hipaa.systems
Privacy Rule · 45 CFR 164.502(e), 164.504(e), 164.308(b)

Business associate agreements (BAAs)

A vendor that creates, receives, maintains or transmits PHI on your behalf is generally a business associate, and you need a signed BAA with it before it touches patient data. No BAA means you should not put PHI in that tool.

Checked 2026-10-05Sources 4

Business associate agreements (BAAs) at a glance

A business associate agreement (BAA) is the written contract HIPAA requires before a vendor creates, receives, maintains or transmits protected health information on behalf of a covered entity. It must set permitted uses of PHI, require safeguards under the Security Rule, require breach reporting, and bind the vendor's subcontractors to the same terms. Without a signed BAA, PHI should not be put into that vendor's service.

Rules45 CFR 164.502(e), 164.504(e), 164.308(b)
Who signsCovered entity and each vendor that handles PHI on its behalf
Must includePermitted uses, safeguards, breach reporting, subcontractor terms, return or destruction of PHI
Common catchBAAs are often limited to specific plans or services
TemplateHHS publishes free sample BAA provisions; most large vendors use their own standard BAA

A business associate is a person or company that handles protected health information on behalf of a covered entity — an email provider, a cloud storage service, a billing company, an IT contractor with access to your systems. Before PHI goes to them, the Privacy and Security Rules require “satisfactory assurances”, in practice a written business associate agreement (164.308(b), 164.502(e)).

Not every recipient of PHI is a business associate

The test is whether the vendor acts on your behalf with PHI. Some relationships fall outside it — for example, a provider receiving PHI for treatment, or a mere conduit such as the postal service or an internet service provider that only transmits data and stores it only temporarily as part of transmission. The conduit exception is narrow: a cloud or email service that maintains PHI is a business associate even if it never looks at the data.

What a BAA has to say

Under 164.504(e)(2), the contract must, among other things:

  • set out the permitted and required uses and disclosures of PHI by the vendor;
  • require the vendor not to use or disclose PHI beyond the contract or the law;
  • require appropriate safeguards, including compliance with the Security Rule for electronic PHI;
  • require the vendor to report unauthorized uses or disclosures, including breaches of unsecured PHI;
  • require the vendor’s own subcontractors that handle PHI to agree to the same restrictions;
  • address return or destruction of PHI when the contract ends.

What this means when choosing tools

  • “HIPAA compliant” on a website is not a BAA. What matters is whether the vendor will sign one, on which plan, and what it covers.
  • BAAs are often plan-specific. Many vendors offer a BAA only on business or enterprise tiers, or as an add-on.
  • BAAs often exclude parts of the product. Add-ons, integrations or consumer features may sit outside the agreement — check the list of covered services.
  • Configuration is on you. A BAA usually assumes you enable the vendor’s security settings; it does not make a misconfigured account safe.
  • Keep the signed copy and note it in your vendor inventory and risk analysis.

A vendor that will not sign a BAA can still be used for work that never involves PHI — but then make sure PHI genuinely never goes there.

Using a BAA template

HHS publishes sample business associate agreement provisions that cover the clauses HIPAA requires. They are useful as a checklist, but they are not a complete contract: they leave out commercial terms such as liability caps, indemnification, breach-cost allocation and termination.

In practice:

  • Large vendors (cloud, email, EHR) sign only their own standard BAA — review it against 164.504(e) rather than sending yours.
  • Smaller vendors and contractors often accept your template — make sure it includes every required clause and fits the services they provide.
  • If you are the vendor (a business associate), you’ll need your own BAA to offer customers and BAAs with your own subcontractors that handle PHI.

Have a healthcare attorney review any template before you rely on it.

Tools and services where this matters

Guides

Scenarios

Frequently asked questions

Is there an official BAA template?

HHS publishes sample business associate agreement provisions you can adapt. They are a starting point, not a complete contract — they cover the clauses HIPAA requires, not commercial terms such as liability or termination fees.

Should I use my BAA template or the vendor's?

Large vendors usually only sign their own standard BAA. Smaller vendors and contractors often accept yours. Either way, check it covers the elements in 45 CFR 164.504(e) and the services you actually use.

Is a website saying "HIPAA compliant" enough?

No. What matters is whether the vendor signs a BAA, on which plan, and which of its services the BAA covers.

Do I need a BAA with my email provider?

Yes, if the mailbox will hold or transmit patient information. Most major providers offer a BAA, often only on business plans or after you accept it in the admin console.