Business Associate Agreement (BAA)
A Business Associate Agreement (BAA) is a written contract between a HIPAA-covered organization (a 'covered entity') and a business associate—a vendor or partner that handles protected health information (PHI) on the covered entity's behalf. It sets out each side's responsibilities for safeguarding that health information. It is generally required whenever a covered entity shares PHI with a business associate.
A BAA is a contractual instrument required under the U.S. Health Insurance Portability and Accountability Act (HIPAA) framework that governs the relationship between a covered entity (or, in some cases, another covered entity) and a business associate that creates, receives, maintains, or transmits protected health information (PHI) on the covered entity's behalf. The agreement allocates responsibilities for permitted uses and disclosures of PHI and related safeguards. It is distinct from HIPAA itself: HIPAA is the binding federal law, while the BAA is the contract used to satisfy certain of its obligations. Notably, a business associate is directly liable under the HIPAA Rules and may be subject to civil and, in some cases, criminal penalties for impermissible uses or disclosures, independent of the contract terms. This entry addresses the U.S. HIPAA context only and does not cover analogous arrangements in other jurisdictions; specific required provisions, applicability, and enforcement should be verified against the current official HHS text.
Why it matters
The BAA is the mechanism through which HIPAA's protections extend beyond the covered entity itself to the wider ecosystem of vendors and partners that touch protected health information (PHI). Modern healthcare operations rely heavily on third parties—cloud hosting providers, billing companies, analytics vendors, and IT service firms—many of which create, receive, maintain, or transmit PHI. Without a BAA in place, a covered entity that shares PHI with such a party generally falls short of HIPAA's requirements, and the arrangement itself may constitute an impermissible disclosure.
Critically, the BAA is not merely a paperwork formality that shifts all risk onto the vendor. Under the HIPAA Rules, a business associate is directly liable and may be subject to civil and, in some cases, criminal penalties for impermissible uses or disclosures of PHI—independent of what the contract itself says. This means both parties carry regulatory exposure. A covered entity cannot fully contract away its obligations, and a business associate cannot rely on the absence or weakness of a BAA to escape statutory liability for its own conduct.
Because the BAA defines each side's safeguarding responsibilities and permitted uses and disclosures, its presence, scope, and accuracy are routinely examined in HIPAA compliance reviews and in the aftermath of data breaches involving vendors. Organizations should treat the BAA as a live compliance control rather than a one-time signature, and should verify required provisions against the current official HHS text, as guidance and interpretation evolve over time.
Who it's relevant to
Inside BAA
Common questions
Answers to the questions practitioners most commonly ask about BAA.

