How to Create and Review a HIPAA Business Associate Agreement

Categories: HIPAA Privacy & SecurityPublished On: August 4th, 202617.8 min read

A Business Associate Agreement is one of the most important contracts in a healthcare organization’s vendor-management program. It defines how a business associate may use protected health information, establishes safeguards, and assigns responsibilities when something goes wrong.

Yet BAAs are often treated as administrative paperwork. An organization downloads a template, inserts the parties’ names, collects signatures, and considers the matter closed.

That approach can leave serious gaps.

A BAA should accurately reflect the service being provided, the PHI involved, the systems and subcontractors that will handle it, and the steps both parties must take during a security incident or breach. It must also contain the provisions required by the HIPAA Rules.

This guide explains how to create or review a HIPAA Business Associate Agreement, what clauses it should contain, and which questions organizations should answer before signing.

What Is a Business Associate Agreement?

A Business Associate Agreement, commonly called a BAA, is a written contract or other arrangement between:

  • A HIPAA covered entity and its business associate
  • A business associate and a subcontractor that creates, receives, maintains, or transmits PHI on its behalf

Covered entities include health plans, healthcare clearinghouses, and certain healthcare providers that conduct covered transactions electronically.

A business associate is generally a person or organization that performs functions or provides services involving PHI on behalf of a covered entity. A subcontractor may also become a business associate when it handles PHI on behalf of another business associate.

The BAA establishes the permitted uses and disclosures of PHI and requires the business associate to protect that information. Business associates also have direct responsibilities under portions of the HIPAA Privacy, Security, and Breach Notification Rules.

HHS explains these responsibilities in its official business associate guidance.

When Is a BAA Required?

A BAA is generally required when an outside person or organization creates, receives, maintains, or transmits PHI while performing a function or service for a covered entity or another business associate.

Examples may include:

  • Medical billing and coding companies
  • Claims-processing vendors
  • Cloud storage and hosting providers
  • Electronic health record vendors
  • Managed IT and cybersecurity providers
  • Medical transcription services
  • Legal, accounting, actuarial, or consulting firms with PHI access
  • Data-analysis and population-health vendors
  • Document-storage and destruction companies
  • Patient-communication platforms
  • AI vendors that receive or maintain PHI
  • Subcontractors that handle PHI for another business associate

The analysis should focus on the vendor’s actual role and access—not merely its job title or marketing category.

For example, HHS states that a software company is not automatically a business associate simply because it sells software to a covered entity. If the company hosts information containing PHI or can access PHI while providing support, however, it may be acting as a business associate.

Similarly, a cloud provider that maintains encrypted electronic PHI is generally a business associate even if it does not possess the decryption key. HHS addresses this distinction in its HIPAA cloud-computing guidance.

For more examples, read Evolve’s guide to HIPAA requirements for contractors and vendors.

When Might a BAA Not Be Required?

Not every person who encounters health information is a business associate.

A BAA may not be required when:

  • The vendor does not create, receive, maintain, or transmit PHI
  • The person is properly treated as a member of the covered entity’s workforce
  • One healthcare provider discloses PHI to another provider for patient treatment
  • A vendor supplies equipment or software but has no access to PHI
  • A service qualifies for HIPAA’s narrow conduit exception because it provides only transient transmission rather than persistent storage

Incidental or remote access may still matter. A vendor does not necessarily avoid business-associate status simply because it claims it does not routinely view the data.

Organizations should document how they reached their determination, particularly when a service interacts with systems containing PHI.

Before Drafting a BAA: Map the Relationship

A reliable BAA begins with an accurate understanding of the service.

Before choosing contract language, answer these questions:

  • What services will the vendor provide?
  • What categories of PHI will it create, receive, maintain, or transmit?
  • Is the information electronic, paper-based, oral, or a combination?
  • Which systems will store or process the information?
  • Will vendor personnel be able to view the PHI?
  • Will subcontractors or cloud providers handle it?
  • Will information be stored or processed outside the United States?
  • How long will the vendor retain the information?
  • Does the vendor intend to de-identify, aggregate, analyze, or reuse the data?
  • What happens to the information when the service ends?
  • Which party will respond to patient requests, investigations, and incidents?

