Skip to main content
Category: Governance and Workforce

Business Associate Contracts

Also known as: BAA, Business Associate Agreement, Business Associate Contract, BAA
Simply put

A Business Associate Contract is a written agreement between a covered entity (such as a healthcare provider or health plan) and a business associate that handles protected health information (PHI) on the covered entity's behalf. It sets out and limits how the business associate may use and disclose that information, and it helps ensure that both parties protect the data. When a business associate uses subcontractors that handle PHI, those subcontractors are generally required to agree to the same kinds of restrictions.

Formal definition

A Business Associate Contract (also called a Business Associate Agreement or BAA) is the legally required written contract that establishes the permitted and required uses and disclosures of protected health information by a business associate, as defined under the HIPAA Privacy Rule. Business associates are generally persons or entities, other than members of a covered entity's workforce, engaged by a covered entity to carry out functions or activities involving PHI on its behalf. The contract serves to clarify and limit, as appropriate, the business associate's permissible uses and disclosures of PHI, and typically obligates the business associate to ensure that any subcontractors that create, receive, maintain, or transmit PHI agree to the same restrictions and conditions that apply to the business associate. The specific content of a BAA can vary depending on the relationship and the nature of the PHI involved. Note that a BAA addresses the contractual relationship and obligations flowing between the parties; it does not by itself establish overall HIPAA compliance, and Security Rule safeguard requirements for ePHI, state law, and HITECH Act provisions may impose additional requirements. Practitioners should confirm required contract terms against the current regulatory text.

Why it matters

Business Associate Contracts are the primary legal mechanism through which a covered entity extends HIPAA-related protections to the outside parties that handle protected health information on its behalf. Because HIPAA obligations generally attach through defined relationships rather than automatically to every vendor that touches data, the BAA is what formally establishes and limits how a business associate may use and disclose PHI. Without it, a covered entity typically lacks the contractual assurances required when engaging a business associate to carry out functions involving PHI.

The contract also matters because compliance responsibilities do not stop at the first vendor. When a business associate engages subcontractors that create, receive, maintain, or transmit PHI, those subcontractors are generally required to agree to the same kinds of restrictions and conditions that apply to the business associate. This flow-down structure is intended to preserve protections for PHI as it moves through a chain of vendors, so a gap at any point in that chain can undermine the safeguards the covered entity relied upon.

It is important to recognize the limits of a BAA. It addresses the contractual relationship and obligations flowing between the parties, but it does not by itself establish overall HIPAA compliance. Security Rule safeguard requirements for ePHI, state law, and HITECH Act provisions may impose additional obligations beyond what the contract covers, and the specific required terms should be confirmed against the current regulatory text.

Who it's relevant to

Covered Entities
Healthcare providers, health plans, and other covered entities are responsible for putting a Business Associate Contract in place before engaging a business associate to carry out functions or activities involving PHI on their behalf. The BAA is how they establish and limit the business associate's permissible uses and disclosures of that information.
Business Associates
Persons or entities, other than a covered entity's workforce members, engaged to perform functions involving PHI are bound by the terms of the BAA. They are generally obligated to use and disclose PHI only as the contract permits and to ensure that subcontractors handling PHI agree to comparable restrictions and conditions.
Subcontractors
Vendors further down the chain that create, receive, maintain, or transmit PHI on behalf of a business associate are generally required to agree to the same kinds of restrictions and conditions that apply to the business associate, preserving protections as PHI moves through the vendor relationship.
Privacy Officers and Compliance Teams
Those responsible for HIPAA compliance oversight use BAAs to document and manage vendor relationships involving PHI. They should tailor contract terms to the specific relationship and nature of the PHI, and confirm required terms against current regulatory text, recognizing that a BAA alone does not establish overall HIPAA compliance.
Legal and Contracting Professionals
Attorneys and contract specialists drafting or reviewing BAAs must ensure the agreement addresses permitted and required uses and disclosures and the flow-down to subcontractors, while noting that Security Rule, state law, and HITECH Act provisions may impose additional requirements beyond the contract itself.

Inside BAA

Permitted Uses and Disclosures
The contract must specify how the business associate may use and disclose protected health information (PHI), limiting such activities to those permitted or required by the agreement and consistent with the covered entity's obligations under the HIPAA Privacy Rule.
Prohibition on Unauthorized Use or Disclosure
The agreement generally requires the business associate not to use or further disclose PHI other than as permitted by the contract or as required by law.
Safeguard Obligations
The business associate is typically required to implement appropriate administrative, physical, and technical safeguards to protect PHI, and for electronic PHI (ePHI), to comply with the applicable requirements of the HIPAA Security Rule.
Reporting of Incidents and Breaches
The contract generally obligates the business associate to report to the covered entity any use or disclosure not provided for by the agreement, including security incidents and breaches of unsecured PHI, consistent with the Breach Notification Rule.
Subcontractor Flow-Down Provisions
The agreement must require the business associate to ensure that any subcontractors that create, receive, maintain, or transmit PHI on its behalf agree to restrictions and conditions that are at least as protective as those applying to the business associate.
Access, Amendment, and Accounting Support
Where applicable, the contract addresses the business associate's role in helping the covered entity meet individual rights obligations under the Privacy Rule, such as access to PHI, amendment of PHI, and accounting of disclosures.
Availability of Records to HHS
The agreement typically requires the business associate to make its internal practices, books, and records relating to the use and disclosure of PHI available to HHS for determining compliance.
Return or Destruction and Termination
The contract generally addresses return or destruction of PHI at termination where feasible, and provides the covered entity with rights to terminate upon the business associate's material breach.

