🏥 HIPAA📝 Contracts⚖️ Enforcement

Business Associate Agreements — What a BAA Must Include and Why

The BAA is the only contract a federal privacy law forces you to sign. It’s also the one document whose absence is a violation all by itself — no breach required.

SS
Soham Sawant
🔐 Cybersecurity Expert & Technical Writer·📖 8 min read
📅 July 2026·🏢 SecComply
Business associate agreement BAA HIPAA contract required provisions signing

A BAA isn’t paperwork that follows the deal — it’s the legal bridge that makes the data flow lawful in the first place. It has to exist before the first byte of PHI moves.

Somewhere in your company’s shared drive there is probably a PDF titled “BAA — signed” that nobody has read since the day it was countersigned. That document is doing more work than almost any other contract you hold. It is the legal mechanism that lets protected health information leave a hospital and land on your servers lawfully; it defines — and limits — everything you may do with that data; and it carries HIPAA’s obligations down to you in writing, with your signature confirming you accepted them. Understanding what’s in it is not a legal nicety. It is the difference between operating a regulated service and merely believing you do.

Legal bridge
The BAA makes the disclosure of PHI to a vendor lawful
~10 clauses
45 CFR 164.504(e) prescribes the required provisions
Flows down
Every subcontractor hop needs its own BAA
$1.55M
What a missing BAA has cost in a single OCR settlement

What a BAA Is (and What It Isn’t)

The Privacy Rule permits a covered entity to disclose PHI to a business associate only if it first obtains satisfactory assurances, in writing, that the vendor will safeguard the information and use it only for the purposes of the engagement. That written assurance is the Business Associate Agreement, and its required contents live at 45 CFR 164.504(e). No BAA, no lawful disclosure — it is genuinely that binary. Every record that moves before the agreement exists is an impermissible disclosure, and a BAA signed later does not retroactively repair it.

It helps to be precise about what the BAA is not. It is not an NDA — confidentiality is one clause among many, and the BAA governs use, not just secrecy. It is not a GDPR data processing agreement, though the two rhyme; if you serve both markets you will likely sign both. And it is not a compliance certificate: signing a BAA doesn’t make you HIPAA compliant any more than signing a lease makes you a good tenant. It obligates you to be compliant, and creates contractual liability — on top of the direct regulatory liability business associates already carry — when you are not.

When You Need One — and When You Don’t

The trigger is functional: a BAA is required with any party that creates, receives, maintains, or transmits PHI on behalf of a covered entity or another business associate. Job titles and industry labels are irrelevant; the data flow decides.

BAA requiredBAA not required
Cloud and hosting providers storing ePHI — even encrypted, even without the keyMembers of your own workforce — employment, not contract, covers them
SaaS platforms: EHR add-ons, scheduling, telehealth, messaging, analyticsDisclosures between providers for treatment of a patient
Billing, coding, transcription, and revenue-cycle servicesTrue conduits — pure transmission with only transient storage (a genuinely narrow category)
Email, backup, and infrastructure vendors if PHI touches themJanitorial, maintenance, and others whose PHI contact is only incidental
Consultants, lawyers, accountants who see PHI to do the workPayment processors acting as financial institutions for transactions

The most consequential row is the first. Since OCR’s 2016 cloud guidance, “we never look at the data” has been a dead argument — a provider that maintains ePHI is a business associate and needs a BAA, full stop. This is why AWS, Google Cloud, and Microsoft all offer standard BAAs, and why using a vendor that won’t sign one is itself the compliance decision you’re making.

The Provisions HIPAA Requires

The regulation doesn’t leave the BAA’s contents to negotiation. 164.504(e) prescribes what the contract must establish — and when OCR audits, it checks agreements against this list:

Required provisionWhat it does
Permitted uses and disclosuresDefines exactly what the business associate may do with PHI — the ceiling on your product’s behaviour
No use beyond the contract or lawAnything not permitted is prohibited; silence means no
Appropriate safeguardsRequires Security Rule compliance for ePHI — administrative, physical, and technical controls
Breach and incident reportingObligates the BA to report breaches of unsecured PHI and security incidents to the covered entity
Subcontractor flow-downRequires the BA to bind its own vendors to the same restrictions via their own BAAs
Individual accessThe BA must make PHI available so patients can exercise their right of access
Amendment supportThe BA must incorporate amendments to PHI when directed
Accounting of disclosuresThe BA must supply the disclosure information the covered entity needs to answer patients
Books and records to HHSThe BA must open its practices to the regulator on request
Return or destroy at terminationPHI goes back or gets destroyed when the relationship ends, where feasible — with protections extended if not
Termination for violationThe covered entity may terminate the contract if the BA materially breaches it

Read that table as a product requirements document, because that is what it becomes the moment you sign. “Individual access” means you can export a patient’s data on request. “Amendment support” means corrections propagate. “Accounting of disclosures” means you log what leaves. “Return or destroy” means deletion actually works — including against backups. Teams that read the BAA as legal boilerplate discover these clauses as emergency engineering projects later; the patient rights they exist to serve come with statutory deadlines.

Beyond the Mandatory: The Terms Worth Negotiating

Around the required core, real BAAs carry negotiated terms — and several of them quietly become engineering requirements:

  • Breach notification timelines. The law says a business associate reports breaches to the covered entity without unreasonable delay, within 60 days at the outside. Covered entities routinely negotiate that down to 5 days, 72 hours, even 24 — because their own clocks start ticking on discovery. Whatever number you sign, your detection and incident response capability must actually meet it.
  • Indemnification and liability caps. Who pays for the breach response, the notification letters, the credit monitoring, the fines? The mandatory clauses are silent; the negotiated ones are not.
  • Cyber insurance requirements. Increasingly standard: minimum coverage amounts, named policy types, proof on request.
  • Audit and assessment rights. Some covered entities reserve the right to audit your controls or demand your SOC 2 or ISO 27001 evidence — one more reason healthcare vendors build those frameworks alongside HIPAA.
  • Data location and offshore restrictions. Where PHI may be stored and processed, and whether non-US teams may access it.
  • De-identification and aggregation rights. If your product improves on aggregated data, the BAA must actually permit that use — remember, silence means no.
THE CLAUSE THAT BECOMES AN SLO

The breach notification deadline you sign is not a legal detail — it is a detection requirement. A 72-hour reporting commitment presumes you can discover an incident, scope it, and characterise it in less time than that. If your logging and alerting can’t support the clock in the contract, the gap belongs to engineering, not legal.

The Subcontractor Chain

Before 2013, obligations effectively stopped at the first vendor. The Omnibus Rule extended the chain: a subcontractor that handles PHI for a business associate is itself a business associate, and the upstream BA must put a BAA in place with it — containing restrictions at least as tight as the ones it accepted. The pattern repeats at every hop: covered entity → your platform → your cloud provider → your cloud provider’s sub-processors.

For a healthtech company this means the BAA you signed upward must be mirrored downward, deliberately, across your entire vendor list. The practical tool is a register: every vendor that touches PHI, what they do with it, whether a BAA is in place, and when it was last reviewed. Every row without an agreement is a gap that belongs to you — the covered entity’s compliance is intact; yours is not.

What No BAA Costs

OCR treats the missing agreement as a standalone violation — no breach, no harm, no hacker required. The settlement record makes the point better than any warning:

CaseWhat happenedSettlement
North Memorial Health Care (2016)Gave a contractor access to a database of 289,904 patients — no BAA, and no enterprise risk analysis either$1.55M
Raleigh Orthopaedic Clinic (2016)Handed 17,300 patients’ X-ray films to a vendor for digitisation with no agreement in place$750K
Advanced Care Hospitalists (2018)Used a billing service with no BAA; patient data later surfaced on a public website$500K
Center for Children’s Digestive Health (2017)Small practice stored paper records with a vendor — neither side could produce a signed BAA$31K
THE PATTERN ACROSS EVERY CASE

In none of these settlements did OCR need to prove the vendor mishandled anything. The impermissible disclosure was complete the moment PHI moved without a signed agreement. That is the asymmetry worth internalising: a BAA costs a signature; its absence has cost seven figures — and it is among the first documents requested in every investigation, including ones that started as something else entirely.

