HIPAA BinderGet my forms

45 CFR § 164.504(e)

Uses and disclosures: Organizational requirements

The section that says what a Business Associate Agreement must actually contain.

Read the full official text on eCFR

Researched and written by Larry Osakwe · Last verified August 4, 2026

Checked against 45 CFR 164.504(e) via eCFR. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.

How we research thisReport an error

What 164.504(e) actually says

45 CFR 164.502(e) is the rule that says you need a Business Associate Agreement. 164.504(e) is the rule that says what has to be in it. That distinction is why people land here: they have a vendor's BAA in hand and want to know whether it is sufficient.

The section is a list of required contract terms. It also imposes an ongoing duty that surprises people: if you know a business associate is materially breaching the agreement, you have to take reasonable steps to cure it, and terminate the contract if you cannot.

The paragraphs above are our plain-English reading. The blocks below are quoted verbatim from the regulation.

The text that matters

Required contract terms, opening
Implementation specifications: Business associate contracts. A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate.
The known-breach duty
A covered entity is not in compliance with the standards in § 164.502(e) and this paragraph, if the covered entity knew of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate's obligation under the contract or other arrangement, unless the covered entity took reasonable steps to cure the breach or end the violation, as applicable, and, if such steps were unsuccessful, terminated the contract or arrangement, if feasible.

Quoted from 45 CFR § 164.504(e). US federal regulations are not subject to copyright. Retrieved from eCFR and last checked August 4, 2026.

What this section means you must hold

The regulation states obligations. This is the paperwork those obligations translate into, which is the part the regulation itself leaves you to work out.

The obligationWhat you produce for it
Hold a signed agreement with every vendor that creates, receives, maintains or transmits PHI for youA BAA per vendor, plus a register so you can answer 'how many do you have' without guessing
Ensure each agreement establishes permitted uses, requires safeguards, and passes obligations to subcontractorsThe agreement itself, checked against the required terms rather than accepted because the vendor supplied it

Where practices get 164.504(e) wrong

Treating the vendor's PDF as the end of it. A BAA you never read is still your obligation, and the common gap is not a missing signature but a missing vendor: cloud backup, email, the scheduling tool, the transcription service. The second gap is having no register, so nobody can say which agreements exist.

Other sections people look up

Educational summaries of federal regulations, not legal advice and not a determination about any specific practice. Where our reading and the regulation differ, the regulation controls; the eCFR link above is authoritative.

Get every document, done for you

Preview the binder free. Your binder is built to order and delivered within 30 days, with a full refund anytime before then.

See the binder and pricing