A BAA — Business Associate Agreement — is a legally required contract under HIPAA between a covered entity and any vendor that creates, receives, maintains, or transmits protected health information (PHI) on its behalf. Without a signed BAA, using any third-party vendor for anything involving PHI is a direct HIPAA violation — regardless of how secure the vendor’s technology may be. The BAA defines what each party is responsible for, what happens in the event of a breach, and how liability is shared.
- A BAA is legally required under HIPAA whenever a vendor handles PHI on your behalf — no exceptions
- A BAA is not a checkbox — it is a legal document that determines who bears liability in the event of a breach
- SOC 2, ISO 27001, and other security certifications do not substitute for a BAA
- Every vendor in your technology stack that touches PHI needs its own signed BAA
- If a vendor refuses to sign a BAA, you cannot legally use them for any PHI-related function
- The HHS Office for Civil Rights enforces BAA requirements — penalties for violations reach into the millions
Need a BAA for your hosting environment? HIPAA Vault includes a signed Business Associate Agreement on every plan — no negotiation required.
View hosting plans → | Talk to a specialist →
What Does BAA Stand For?
BAA stands for Business Associate Agreement. It is sometimes called a Business Associate Contract (BAC) or a Data Processing Agreement (DPA) in non-U.S. contexts, though these terms are not exactly interchangeable.
Under HIPAA’s Privacy Rule (45 CFR Part 164), a business associate is any person or organization that performs functions or activities involving PHI on behalf of a covered entity. The BAA is the contract that governs that relationship.
Who Needs a BAA?
Any organization that qualifies as a covered entity under HIPAA must have BAAs with all of its business associates. Covered entities include:
- Healthcare providers (hospitals, clinics, physicians, dentists, therapists, pharmacies)
- Health plans (insurance companies, HMOs, employer health plans)
- Healthcare clearinghouses (entities that process health information between providers and payers)
Business associates — organizations that must sign a BAA before handling PHI — include:
| Business Associate Type | Examples |
|---|---|
| Cloud hosting providers | HIPAA Vault, AWS, Google Cloud, Azure |
| Email providers | Google Workspace, Microsoft 365 |
| EHR vendors | Epic, Cerner, athenahealth |
| Medical billing companies | Any third-party billing service |
| IT service providers | Managed service providers with PHI access |
| Software as a Service (SaaS) | Any app that stores or processes PHI |
| Lawyers and accountants | When accessing PHI for client work |
| Shredding and storage companies | When handling physical PHI records |
| Transcription services | When transcribing patient encounters |
As Gil Vidals, CTO and co-founder of HIPAA Vault, explains:
“A lot of people think HIPAA only applies to hospitals and doctors. But if you’re a software company, a hosting provider, a billing service — anyone who touches that data — you’re a business associate, and you have to sign a BAA and meet the same standards.”
What Does a BAA Actually Do?
Gil Vidals describes a BAA as a legal marriage:
“That document is essentially a marriage between you and that provider. It’s a legal marriage where you say, look, we’re both responsible for the data. If there’s a breach, we’re both responsible. And it avoids the finger pointing — saying, well, I thought he did that and I thought they did that. No, no, you’re in it together. And that’s why it’s such an important document. You want to find a good partner, just like in marriage. You want to find a good partner that is doing their part in the partnership.”
In practical terms, a BAA:
Defines permitted uses of PHI — the vendor may only use PHI in ways authorized by the agreement and required by law. They cannot use your patients’ data for their own purposes.
Establishes security safeguards — the vendor agrees to implement appropriate safeguards to protect PHI, including the technical and administrative controls required by the HIPAA Security Rule.
Requires breach notification — if the vendor discovers a breach or security incident involving your PHI, they must notify you within a defined time window (typically 60 days, though contracts may require shorter windows).
Defines subcontractor requirements — if the vendor uses subcontractors who also handle PHI, those subcontractors must also sign BAAs. This is known as the “chain BAA” requirement — HIPAA liability flows down the entire chain.
Establishes return or destruction of PHI — when the relationship ends, the vendor must return or destroy all PHI in their possession.
Why a BAA Is Not Just a Checkbox
Gil Vidals is direct about a common mistake healthcare organizations make:
“It’s more than just a checkbox. It’s not something you do and just move on. It will have repercussions if there is a breach. You’re going to go to that document to find out who’s responsible for what. And I think that’s worthy of consideration — taking your time with it.”
A poorly drafted BAA can leave significant liability gaps:
- Vague breach notification timelines — if the BAA doesn’t specify when the vendor must notify you, they may take months
- Undefined subcontractor coverage — if the BAA doesn’t address subcontractors, your PHI may flow to vendors you’ve never evaluated
- Broad permitted use clauses — some BAAs allow vendors to use PHI for “service improvement” — potentially including AI model training
- Weak remediation requirements — if a breach occurs and the BAA doesn’t specify remediation obligations, your recourse is limited
- Unclear termination procedures — what happens to your PHI when you stop using a vendor matters enormously
The HHS model BAA provides a solid foundation — but it is a template, not a complete solution. Healthcare organizations should review BAAs carefully and consult a qualified HIPAA compliance attorney for high-stakes vendor relationships.
