HIPAA Business Associate Agreement (BAA): What to Include and Why

A Business Associate Agreement is the contract that lets protected health information cross an organizational boundary without breaking HIPAA. The distinct thing to understand about a BAA is that it is not paperwork you sign and file — it is a liability allocation document with legal force. Under the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for HIPAA compliance, and the BAA is where each party’s obligations, breach duties, and termination rights are spelled out. A missing or boilerplate BAA is one of the most common findings in Office for Civil Rights enforcement actions.

When a BAA is required

A BAA is required whenever a covered entity discloses PHI to a vendor that creates, receives, maintains, or transmits that PHI to perform a function on its behalf — billing companies, cloud hosting providers, IT managed-service firms, transcription services, analytics platforms, and email providers among them. It is also required downstream: a business associate that hands PHI to a subcontractor must have its own BAA with that subcontractor. The frequent myth is the “conduit exception,” which is genuinely narrow — it covers entities like the postal service or an internet backbone that only transport data, not vendors that store or have persistent access to it. If a vendor can reach your PHI, assume a BAA is needed.

What every BAA must include

The required elements come straight from 45 CFR § 164.504(e). A compliant BAA must: establish the permitted and required uses and disclosures of PHI; prohibit uses beyond what the contract or law allows; require appropriate safeguards, including Security Rule compliance for electronic PHI; obligate the business associate to report security incidents and breaches; require that subcontractors agree to the same restrictions through their own BAAs; provide for access, amendment, and accounting of disclosures so the covered entity can meet individual rights; require return or destruction of PHI at termination where feasible; and authorize termination if the business associate materially violates the agreement. Vague language — “the vendor will keep data secure” — does not satisfy these specifics. Each obligation should be explicit and enforceable.

A signed BAA is the floor, not the ceiling

The most important practical point is that a BAA on file does not make a vendor safe — it makes them accountable. The contract is a promise; the safeguards are what actually protect PHI. Real third-party breaches happen at vendors that signed a perfectly good BAA and then misconfigured a server or reused a password. That is why your Security Risk Analysis must reach the vendors you depend on. The Security Rule requires “an accurate and thorough assessment of the potential risks and vulnerabilities” to electronic PHI — 45 CFR § 164.308(a)(1)(ii)(A) — and that analysis should account for the access your business associates hold and the data you have entrusted to them. Pair every BAA with vendor due diligence, not as a substitute for it. Our guide to HIPAA and IT vendors covers how to evaluate the partners with the deepest access to your systems.

The proposed 2026 Security Rule update

Vendor oversight is poised to get stricter. The Notice of Proposed Rulemaking (NPRM) the Office for Civil Rights published in December 2024 would, among other changes, require business associates to provide written verification — backed by a subject-matter expert’s analysis — that they have deployed the required technical safeguards, on a recurring basis. The proposal is not final; if adopted, regulated parties would generally have 240 days from publication of the final rule to comply. In practice, that means the casual BAA-and-trust model is on its way out, and documented proof of a vendor’s controls is becoming the expectation.

How Medcurity helps

Medcurity helps covered entities and business associates keep their agreements and vendor risk organized — tracking which partners have signed BAAs, where PHI flows, and how each vendor maps to your Security Risk Analysis and remediation plan. Pricing is $499/year (about $42/month); larger organizations with extensive vendor networks can request a quote for a tailored engagement. The goal is simple: make sure every BAA you sign is matched by evidence the vendor is actually doing what they promised.

Frequently asked questions

Who is responsible if a business associate causes a breach?

Since the HITECH Act and the 2013 Omnibus Rule, business associates are directly liable for their own HIPAA violations and can be penalized by the Office for Civil Rights. The covered entity may also bear responsibility depending on the facts, which is why the BAA’s breach-notification and indemnification terms matter.

Does a BAA need to be signed before sharing PHI?

Yes. The BAA must be in place before any PHI is disclosed to the business associate. Sharing data first and papering the agreement later is itself a HIPAA violation, even if no breach occurs.

Is a vendor’s standard BAA good enough to sign as-is?

Often, but not always. Confirm it contains every element required by 45 CFR § 164.504(e), defines breach-notification timelines you can live with, and addresses subcontractors. A template missing required terms leaves you exposed regardless of who drafted it.

Do I need a BAA with another covered entity?

Generally not when PHI is exchanged for treatment, payment, or shared health care operations between covered entities. A BAA is required when one party performs a service on the other’s behalf that involves PHI, which makes it a business associate rather than a peer covered entity.