What Is a Business Associate Agreement in Medical Billing

EditorialOriginal analysis · MedOutbound Editorial
TL;DR

A Business Associate Agreement (BAA) is a HIPAA-required contract between a covered entity (physician practice) and any vendor that creates, receives, maintains, or transmits Protected Health Information on behalf of the practice. The required elements are specified at 45 CFR 164.504(e): permitted PHI uses and disclosures, mandatory Security Rule safeguards, breach reporting obligation, subcontractor flow-down, individual access rights, and PHI return or destruction at termination. No BAA means no compliant PHI transmission.

The regulatory basis

A Business Associate Agreement (BAA) is a contract required under the HIPAA Privacy Rule at 45 CFR 164.502(e) and 45 CFR 164.504(e). The BAA obligates a business associate to protect the Protected Health Information (PHI) it receives on behalf of a covered entity, and creates a documented chain of responsibility for HIPAA compliance.

Covered entities under HIPAA are healthcare providers, health plans, and healthcare clearinghouses. Business associates are any persons or entities that create, receive, maintain, or transmit PHI on behalf of a covered entity to perform a service.

Common business associates in a physician practice:

  • Medical billing and coding vendors
  • Electronic Health Record (EHR) system providers
  • Cloud storage and backup services
  • IT support and managed service providers
  • Practice management software providers
  • Analytics and reporting platforms
  • Transcription services
  • Answering services and virtual receptionists
  • Shredding and document destruction services

Any transmission of PHI to any of these without a signed BAA is a HIPAA violation, exposing both the covered entity and the business associate to enforcement.

The required elements

The HIPAA regulations specify the elements a BAA must contain. Missing any element makes the agreement non-compliant even if it is signed.

1. Permitted and required uses and disclosures of PHI

The BAA must specify:

  • The purposes for which the business associate may use PHI
  • The purposes for which the business associate may disclose PHI
  • Whether de-identified data may be created and used
  • Whether data aggregation is permitted

Uses beyond what is specified are prohibited. A billing vendor cannot use PHI for marketing to the covered entity's patients, for example, without separate patient authorization.

2. Safeguards to protect PHI

The BAA must require the business associate to:

  • Implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR Part 164 Subpart C)
  • Prevent uses or disclosures of PHI not permitted by the BAA
  • Report to the covered entity any use or disclosure not permitted by the agreement

3. Reporting of security incidents and breaches

The BAA must require the business associate to:

  • Report to the covered entity any security incident of which the business associate becomes aware
  • Report breaches of unsecured PHI in accordance with the Breach Notification Rule (45 CFR Part 164 Subpart D)
  • Provide sufficient information for the covered entity to meet its own notification obligations

Typical timeframes: 24 to 72 hours for incident notification; 60 days maximum for breach notification (though most BAAs impose stricter internal timelines).

4. Subcontractor flow-down

The BAA must require that any subcontractor the business associate engages to help perform functions that involve PHI enter into an equivalent BAA with the business associate. The obligations flow down through the entire chain.

This is why practices should ask which functions the vendor subcontracts, where the subcontractors operate, and whether the subcontractor BAAs are available on request.

5. Individual access, amendment, and accounting rights

The BAA must require the business associate to:

  • Make PHI available to individuals for access under 45 CFR 164.524
  • Make PHI available for amendment under 45 CFR 164.526
  • Make available an accounting of disclosures under 45 CFR 164.528

These are the individual patient rights preserved through the business associate layer.

6. PHI availability for compliance activity

The BAA must require the business associate to make its books, records, policies, and practices relating to PHI available to HHS for compliance investigation and audit.

7. Return or destruction of PHI at termination

At the end of the BAA:

  • The business associate must return or destroy all PHI in its possession
  • If neither is feasible, the business associate must extend the protections of the BAA to the retained PHI and limit further uses and disclosures to what makes return or destruction infeasible

This is why the data-return process should be specified in the service agreement in parallel with the BAA.

8. Covered entity termination rights

The BAA must permit the covered entity to terminate the agreement if the business associate violates a material term. Some BAAs include cure periods (30 to 60 days) before termination; unremediated breach after the cure period triggers immediate termination.

