What Is a Business Associate Agreement (BAA)?

What Is a Business Associate Agreement (BAA), and Do You Need One?

A Business Associate Agreement (BAA) is the HIPAA-required contract between a healthcare provider and any vendor that handles its patient data. If a vendor can create, receive, store or transmit your PHI, you almost certainly need one with them.

BAA is one of those terms that comes up constantly in healthcare IT conversations and rarely gets explained. The idea is simple, but skipping it or using a weak template can cause real trouble. Here's what a BAA is, who needs one, what it must contain and what happens without one.

What a BAA is

A BAA is a written contract required under HIPAA between a covered entity (a healthcare provider, health plan or healthcare clearinghouse) and a business associate: an outside vendor or service provider that creates, receives, maintains or transmits protected health information (PHI) on the covered entity's behalf.

The agreement commits the business associate to use PHI only as permitted, protect it with appropriate safeguards, report breaches and security incidents, and follow the HIPAA Security Rule where it applies. It's both a compliance requirement and a way of spelling out who is responsible for what if something goes wrong.

Who counts as a business associate

Many practices underestimate this list. Beyond your EHR vendor, business associates include any outside party that handles PHI while providing services to you, for example:

  • Your IT provider, if it has access to systems that store or process PHI (managed IT firms, cloud providers and remote support vendors)
  • Medical billing, coding and revenue cycle management companies
  • Transcription services
  • Answering services that handle patient calls
  • Shredding companies that destroy records containing PHI
  • Cloud storage and backup providers that hold PHI
  • Email encryption and secure messaging vendors
  • Hosted practice management and EHR software vendors
  • Attorneys and accountants who access PHI in the course of their work

There's a narrow exception for "mere conduits," such as an internet service provider or the postal service, that only transport data and don't store or access it beyond what transmission requires. A cloud service that stores PHI doesn't qualify, even if it never looks at the data.

What a BAA must contain

HIPAA lists the required elements. A compliant BAA must:

  • Describe the permitted and required uses and disclosures of PHI by the business associate
  • Prohibit uses or disclosures beyond what the contract or the law allows
  • Require appropriate safeguards, including compliance with the applicable parts of the Security Rule
  • Require reporting of breaches of unsecured PHI and other security incidents to the covered entity
  • Require the business associate to have its own BAAs with any subcontractors that handle the PHI, with the same restrictions
  • Make PHI available for patients' access and amendment requests where applicable
  • Make the business associate's records available to HHS to determine compliance
  • Address what happens to PHI when the relationship ends (return, destruction or continued protection)
  • Allow the covered entity to terminate the agreement if the business associate violates a material term

A signed BAA missing required elements doesn't satisfy the requirement. Vendor templates vary widely in quality, so have your compliance counsel review the ones you rely on.

What happens without one

Sharing PHI with a business associate without a required BAA is a HIPAA violation on its own, whether or not a breach ever happens. HHS's Office for Civil Rights has brought enforcement actions specifically over missing BAAs. Penalties are tiered and adjusted for inflation each year.

If a breach does happen at a vendor you never signed a BAA with, your position is much weaker. The BAA is part of how you show you took reasonable steps to protect patient data.

How NerdSquad helps

Because we support systems that hold PHI, NerdSquad signs a BAA with healthcare clients. We also help practices keep a BAA inventory: a list of every vendor that handles PHI, with agreement status and review dates. When you add a new technology vendor, we help you work out whether it touches PHI so you know to get a BAA in place before it goes live. Your compliance counsel decides whether an agreement's terms are sufficient; we make sure the technology side is accounted for.

A current inventory is one of the first things an OCR investigator or HIPAA auditor may ask for, and it's much easier to keep up to date than to rebuild under pressure. See HIPAA compliance support in Naples, Do you help us stay HIPAA compliant? and What makes your IT support different for medical and dental practices?

NerdSquad is not a law firm; confirm your obligations with your compliance counsel.


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT support for medical and dental practices