Business Associate Contracts
A Business Associate Contract is a written agreement between a covered entity (such as a healthcare provider or health plan) and a business associate that handles protected health information (PHI) on the covered entity's behalf. It sets out and limits how the business associate may use and disclose that information, and it helps ensure that both parties protect the data. When a business associate uses subcontractors that handle PHI, those subcontractors are generally required to agree to the same kinds of restrictions.
A Business Associate Contract (also called a Business Associate Agreement or BAA) is the legally required written contract that establishes the permitted and required uses and disclosures of protected health information by a business associate, as defined under the HIPAA Privacy Rule. Business associates are generally persons or entities, other than members of a covered entity's workforce, engaged by a covered entity to carry out functions or activities involving PHI on its behalf. The contract serves to clarify and limit, as appropriate, the business associate's permissible uses and disclosures of PHI, and typically obligates the business associate to ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions and conditions that apply to the business associate. The specific content of a BAA can vary depending on the relationship and the nature of the PHI involved. Note that a BAA addresses the contractual relationship and obligations flowing between the parties; it does not by itself establish overall HIPAA compliance, and Security Rule safeguard requirements for ePHI, state law, and HITECH Act provisions may impose additional requirements. Practitioners should confirm required contract terms against the current regulatory text.
Why it matters
Business Associate Contracts are the primary legal mechanism through which a covered entity extends HIPAA-related protections to the outside parties that handle protected health information on its behalf. Because HIPAA obligations generally attach through defined relationships rather than automatically to every vendor that touches data, the BAA is what formally establishes and limits how a business associate may use and disclose PHI. Without it, a covered entity typically lacks the contractual assurances required when engaging a business associate to carry out functions involving PHI.
The contract also matters because compliance responsibilities do not stop at the first vendor. When a business associate engages subcontractors that create, receive, maintain, or transmit PHI, those subcontractors are generally required to agree to the same kinds of restrictions and conditions that apply to the business associate. This flow-down structure is intended to preserve protections for PHI as it moves through a chain of vendors, so a gap at any point in that chain can undermine the safeguards the covered entity relied upon.
It is important to recognize the limits of a BAA. It addresses the contractual relationship and obligations flowing between the parties, but it does not by itself establish overall HIPAA compliance. Security Rule safeguard requirements for ePHI, state law, and HITECH Act provisions may impose additional obligations beyond what the contract covers, and the specific required terms should be confirmed against the current regulatory text.
Who it's relevant to
Inside BAA
Common questions
Answers to the questions practitioners most commonly ask about BAA.