The BAA should match these answers. If the data flow changes, the agreement and accompanying risk analysis may need to be reviewed.

Ten Required Areas to Address in a BAA

HHS publishes sample Business Associate Agreement provisions. Its guidance identifies ten areas a written business associate contract must address.

The precise wording may vary, but these obligations should not disappear during negotiation.

1. Permitted and Required Uses and Disclosures

The BAA must explain how the business associate is allowed or required to use and disclose PHI.

The language should connect those permissions to the actual services. A vague statement allowing the business associate to use PHI for any lawful business purpose may be broader than the relationship requires.

Review questions include:

  • Are permitted uses tied to the underlying service agreement?
  • Is each secondary use of PHI clearly authorized?
  • May the business associate de-identify the information?
  • May it perform data aggregation?
  • May it use PHI for its own management or legal responsibilities?
  • Does the agreement address the minimum necessary standard where applicable?
  • Does it prohibit independent sale, marketing, model training, or product development unless expressly authorized and legally permitted?

The parties should understand exactly what the vendor may do with the information—not simply what it may not do.

2. Limits on Further Use or Disclosure

The BAA must state that the business associate will not use or further disclose PHI except as permitted or required by the agreement or as required by law.

Check for language elsewhere in the contract that could undermine this restriction. A privacy policy or service agreement should not give the vendor broader rights to customer data than the BAA allows.

If multiple documents govern the relationship, specify which document controls when their privacy or security terms conflict.

3. Appropriate Safeguards

The agreement must require the business associate to use appropriate safeguards to prevent unauthorized use or disclosure of PHI. For electronic PHI, the business associate must comply with applicable HIPAA Security Rule requirements.

The BAA may state this obligation generally, while a security addendum or service-level agreement addresses operational details such as:

  • Encryption
  • Multifactor authentication
  • Role-based access
  • Audit logging
  • Vulnerability management
  • Backups and disaster recovery
  • Workforce security
  • Security testing
  • Data segregation
  • Incident response

A contractual promise to “comply with HIPAA” should not replace vendor due diligence or a documented risk analysis.

4. Reporting Improper Uses, Disclosures, Security Incidents, and Breaches

The BAA must require the business associate to report uses or disclosures not permitted by the agreement, including breaches of unsecured PHI.

This clause deserves careful review because regulatory deadlines are outer limits, not necessarily appropriate operational deadlines.

Under the HIPAA Breach Notification Rule, a business associate must notify the covered entity of a breach without unreasonable delay and no later than 60 calendar days after discovery. The parties may negotiate a shorter contractual deadline so the covered entity has enough time to investigate and fulfill its own responsibilities.

The provision should answer:

  • When does the reporting period begin?
  • Which incidents require immediate notice?
  • What information must the initial report include?
  • May details be provided in stages as the investigation develops?
  • Who receives the notice?
  • Must the vendor preserve evidence and cooperate with the investigation?
  • Who performs the HIPAA breach-risk assessment?
  • Who communicates with affected individuals and regulators?
  • Who pays investigation, remediation, and notification expenses?

Not every security incident is a breach. However, an impermissible use or disclosure of PHI is generally presumed to be a breach unless the regulated entity demonstrates a low probability that the PHI was compromised or an exception applies.

The agreement should support—not obstruct—that assessment.

5. Support for Individual HIPAA Rights

The BAA must require the business associate to make PHI available as needed for the covered entity to fulfill applicable obligations concerning:

  • Individual access to PHI
  • Amendment of PHI
  • Accounting of certain disclosures

The agreement should identify practical response procedures and deadlines. A business associate may need to search multiple systems, retrieve archived information, or provide records in a usable format.

Review whether the service creates or maintains information in a designated record set and whether the vendor can retrieve that information when requested.

6. Performance of Covered Entity Privacy Rule Obligations

If the business associate performs a Privacy Rule obligation on behalf of the covered entity, the agreement must require the business associate to comply with the requirements that apply to that obligation.

