Governance DocsGovernance Docs
Browse Toolkits

CART

No products in the cart.

ISO Compliance Insights & Best Practices

HIPAA BAA guide - what a business associate agreement is and its required provisions

HIPAA Business Associate Agreement (BAA): A Guide

Whenever a healthcare organization shares protected health information with a vendor, HIPAA requires a specific contract between them — the HIPAA BAA, or Business Associate Agreement. Missing or inadequate BAAs are a frequent cause of HIPAA violations, so getting them right is essential. This guide explains what a BAA is, when you need one, and what it must contain.

HIPAA BAA guide - what a business associate agreement is and its required provisions

For the wider context, see our complete HIPAA guide.

What is a HIPAA BAA?

A Business Associate Agreement is a legally binding contract between a covered entity (or a business associate) and a business associate that will create, receive, maintain, or transmit protected health information on its behalf. Required by HIPAA, the BAA obligates the business associate to safeguard PHI in line with the HIPAA rules and defines each party’s responsibilities. Without a compliant BAA in place, sharing PHI with a vendor is itself a HIPAA violation.

When do you need a HIPAA BAA?

You need a BAA whenever a third party will handle PHI on your behalf — for example a cloud hosting provider, a billing or coding company, an IT support firm, an email or analytics platform, or a shredding service that disposes of records. If a vendor could access PHI as part of the service they provide, a BAA is almost certainly required. Modern healthcare supply chains involve many such relationships, which is why a reliable template is so valuable.

What a HIPAA BAA must include

A compliant BAA must, among other things:

  • Describe the permitted uses and disclosures of PHI by the business associate.
  • Require the business associate to safeguard PHI and comply with the Security Rule.
  • Require reporting of security incidents and breaches to the covered entity.
  • Ensure that subcontractors handling PHI agree to the same restrictions.
  • Provide for access, amendment, and accounting of disclosures to support patient rights.
  • Require the return or destruction of PHI when the contract ends.
  • Allow the covered entity to monitor compliance.

Covered entity and business associate duties

The BAA formalises a shared responsibility for protecting PHI. The covered entity must only share PHI with business associates that provide satisfactory assurances, and must have a signed BAA in place before sharing. The business associate must safeguard the data, limit its use to permitted purposes, control its subcontractors, report incidents, and support the covered entity’s HIPAA obligations. Understanding your role — and that many organizations are business associates themselves — is key to getting your BAAs right.

A compliant BAA, ready to use.

Our HIPAA Toolkit includes a ready-to-use Business Associate Agreement template covering every required provision — plus the wider HIPAA documentation you need, editable in Word.

Get the HIPAA Toolkit →

Frequently asked questions

What is a HIPAA BAA?

A Business Associate Agreement is a HIPAA-required contract between a covered entity (or business associate) and a vendor that handles protected health information, obligating the vendor to safeguard that data.

When is a HIPAA BAA required?

Whenever a third party creates, receives, maintains, or transmits PHI on your behalf — such as cloud providers, billing companies, or IT support.

What must a HIPAA BAA contain?

Permitted uses of PHI, safeguarding and Security Rule compliance, breach reporting, subcontractor obligations, support for patient rights, return or destruction of PHI at contract end, and monitoring rights.

Stay Compliance-Ready

Get compliance tips, new toolkit releases, and standard updates in your inbox.

We don’t spam! Read our privacy policy for more info.