Business Associate Agreement (BAA)
The contract HIPAA requires before a vendor can handle a healthcare organization's patient data.
What Is a Business Associate Agreement (BAA)?
A Business Associate Agreement (BAA) is a written contract required under HIPAA between a covered entity, such as a medical practice, and any vendor that will create, receive, maintain, or transmit protected health information on its behalf. The BAA legally binds the vendor to safeguard that data, and it must be signed before any patient information is shared.
How It Works
Under HIPAA, you cannot share protected health information with an outside vendor until a BAA is in place. The agreement makes that vendor, known as a business associate, legally responsible for protecting the data to the same standards the covered entity must meet.
A compliant BAA must include specific provisions defined at 45 CFR 164.504(e). These require the vendor to use PHI only for permitted purposes, safeguard the data, report any breach without unreasonable delay, ensure that any subcontractors agree to the same restrictions, support patient rights, make records available to HHS, and return or destroy the PHI when the contract ends.
Critically, the timing matters: the BAA must be signed before any PHI is shared, not afterward. A contract missing any of the required provisions is not fully compliant, even if both parties signed it, which is why a generic template off the internet can leave you exposed.
Why It Matters
Sharing patient data with a vendor without a signed BAA is a direct HIPAA violation, and it is one of the most common findings in OCR enforcement actions. You can face penalties even if no breach occurs, simply for the missing agreement. Beyond compliance, the BAA is what extends your data protection obligations to every vendor who touches your patients’ information, closing a gap that attackers and auditors both look for.
Related Terms
For a complete guide, read our full article on the business associate agreement explained for medical practice owners.
SecTec helps healthcare organizations manage BAAs and vendor compliance as part of our HIPAA compliance service.
Years Protecting Businesses
BAA Coverage on Healthcare Engagements