For example, if a vendor manages requests for access to health records, the contract should address the Privacy Rule standards relevant to that function.

The business associate should not receive a responsibility without the operational ability, staffing, and information required to carry it out.

7. Access for HHS

The agreement must require the business associate to make relevant internal practices, books, and records available to HHS when necessary to determine compliance with the HIPAA Rules.

Reviewers should watch for language that improperly conditions this access on burdensome approvals or procedures.

The parties can establish a notification and coordination process, but the agreement should not interfere with lawful regulatory access.

8. Return or Destruction of PHI at Termination

The BAA must require the business associate, when feasible, to return or destroy PHI when the relationship ends.

The provision should address:

  • Active systems
  • Archives
  • Backups
  • Portable media
  • Test environments
  • Subcontractor systems
  • Derived files and exports
  • The format in which data will be returned
  • Written confirmation of destruction

If return or destruction is not feasible, the agreement should extend the applicable protections and limit further uses and disclosures to the purposes that make return or destruction infeasible.

Avoid treating “infeasible” as an automatic exception. The business associate should be prepared to explain why certain information cannot be returned or destroyed.

9. Downstream Subcontractors

The BAA must require the business associate to ensure that subcontractors with PHI access agree to the same restrictions and conditions that apply to the business associate.

A covered entity ordinarily contracts with its direct business associate. The business associate is responsible for entering into appropriate agreements with its own subcontractors.

Review questions include:

  • Must the business associate disclose or maintain a list of relevant subcontractors?
  • Is advance notice required when subprocessors change?
  • May the covered entity object to a new subprocessor?
  • Are subcontractors held to appropriate security and incident-reporting standards?
  • Does the business associate remain responsible for subcontractor performance?
  • Can the business associate obtain the information needed to investigate a downstream breach?

An organization’s PHI protections should not disappear merely because the information travels through multiple service providers.

10. Termination for Material Violation

The BAA must authorize termination if the business associate violates a material term of the agreement.

The contract should also describe any applicable process for:

  • Notifying the business associate of a violation
  • Taking reasonable steps to cure the problem
  • Ending the violation
  • Suspending data access
  • Terminating the underlying services
  • Returning or destroying PHI

Termination provisions in the BAA and the main service agreement should be consistent. A covered entity should not find itself authorized to terminate the BAA while remaining locked into a service that cannot lawfully continue without PHI access.

Important Operational Terms Beyond the Minimum HIPAA Provisions

The required clauses establish a regulatory foundation. They may not resolve every practical or financial issue.

Depending on the service and risk, the parties may also need to address:

  • Specific incident-notification deadlines
  • Cooperation during investigations
  • Allocation of breach-response costs
  • Cybersecurity insurance
  • Indemnification
  • Liability limitations
  • Audit or assessment rights
  • Security documentation
  • Data location and cross-border processing
  • Service availability and disaster recovery
  • Data portability
  • Regulatory-change procedures
  • Record-retention requirements
  • Responsibility for legal holds
  • Restrictions on advertising, analytics, or AI model training
  • Order of precedence among the BAA, service agreement, privacy policy, and security addendum

These terms can have significant legal and financial consequences. They should be evaluated by qualified counsel based on the parties, applicable state law, and the nature of the service.

Reviewing a BAA From the Covered Entity’s Perspective

A covered entity should confirm that the BAA provides both regulatory protection and operational visibility.

Ask:

  • Does the agreement accurately describe the vendor’s services?
  • Are the vendor’s uses of PHI appropriately limited?
  • Does the business associate acknowledge its applicable Security Rule obligations?
  • Are incident-reporting deadlines fast enough to support our response?
  • Can the vendor identify affected individuals and records?
  • Will the vendor cooperate with breach assessment and notification?
  • Are subcontractors adequately controlled?
  • Can we obtain meaningful security information?
  • Can we recover our data in a usable format?
  • Can we terminate if the vendor creates an unacceptable compliance risk?
  • Do the BAA and service agreement contradict one another?

