Glossary
Business associate agreement
Also called: BAA
A business associate agreement is the contract HIPAA requires between a covered entity and any vendor that creates, receives, maintains or transmits protected health information on its behalf. It allocates responsibility for safeguards, for breach reporting, and for the uses that are permitted at all.
Business associate agreement explained
Who needs one
Any vendor that handles protected health information for a covered entity, which includes document management, hosting, backup and support providers. It is a legal requirement rather than a negotiating position, and a vendor unwilling to execute one cannot lawfully be used for PHI.
What it must address
Permitted uses and disclosures, a commitment to safeguards under the Security Rule, reporting of unauthorised use or disclosure, flow-down obligations to subcontractors, availability of records to the Department of Health and Human Services, and return or destruction of PHI at termination.
Subcontractor flow-down
The obligations extend down the chain. A business associate that engages a sub-processor must bind it to equivalent terms, which is why a published sub-processor list matters as much here as under the GDPR — the covered entity carries accountability for parties it never contracted with.
Breach reporting timing
The agreement should state a specific period rather than relying on "without unreasonable delay", because the covered entity's own 60-day notification clock under HITECH runs from discovery and it cannot start on time if the vendor reports late.
Why hesitation is informative
A vendor that treats a BAA as an unusual request has probably not handled regulated health data before. That is not disqualifying, but it changes what the security review should examine.
FAQ
Business associate agreement: common questions
Does a BAA replace a data processing addendum?
No — they cover different regimes and are usually both required where an organisation handles both PHI and personal data of EU or UK residents. They can be executed as separate addenda to one agreement.
Is a BAA needed if data is encrypted?
Yes. Encryption affects breach notification analysis; it does not remove business associate status, because the vendor still maintains the information.
Related terms
- 21 CFR Part 1121 CFR Part 11 is the FDA regulation governing electronic records and electronic signatures in regulated life sciences.
- Data processing addendumA data processing addendum is the contract between a controller and a processor governing how personal data is handled.
- eIDASeIDAS is the EU regulation establishing a framework for electronic identification and trust services.
- ESIGN ActThe ESIGN Act is the US federal statute giving electronic signatures and records the same legal effect as paper, provided the parties intended to sign and consented to transact electronically.
- GDPRThe General Data Protection Regulation governs the processing of personal data in the EU, with an equivalent UK regime.
- Golden threadThe golden thread is the requirement, introduced by the UK Building Safety Act 2022, to create and maintain accurate building safety information for higher-risk buildings throughout their life.
Last reviewed: August 28, 2026. Browse the full glossary.