What Is a Business Associate Agreement? The Complete HIPAA BAA Guide
Last Updated: September 8, 2026
Disclosure: This article contains no affiliate links. It is independent editorial content based on publicly available guidance from the U.S. Department of Health and Human Services and HIPAA regulations.
If you work with healthcare organizations or provide technology, billing, consulting, storage, or other services involving protected health information, you may have heard the term business associate agreement or BAA.
So, what is a business associate agreement?
A business associate agreement is a written contract or other arrangement required by HIPAA between a covered entity and a business associate, or between a business associate and its business associate subcontractor. The agreement establishes permitted uses and disclosures of protected health information (PHI), requires appropriate safeguards, and sets out other responsibilities required by HIPAA.
For example, a doctor’s office might use an outside medical billing company. If that company performs services involving the doctor’s patients’ PHI on behalf of the practice, the relationship may require a BAA.
A business associate agreement is more than a privacy promise. It is part of the legal and compliance framework governing how PHI is handled between organizations.
The U.S. Department of Health and Human Services explains that covered entities generally need a written contract or other arrangement with a business associate that establishes what the business associate has been engaged to do and requires appropriate protections for PHI. HHS guidance on Covered Entities and Business Associates
In this guide, you will learn:
- What a business associate agreement is
- Why HIPAA requires BAAs
- Who is considered a business associate
- When a BAA is required
- What HIPAA requires a BAA to contain
- How business associates handle PHI and breaches
- Examples of common business associate relationships
- Common BAA mistakes
- BAA templates and agreements
- Questions businesses frequently ask about BAAs
Table of Contents
- What Is a Business Associate Agreement?
- Why Does a Business Associate Agreement Matter?
- Who Is a Business Associate Under HIPAA?
- When Is a BAA Required?
- How a Business Associate Agreement Works
- HIPAA BAA Requirements: What Must Be Included?
- Business Associate Agreement Examples
- What Is a BAA in Business Outside Healthcare?
- Common Business Associate Agreement Mistakes
- BAA Templates and Agreements
- Frequently Asked Questions
- Conclusion
What Is a Business Associate Agreement?
A business associate agreement is a written contract or other arrangement that establishes the responsibilities of a business associate when the business associate handles protected health information for a HIPAA covered entity.
HHS explains that business associates are generally organizations or individuals that perform certain functions or provide certain services for a covered entity involving PHI. Examples include claims processing, billing, data analysis, legal services, accounting, consulting, and certain technology services. HHS Business Associates guidance
Examples can include:
- Medical billing
- Claims processing
- Data analysis
- Legal services
- Accounting
- Consulting
- IT services
- Cloud or data storage
- Medical record storage
- Certain administrative services
What Is a Business Associate Agreement in Plain English?
Think of a business associate agreement as a formal agreement that answers several important questions:
- What PHI can the business associate use?
- What can the business associate disclose?
- What safeguards must it use?
- What happens if there is a security incident or breach?
- What must happen to PHI when the relationship ends?
- What responsibilities apply to subcontractors?
The agreement creates a documented framework for handling PHI between the covered entity and business associate.
However, a BAA does not replace the organization’s broader HIPAA compliance responsibilities.
A company may need appropriate security controls, policies, workforce training, risk management, incident response procedures, and other safeguards in addition to having a signed business associate agreement.
Why Does a Business Associate Agreement Matter?
A business associate agreement matters because healthcare organizations frequently rely on outside companies to perform important functions.
A medical practice may not process its own insurance claims.
A hospital may not operate its own data center.
A healthcare company may use outside IT specialists.
A health plan may rely on another organization for administrative services.
When those relationships involve PHI, HIPAA establishes requirements for protecting that information.
HHS states that business associates can be directly liable for certain HIPAA requirements. HHS guidance on the direct liability of business associates
A BAA Is a Compliance Requirement
For relationships that meet the HIPAA definition of a business associate, the covered entity generally needs a written business associate contract or other arrangement meeting HIPAA requirements.