Signed and Filed vs Operationalised

The gap between companies that have BAAs and companies that run them follows a recognisable shape:

Signed and filedOperationalised
✗ BAA signed after data was already flowing✓ Executed before the first byte of PHI moves
✗ Template countersigned unread✓ Every clause mapped to a real capability
✗ Breach clause discovered during a breach✓ Notification deadline wired into the IR runbook
✗ No inventory of which vendors touch PHI✓ A BAA register reviewed on a schedule
✗ Subcontractors onboarded on an MSA alone✓ Flow-down BAAs at every hop of the chain
✗ Termination clause treated as decoration✓ Return-or-destroy tested against real backups

Five Checks Before You Sign

Whether you are the covered entity sending the template or the vendor receiving it, five questions surface most of what matters:

  • 1. Do the permitted uses match what the product actually does? If you de-identify, aggregate, or use data to improve the service, the agreement must say so — silence prohibits it.
  • 2. Can you meet the breach clock? Map the notification deadline to your real detection and response capability before agreeing to it.
  • 3. Is the subcontractor story true? You are promising your entire downstream chain is bound by equivalent terms. Is it?
  • 4. Is return-or-destroy feasible? Termination clauses collide with backup retention and multi-tenant architectures; know your answer before signing, not at offboarding.
  • 5. Do liability terms match your insurance? Uncapped indemnification with a capped policy is a gap someone will eventually measure precisely.

Final Thought

The BAA is where HIPAA stops being an abstraction and becomes contract law with your signature on it. Every clause in the required list corresponds to something a regulator can ask you to demonstrate and a customer can ask you to prove — safeguards, reporting, access, deletion, the discipline of your vendor chain. Read it the way OCR reads it: as a specification. Then check, honestly, whether your product meets the spec you already signed.

The test: pull your most important BAA and, for each obligation it contains, name the system, process, or runbook that fulfils it. Any clause you can’t map to something real is the finding an auditor — or an incident — will eventually write up for you.

Are Your BAAs Signed — or Operational?

SecComply reviews your BAA obligations against what your product actually does, builds the vendor register and flow-down chain, and closes the gaps before a customer or regulator finds them.

Frequently Asked Questions

What is a Business Associate Agreement (BAA)?

A BAA is the written contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It is the legal mechanism that makes the disclosure of PHI to the vendor lawful, defines and limits what the vendor may do with that data, and passes HIPAA obligations — safeguards, breach reporting, subcontractor controls — down the chain in writing.

What must a BAA include?

45 CFR 164.504(e) prescribes the required provisions: the permitted and required uses and disclosures of PHI; a prohibition on use or disclosure beyond the contract or the law; appropriate safeguards including Security Rule compliance for ePHI; reporting of breaches and security incidents to the covered entity; a requirement that subcontractors agree to the same restrictions; support for individuals’ access, amendment, and accounting-of-disclosures rights; making records available to HHS; return or destruction of PHI at termination where feasible; and the covered entity’s right to terminate for violation.

When does a BAA need to be signed?

Before any PHI changes hands. The Privacy Rule requires the covered entity to obtain satisfactory assurances in writing — the BAA — before disclosing PHI to a business associate. A BAA signed after data has already been flowing does not retroactively legalise the earlier disclosures; every record transferred before signature was an impermissible disclosure, which is why OCR treats a missing or late BAA as a standalone violation.

What happens if you don’t have a BAA?

Every disclosure of PHI to the vendor is impermissible, regardless of whether anything went wrong. OCR has repeatedly settled over exactly this: North Memorial Health Care paid $1.55 million in part for giving a contractor access to a database of 289,904 patients with no BAA; Raleigh Orthopaedic Clinic paid $750,000 for handing X-ray films to a vendor without one; Advanced Care Hospitalists paid $500,000 after using a billing service with no agreement in place. The absence of the document is itself the violation.

Do subcontractors of a business associate need their own BAA?

Yes. Since the 2013 Omnibus Rule, a subcontractor that handles PHI for a business associate is itself a business associate, and the upstream business associate must put a BAA in place with it containing the same restrictions it accepted. The obligations flow down every hop of the chain — covered entity to vendor, vendor to sub-vendor, and onward — and each link without an agreement is a compliance gap for the party above it.