Auditen
Home / Frameworks / HIPAA / Business Associate Agreements (BAAs)
HIPAA · 164.504(e)

Business Associate Agreements (BAAs)

A Business Associate Agreement (BAA) is a legally binding contract required whenever a Covered Entity or another Business Associate shares Protected Health Information (PHI) with a third-party vendor. It ensures that the vendor provides sufficient safeguards to protect the PHI and agrees to comply with specific HIPAA Privacy and Security Rule requirements.

What it means

The intent of the BAA is to extend the regulatory obligations of HIPAA from the primary healthcare provider or health plan to any external entity that handles their data. This prevents "security gaps" where a vendor might otherwise treat sensitive health data as standard commercial data rather than regulated PHI.

In practice, this applies to almost any third-party service provider—such as cloud hosting services, billing companies, legal counsel, or IT consultants—that creates, receives, maintains, or transmits PHI on behalf of the organization.

The BAA establishes a chain of trust and liability. It mandates that the Business Associate (BA) will only use PHI for the purposes specified in the contract and requires them to notify the Covered Entity if a data breach occurs.

How to meet it

Evidence an auditor asks for

  • A comprehensive inventory list of all third-party vendors and a designation of which are "Business Associates."
  • Signed and dated BAA copies for every vendor listed in the inventory.
  • Procurement records showing that BAAs were signed prior to the start of data transmission.
  • Documentation of the process used to review and renew agreements periodically.

Common pitfalls

  • Relying on a vendor's general "Terms of Service" or Privacy Policy instead of a specific, signed BAA.
  • Sharing PHI with a new tool or service during a "trial period" before the legal agreement is finalized.
  • Failing to track "downstream" BAAs, assuming that if the primary vendor is compliant, their subcontractors automatically are as well.
  • Neglecting to update agreements when the scope of work changes and more types of PHI are shared with the vendor.