Customize Your HIPAA Bundle—Pick 3 and Save 15%
Don't pay for tools you don't use. Combine Hosting, Email, Fax, or Text into one affordable, managed plan.
Learn MoreWhat Happens When There’s No BAA
The consequences of operating without a BAA are well-documented by the HHS Office for Civil Rights. A real-world example from HIPAA Vault’s podcast:
In 2024, the HHS Office for Civil Rights announced a $4.75 million HIPAA penalty against Montefiore Medical Center — stemming from a malicious insider incident in which an employee copied and sold patient data including names and Social Security numbers. The investigation revealed that the medical center had failed to implement appropriate safeguards and oversight — and the penalty exceeded OCR’s total HIPAA enforcement collections for all of 2023.
The lesson, as Adam Zeineddine of the HIPAA Insider Show noted: “In one penalty, they’ve already exceeded 2023’s total collections.”
Absent a proper BAA framework, when a breach occurs, covered entities face:
- Full regulatory liability — without a BAA, the covered entity bears complete responsibility for any vendor breach
- Civil penalties — OCR penalties vary based on culpability and are adjusted periodically for inflation, with annual caps reaching into the millions for willful neglect
- Breach notification obligations — notification to affected individuals within 60 days, HHS reporting, and in some cases media notification
- No contractual recourse — without a BAA, the vendor has no legal obligation to compensate the covered entity for damages from their breach
- Reputational damage — healthcare data breaches are among the most publicly reported
Do You Need a BAA With Every Vendor?
Not every vendor requires a BAA — only those that qualify as business associates by handling PHI on your behalf.
Does require a BAA:
- Your cloud hosting provider (if patient data is stored or transmitted)
- Your email provider (if patient information is sent via email)
- Your EHR vendor
- Your medical billing service
- Your IT support company (if they have access to systems containing PHI)
- Any SaaS application that stores patient data
Does NOT require a BAA:
- Your internet provider (covered by the conduit exception — they transmit but don’t access PHI)
- Your phone carrier (same conduit exception)
- Vendors who only handle de-identified data
- Vendors with no access to PHI
The HHS guidance on business associates provides the regulatory framework for making this determination.
Does a Security Certification Replace a BAA?
No — and this is one of the most common misconceptions in healthcare IT.
SOC 2, ISO 27001, HITRUST, and similar certifications demonstrate strong security practices. They do not satisfy the BAA requirement under HIPAA. A vendor can be SOC 2 Type II certified and still not be HIPAA compliant — because HIPAA compliance requires both technical safeguards AND the legal contractual obligation of a signed BAA.
As we covered in our guide to HIPAA certification: there is no official government HIPAA certification. The BAA is the only legal mechanism that creates shared compliance responsibility between a covered entity and a vendor.
What Should a BAA Include?
A HIPAA-compliant BAA must include, at minimum, the following provisions as required by 45 CFR § 164.504(e):
Required elements:
- Permitted and required uses and disclosures of PHI by the business associate
- Prohibition on using PHI beyond what’s permitted by the agreement
- Appropriate safeguards to protect PHI
- Reporting of breaches and security incidents to the covered entity
- Ensuring subcontractors sign BAAs
- Making PHI available for patient access requests
- Making records available to HHS for compliance reviews
- Return or destruction of PHI upon termination
- Authorization for the covered entity to terminate the agreement if the BAA is breached
The HHS model BAA template provides sample language for each of these provisions.
Chain BAAs: When Your Vendor Has Vendors
One of the most overlooked aspects of BAA compliance is the subcontractor chain. Under the HIPAA Omnibus Rule, business associates must ensure that their own subcontractors who handle PHI also sign BAAs.
This means:
- Your cloud hosting provider must have BAAs with their data center operators
- Your EHR vendor must have BAAs with their subcontractors who access your data
- SaaS vendors must have BAAs with their infrastructure providers
When evaluating vendors, ask specifically: “Do you have signed BAAs with all subcontractors who may have access to our PHI?” If the vendor cannot answer this clearly, it is a significant compliance risk.
How to Get a BAA
For most vendors: Request a BAA directly from the vendor’s legal or compliance team. Many major providers — Google Workspace, Microsoft 365, AWS, Dropbox Business Advanced — include BAA terms within their enterprise agreements or make them available upon request.
For HIPAA Vault: A signed BAA is included on every plan — no negotiation required. It is part of the service, not an add-on.
For vendors who refuse: If a vendor refuses to sign a BAA or claims they don’t need one, and they handle PHI on your behalf, you cannot legally use them for that purpose. Full stop. Find an alternative vendor.
Every HIPAA Vault plan includes a signed BAA — along with the encryption, monitoring, and U.S.-based infrastructure that makes it meaningful.
Frequently Asked Questions
This article draws on expert commentary from Gil Vidals, CTO and co-founder of HIPAA Vault, from HIPAA Vault Show Episodes 2 and 42. HIPAA Vault provides managed HIPAA-compliant hosting with a signed BAA included on every plan. This content is educational and does not constitute legal advice. Consult a qualified HIPAA compliance attorney for guidance specific to your organization.