Common questions

Answers to the questions practitioners most commonly ask about BAA.

Does having a business associate agreement in place mean my vendor is now HIPAA compliant?
No. A business associate agreement (BAA) is a contract that establishes obligations and allocates responsibility between the parties; it does not by itself make either party compliant. Each party must still implement the safeguards and practices required under HIPAA. Signing a BAA is generally a necessary step for permitting certain disclosures of PHI to a business associate, but it is not evidence that the vendor has actually met its Privacy Rule or Security Rule obligations. Readers should verify vendor practices independently and against current regulatory requirements.
Does HIPAA directly regulate every vendor that touches our data once we sign a contract with them?
Not in that broad sense. HIPAA obligations attach through defined relationships. A vendor becomes a business associate when it creates, receives, maintains, or transmits PHI to perform a function or service on behalf of a covered entity or another business associate. A vendor that does not handle PHI in a qualifying capacity is generally not a business associate, and a BAA would not typically be required. Where a business associate uses a subcontractor that handles PHI, obligations flow further down through a separate BAA between the business associate and the subcontractor. The contract reflects and formalizes these relationships rather than creating regulatory jurisdiction on its own.
What core provisions should a business associate agreement generally include?
A BAA typically addresses the permitted and required uses and disclosures of PHI, a commitment not to use or disclose PHI beyond what the contract or law allows, safeguards the business associate will apply (including Security Rule safeguards for ePHI), reporting of unauthorized uses, disclosures, and security incidents or breaches, requirements to bind subcontractors through equivalent terms, availability of PHI to support individual rights, cooperation with HHS OCR compliance reviews, and return or destruction of PHI at termination where feasible. The specific required elements are set out in the applicable regulatory text, and readers should confirm them against the current regulation.
How should breach and security incident reporting obligations be handled in a BAA?
The BAA should generally specify how and how quickly the business associate must notify the covered entity of a breach of unsecured PHI, as well as of security incidents affecting ePHI. Many organizations negotiate defined notification timeframes and the information to be provided, since these details help the covered entity meet its own Breach Notification Rule obligations. The parties should be precise about which entity performs breach risk assessments and issues notifications. Applicable timeframes and thresholds should be confirmed against current guidance, and state law or the HITECH Act may impose additional requirements.
How do subcontractor relationships affect our business associate agreements?
When a business associate engages a subcontractor that creates, receives, maintains, or transmits PHI on its behalf, that subcontractor is itself treated as a business associate, and a BAA is generally required between the business associate and the subcontractor. The terms flowed down to the subcontractor should be at least as protective as those in the upstream agreement. Covered entities typically address this by requiring, in their own BAA, that the business associate obtain equivalent commitments from any subcontractors that handle PHI.
What should happen to PHI under the BAA when the relationship ends?
A BAA should generally address return or destruction of PHI upon termination of the agreement, to the extent feasible. Where return or destruction is not feasible, the contract typically requires the business associate to extend the protections of the BAA to the retained PHI and to limit further uses and disclosures to those that make return or destruction infeasible. Organizations should confirm the specific requirements against the current regulatory text and consider how data retention obligations under other laws may interact with these terms.

Common misconceptions

Signing a business associate agreement (BAA) by itself makes both parties HIPAA compliant.
A BAA is a required contractual mechanism, but it does not guarantee compliance. Both parties must actually implement the underlying safeguards and practices. HIPAA obligations attach through defined relationships and conduct, not merely through executing a document.
HIPAA directly regulates every vendor that touches healthcare data, so a contract is unnecessary.
Obligations generally attach through defined relationships. A vendor that creates, receives, maintains, or transmits PHI on behalf of a covered entity is a business associate, and the BAA is the mechanism that extends applicable obligations to that party and, through flow-down provisions, to its subcontractors.
A business associate is not directly liable to regulators as long as a BAA exists.
Business associates can be directly subject to certain HIPAA requirements and enforcement by HHS OCR, in addition to their contractual obligations under the BAA. The contract does not shield a business associate from applicable direct regulatory responsibility. Readers should verify current enforcement provisions against the applicable regulatory text.

Best practices

Execute a written BAA before any PHI is shared, and confirm the vendor genuinely qualifies as a business associate under the defined relationship rather than assuming a contract alone establishes the arrangement.
Ensure the agreement includes flow-down provisions so subcontractors handling PHI are bound by restrictions at least as protective as those applying to the business associate.
Specify permitted uses and disclosures narrowly, aligning them with the covered entity's own Privacy Rule obligations, and prohibit any use or disclosure beyond what the contract or law allows.
Include clear breach and security incident reporting requirements and timelines consistent with the Breach Notification Rule, and confirm they support the covered entity's own notification duties.
Address return or destruction of PHI at termination and preserve the covered entity's right to terminate for material breach.
Periodically review and update BAAs to reflect current regulatory text and organizational changes, and verify specific requirements, timelines, and citations against the current regulation, noting that state law or the HITECH Act may impose additional requirements.