2026-07-04 · Miky Bayankin
Business Associate Agreement Template: How to Write a HIPAA BAA
A step-by-step guide to drafting a HIPAA business associate agreement, covering the required clauses, breach rules, and when a covered entity needs one.
If your organization handles health information and works with outside vendors, a business associate agreement (BAA) is one contract you cannot skip. It is the document HIPAA requires before a healthcare provider, health plan, or clearinghouse lets a third party touch patient data, and regulators treat a missing one as a violation in its own right.
This guide explains what a BAA is, when you need one, exactly which clauses HIPAA requires, and how to draft an agreement that holds up if a breach or an audit ever forces you to prove your vendors were bound.
What Is a Business Associate Agreement?
A business associate agreement is a contract between a covered entity and a business associate that spells out how the business associate may use and protect protected health information (PHI). HIPAA uses precise definitions here, and getting them right decides whether you even need a BAA:
- A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically. Think hospitals, clinics, dentists, and insurers.
- A business associate is any person or company that creates, receives, maintains, or transmits PHI to perform a function on the covered entity's behalf. Billing firms, EHR vendors, cloud storage providers, IT contractors, and document-shredding services all qualify.
- Protected health information is individually identifiable health data. A patient's name paired with a diagnosis counts, and so does an appointment date linked to a named provider.
The BAA is what makes the vendor legally responsible for that data. Without it, the covered entity has disclosed PHI to an outsider with no enforceable protections, which HIPAA prohibits.
When Do You Need a BAA?
You need a signed BAA before, not after, a vendor gets access to PHI. The common trigger points:
- Outsourcing billing or coding. A medical billing company sees names, procedure codes, and insurance details.
- Using cloud or hosting services. Any provider that stores records containing PHI is a business associate, even if it never opens a file.
- Bringing in IT or managed services. A contractor with admin access to systems that hold PHI needs a BAA. If you formalize that relationship in a broader managed services agreement, the BAA sits alongside it as a required addendum.
- Hiring specialized vendors. Transcription services, e-prescribing tools, answering services, and analytics platforms usually qualify.
- Working with professional advisors. Lawyers, accountants, and consultants who review files containing PHI are business associates too.
There is a subcontractor rule that trips people up. If a business associate hands PHI to its own subcontractor, that subcontractor also needs a BAA, signed with the business associate rather than the covered entity. The chain of agreements has to reach every party that touches the data.
A few relationships are not business associate arrangements. A provider disclosing PHI to another provider for treatment does not need a BAA. Neither does a courier that transports sealed records without accessing them, or a vendor with only incidental, unavoidable exposure to data.
What HIPAA Requires a BAA to Include
The rule at 45 CFR 164.504(e) lists provisions a BAA must contain. This is not a place to improvise. An agreement missing these terms fails to satisfy HIPAA even if both parties act in good faith. A compliant BAA must:
- Describe the permitted and required uses of PHI by the business associate.
- Prohibit any use or disclosure beyond what the contract or the law allows.
- Require appropriate safeguards to prevent unauthorized use or disclosure.
- Require the business associate to report breaches and security incidents to the covered entity.
- Ensure that subcontractors agree to the same restrictions through their own BAAs.
- Give individuals access to their PHI and the ability to request amendments, as HIPAA grants them.
- Make the business associate's practices available to regulators for compliance review.
- Require return or destruction of PHI at the end of the contract, where feasible.
- Authorize the covered entity to terminate the agreement if the business associate materially breaches it.
Because these obligations track the regulation so closely, a BAA reads differently from an ordinary vendor contract. Each requirement below becomes one of the clauses you actually write.
Key Clauses in a BAA
Permitted Uses and Disclosures
State exactly what the business associate may do with PHI and nothing more. Tie every permitted use to the service being provided. If a billing company only needs data to submit claims, say so, and bar any secondary use such as marketing or resale. Vague grants invite trouble, so define the purpose narrowly.
Safeguards
Require the business associate to implement administrative, physical, and technical safeguards consistent with the HIPAA Security Rule. Many covered entities go further and name specific expectations: encryption of data at rest and in transit, access controls, audit logging, and workforce training. The more concrete this clause, the easier it is to hold a vendor accountable later.
Breach and Security Incident Notification
Set a clear timeline. HIPAA's outer limit is 60 days from discovery, but that is far too long for a covered entity that must notify patients within its own 60-day window. Negotiate a shorter reporting period, commonly 5 to 15 days, and require the business associate to include the nature of the breach, the data involved, and the remediation steps taken.
Subcontractor Flow-Down
Require the business associate to bind every subcontractor to protections at least as strict as those in your BAA. This is the clause that keeps the compliance chain intact. Without it, PHI can end up with a fourth party that never agreed to any of it.
Return or Destruction of PHI
Spell out what happens when the relationship ends. The business associate should return or securely destroy all PHI and certify that it has done so. Where return or destruction is not feasible, the BAA's protections must continue to apply to any retained data for as long as it exists.
