Somewhere in your company’s shared drive there is probably a PDF titled “BAA — signed” that nobody has read since the day it was countersigned. That document is doing more work than almost any other contract you hold. It is the legal mechanism that lets protected health information leave a hospital and land on your servers lawfully; it defines — and limits — everything you may do with that data; and it carries HIPAA’s obligations down to you in writing, with your signature confirming you accepted them. Understanding what’s in it is not a legal nicety. It is the difference between operating a regulated service and merely believing you do.
What a BAA Is (and What It Isn’t)
The Privacy Rule permits a covered entity to disclose PHI to a business associate only if it first obtains satisfactory assurances, in writing, that the vendor will safeguard the information and use it only for the purposes of the engagement. That written assurance is the Business Associate Agreement, and its required contents live at 45 CFR 164.504(e). No BAA, no lawful disclosure — it is genuinely that binary. Every record that moves before the agreement exists is an impermissible disclosure, and a BAA signed later does not retroactively repair it.
It helps to be precise about what the BAA is not. It is not an NDA — confidentiality is one clause among many, and the BAA governs use, not just secrecy. It is not a GDPR data processing agreement, though the two rhyme; if you serve both markets you will likely sign both. And it is not a compliance certificate: signing a BAA doesn’t make you HIPAA compliant any more than signing a lease makes you a good tenant. It obligates you to be compliant, and creates contractual liability — on top of the direct regulatory liability business associates already carry — when you are not.
When You Need One — and When You Don’t
The trigger is functional: a BAA is required with any party that creates, receives, maintains, or transmits PHI on behalf of a covered entity or another business associate. Job titles and industry labels are irrelevant; the data flow decides.
| BAA required | BAA not required |
|---|---|
| Cloud and hosting providers storing ePHI — even encrypted, even without the key | Members of your own workforce — employment, not contract, covers them |
| SaaS platforms: EHR add-ons, scheduling, telehealth, messaging, analytics | Disclosures between providers for treatment of a patient |
| Billing, coding, transcription, and revenue-cycle services | True conduits — pure transmission with only transient storage (a genuinely narrow category) |
| Email, backup, and infrastructure vendors if PHI touches them | Janitorial, maintenance, and others whose PHI contact is only incidental |
| Consultants, lawyers, accountants who see PHI to do the work | Payment processors acting as financial institutions for transactions |
The most consequential row is the first. Since OCR’s 2016 cloud guidance, “we never look at the data” has been a dead argument — a provider that maintains ePHI is a business associate and needs a BAA, full stop. This is why AWS, Google Cloud, and Microsoft all offer standard BAAs, and why using a vendor that won’t sign one is itself the compliance decision you’re making.
The Provisions HIPAA Requires
The regulation doesn’t leave the BAA’s contents to negotiation. 164.504(e) prescribes what the contract must establish — and when OCR audits, it checks agreements against this list:
| Required provision | What it does |
|---|---|
| Permitted uses and disclosures | Defines exactly what the business associate may do with PHI — the ceiling on your product’s behaviour |
| No use beyond the contract or law | Anything not permitted is prohibited; silence means no |
| Appropriate safeguards | Requires Security Rule compliance for ePHI — administrative, physical, and technical controls |
| Breach and incident reporting | Obligates the BA to report breaches of unsecured PHI and security incidents to the covered entity |
| Subcontractor flow-down | Requires the BA to bind its own vendors to the same restrictions via their own BAAs |
| Individual access | The BA must make PHI available so patients can exercise their right of access |
| Amendment support | The BA must incorporate amendments to PHI when directed |
| Accounting of disclosures | The BA must supply the disclosure information the covered entity needs to answer patients |
| Books and records to HHS | The BA must open its practices to the regulator on request |
| Return or destroy at termination | PHI goes back or gets destroyed when the relationship ends, where feasible — with protections extended if not |
| Termination for violation | The covered entity may terminate the contract if the BA materially breaches it |
Read that table as a product requirements document, because that is what it becomes the moment you sign. “Individual access” means you can export a patient’s data on request. “Amendment support” means corrections propagate. “Accounting of disclosures” means you log what leaves. “Return or destroy” means deletion actually works — including against backups. Teams that read the BAA as legal boilerplate discover these clauses as emergency engineering projects later; the patient rights they exist to serve come with statutory deadlines.
Beyond the Mandatory: The Terms Worth Negotiating
Around the required core, real BAAs carry negotiated terms — and several of them quietly become engineering requirements:
- Breach notification timelines. The law says a business associate reports breaches to the covered entity without unreasonable delay, within 60 days at the outside. Covered entities routinely negotiate that down to 5 days, 72 hours, even 24 — because their own clocks start ticking on discovery. Whatever number you sign, your detection and incident response capability must actually meet it.
- Indemnification and liability caps. Who pays for the breach response, the notification letters, the credit monitoring, the fines? The mandatory clauses are silent; the negotiated ones are not.
- Cyber insurance requirements. Increasingly standard: minimum coverage amounts, named policy types, proof on request.
- Audit and assessment rights. Some covered entities reserve the right to audit your controls or demand your SOC 2 or ISO 27001 evidence — one more reason healthcare vendors build those frameworks alongside HIPAA.
- Data location and offshore restrictions. Where PHI may be stored and processed, and whether non-US teams may access it.
- De-identification and aggregation rights. If your product improves on aggregated data, the BAA must actually permit that use — remember, silence means no.
The breach notification deadline you sign is not a legal detail — it is a detection requirement. A 72-hour reporting commitment presumes you can discover an incident, scope it, and characterise it in less time than that. If your logging and alerting can’t support the clock in the contract, the gap belongs to engineering, not legal.
