Business Associate AgreementBAA
A Business Associate Agreement (BAA) is the written contract a covered entity must have with any vendor that handles PHI on its behalf. Under 45 CFR 164.502(e) the covered entity must obtain satisfactory assurances the vendor will safeguard the data, and 45 CFR 164.504(e) sets the clauses the contract must contain.
Last verified: July 23, 2026
What BAA means under HIPAA
The requirement comes from two sections working together. Section 164.502(e) says a covered entity may let a business associate create, receive, maintain, or transmit PHI on its behalf only if it obtains satisfactory assurance the business associate will appropriately safeguard the information. Section 164.504(e) then specifies what that assurance looks like: a contract that, among other things, limits how the business associate may use and disclose PHI, requires appropriate safeguards, requires reporting of breaches, and requires return or destruction of PHI at termination where feasible.
In practice the BAA is one of the easiest things to get wrong, because vendors sign PHI-bearing relationships that no one papers. The fix is a vendor register: list every vendor that can touch patient data, note whether a signed BAA is on file, and chase the gaps. A generic downloaded template can satisfy the clause requirements, but it still has to name your real vendors and be actually signed.
One nuance: a BAA does not make either party compliant on its own. It is a promise about how PHI will be handled. The covered entity still needs its own policies and Security Risk Analysis, and the business associate still has direct statutory duties. The contract allocates responsibility; it does not replace the underlying work.
BAA FAQ
Related terms
See every term in the HIPAA glossary.
Turn the vocabulary into the documents
Knowing the terms is step one. See the full document set a covered practice keeps, or generate the ones you can build yourself now.
See what goes in a HIPAA binderSource
Last verified July 23, 2026. This definition is educational self-help information, not legal advice, and it paraphrases the regulation; the controlling text is 45 CFR § 164.502(e), § 164.504(e), linked above. Whether HIPAA applies to your practice depends on the covered-entity test. State law may add stronger requirements.