/draft-master-services-agreement
description: Comprehensive master services agreement for a healthcare data analytics engagement, with a cover memo explaining key drafting decisions and open items, based on a prior agreement, playbook, and negotiated business terms.
activates_for: [planner, solver, checker]
---
# Skill: Draft Master Services Agreement for Healthcare Data Analytics
## 1. Subject-matter triage
- Treat the MSA as the primary deliverable and draft it first; do not let the memo substitute for a complete agreement.
- If the source set includes a prior form, a playbook, and negotiated business terms, treat them as a hierarchy to reconcile rather than as parallel references.
- Identify whether the engagement touches protected health information, de-identified data, limited data sets, or other regulated health data before selecting privacy, security, and use restrictions.
- If multiple statements of work, service lines, data sets, or performance periods are in scope, enumerate them before drafting the operative provisions so each can be addressed consistently.
## 2. Failure modes the skill is correcting
- Reusing a prior template without testing it against the current playbook, business terms, and engagement facts.
- Failing to resolve conflicts among the source documents and leaving inconsistent provisions in the agreement.
- Missing healthcare-specific protections, including data-use limits, security controls, access restrictions, incident handling, audit rights, and any required business associate framework.
- Drafting a generic services contract that does not clearly allocate ownership, permitted use, service levels, acceptance, change management, indemnity, limitation of liability, and termination rights for analytics work.
- Omitting the cover memorandum or reducing it to a summary that does not explain drafting choices, unresolved points, and deviations from the prior form.
- Stating conclusions about regulatory or contractual requirements without tying them to the governing authority reflected in the source set or a recognized healthcare contracting convention.
## 3. Legal frameworks / domain conventions that apply
- Use the source hierarchy deliberately: negotiated business terms control over the playbook, and both inform how the prior agreement should be updated.
- In healthcare data analytics, privacy and security provisions should be aligned to applicable health-data rules, including HIPAA privacy and security requirements where PHI is involved, and should address subcontractor flow-downs, breach/incident notice, access controls, and audit support.
- Where a business associate relationship is required, the agreement should incorporate the necessary business associate terms or attach a compliant exhibit rather than leaving them implicit.
- The services framework should define the statement-of-work process, change-order mechanics, dependencies, acceptance criteria, reporting, and any milestone-based invoicing or credits.
- IP allocation should clearly distinguish customer data, pre-existing materials, analytics outputs, and custom deliverables; vendor-friendly ownership of all work product is not assumed unless the sources support it.
- Confidentiality, security, records retention, and return/destruction obligations should be coordinated so they operate consistently at termination and after any suspension of services.
- Liability allocation should reflect the sensitivity of the data and the operational consequences of a failure, while staying consistent with the negotiated terms and the playbook.
## 4. Analytical scaffolds
- Start with a source reconciliation pass: identify every material term that appears in the prior agreement, the playbook, and the negotiated terms, then determine whether each is adopted, modified, or rejected.
- For each core topic—scope, data rights, privacy/security, fees, term/termination, warranties, indemnities, liability, dispute resolution, and boilerplate—confirm the draft states one clear rule and does not leave competing versions in different sections.
- For healthcare compliance, test whether the agreement needs business associate language, data-processing restrictions, security obligations, audit rights, and incident notice mechanics; if any source is silent, flag the gap in the memo.
- For services mechanics, check that the drafting covers ordering, dependencies, customer inputs, acceptance, re-performance, service credits or remedies if negotiated, and a workable change-control path.
- For deliverables and IP, separate customer-owned inputs from vendor background materials and from outputs created for the engagement; ensure the license or assignment language matches the business intent reflected in the sources.
- For risk allocation, confirm the draft addresses confidentiality, regulatory cooperation, indemnities, limitation of liability, exclusions, and injunctive relief in a way that fits the sensitivity of healthcare data.
- For each open item, identify the concrete decision needed, why the source materials do not answer it, and which section of the MSA would need revision once the client decides.
## 5. Vertical / structural / temporal relationships
- Use the agreement’s structure to track hierarchy: definitions, order of precedence, statement of work mechanics, data governance, security, IP, fees, compliance, warranties, indemnities, limitation of liability, term, termination, and miscellaneous.
- Make temporal sequencing explicit where it matters: pre-engagement diligence, onboarding, service commencement, SOW approval, recurring performance periods, audit windows, notice periods, cure periods, transition assistance, and post-termination return or destruction.
- Tie operational obligations to the party that can perform them: customer-provided data and approvals, vendor processing and reporting, subcontractor controls, and any required customer cooperation.
- If the engagement contemplates multiple phases or workstreams, reflect the phase-to-phase dependencies and ensure the MSA can support future SOWs without reopening settled core terms.
## 6. Output structure conventions
- Produce `master-services-agreement.docx` as a complete, execution-ready MSA with any needed exhibits, schedules, or SOW template language embedded or attached in conventional form.
- Produce `cover-memorandum.docx` second, after the agreement exists, and use it to explain major drafting decisions, source conflicts, departures from the prior form, and unresolved points for client input.
- The memo should be practical and decision-oriented: identify what changed, why it changed, what remains open, and what the client should review next.
- If any required term is not resolved by the sources, reflect a sensible placeholder in the draft only if the agreement can still function; otherwise flag it plainly in the memo.
- Keep the drafting internally consistent across the agreement and memo, and ensure the final files are substantive documents rather than summaries of what should be drafted.
Is this your skill, or is something wrong with this listing? Request removal or report an issue. Author removals are honored within 72 hours.
No comments yet. Be the first to comment!