The covered entity should also determine whether the vendor can fulfill its promises. Contract language does not compensate for missing security controls, poor staffing, or an immature incident-response program.

Reviewing a BAA From the Business Associate’s Perspective

A business associate should not sign obligations it cannot perform or that do not match its service.

Ask:

  • Does the agreement accurately describe the PHI we will handle?
  • Are permitted uses sufficient to provide the contracted service?
  • Can we meet the proposed incident-reporting deadline?
  • Do our systems support access, amendment, and accounting requests when applicable?
  • Have we identified every subcontractor that will handle PHI?
  • Do our subcontractor agreements support our promises to the covered entity?
  • Can we return or destroy all relevant PHI at termination?
  • Are audit and documentation demands clearly defined?
  • Does the contract assign us responsibility for events outside our control?
  • Do the indemnification and liability provisions align with our insurance and risk?
  • Have our privacy policy and customer terms been checked for conflicts?

A business associate also needs internal policies, security controls, workforce training, and documentation to support its contractual commitments.

Common BAA Mistakes

Using a Template Without Adapting It

The HHS sample provisions are a helpful starting point, but HHS cautions that sample language alone may not create a complete contract or satisfy applicable state law.

A BAA should reflect the service, data, systems, and responsibilities involved.

Signing the BAA After PHI Has Already Been Shared

Complete the BAA before the business associate begins creating, receiving, maintaining, or transmitting PHI.

Treat the BAA as part of vendor onboarding—not a document to collect after implementation.

Giving the Vendor Overly Broad Data Rights

Language allowing data use for “business purposes,” “service improvement,” analytics, or product development may be broader than expected.

Clarify what information the vendor may use, for which purposes, and under what conditions.

Assuming a BAA Proves the Vendor Is HIPAA Compliant

A signed agreement is not a certification, security assessment, or guarantee of compliance.

Organizations still need to evaluate the vendor, conduct an appropriate risk analysis, configure the service securely, and monitor the relationship.

Ignoring Subcontractors

Cloud platforms, hosting providers, support companies, and data-processing services may all sit behind the primary vendor.

The business associate must extend appropriate restrictions and protections to subcontractors that handle PHI.

Using the Regulatory Maximum as the Incident-Reporting Deadline

Waiting up to 60 days for notice from a business associate could leave a covered entity with too little time to investigate and meet its own obligations.

Set a deadline appropriate to the service and risk, with prompt preliminary notice followed by additional details as they become available.

Failing to Plan for Termination

Organizations often focus on onboarding and overlook exit procedures.

Before signing, understand how information will be exported, returned, deleted, or retained—and how those actions will be verified.

Forgetting to Revisit the Agreement

A BAA can become outdated when the vendor introduces new services, subprocessors, storage locations, integrations, or data uses.

Review the agreement when the relationship materially changes.

A Practical BAA Review Checklist

Before signing or renewing a Business Associate Agreement, confirm that:

  • The correct legal parties are identified
  • The business-associate relationship has been documented
  • The underlying services and PHI data flows are understood
  • Permitted uses and disclosures are clearly defined
  • Unauthorized secondary uses are prohibited
  • Minimum necessary requirements are addressed where applicable
  • Security Rule obligations are included
  • Incident and breach-reporting procedures are workable
  • Contractual reporting deadlines are clearly stated
  • Individual access, amendment, and accounting responsibilities are assigned
  • HHS access to required records is preserved
  • Subcontractor obligations flow downstream
  • Return and destruction requirements cover all relevant systems
  • Infeasible destruction is addressed
  • Material violations permit cure, suspension, or termination as appropriate
  • The BAA and service agreement do not conflict
  • Security, insurance, audit, and cost-allocation terms have been evaluated
  • Responsible privacy, security, operational, and legal stakeholders have reviewed the agreement
  • The BAA will be executed before PHI is shared
  • The organization has a process for monitoring and reassessing the relationship

Managing the BAA After It Is Signed

The work does not end with signature.

