A business associate agreement (BAA) is a contract that US HIPAA rules require between a healthcare organization and a vendor that handles protected health information (PHI) on its behalf. It sets out how the vendor may use and disclose that information, the safeguards it must apply, how it reports breaches, and what happens to the data when the relationship ends. For buyers, the practical question is whether a provider will sign one, for which services, and what it expects the customer to configure. This entry is an overview for buyers, not legal advice.
At a glance
- BAAs come from HIPAA, so they apply in the United States to health plans, most healthcare providers, clearinghouses and the vendors that serve them.
- A vendor that creates, receives, maintains or transmits PHI for a covered entity is a business associate and generally needs a BAA.
- Business associates need similar agreements with their own subcontractors that handle PHI.
- Many cloud, SaaS, UCaaS and contact center providers sign BAAs only for certain products, plans or configurations.
- A signed BAA does not make a service compliant by itself; configuration and use still matter.
What problem it solves
Healthcare organizations depend on outside services: electronic records, billing, cloud hosting, email, phone systems, contact centers, transcription, backup and IT support. Each of these may touch patient information. HIPAA holds the healthcare organization responsible for protecting that information, so it needs written assurance that every vendor handling it will protect it too.
The BAA provides that assurance in a standard form. It makes the vendor contractually responsible for safeguards and breach reporting, and it gives the healthcare organization a basis to vet vendors, limit use of the data and recover or destroy it at the end. For vendors, being willing to sign a BAA is often the price of entry to healthcare customers.
How it works
Identifying business associates. The healthcare organization lists vendors whose services involve PHI. Common examples include cloud and SaaS platforms, UCaaS and contact center providers that record calls or store voicemail and messages, managed IT and security providers, backup services, billing companies and consultants.
Contract terms. A BAA typically covers permitted uses and disclosures of PHI, required administrative, physical and technical safeguards, reporting of security incidents and breaches, passing equivalent terms to subcontractors, supporting individuals’ rights to their records, making records available to regulators, and returning or destroying PHI at termination.
Scope. Providers often attach a BAA to specific services or plans and publish a list of covered features. Anything outside that list, such as a new add-on or an AI feature, may not be covered.
Configuration. The customer usually has to configure the service correctly: encryption, access controls, audit logging, retention settings and limits on features that would move data outside the covered scope.
Ongoing management. Organizations keep an inventory of BAAs, review them at renewal, and confirm that new services are added before PHI flows to them.
When it matters for buyers
- When choosing UCaaS, contact center or messaging platforms for healthcare. Call recordings, voicemail, texts and chat can all contain PHI.
- When moving workloads to cloud computing providers. Confirm the BAA and which services it covers.
- When hiring a managed IT or security provider. Access to systems containing PHI usually makes it a business associate.
- When a healthcare customer asks you to sign. Read the obligations carefully; they will flow down to your own vendors.
- When adding new features. Check whether they fall inside the BAA’s scope before enabling them.
Our unified communications as a service overview covers what to check when choosing a phone and collaboration platform for a regulated environment.
Questions to ask vendors
- Will you sign a BAA, and is it your standard form or can we use ours?
- Which products, plans and features does the BAA cover, and which are excluded?
- Does the plan we are buying include BAA coverage, or does it require an upgrade?
- What configuration do you require from us to stay within the BAA’s scope?
- Which subcontractors handle PHI, and do you have BAAs with each of them?
- How quickly will you report a security incident or breach to us?
- How is PHI returned or destroyed when the contract ends?
How it differs from a data processing agreement (DPA)
A data processing agreement is the contract that privacy laws such as the GDPR require when a processor handles personal data for a controller. A BAA is specific to US HIPAA and to protected health information. They cover similar ground, including permitted uses, security, subcontractors, breach reporting and deletion, but are required by different laws, use different terms and are not interchangeable. PHI is also a narrower category than personally identifiable information (PII). Both kinds of agreements belong in a wider data security compliance and governance, risk and compliance (GRC) program that tracks vendors and obligations.
