What Is a Business Associate Agreement (BAA), and When Does a Healthcare Practice Need One?
This article has been written by Elissa Brewster

What Is a Business Associate Agreement?
A Business Associate Agreement (BAA) is a written contract or other arrangement used when a HIPAA-covered entity works with a business associate that creates, receives, maintains, or transmits protected health information (PHI) on its behalf.
For healthcare practices, BAAs can be an important part of managing relationships with outside companies and service providers that handle PHI.
The U.S. Department of Health and Human Services (HHS) explains that when a covered entity engages a business associate to help perform healthcare activities or functions, the parties generally must have a written business associate contract or other arrangement establishing the business associate's responsibilities for protecting PHI.
But not every vendor relationship automatically requires a BAA.
Understanding who qualifies as a business associate, what information is involved, and what services are being performed is an important part of evaluating whether a BAA is required.
Who Is Considered a Business Associate Under HIPAA?
A business associate is generally a person or organization that performs certain functions or provides certain services for a covered entity that involve PHI.
HHS identifies examples of services that may create business associate relationships, including legal, consulting, management, billing, claims processing, data analysis, and certain administrative services when the applicable requirements are met.
For a healthcare practice, potential business associates might include certain:
- Billing companies
- IT and technology providers
- Cloud service providers
- Practice management vendors
- Consultants
- Legal or professional service providers
- Data processing companies
- Other vendors that create, receive, maintain, or transmit PHI on the practice's behalf
The important question is not simply what the vendor calls itself.
The actual services being performed and the vendor's relationship to PHI matter.
For example, HHS explains that simply selling software to a healthcare provider does not necessarily make the software company a business associate. If the vendor needs access to PHI to provide its services, however, a business associate relationship may arise.
When Does a Healthcare Practice Need a BAA?
A healthcare practice subject to HIPAA generally needs an appropriate written BAA when it engages a business associate to perform applicable functions or services involving PHI on the practice's behalf.
For example, imagine a healthcare practice hires an outside company to host software containing patient information.
If the company creates, receives, maintains, or transmits electronic PHI on behalf of the practice, HHS states that the covered entity must enter into a HIPAA-compliant BAA with the cloud service provider and otherwise comply with the HIPAA Rules.
The same analysis can arise with other vendors.
Before entering into a relationship involving patient information, a healthcare practice should consider:
What service is the vendor providing?
Will the vendor create, receive, maintain, or transmit PHI?
Is it doing so on behalf of the healthcare practice?
Does the relationship meet HIPAA's definition of a business associate?
Is an appropriate BAA already in place?
These questions should be considered as part of vendor contracting and compliance—not after PHI has already been shared.
What Should a Business Associate Agreement Address?
A BAA isn't simply a document stating that both parties will “comply with HIPAA.”
HIPAA requires particular provisions.
According to HHS, a BAA must address matters including the permitted and required uses and disclosures of PHI and restrict the business associate from using or disclosing PHI in ways not permitted by the agreement or required by law.
HHS's guidance on business associate contracts identifies additional required elements, including provisions addressing:
- Permitted and required uses and disclosures of PHI
- Appropriate safeguards
- Reporting certain unauthorized uses, disclosures, and breaches
- Access to PHI where required
- Amendments and accountings where applicable
- Compliance with applicable Privacy Rule obligations undertaken for the covered entity
- Access by HHS to relevant records for compliance purposes
- Return or destruction of PHI at termination when feasible
- Applicable subcontractor obligations
- Termination when a material BAA term is violated
HHS provides sample BAA provisions, but it also cautions that its sample language may need to be adapted to the actual business arrangement and may not, by itself, be sufficient to create a binding contract under state law.
That last point is important.
A BAA should reflect the actual relationship between the parties, not simply exist as a generic form in a compliance folder.
Related Legal Service: Healthcare Compliance & Regulations →
What About Business Associate Subcontractors?
BAA obligations do not necessarily stop with the healthcare practice's direct vendor.
A business associate may engage a subcontractor that also creates, receives, maintains, or transmits PHI on the business associate's behalf.
HHS states that the HIPAA Privacy and Security Rules establish BAA requirements not only between covered entities and business associates but also between business associates and their applicable subcontractors.
