Business associate agreement (HIPAA BAA): what it is and what to include

A business associate agreement (BAA) is a HIPAA-required contract that binds a vendor handling protected health information to the same privacy and security duties as the covered entity that hired it. Without a signed BAA in place before any protected health information changes hands, both parties risk regulatory penalties, breach liability, and lasting reputational damage.

What a business associate agreement is

The Health Insurance Portability and Accountability Act (HIPAA) governs how protected health information (PHI) is used and disclosed in the United States. A covered entity, such as a healthcare provider, health plan, or healthcare clearinghouse, often needs outside help to run its operations. When that outside party creates, receives, maintains, or transmits PHI on the covered entity’s behalf, HIPAA calls it a business associate, and a written contract between the two is mandatory.

That contract is the business associate agreement. Its legal foundation sits in the HIPAA Privacy Rule and Security Rule, with the required contract elements set out at 45 CFR 164.504(e) and the obligation to obtain satisfactory assurances at 45 CFR 164.308(b). The HITECH Act of 2009 and the 2013 Omnibus Rule extended direct HIPAA liability to business associates, so a BAA is no longer a one-way promise; both sides carry enforceable duties to the Department of Health and Human Services (HHS) and to affected individuals.

In plain terms, the BAA does three things. It defines exactly what the business associate may do with PHI, it requires safeguards to protect that PHI, and it sets out what happens when something goes wrong or the relationship ends. A BAA is not a substitute for the underlying services contract; it is a specialized layer that travels alongside it.

Key terms and clauses to include

A compliant BAA should address each element required by the Privacy Rule, written to match the real data flow between the parties. The core clauses are:

  • Permitted uses and disclosures: describe the specific purposes for which the business associate may use or disclose PHI, and confirm it will not use or disclose PHI beyond what the contract or law allows.
  • Safeguards: require the business associate to implement administrative, physical, and technical safeguards, including the HIPAA Security Rule requirements for electronic PHI (ePHI).
  • Reporting and breach notification: obligate the business associate to report any use or disclosure not permitted by the agreement, any security incident, and any breach of unsecured PHI, within a defined and reasonable timeframe.
  • Subcontractor flow-down: require the business associate to bind any subcontractor that handles PHI to restrictions and conditions at least as strict as those in the BAA.
  • Individual rights support: require the business associate to make PHI available so the covered entity can meet individual rights to access (45 CFR 164.524), amendment (164.526), and an accounting of disclosures (164.528).
  • Access for HHS: require the business associate to make its internal practices, books, and records available to HHS for compliance review.
  • Return or destruction at termination: require the business associate to return or destroy all PHI when the agreement ends, or to extend protections if return or destruction is not feasible.
  • Termination for cause: allow the covered entity to terminate if the business associate materially breaches the agreement and fails to cure.

Beyond the mandatory elements, well-drafted BAAs also spell out indemnification, allocation of breach-response costs, cyber-insurance expectations, the term and renewal mechanics, and how the agreement interacts with the master services agreement. These commercial terms are where negotiation actually happens, and where a BAA either protects the covered entity or quietly shifts risk onto it.

When you need one

You need a BAA whenever a party outside the covered entity will create, receive, maintain, or transmit PHI to perform a function or service. Common business associates include cloud storage and hosting providers, billing and claims processors, electronic health record and practice-management software vendors, medical transcription services, IT and managed security providers, data analytics firms, shredding companies, and outside counsel or accountants who touch PHI in the course of their work.

The requirement flows downstream. A business associate that hands PHI to its own vendor, a subcontractor, must sign a BAA with that subcontractor too, so the chain of protection reaches every party that touches the data. A narrow conduit exception exists for entities that only transport PHI without accessing it, such as the postal service or an internet service provider, but courts and regulators read that exception strictly, so most technology vendors do not qualify. When in doubt, treat the vendor as a business associate and paper the relationship before any PHI moves.