This means a company should not wait until after a security incident to determine whether a BAA was necessary.
The relationship should be evaluated before PHI is shared or made available for the business associate’s services.
A BAA Helps Define Vendor Responsibilities
A good business associate agreement makes responsibilities clearer.
For example, it can establish how a vendor must:
- Use PHI
- Protect PHI
- Report unauthorized uses or disclosures
- Report breaches
- Assist with certain HIPAA obligations
- Handle subcontractors
- Return or destroy PHI when appropriate
HHS explains that HIPAA establishes specific requirements for BAAs between covered entities and business associates and between business associates and their subcontractors. HHS Business Associate Agreement requirements
Who Is a Business Associate Under HIPAA?
A business associate is generally a person or organization, other than a member of the covered entity’s workforce, that performs certain functions or provides certain services for a covered entity involving PHI.
The official HHS guidance explains that a business associate can perform functions involving the creation, receipt, maintenance, or transmission of PHI on behalf of a covered entity. HHS Business Associates definition
Medical Billing Companies
A billing company that handles patient information while submitting claims or performing billing services may be a business associate.
IT and Technology Providers
An IT company that provides services involving access to PHI may qualify as a business associate.
Cloud and Data Storage Providers
A company that maintains PHI on behalf of a covered entity may be a business associate.
Accounting and Legal Services
Outside professionals may qualify when their services involve PHI in a way that meets the business associate definition.
Medical Record Storage Companies
Organizations that store or maintain medical records for covered entities may also qualify.
HHS specifically identifies billing companies, outside lawyers and accountants, IT specialists, and companies that store or destroy medical records as examples of business associates. HHS examples of business associates
When Is a BAA Required?
A business associate agreement is generally required when a covered entity engages a business associate to perform functions or provide services involving PHI.
The important question is not simply:
“Is this company outside our organization?”
The better question is:
“Does this organization meet HIPAA’s definition of a business associate based on the services it provides and how PHI is handled?”
Not Every Vendor Needs a BAA
This is an important distinction.
A healthcare organization may work with many vendors that never become business associates.
For example, a vendor that provides a service completely unrelated to PHI and does not handle PHI on behalf of the covered entity may not require a BAA.
HHS also identifies situations where a business associate contract is not required, including certain organizations whose functions do not involve the use or disclosure of PHI and where access to PHI would be incidental, if any. HHS Business Associate FAQs
There are also specific HIPAA exceptions.
For example, disclosures of PHI to another healthcare provider for treatment purposes do not automatically create a business associate relationship.
Another example involves certain applications that allow individuals to access or transmit their own electronic health information at the individual’s direction. The specific circumstances matter.
This is why organizations should evaluate the actual relationship rather than using a blanket rule that every vendor connected to healthcare requires a business associate agreement.
How a Business Associate Agreement Works
A typical business associate agreement process can be organized into several steps.
Step 1: Identify the Vendor
Start by listing outside organizations that receive, maintain, create, or transmit PHI on behalf of the covered entity.
Examples might include:
- Billing companies
- Cloud providers
- IT companies
- Data processing vendors
- Record storage companies
- Certain consultants
Step 2: Determine Whether the Vendor Is a Business Associate
Review what the vendor actually does.
Ask:
- Does the vendor handle PHI?
- Is the vendor performing services on behalf of the covered entity?
- Does the relationship fall within HIPAA’s business associate definition?
- Does an exception apply?
Step 3: Establish the BAA
If the vendor is a business associate, the covered entity and business associate should establish the required written agreement or other arrangement.
The agreement should accurately reflect the services being provided and the applicable HIPAA requirements.
Step 4: Review the Permitted Uses and Disclosures
The agreement should clearly explain how the business associate may use or disclose PHI.
The business associate generally cannot use or disclose PHI beyond what is permitted by the agreement or required by law.
Step 5: Establish Security Responsibilities
The agreement should address appropriate safeguards for PHI.