This means healthcare organizations should understand not only their immediate vendor relationships but also how PHI may move through the broader service arrangement.
Are All Vendors Business Associates?
No.
This is an important distinction because a BAA should not automatically be used for every outside relationship.
Whether a company or individual is a business associate depends on the function or service being performed and the relationship to PHI.
For example, HHS explains that an app receiving information solely at an individual's direction does not automatically become a business associate. But if the app creates, receives, maintains, or transmits ePHI on behalf of the covered entity, a BAA may be required.
Similarly, certain disclosures between healthcare providers for treatment purposes do not create a business associate relationship simply because PHI is exchanged.
The correct analysis therefore begins with the relationship, not with the assumption that every third party touching healthcare information requires the same contract.
Why Healthcare Practices Should Review Existing BAAs
Healthcare practices shouldn't think about BAAs only when opening a new practice.
Existing agreements may also deserve review when:
- A vendor's services change
- A vendor begins handling PHI in a new way
- New technology is introduced
- A practice changes vendors
- Subcontractors become involved
- The underlying service agreement changes
- The practice expands or restructures
- An agreement no longer reflects the actual business relationship
This is particularly relevant as healthcare practices adopt cloud platforms, digital tools, patient communication systems, and other technology.
HHS's current Security Rule guidance emphasizes evaluating safeguards as the security environment changes, including when new technology is adopted or new risks are recognized.
A BAA Is Part of a Larger Business Relationship
A BAA addresses HIPAA-related responsibilities, but it may exist alongside a broader service agreement, such as a Master Service Agreement.
These documents should not be considered in isolation.
For example, a healthcare practice may have:
A service agreement defining the commercial relationship, services, payment obligations, responsibilities, and other business terms.
and
A BAA addressing the parties' responsibilities concerning PHI and applicable HIPAA requirements.
HHS expressly notes that BAA provisions may be incorporated into a broader services agreement or placed in a separate agreement.
Reviewing the documents together can help identify inconsistencies between the underlying business relationship and the healthcare privacy obligations.
Related Legal Service:
Corporate Contracting & Transactional Law →
Key Takeaways
A Business Associate Agreement is more than a standard form added to a vendor contract.
For healthcare practices, the important questions are:
Does the third party qualify as a business associate?
What PHI will it create, receive, maintain, or transmit?
Does the BAA contain the required provisions?
Does the agreement accurately reflect the actual business relationship?
Are applicable subcontractor relationships addressed?
Do the BAA and underlying service agreement work together?
Reviewing these issues before PHI is shared can help a healthcare practice build stronger contractual and compliance foundations.
Sources & References
HHS — Business Associate Contracts & Sample Provisions
FAQs
Frequently Asked Questions
About Business Associate Agreements
What does BAA stand for?
BAA stands for Business Associate Agreement. It is commonly used to describe the written contract or arrangement required in applicable relationships between HIPAA-covered entities and business associates, and between business associates and applicable subcontractors.
Does every healthcare vendor need a BAA?
No. Whether a BAA is required depends on the vendor's function, the information involved, and whether the vendor qualifies as a business associate under HIPAA.
Does a software company need to sign a BAA?
It depends. HHS explains that merely selling software does not necessarily create a business associate relationship. A vendor that needs access to PHI to provide services may qualify as a business associate.
Does a cloud provider need a BAA?
When a cloud service provider creates, receives, maintains, or transmits ePHI on behalf of a covered entity or business associate, HHS states that a HIPAA-compliant BAA is required.
Can I use a standard BAA template?
HHS provides sample provisions, but it specifically notes that its sample language may be modified to reflect the actual business arrangement and may not alone be sufficient to create a binding contract under state law.
Is a business associate directly responsible for HIPAA compliance?
Business associates are directly liable for compliance with certain provisions of the HIPAA Rules, including specified Security Rule, breach-notification, and PHI-use requirements.
Still have a question?
Need Help With a Business Associate Agreement?
Brewster Law Firm drafts and reviews Business Associate Agreements for healthcare organizations and businesses navigating healthcare privacy, compliance, and contractual relationships.
Whether you're establishing a new vendor relationship, reviewing an agreement you've been asked to sign, or evaluating an existing BAA, Brewster Law Firm can help you understand the legal considerations involved.
Share this article


