Technology, Data & Privacy

Business Associate Agreement

A business associate agreement allocates HIPAA duties when a covered entity or business associate gives another business associate access to protected health information for permitted services.

Direct answer

What is the purpose of Business Associate Agreement?

Use a HIPAA-compliant business associate agreement when the relationship and data qualify under HIPAA, and align its promises with the parties’ real security and incident-response operations.

01

What Business Associate Agreement does

A business associate agreement allocates HIPAA duties when a covered entity or business associate gives another business associate access to protected health information for permitted services.

A useful document turns the parties' actual arrangement into measurable duties, approvals, timing, remedies, and a reliable execution record. Its terms should be reconciled to the transaction rather than copied from an unrelated form.

02

When this agreement is commonly used

  • A covered health provider hires a vendor that handles protected health information
  • A business associate engages a subcontractor with PHI access
  • A service arrangement changes the permitted uses, systems, or breach responsibilities for PHI

03

When another document or professional review may be better

The document name alone does not determine the right structure. Consider a different instrument or qualified legal review when any of these conditions applies:

  • Do not call ordinary personal data PHI or use a BAA when the parties do not have a HIPAA covered-entity or business-associate relationship.
  • A BAA does not replace a security risk analysis, privacy notices, patient authorization, or other applicable data-protection contracts.

04

Information to collect before drafting

Record exact facts before clauses are written. Names, authority, dates, amounts, defined terms, dependencies, and incorporated materials should be verifiable and consistent.

  • Covered entity, business associate, subcontractor chain, and underlying services
  • PHI types, permitted uses and disclosures, systems, locations, and workforce access
  • Administrative, physical, and technical safeguards plus incident contacts
  • Breach reporting, individual requests, audit access, return or destruction, and termination limits

05

Key decisions to make

These decisions shape the allocation of responsibility and should not be left for boilerplate to decide:

  • Whether each party is a covered entity, business associate, or subcontractor
  • Which PHI uses are necessary for the services
  • What incident facts and timing the parties can operationally report
  • Whether PHI can be returned or destroyed at termination

06

Provisions the agreement commonly addresses

  • Permitted and required PHI uses and disclosures
  • Safeguards and Security Rule obligations
  • Breach, security-incident, and impermissible-use reporting
  • Subcontractors, individual rights, records, and HHS access
  • Termination, mitigation, return or destruction, and survival

Every provision should use the same parties, dates, standards, defined terms, and document hierarchy. A clause that is reasonable by itself can still create a conflict when it is not reconciled with payment, default, termination, or another exhibit.

07

How to prepare a Business Associate Agreement

  1. 01Describe the intended result and the relationship in plain language.
  2. 02Confirm parties, authority, governing jurisdiction, dates, money, property, services, and approvals.
  3. 03Resolve the key decisions and identify every schedule, exhibit, disclosure, consent, or filing.
  4. 04Draft the provisions as one consistent system, then review the complete execution set before signature.

08

Material risks and source-backed checks

A BAA copied without role and system analysis may promise impossible reporting or omit actual subcontractor flows. HIPAA duties attach by law when the relationship qualifies, even if the document is missing.

09

Supporting documents and the complete package

The main agreement may establish the framework while schedules, exhibits, disclosures, consents, or operational records supply transaction-specific details.

  • Underlying services agreement
  • Security controls and PHI systems schedule
  • Incident-response and subcontractor list

Each incorporated document should be identified precisely, use the same names and effective date, and follow a stated order of precedence if terms conflict.

10

Review and execution checklist

Map PHI before signing, verify security ownership and incident contacts, flow terms to subcontractors, connect request handling to operations, and review the BAA whenever systems or services change.

  • Confirm legal names, roles, capacity, addresses, and signing authority
  • Reconcile dates, amounts, definitions, cross-references, schedules, and exhibits
  • Confirm that duties, deadlines, approvals, acceptance standards, and payment triggers are measurable
  • Check that default, termination, remedies, and surviving obligations work together
  • Complete jurisdiction-specific forms, notices, witnesses, notarization, filings, or professional review when applicable
  • Deliver and preserve the complete signed package with its incorporated documents

11

Authoritative references and further reading

These sources provide federal, state-resource, regulatory, or institutional context. They do not replace checking the law and required forms applicable to the parties, transaction, and governing jurisdiction.

  1. Source 1

    Business Associate Contracts

    U.S. Department of Health and Human Services. HIPAA business-associate requirements and sample provisions.

  2. Source 2

    The Security Rule

    U.S. Department of Health and Human Services. HIPAA administrative, physical, and technical safeguard requirements.

  3. Source 3

    Breach Notification Rule

    U.S. Department of Health and Human Services. HIPAA breach-assessment and notification framework.

Frequently asked questions

Questions about Business Associate Agreement

What does a Business Associate Agreement establish?

A business associate agreement allocates HIPAA duties when a covered entity or business associate gives another business associate access to protected health information for permitted services.

When is a Business Associate Agreement usually the wrong document?

Do not call ordinary personal data PHI or use a BAA when the parties do not have a HIPAA covered-entity or business-associate relationship. A BAA does not replace a security risk analysis, privacy notices, patient authorization, or other applicable data-protection contracts.

Does every healthcare vendor need a business associate agreement?

No. The analysis depends on whether the vendor creates, receives, maintains, or transmits PHI on behalf of a covered entity or business associate and whether an exception applies.

Which decisions should be settled before drafting a Business Associate Agreement?

Before drafting, the parties should resolve these agreement-specific questions: Whether each party is a covered entity, business associate, or subcontractor; Which PHI uses are necessary for the services; What incident facts and timing the parties can operationally report; Whether PHI can be returned or destroyed at termination. They should reconcile those choices with the governing jurisdiction and the verified intake facts, including: Covered entity, business associate, subcontractor chain, and underlying services.

What may need to accompany a Business Associate Agreement?

The execution package may include Underlying services agreement, Security controls and PHI systems schedule, Incident-response and subcontractor list. The parties should attach only the materials that apply and identify each one by name, date, or version.

Related contract guides

Documents commonly considered alongside this agreement