For electronic PHI, business associates are subject to applicable HIPAA Security Rule requirements. HHS explains that the Security Rule applies to business associates as well as covered entities. HHS HIPAA Security Rule guidance
Step 6: Address Breach and Security Incident Reporting
The business associate agreement should establish the business associate’s reporting responsibilities.
HIPAA requires a business associate to notify the covered entity following discovery of a breach of unsecured PHI. The notice must be provided without unreasonable delay and no later than 60 calendar days after discovery.
A contract can also establish a shorter contractual reporting deadline.
Step 7: Address the End of the Relationship
The agreement should address what happens to PHI when the relationship ends.
Depending on the circumstances and the agreement, PHI generally must be returned or destroyed when feasible, with continued protections where required.
HHS’s guidance explains that BAA provisions address the return or destruction of PHI when the business relationship ends. HHS Business Associate Agreement guidance
HIPAA BAA Requirements: What Must Be Included?
HIPAA establishes specific requirements for a business associate agreement.
The HHS guidance identifies several important elements.
1. Permitted Uses and Disclosures
The BAA should describe the permitted and required uses and disclosures of PHI.
It should also restrict the business associate from using or disclosing PHI in ways that are not permitted by the agreement or required by law.
2. Appropriate Safeguards
The business associate must agree to use appropriate safeguards.
For electronic PHI, this includes complying with applicable requirements of the HIPAA Security Rule.
3. Reporting Unauthorized Uses and Disclosures
The business associate must report unauthorized uses or disclosures of PHI of which it becomes aware.
The agreement should also address applicable breach and security incident reporting responsibilities.
4. Assistance With Certain Individual Rights
The agreement must address the business associate’s responsibilities when it maintains PHI needed by the covered entity to fulfill certain HIPAA obligations.
This can include helping the covered entity respond to requests involving access to PHI and other applicable individual rights.
5. Assistance With HIPAA Compliance
Where the business associate is performing functions on behalf of the covered entity, the agreement should address applicable responsibilities that the business associate must carry out.
6. Subcontractor Requirements
If a business associate uses subcontractors that handle PHI, applicable HIPAA requirements must flow down to those subcontractors.
HHS states that business associates must have appropriate arrangements with their business associate subcontractors before disclosing PHI to them. HHS guidance on business associate subcontractors
7. Return or Destruction of PHI
The agreement should address the return or destruction of PHI when the relationship ends, where feasible.
HHS’s model provisions specifically address these requirements.
8. Termination for Violations
The agreement should address appropriate termination provisions when a business associate violates a material term of the agreement.
The exact contractual language should reflect the relationship and applicable law.
Business Associate Agreement Examples
A business associate agreement in healthcare can apply to many different types of relationships.
Here are common examples.
Example 1: Medical Billing Company
A medical practice hires a billing company to process insurance claims.
The billing company handles patient information while performing billing services.
Because the company is performing services involving PHI on behalf of the practice, the relationship may require a BAA.
Example 2: Cloud Storage Provider
A healthcare organization stores electronic patient records using an outside cloud service.
If the provider maintains PHI on behalf of the healthcare organization, the provider may be a business associate.
The parties should evaluate the relationship and applicable HIPAA requirements before PHI is placed into the service.
Example 3: IT Support Company
A healthcare practice hires an outside IT company to maintain its computer systems.
If the IT company’s work involves access to PHI or systems containing PHI, the relationship may create business associate obligations.
Example 4: Medical Record Storage
A company stores physical or electronic medical records for a healthcare organization.
HHS identifies companies that store or destroy medical records as examples of business associates. HHS Business Associates guidance
Example 5: Healthcare Data Services
A company performs data analysis or other services involving PHI for a covered entity.
Depending on the specific arrangement, the organization may qualify as a business associate.
The key is the actual function being performed and the relationship to the covered entity.
What Is a BAA in Business Outside Healthcare?
You may also wonder, what is a BAA in business if your company is not a hospital, doctor’s office, or health insurer?