What a BAA is not

  • Not a substitute for the service agreement. The BAA governs PHI handling; the service agreement governs commercial terms (fees, deliverables, performance metrics). Both are required.
  • Not a one-time signature. The BAA remains in force for the duration of the relationship and applies to every PHI transmission during that period.
  • Not fungible across vendors. Each business associate needs its own BAA. Sharing a BAA template is fine; each relationship requires its own executed instance.

When a BAA is not required

The HHS Business Associates guidance identifies exceptions where a BAA is not required:

  • Disclosures by a covered entity to another healthcare provider for treatment of the individual
  • Disclosures to a health plan sponsor by a group health plan for enrollment or eligibility
  • The collection and sharing of PHI by a health plan that is a public benefits program
  • Conduits that only transport PHI without any access on other than a random or infrequent basis (traditional postal service, some cloud transmission-only services)

The conduit exception is narrowly interpreted. Most cloud storage and software-as-a-service providers do have access to PHI (even if just for troubleshooting) and require a BAA.

Enforcement examples

HHS Office for Civil Rights has settled a series of enforcement actions specifically citing missing or inadequate BAAs. Public settlements have ranged from $100,000 to over $5 million. Common patterns include:

  • Practice used a cloud storage service without a BAA; storage breach exposed patient records
  • Business associate used subcontractor without subcontractor BAA; subcontractor breach cascaded up
  • BAA lacked required elements (breach notification timeline, subcontractor flow-down); enforcement treated as if no BAA existed

Practical BAA review process

When a vendor provides a BAA for signature:

  1. Verify all eight required elements are present
  2. Verify breach notification timing (24-72 hours preferred; 60 days is the ceiling)
  3. Verify subcontractor flow-down is unambiguous
  4. Verify data-return process at termination is specified (or that the service agreement covers it)
  5. Verify liability language does not conflict with any liability cap in the service agreement
  6. Verify indemnification provisions (if any) are mutual
  7. Have healthcare counsel review before signing on any contract worth more than $25,000 annually

Bottom line

A Business Associate Agreement is not a formality. It is a HIPAA-required contract with eight specified elements, enforced by direct liability to HHS Office for Civil Rights. Any vendor handling PHI needs one signed before any data is shared. Any vendor that resists signing or provides a BAA missing required elements is not equipped to be a compliant business associate.

Continue the conversation

Working on this problem?

If this hit close to home, tell us where you're stuck. One reply from a real inbox — no drip campaigns.

Editorial · geo-cluster-a-safety · widget-tag: what-is-a-business-associate-agreement-m

Answers

Who needs to sign a Business Associate Agreement?
Any covered entity (healthcare provider, health plan, healthcare clearinghouse) must sign a BAA with any business associate that creates, receives, maintains, or transmits PHI on the covered entity's behalf. Medical billing companies, coding services, EHR vendors, cloud storage providers, IT support, and analytics vendors are all common business associates.
What must a Business Associate Agreement include?
The required elements per 45 CFR 164.504(e) are: permitted uses and disclosures of PHI, requirement to implement Security Rule safeguards, breach and security incident reporting, subcontractor BAA flow-down, availability of PHI for individual access and accounting, PHI return or destruction at termination, and covered entity termination rights for material breach. Missing any element makes the BAA non-compliant.
What happens if you don't have a Business Associate Agreement?
HHS Office for Civil Rights can penalize both the covered entity and the business associate directly for permitting PHI transmission without a BAA in place. Penalties range from $141 per violation to $71,162 per violation with annual caps in the low millions. HHS enforcement actions have specifically targeted missing-BAA cases, with settlements ranging from $100,000 to over $5 million.
Does a Business Associate Agreement need to be signed before any PHI is shared?
Yes. The BAA must be executed before the covered entity discloses PHI to the business associate. Any PHI transmission before BAA execution is a compliance violation. This is why reputable medical billing vendors provide the BAA template early in the sales cycle and complete signature before onboarding data migration begins.