A Business Associate Agreement (BAA) is a contract required under the HIPAA Privacy Rule at 45 CFR 164.502(e) and 45 CFR 164.504(e). The BAA obligates a business associate to protect the Protected Health Information (PHI) it receives on behalf of a covered entity, and creates a documented chain of responsibility for HIPAA compliance.
Covered entities under HIPAA are healthcare providers, health plans, and healthcare clearinghouses. Business associates are any persons or entities that create, receive, maintain, or transmit PHI on behalf of a covered entity to perform a service.
Common business associates in a physician practice:
- Medical billing and coding vendors
- Electronic Health Record (EHR) system providers
- Cloud storage and backup services
- IT support and managed service providers
- Practice management software providers
- Analytics and reporting platforms
- Transcription services
- Answering services and virtual receptionists
- Shredding and document destruction services
Any transmission of PHI to any of these without a signed BAA is a HIPAA violation, exposing both the covered entity and the business associate to enforcement.
The required elements
The HIPAA regulations specify the elements a BAA must contain. Missing any element makes the agreement non-compliant even if it is signed.
1. Permitted and required uses and disclosures of PHI
The BAA must specify:
- The purposes for which the business associate may use PHI
- The purposes for which the business associate may disclose PHI
- Whether de-identified data may be created and used
- Whether data aggregation is permitted
Uses beyond what is specified are prohibited. A billing vendor cannot use PHI for marketing to the covered entity's patients, for example, without separate patient authorization.
2. Safeguards to protect PHI
The BAA must require the business associate to:
- Implement the administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR Part 164 Subpart C)
- Prevent uses or disclosures of PHI not permitted by the BAA
- Report to the covered entity any use or disclosure not permitted by the agreement
3. Reporting of security incidents and breaches
The BAA must require the business associate to:
- Report to the covered entity any security incident of which the business associate becomes aware
- Report breaches of unsecured PHI in accordance with the Breach Notification Rule (45 CFR Part 164 Subpart D)
- Provide sufficient information for the covered entity to meet its own notification obligations
Typical timeframes: 24 to 72 hours for incident notification; 60 days maximum for breach notification (though most BAAs impose stricter internal timelines).
4. Subcontractor flow-down
The BAA must require that any subcontractor the business associate engages to help perform functions that involve PHI enter into an equivalent BAA with the business associate. The obligations flow down through the entire chain.
This is why practices should ask which functions the vendor subcontracts, where the subcontractors operate, and whether the subcontractor BAAs are available on request.
5. Individual access, amendment, and accounting rights
The BAA must require the business associate to:
- Make PHI available to individuals for access under 45 CFR 164.524
- Make PHI available for amendment under 45 CFR 164.526
- Make available an accounting of disclosures under 45 CFR 164.528
These are the individual patient rights preserved through the business associate layer.
6. PHI availability for compliance activity
The BAA must require the business associate to make its books, records, policies, and practices relating to PHI available to HHS for compliance investigation and audit.
7. Return or destruction of PHI at termination
At the end of the BAA:
- The business associate must return or destroy all PHI in its possession
- If neither is feasible, the business associate must extend the protections of the BAA to the retained PHI and limit further uses and disclosures to what makes return or destruction infeasible
This is why the data-return process should be specified in the service agreement in parallel with the BAA.
8. Covered entity termination rights
The BAA must permit the covered entity to terminate the agreement if the business associate violates a material term. Some BAAs include cure periods (30 to 60 days) before termination; unremediated breach after the cure period triggers immediate termination.
What a BAA is not
- Not a substitute for the service agreement. The BAA governs PHI handling; the service agreement governs commercial terms (fees, deliverables, performance metrics). Both are required.
- Not a one-time signature. The BAA remains in force for the duration of the relationship and applies to every PHI transmission during that period.
- Not fungible across vendors. Each business associate needs its own BAA. Sharing a BAA template is fine; each relationship requires its own executed instance.
When a BAA is not required
The HHS Business Associates guidance identifies exceptions where a BAA is not required:
- Disclosures by a covered entity to another healthcare provider for treatment of the individual
- Disclosures to a health plan sponsor by a group health plan for enrollment or eligibility
- The collection and sharing of PHI by a health plan that is a public benefits program
- Conduits that only transport PHI without any access on other than a random or infrequent basis (traditional postal service, some cloud transmission-only services)
The conduit exception is narrowly interpreted. Most cloud storage and software-as-a-service providers do have access to PHI (even if just for troubleshooting) and require a BAA.
Enforcement examples
HHS Office for Civil Rights has settled a series of enforcement actions specifically citing missing or inadequate BAAs. Public settlements have ranged from $100,000 to over $5 million. Common patterns include:
- Practice used a cloud storage service without a BAA; storage breach exposed patient records
- Business associate used subcontractor without subcontractor BAA; subcontractor breach cascaded up
- BAA lacked required elements (breach notification timeline, subcontractor flow-down); enforcement treated as if no BAA existed
Practical BAA review process
When a vendor provides a BAA for signature:
- Verify all eight required elements are present
- Verify breach notification timing (24-72 hours preferred; 60 days is the ceiling)
- Verify subcontractor flow-down is unambiguous
- Verify data-return process at termination is specified (or that the service agreement covers it)
- Verify liability language does not conflict with any liability cap in the service agreement
- Verify indemnification provisions (if any) are mutual
- Have healthcare counsel review before signing on any contract worth more than $25,000 annually
Bottom line
A Business Associate Agreement is not a formality. It is a HIPAA-required contract with eight specified elements, enforced by direct liability to HHS Office for Civil Rights. Any vendor handling PHI needs one signed before any data is shared. Any vendor that resists signing or provides a BAA missing required elements is not equipped to be a compliant business associate.