A business does not automatically become subject to HIPAA simply because it works with a healthcare company.
However, a company can become a business associate when it meets the HIPAA definition by performing covered functions or services involving PHI on behalf of a covered entity or another business associate.
For example, a technology company may provide software that handles patient information for a healthcare provider.
A marketing company might also encounter PHI in certain arrangements.
An IT company may maintain systems containing PHI.
In each situation, the parties should evaluate the actual relationship rather than assuming that the presence of a healthcare customer automatically creates a BAA requirement.
For a broader look at how professional service providers help businesses solve operational problems, you can also read our guide on what a business consultant does.
Common Business Associate Agreement Mistakes
Mistake 1: Assuming an NDA Replaces a BAA
A general non-disclosure agreement is not automatically a substitute for a HIPAA business associate agreement.
A BAA addresses specific HIPAA responsibilities involving PHI.
Mistake 2: Signing the Agreement Without Reviewing the Relationship
A signed document does not automatically make a relationship compliant.
The actual services, data flows, safeguards, subcontractors, and responsibilities should match what the agreement says.
Mistake 3: Using an Outdated Template
HIPAA requirements have evolved over time.
Organizations should use current guidance and appropriate contract language rather than relying on an old template found online.
HHS provides guidance and sample business associate contract provisions that can serve as a useful reference. HHS Business Associate contract guidance
Mistake 4: Ignoring Subcontractors
A business associate may use another organization to perform part of its services.
If the subcontractor handles PHI and meets the applicable definition, the required HIPAA obligations must flow down through the relationship.
Mistake 5: Waiting Until After a Breach
A BAA should not be treated as paperwork to complete after something goes wrong.
The relationship should be evaluated and documented before PHI is handled under the arrangement.
Mistake 6: Assuming a BAA Alone Creates Compliance
A BAA is important, but it is not a complete HIPAA compliance program.
Organizations may also need:
- Risk analysis
- Security policies
- Access controls
- Workforce training
- Incident response
- Data safeguards
- Vendor management
- Documentation
Mistake 7: Using Arbitrary Breach Deadlines
HIPAA establishes a maximum federal deadline for a business associate to notify the covered entity of a breach of unsecured PHI, but the parties may agree contractually to a shorter reporting period.
The agreement should clearly establish the reporting process and responsibilities.
BAA Templates and Agreements
Organizations often look for a business associate agreement template when they first encounter HIPAA requirements.
The safest starting point is to understand the requirements rather than simply downloading the first template you find.
HHS publishes guidance and sample business associate agreement provisions that cover many of the required elements. HHS Business Associate contract provisions
A template can be useful for understanding the basic structure, but it may not address every detail of a particular vendor relationship.
For example, a simple vendor relationship may have different contractual needs from a technology provider that hosts a large volume of electronic PHI.
Before using a template, review:
- The services being provided
- The types of PHI involved
- How PHI is accessed
- Where PHI is stored
- Subcontractor relationships
- Security responsibilities
- Breach notification procedures
- Return or destruction of PHI
- Termination provisions
For complicated or high-risk arrangements, obtaining advice from qualified healthcare counsel may be appropriate.
Frequently Asked Questions
What is a business associate agreement under HIPAA?
A business associate agreement is a written contract or other arrangement that establishes the permitted uses and disclosures of PHI and other HIPAA responsibilities between a covered entity and a business associate, or between a business associate and its subcontractor.
What is the purpose of a business associate agreement?
The purpose of a BAA is to establish how a business associate may handle PHI and what responsibilities it has for protecting that information and supporting applicable HIPAA obligations.
Who needs a business associate agreement?
A covered entity generally needs a compliant written business associate agreement or other required arrangement when it engages a business associate to perform functions or services involving PHI.
Business associates also generally need appropriate agreements with their business associate subcontractors.
Does every healthcare vendor need a BAA?
No. Not every healthcare vendor is a business associate.
The determination depends on the services provided, the handling of PHI, the relationship between the parties, and applicable HIPAA exceptions.
