Glossary · Compliance concepts

What is Business Associate Agreement?

Also known as: BAA, HIPAA BAA, Business Associate Contract

A Business Associate Agreement (BAA) is a HIPAA-required contract between a covered entity (or a business associate) and a vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. The BAA binds the vendor to safeguard PHI, limits how it may be used, and sets breach-notification and other obligations.

Key takeaways

  • Required by HIPAA whenever a vendor handles PHI on your behalf.
  • Contractually obliges the business associate to protect PHI and follow the Security and Privacy Rules.
  • Specifies permitted uses of PHI, breach-notification duties, and return/destruction of PHI at termination.
  • Without a signed BAA in place, sharing PHI with a vendor is itself a HIPAA violation.
  • Business associates must in turn sign BAAs with their own subcontractors that touch PHI.

When is a BAA required?

Under HIPAA, a covered entity must have a BAA in place before a business associate handles PHI. Business associates include cloud hosts, analytics vendors, billing services, and any subcontractor that creates, receives, maintains, or transmits PHI.

The BAA flows obligations down the chain: a business associate that uses subcontractors to handle PHI must obtain BAAs from them as well.

Frequently asked questions

Who needs to sign a BAA?
Any covered entity and the business associates that handle protected health information on its behalf. Business associates must also sign BAAs with subcontractors that touch PHI.
What happens if there is no BAA?
Sharing PHI with a vendor without a signed BAA is itself a HIPAA violation and can lead to enforcement action and penalties from the HHS Office for Civil Rights.
Does a BAA replace a security assessment?
No. A BAA is a contractual safeguard. You still need to verify the vendor actually protects PHI through security assessments and monitoring.

Authoritative sources

← Back to the glossary