Definition

Business Associate Agreement (BAA)

A business associate agreement (BAA) is the contract HIPAA requires between a covered entity and a vendor that handles protected health information on its behalf, setting how the vendor may use, protect and report on that information.

2 min readReviewed September 14, 2026

Also known as: Business associate contract, HIPAA BAA, Subcontractor BAA

Key facts

Required by
HIPAA rules at 45 CFR 164.502(e), 164.504(e) and 164.314(a)
Parties
Covered entity and business associate, or business associate and subcontractor
Direct liability
Business associates directly liable since the 2013 Omnibus Rule
Model language
HHS sample business associate agreement provisions

What is a business associate agreement?

A business associate is a person or organization, other than a workforce member, that performs functions or services for a covered entity involving protected health information (PHI). Common examples include billing companies, claims processors, cloud storage providers, IT and analytics vendors, consultants and law firms with access to PHI.

HIPAA allows a covered entity to share PHI with a business associate only after getting written assurances that the vendor will safeguard it. The BAA is that written assurance. A business associate that uses a subcontractor to handle PHI must sign its own BAA with that subcontractor.

What a BAA must include

The HIPAA Privacy and Security Rules require specific terms, including:

  • Permitted and required uses and disclosures of PHI, which cannot exceed what the covered entity itself could do.
  • Safeguards consistent with the HIPAA Security Rule for electronic PHI.
  • Reporting of uses or disclosures the contract does not allow, security incidents and breaches of unsecured PHI.
  • Flow-down of the same restrictions to subcontractors.
  • Support for individuals' rights to access and amend PHI and to receive an accounting of disclosures.
  • Return or destruction of PHI when the contract ends, where feasible, and termination rights if the vendor violates a material term.

Why BAAs matter

BAAs sit at the center of most health data vendor relationships:

  • Health IT, AI and data vendors: selling to providers or plans that will send PHI usually requires signing a BAA, and cloud and AI service providers often offer HIPAA-eligible services only under one.
  • Compliance: sharing PHI with a vendor without a required BAA can itself violate HIPAA, and HHS OCR has reached settlements over missing agreements.
  • Liability: since the HITECH Act and the 2013 Omnibus Rule, business associates can be penalized directly for Security Rule failures and impermissible uses or disclosures.
  • Scope: not every vendor is a business associate; providers receiving PHI for treatment and mere conduits such as postal services do not need a BAA.

Sources

All glossary terms