HHS explains that organizations whose functions do not involve the use or disclosure of PHI generally do not require a business associate contract merely because they may have incidental access. HHS Business Associate FAQ guidance
Does a business associate need a BAA with a subcontractor?
When a business associate engages a subcontractor that will handle PHI on its behalf, HIPAA requires applicable restrictions and conditions to flow down to the subcontractor through a written arrangement.
How quickly must a business associate report a breach?
Under HIPAA’s Breach Notification Rule, a business associate must notify the covered entity of a breach of unsecured PHI without unreasonable delay and no later than 60 calendar days after discovery of the breach.
The parties may agree contractually to a shorter reporting period.
Is an NDA the same as a business associate agreement?
No. An NDA generally addresses confidentiality, while a BAA addresses specific HIPAA responsibilities involving PHI. An NDA by itself should not be assumed to satisfy HIPAA’s business associate requirements.
Can a business associate use a subcontractor?
Yes, but when the subcontractor handles PHI on behalf of the business associate, applicable HIPAA obligations must flow down to that subcontractor through the required written arrangement.
Does signing a BAA make a company HIPAA compliant?
No. A BAA is only one part of HIPAA compliance.
The organizations involved may also need appropriate administrative, physical, and technical safeguards, policies, procedures, training, risk management, and other controls.
Can a BAA be terminated?
A BAA can include termination provisions, including provisions addressing material violations.
The agreement should also address what happens to PHI when the relationship ends, including applicable return or destruction requirements.
Conclusion
So, what is a business associate agreement?
A business associate agreement is a critical HIPAA contract or arrangement that establishes how a business associate may handle protected health information and what responsibilities apply to the relationship.
BAAs are especially important for healthcare organizations that depend on outside companies for services such as billing, IT, cloud storage, data processing, record storage, and other functions involving PHI.
Before signing or creating a business associate agreement, make sure you understand:
- Whether the vendor actually qualifies as a business associate
- What PHI the vendor will handle
- What uses and disclosures are permitted
- What safeguards are required
- How breaches must be reported
- How subcontractors are handled
- What happens to PHI when the relationship ends
A BAA is important, but it should be viewed as one component of a broader HIPAA compliance program rather than a complete solution by itself.
If you are also researching business services and professional support, you may find our guide on what a business consultant does useful.
You can also read our guide on why businesses need a professional website if you are building or improving an online business presence.
Next Steps
- Review your current vendors and identify relationships involving PHI.
- Determine which vendors meet the HIPAA business associate definition.
- Review existing BAAs against current HHS requirements.
- Confirm that applicable subcontractor relationships are covered.
- Establish a process for reviewing vendor agreements when services or data handling change.
Important: This article provides general educational information about HIPAA and business associate agreements. It is not legal or compliance advice. For a specific vendor relationship or high-risk healthcare arrangement, consult qualified healthcare privacy or legal counsel.
Sources and Further Reading
For the most authoritative information, start with the U.S. Department of Health and Human Services:
- HHS: Business Associates
- HHS: Covered Entities and Business Associates
- HHS: Summary of the HIPAA Privacy Rule
- HHS: HIPAA Security Rule
- HHS: Direct Liability of Business Associates
- HHS: Business Associate FAQs
Author Note
This article was prepared as educational content based on publicly available HIPAA guidance and regulations. It is intended to explain the concept of business associate agreements in plain language and should not be treated as a substitute for professional legal or compliance advice.
MOST COMMENTED
Uncategorized
What Does a Business Consultant Do?- Best 2026 Guide
Uncategorized
What Does a Business Consultant Do? Best 2026 Guide
Uncategorized
Why Businesses Need a Professional Website?- Best 2026 Guide
Uncategorized
How to Invest in a Small Business? -Best 2026 Guide
Uncategorized
What Is Business Attire? The Best Guide (2026)
Uncategorized
How to Start a Construction Business in 2026: Complete Guide
Uncategorized
How to Succeed in Business: The Complete 2026 Guide