45 CFR § 164.504(e)
Uses and disclosures: Organizational requirements
The section that says what a Business Associate Agreement must actually contain.
Read the full official text on eCFRResearched and written by Larry Osakwe · Last verified August 4, 2026
Checked against 45 CFR 164.504(e) via eCFR. Not a lawyer, not a certified compliance professional, and not affiliated with HHS.
What 164.504(e) actually says
45 CFR 164.502(e) is the rule that says you need a Business Associate Agreement. 164.504(e) is the rule that says what has to be in it. That distinction is why people land here: they have a vendor's BAA in hand and want to know whether it is sufficient.
The section is a list of required contract terms. It also imposes an ongoing duty that surprises people: if you know a business associate is materially breaching the agreement, you have to take reasonable steps to cure it, and terminate the contract if you cannot.
The paragraphs above are our plain-English reading. The blocks below are quoted verbatim from the regulation.
The text that matters
Implementation specifications: Business associate contracts. A contract between the covered entity and a business associate must: (i) Establish the permitted and required uses and disclosures of protected health information by the business associate.
A covered entity is not in compliance with the standards in § 164.502(e) and this paragraph, if the covered entity knew of a pattern of activity or practice of the business associate that constituted a material breach or violation of the business associate's obligation under the contract or other arrangement, unless the covered entity took reasonable steps to cure the breach or end the violation, as applicable, and, if such steps were unsuccessful, terminated the contract or arrangement, if feasible.
Quoted from 45 CFR § 164.504(e). US federal regulations are not subject to copyright. Retrieved from eCFR and last checked August 4, 2026.
What this section means you must hold
The regulation states obligations. This is the paperwork those obligations translate into, which is the part the regulation itself leaves you to work out.
| The obligation | What you produce for it |
|---|---|
| Hold a signed agreement with every vendor that creates, receives, maintains or transmits PHI for you | A BAA per vendor, plus a register so you can answer 'how many do you have' without guessing |
| Ensure each agreement establishes permitted uses, requires safeguards, and passes obligations to subcontractors | The agreement itself, checked against the required terms rather than accepted because the vendor supplied it |
Where practices get 164.504(e) wrong
Treating the vendor's PDF as the end of it. A BAA you never read is still your obligation, and the common gap is not a missing signature but a missing vendor: cloud backup, email, the scheduling tool, the transcription service. The second gap is having no register, so nobody can say which agreements exist.
Other sections people look up
45 CFR § 160.103
Definitions
45 CFR § 164.520
Notice of privacy practices for protected health information
45 CFR § 164.308
Administrative safeguards
45 CFR § 164.508
Uses and disclosures for which an authorization is required
Educational summaries of federal regulations, not legal advice and not a determination about any specific practice. Where our reading and the regulation differ, the regulation controls; the eCFR link above is authoritative.
Get every document, done for you
Preview the binder free. Your binder is built to order and delivered within 30 days, with a full refund anytime before then.
See the binder and pricing