HIPAA & privacy

What is a business associate agreement (BAA)?

A business associate agreement (BAA) is a contract required by HIPAA between a covered entity (or a business associate) and a vendor that will create, receive, maintain, or transmit protected health information (PHI) on its behalf. It sets out how the business associate will safeguard PHI and its breach-notification duties. You must have a signed BAA in place before sharing PHI with that vendor.

What a BAA covers

A BAA spells out the permitted uses of PHI, the safeguards the business associate must apply, its breach-notification obligations, the flow-down of terms to any subcontractors, and what happens to the PHI when the relationship ends (return or destruction).

Who needs one

A covered entity needs a BAA with each business associate that handles PHI on its behalf, and a business associate needs one with each of its subcontractors that do the same. The obligation flows down the chain.

Sign it before sharing PHI

The single most common mistake is sharing PHI with a vendor before a BAA is signed. If a vendor will store, process, or transmit PHI for you, get the BAA in place first.

FAQ

Is a BAA legally required?

Yes. HIPAA requires a signed BAA before a covered entity or business associate shares PHI with a business associate that will handle it on their behalf.

Does a cloud provider need a BAA?

If it stores, processes, or transmits PHI on your behalf, yes, even if it never actually accesses the data. Major cloud providers offer a BAA for their in-scope services.

Related

What is HIPAA? → Does my startup need to be HIPAA compliant? → HIPAA in Keel →

Get audit-ready with Keel

The AI-native GRC platform for SMBs: one control-and-evidence graph across SOC 2, ISO 27001, HIPAA, PCI DSS, NIST CSF, and more. Start free, no credit card.

Start free