Term and Termination
Define how long the agreement lasts and give the covered entity the right to terminate for a material breach. Some agreements add a cure period; others allow immediate termination for serious violations. Confidentiality and data-handling duties should survive termination.
Notice how much of this overlaps with a general confidentiality contract. Many vendors sign both a BAA and a broader non-disclosure agreement, with the NDA covering trade secrets and business terms while the BAA governs PHI specifically.
How to Write a BAA: Step-by-Step
Step 1: Confirm the relationship actually requires a BAA. Verify the vendor is a business associate under HIPAA's definition. If they never create, receive, maintain, or transmit PHI, you may not need one, though erring toward an agreement rarely hurts.
Step 2: Identify the parties precisely. Use full legal names and the role of each side. Name the covered entity and the business associate, and reference any underlying service contract the BAA supports.
Step 3: Define PHI and the permitted purpose. Describe the categories of PHI involved and limit use to the specific service. This scoping clause does most of the work of preventing misuse.
Step 4: Insert the HIPAA-required provisions. Work through the list at 45 CFR 164.504(e) and make sure every mandatory term appears. Skipping one is the most common way a BAA fails an audit.
Step 5: Set the breach notification timeline. Pick a window shorter than 60 days and specify what the report must contain.
Step 6: Address subcontractors and termination. Add the flow-down clause and the right to terminate for material breach, plus the return-or-destroy obligation at the end of the term.
Step 7: Sign with authorized representatives. Someone with authority to bind each organization must sign. A dated signature, electronic or otherwise, records when the obligations took effect.
Common Mistakes to Avoid
Signing the vendor's contract without reading it. Large vendors often provide their own BAA drafted to protect themselves. Check that the breach timeline, indemnification, and subcontractor terms actually work for you before signing.
Treating an NDA as a substitute. A confidentiality agreement does not contain the HIPAA-mandated clauses. If a vendor offers only an NDA, you still need a separate BAA.
Forgetting the subcontractor chain. A BAA with your direct vendor does nothing if that vendor's subcontractor handles PHI without its own agreement. Confirm the flow-down clause is present and enforced.
Letting agreements go stale. BAAs signed years ago may predate the current Security Rule expectations or a vendor's new subprocessors. Review them when the relationship or the data flow changes.
Skipping the BAA for "low-risk" vendors. A service that only occasionally sees PHI still needs one. Regulators do not weigh the volume of data when they find a missing agreement.
Who Enforces a BAA and What Non-Compliance Costs
The Office for Civil Rights (OCR) within the U.S. Department of Health and Human Services enforces HIPAA, including the requirement to have BAAs in place. Enforcement usually starts one of two ways: a reported breach that triggers an investigation, or a complaint from a patient or employee.
When OCR investigates, one of the first documents it asks for is the set of BAAs covering the vendors involved. A missing agreement is a finding on its own, separate from any breach. Penalties scale with the level of culpability, from a few hundred dollars per violation for an honest oversight to tens of thousands for willful neglect, and settlements for missing or inadequate BAAs have run well into six and seven figures.
Business associates are directly liable too. Since the 2013 Omnibus Rule, a vendor that mishandles PHI can be penalized by OCR whether or not the covered entity had a compliant agreement in place. That shared exposure is why both sides have a real incentive to get the contract right, not just the covered entity that drafts it.
The practical takeaway: keep a signed BAA on file for every business associate, store them where you can produce them quickly, and treat the agreement as a living record you update when the relationship changes.
Business Associate Agreement vs. Data Processing Agreement
These two contracts are often confused because both govern how a vendor handles sensitive data, but they answer to different laws. A BAA is a HIPAA instrument covering PHI in the United States. A data processing agreement is a GDPR instrument covering personal data of individuals in the EU and UK.
A healthcare vendor serving patients on both sides of the Atlantic may need both. They share a family resemblance, since each names the roles, restricts processing, and requires breach reporting, but the required clauses and the governing authority differ. Signing one does not satisfy the other.
If you want to see how these obligations play out in a real vendor relationship, the deeper compliance mechanics in a medical records service agreement show how a BAA connects to the day-to-day handling of patient data.
Related guides
- Home Health Aide Service Agreement: HIPAA Compliance and Care Scope
- When to Use a HIPAA Authorization Form
- How to Report a HIPAA Violation: A Guide for Medical Records and Insurance Claims
- How to Write a Business Purchase Agreement
- How to Write a Business Partnership Agreement
Generate Your Business Associate Agreement with Contractable
A BAA is one of the few contracts where a missing clause is not a stylistic problem but a compliance failure. Getting the HIPAA-required provisions, the breach timeline, and the subcontractor language right matters more than the wording sounds. Contractable generates a business associate agreement built around your vendor relationship, with the mandatory clauses in place and terms you can adjust to fit your risk. No legal team required.
Ready to create your contract?
Describe your situation in one sentence and we'll generate a custom contract for you instantly.
Generate your contract →Popular templates: NDAIndependent Contractor AgreementService Agreement