What a BAA must contain, who needs one, and why most organisations have fewer valid ones than they think.
What a BAA actually is
A business associate agreement is the contract HIPAA requires before a covered entity lets any outside party handle protected health information on its behalf. It is not a courtesy document and it is not a formality — 45 CFR §164.308(b) and §164.314(a) make it a condition of the disclosure itself. Hand PHI to a vendor without one and the disclosure is impermissible from the first byte, regardless of how secure the vendor is.
The agreement does three things at once. It makes the vendor directly accountable under the Security Rule and parts of the Privacy Rule. It defines exactly what the vendor may do with the data. And it creates the contractual machinery — breach reporting, termination, return of data — that you will lean on when something goes wrong.
Who needs one
Any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. Cloud providers count even if they never look at the data. Conduits like the postal service do not.
The list is longer than most teams expect. Obvious candidates: your EHR vendor, billing service, transcription provider, and IT managed service provider. Less obvious but equally covered: your cloud hosting provider, your email platform if PHI passes through it, your analytics vendor if it touches identifiable data, the shredding company that destroys your records, the answering service that takes patient calls, and the lawyer or accountant who sees PHI in the course of their work.
The persistence-of-custody test is the useful one. If a vendor maintains PHI — even encrypted, even without the key, even without ever opening a file — HHS treats them as a business associate. The conduit exception is genuinely narrow: it covers entities that merely transport data with only random or transient access, like the postal service or an ISP. Almost nothing you buy as a SaaS product qualifies as a conduit.
Two relationships that do not need a BAA and often get one anyway: members of your own workforce, and other covered entities you disclose to for treatment. Signing unnecessary BAAs is mostly harmless; missing necessary ones is not.
Required provisions
Permitted uses, safeguard obligations, subcontractor flow-down, reporting of breaches and security incidents, access and amendment support, HHS availability, return or destruction at termination, and termination rights.
Those are the elements §164.504(e) actually requires, and each one has an operational meaning worth understanding before you sign:
- Permitted uses and disclosures — the vendor may only use PHI for the services in the underlying contract. Watch for language granting rights to “de-identified” or “aggregated” data; that is a business term, not a compliance one, and you should decide it deliberately.
- Safeguards — the business associate commits to complying with the Security Rule for any ePHI it handles. Since the HITECH changes this is a direct regulatory obligation, but the contract clause is still required.
- Breach and incident reporting — the BAA must require the vendor to report breaches of unsecured PHI and security incidents. Negotiate the timeline here: the regulation gives business associates up to 60 days, and your own notification clock starts running on discovery, so a shorter contractual reporting window protects you.
- Subcontractor flow-down — see below.
- Individual rights support — the vendor must make PHI available for access and amendment requests and provide information for an accounting of disclosures.
- HHS availability — the vendor must make its books and practices available to HHS.
- Return or destruction — at termination, PHI comes back or is destroyed, or the protections survive if neither is feasible. Test this clause mentally against your actual vendor: can they really return your data in usable form?
- Termination rights — you must be able to terminate if the vendor materially breaches the agreement.
Subcontractor chains
A business associate must have a BAA with each of its subcontractors handling PHI. The obligation flows all the way down, and gaps in the chain are the covered entity’s problem too.
In practice this means your billing vendor needs a BAA with its cloud host, and that host needs agreements with anyone it subcontracts storage to. You cannot audit the whole chain, but you can — and should — ask each direct vendor to confirm in writing that its subcontractor agreements are in place. A vendor that cannot answer that question quickly is telling you something about the rest of its programme.
Signing versus verifying
A signed BAA transfers obligations; it does not transfer competence. The mistake we see repeatedly is treating the signature as the end of vendor diligence. A BAA with a vendor that has no security programme is a well-documented liability. Pair every BAA with a proportionate review — a SOC 2 report, a completed security questionnaire, or at minimum a conversation — and record what you reviewed. Our vendor management guide covers how to scale this without a procurement department.
Common gaps
The same handful of failures account for most BAA findings:
- The unsigned draft. Someone sent the agreement, nobody chased the signature, and the vendor has been processing PHI for two years.
- The legacy vendor. Signed before 2013, never updated for the Omnibus Rule requirements, and nobody can find the original anyway.
- The shadow tool. A team adopted a scheduling app or transcription AI on a credit card, PHI followed, and procurement never saw it.
- The expired service. The vendor relationship ended, the data was never returned or destroyed, and the termination clause was never exercised.
- The wrong direction. Health-tech companies acting as business associates often collect BAAs from their customers but forget the ones they owe their own subcontractors.
The audit failure
Ask a compliance team for a signed, current BAA for a random vendor and time how long it takes. If it is more than an hour, you have a finding waiting to happen.
The fix is unglamorous: a BAA register. One list — vendor, service, PHI touched, agreement date, signatory, renewal or review date, and a link to the signed copy. Reviewed quarterly, updated when procurement adds a vendor, and retained for six years like every other HIPAA document. When OCR or an enterprise customer asks, you answer in minutes, and the question moves on. If you need a starting document, the free BAA template includes the required provisions with fill-in guidance, in both covered-entity and subcontractor directions — and the vendor management guide shows where the register sits in the wider vendor programme.
Where SuperHIPAA fits
Everything above is work. The platform does the parts that are mechanical — evidence collection, acknowledgement tracking, register maintenance, renewal reminders — and our team does the parts that need judgement. You keep the parts that need to be yours.
Start where you are
Take the free readiness assessment — 24 questions, about eight minutes, no call required. You get a scored report identifying which required specifications you are missing and what to fix first. If it turns out you are further along than you thought, we will tell you that too.