A sound BAA-management process should include:

  1. Keeping an inventory of business associates and executed agreements
  2. Recording agreement owners, effective dates, and related service contracts
  3. Confirming required vendor assessments are complete
  4. Training employees who manage vendors or share PHI
  5. Monitoring incidents, service changes, and subprocessor updates
  6. Reviewing agreements during renewals and material changes
  7. Documenting termination, data return, and destruction
  8. Retaining required records according to applicable policies and legal requirements

Centralized tracking helps prevent expired service arrangements, missing agreements, and vendors continuing to access PHI after their work has ended.

Build Business Associate Compliance Into Workforce Training

A BAA assigns legal responsibilities, but employees carry out many of those responsibilities in practice.

Workforce members need to understand:

  • When a vendor may be a business associate
  • Why PHI should not be shared before appropriate review
  • Who can approve and sign a BAA
  • How to report vendor security concerns
  • What to do when services or data uses change
  • How to escalate a suspected improper disclosure
  • Why vendor access should end when the relationship terminates

Evolve e-Learning Solutions provides HIPAA Privacy and Security training for covered entities, business associates, healthcare professionals, administrative teams, and support staff.

Evolve’s courses can be delivered through its learning platform or integrated into an existing LMS in SCORM-compatible formats. Organizations can assign role-appropriate training, track completion, and maintain documentation supporting their compliance program.

Contact Evolve e-Learning to request a course preview or discuss a HIPAA training program for your organization.

Download a free BAA review checklist here: BAA Review Checklist

Frequently Asked Questions About Business Associate Agreements

Does Every Healthcare Vendor Need a BAA?

No. A BAA is generally required when a vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity or another business associate. A vendor that does not handle PHI may not be a business associate.

Can We Use the HHS Sample BAA?

Yes, the HHS sample provisions can be a useful starting point. HHS cautions that its sample addresses HIPAA concepts and may not include every provision required for a binding contract under state law or appropriate for a particular business relationship.

Who Should Provide the BAA?

Either party may provide the initial draft. What matters is that the final agreement accurately reflects the relationship, includes the required provisions, and is reviewed and accepted by both parties.

Can a BAA Be Part of the Main Service Agreement?

Yes. HHS permits the required provisions to be incorporated into a service agreement or placed in a separate Business Associate Agreement.

Does a BAA Make a Vendor HIPAA Compliant?

No. A BAA establishes contractual obligations, but compliance also depends on actual policies, safeguards, risk analysis, training, system configuration, monitoring, and incident response.

How Quickly Must a Business Associate Report a Breach?

The HIPAA Breach Notification Rule requires a business associate to notify the covered entity without unreasonable delay and no later than 60 calendar days after discovering a breach. A BAA may require faster notice.

Does a Business Associate Need BAAs With Its Subcontractors?

A business associate must ensure that subcontractors creating, receiving, maintaining, or transmitting PHI on its behalf agree to the same applicable restrictions and conditions. This is generally accomplished through downstream BAAs.

Does a BAA Expire?

HIPAA does not establish a universal expiration period for BAAs. The agreement’s term is typically connected to the underlying relationship. Organizations should review it during renewals, service changes, and regulatory or operational changes.

What Should Happen to PHI When the Contract Ends?

The business associate should return or destroy the PHI when feasible, according to the agreement. If return or destruction is infeasible, protections must continue and further use or disclosure should be limited to the purpose that makes return or destruction infeasible.

What Should We Do if a Vendor Refuses to Sign a BAA?

If a vendor is acting as a business associate and will not enter into an appropriate BAA, the covered entity or upstream business associate generally should not disclose PHI to or use that vendor for the service. Consult qualified counsel about the specific relationship and available alternatives.

This guide provides general educational information and is not a contract template or legal advice. Business Associate Agreements can create significant regulatory, operational, and financial obligations. Organizations should have qualified legal, privacy, and security professionals review agreements based on their circumstances and applicable laws.

Share this article

Follow us

A quick overview of the topics covered in this article.

Contact us

Contact us today to learn how Evolve e-Learning can support your team.

Latest articles