Timing matters as much as scope. The BAA must be executed before the business associate begins handling PHI, not after the fact and not once a problem surfaces.

Common pitfalls

The most damaging mistake is having no BAA at all. Regulators have repeatedly penalized covered entities that shared PHI with a vendor on nothing more than a handshake, and enforcement actions in this area can reach well into six or seven figures depending on the conduct and its duration. Other frequent failures include:

  • Assuming a vendor is not a business associate. If the vendor can access PHI, the conduit exception rarely saves you.
  • Using a generic template that does not match the actual services, leaving permitted uses either too broad or too narrow.
  • Forgetting to flow the obligations down to subcontractors, which breaks the chain of protection.
  • Leaving breach-notification timing vague, so the covered entity cannot meet its own reporting deadlines to HHS and to individuals.
  • Confusing HIPAA duties with other frameworks. A GDPR data processing agreement is not a HIPAA BAA, and one cannot stand in for the other.
  • Signing the BAA and then losing track of it, so renewal dates, termination duties, and the obligation to return or destroy PHI are never enforced.
  • Never updating the agreement as regulations, services, or data flows change.

Turning a BAA into an obligation you actually manage

A BAA only protects you if its promises are tracked and enforced across the whole vendor portfolio, not just filed away after signature. That is a contract management discipline, and it is where a CLM platform earns its place. Pactolane keeps every executed BAA in a central contract repository with a full audit trail, sends renewal and deadline alerts so termination and return-of-PHI duties are never missed, and routes new agreements through approval workflows before signature with built-in electronic signature. PactAI can check a draft BAA against a compliance playbook to flag missing required elements, score residual risk from 0 to 100, and run conflict detection across a portfolio of agreements so inconsistent terms surface before they become an incident. Treated this way, the BAA stops being a static PDF and becomes a live set of obligations you can prove you are meeting.

This page is general legal information, not legal advice; consult qualified counsel about your specific circumstances.

Key clauses in this agreement

The clauses that carry the risk in this contract type.

Frequently asked questions

What is a business associate agreement (HIPAA BAA)?

A business associate agreement is a HIPAA-required contract between a covered entity and a vendor that handles protected health information on its behalf. It binds the vendor to specific privacy and security duties, breach-reporting obligations, and strict limits on how the data may be used. HIPAA requires it in writing before any protected health information is shared.

Who needs a business associate agreement?

Any covered entity, such as a healthcare provider, health plan, or clearinghouse, needs a BAA before letting an outside vendor create, receive, maintain, or transmit protected health information. Common business associates include cloud hosting, billing services, EHR software, IT providers, and outside professionals who touch the data. The requirement also flows downstream, so a business associate must sign a BAA with each subcontractor that handles protected health information.

What clauses must a HIPAA BAA include?

A compliant BAA must define permitted uses and disclosures, require appropriate safeguards, and obligate the vendor to report breaches and impermissible disclosures. It must also bind subcontractors, support individual rights to access and amend records, allow HHS compliance review, and require return or destruction of protected health information at termination. These elements come from the HIPAA Privacy Rule at 45 CFR 164.504(e).

What happens if you do not have a BAA?

Sharing protected health information without a signed BAA is itself a HIPAA violation, exposing the covered entity to civil penalties and enforcement action even if no breach occurs. If a breach then happens, liability and notification costs compound quickly. Regulators have penalized organizations that relied on informal vendor arrangements, so the agreement should be signed before any data is shared.

Is a business associate agreement the same as a standard vendor contract?

No. A BAA is a specialized HIPAA compliance document that sits alongside the underlying services or master agreement, not in place of it. The services contract covers price, scope, and general commercial terms, while the BAA governs how protected health information is protected, reported on, and returned. Both should be executed together and kept in sync.

On the same topic

Other pages closely related to this one.

This page provides general legal information, not legal advice. Every situation is specific: for a binding contract, consult a qualified legal professional.

Manage my cookies