The Subcontractor Chain
Before 2013, obligations effectively stopped at the first vendor. The Omnibus Rule extended the chain: a subcontractor that handles PHI for a business associate is itself a business associate, and the upstream BA must put a BAA in place with it — containing restrictions at least as tight as the ones it accepted. The pattern repeats at every hop: covered entity → your platform → your cloud provider → your cloud provider’s sub-processors.
For a healthtech company this means the BAA you signed upward must be mirrored downward, deliberately, across your entire vendor list. The practical tool is a register: every vendor that touches PHI, what they do with it, whether a BAA is in place, and when it was last reviewed. Every row without an agreement is a gap that belongs to you — the covered entity’s compliance is intact; yours is not.
What No BAA Costs
OCR treats the missing agreement as a standalone violation — no breach, no harm, no hacker required. The settlement record makes the point better than any warning:
| Case | What happened | Settlement |
|---|---|---|
| North Memorial Health Care (2016) | Gave a contractor access to a database of 289,904 patients — no BAA, and no enterprise risk analysis either | $1.55M |
| Raleigh Orthopaedic Clinic (2016) | Handed 17,300 patients’ X-ray films to a vendor for digitisation with no agreement in place | $750K |
| Advanced Care Hospitalists (2018) | Used a billing service with no BAA; patient data later surfaced on a public website | $500K |
| Center for Children’s Digestive Health (2017) | Small practice stored paper records with a vendor — neither side could produce a signed BAA | $31K |
In none of these settlements did OCR need to prove the vendor mishandled anything. The impermissible disclosure was complete the moment PHI moved without a signed agreement. That is the asymmetry worth internalising: a BAA costs a signature; its absence has cost seven figures — and it is among the first documents requested in every investigation, including ones that started as something else entirely.
Signed and Filed vs Operationalised
The gap between companies that have BAAs and companies that run them follows a recognisable shape:
| Signed and filed | Operationalised |
|---|---|
| ✗ BAA signed after data was already flowing | ✓ Executed before the first byte of PHI moves |
| ✗ Template countersigned unread | ✓ Every clause mapped to a real capability |
| ✗ Breach clause discovered during a breach | ✓ Notification deadline wired into the IR runbook |
| ✗ No inventory of which vendors touch PHI | ✓ A BAA register reviewed on a schedule |
| ✗ Subcontractors onboarded on an MSA alone | ✓ Flow-down BAAs at every hop of the chain |
| ✗ Termination clause treated as decoration | ✓ Return-or-destroy tested against real backups |
Five Checks Before You Sign
Whether you are the covered entity sending the template or the vendor receiving it, five questions surface most of what matters:
- 1. Do the permitted uses match what the product actually does? If you de-identify, aggregate, or use data to improve the service, the agreement must say so — silence prohibits it.
- 2. Can you meet the breach clock? Map the notification deadline to your real detection and response capability before agreeing to it.
- 3. Is the subcontractor story true? You are promising your entire downstream chain is bound by equivalent terms. Is it?
- 4. Is return-or-destroy feasible? Termination clauses collide with backup retention and multi-tenant architectures; know your answer before signing, not at offboarding.
- 5. Do liability terms match your insurance? Uncapped indemnification with a capped policy is a gap someone will eventually measure precisely.
Final Thought
The BAA is where HIPAA stops being an abstraction and becomes contract law with your signature on it. Every clause in the required list corresponds to something a regulator can ask you to demonstrate and a customer can ask you to prove — safeguards, reporting, access, deletion, the discipline of your vendor chain. Read it the way OCR reads it: as a specification. Then check, honestly, whether your product meets the spec you already signed.
The test: pull your most important BAA and, for each obligation it contains, name the system, process, or runbook that fulfils it. Any clause you can’t map to something real is the finding an auditor — or an incident — will eventually write up for you.
Frequently Asked Questions
A BAA is the written contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information on its behalf. It is the legal mechanism that makes the disclosure of PHI to the vendor lawful, defines and limits what the vendor may do with that data, and passes HIPAA obligations — safeguards, breach reporting, subcontractor controls — down the chain in writing.
45 CFR 164.504(e) prescribes the required provisions: the permitted and required uses and disclosures of PHI; a prohibition on use or disclosure beyond the contract or the law; appropriate safeguards including Security Rule compliance for ePHI; reporting of breaches and security incidents to the covered entity; a requirement that subcontractors agree to the same restrictions; support for individuals’ access, amendment, and accounting-of-disclosures rights; making records available to HHS; return or destruction of PHI at termination where feasible; and the covered entity’s right to terminate for violation.
Before any PHI changes hands. The Privacy Rule requires the covered entity to obtain satisfactory assurances in writing — the BAA — before disclosing PHI to a business associate. A BAA signed after data has already been flowing does not retroactively legalise the earlier disclosures; every record transferred before signature was an impermissible disclosure, which is why OCR treats a missing or late BAA as a standalone violation.
Every disclosure of PHI to the vendor is impermissible, regardless of whether anything went wrong. OCR has repeatedly settled over exactly this: North Memorial Health Care paid $1.55 million in part for giving a contractor access to a database of 289,904 patients with no BAA; Raleigh Orthopaedic Clinic paid $750,000 for handing X-ray films to a vendor without one; Advanced Care Hospitalists paid $500,000 after using a billing service with no agreement in place. The absence of the document is itself the violation.
Yes. Since the 2013 Omnibus Rule, a subcontractor that handles PHI for a business associate is itself a business associate, and the upstream business associate must put a BAA in place with it containing the same restrictions it accepted. The obligations flow down every hop of the chain — covered entity to vendor, vendor to sub-vendor, and onward — and each link without an agreement is a compliance gap for the party above it.