What Is a Business Associate Agreement (BAA)?

What is a HIPAA business associate agreement (BAA)
What Is a Business Associate Agreement (BAA)? | Osto

The business associate agreement is the contract that lets health data move between a healthcare customer and a vendor. If your product touches PHI, it is the document that unlocks the deal.

Osto Security Team7 min readCompliance & Trust

TL;DR

A business associate agreement (BAA) is the HIPAA contract between a covered entity and a vendor that handles protected health information on its behalf. It makes your HIPAA obligations explicit and legally binding.

A covered entity cannot share PHI with you until it is signed, so it is often the gate to a healthcare deal. The obligation flows downhill: if you pass PHI to a subcontractor, you need a BAA with them too.

What is a business associate agreement?

A business associate agreement is a written contract required by HIPAA whenever a covered entity, such as a hospital or health plan, lets another organisation handle protected health information on its behalf. That other organisation is the business associate, and for most software companies serving healthcare, that is you. The BAA sets out how you will protect the data and makes your HIPAA responsibilities legally binding.

What a BAA does
The contract that lets health data change hands
Makes duties explicit
It puts your HIPAA obligations in writing between the two parties.
Unlocks the data
A covered entity cannot legally share PHI with you until it is signed.
Assigns liability
It commits you, the business associate, to protect that data by law.

When you need a BAA

The rule is simple: if you create, receive, store, or transmit PHI on behalf of a covered entity, you need a signed BAA before any of that data changes hands. This catches many companies that do not think of themselves as healthcare businesses, a cloud host, an analytics tool, a billing platform. If PHI flows through your product for a healthcare customer, a BAA is required.

The gate to the deal
For a covered entity, sharing PHI without a signed BAA is itself a HIPAA violation. That is why your ability to sign one, and actually meet it, often decides whether a healthcare deal can close at all.

How the BAA chain works

HIPAA obligations do not stop at the first vendor. They flow down every link where PHI is shared.

How the chain works
Every party that touches PHI needs a BAA
The obligation flows down the chain. If you pass PHI to a subcontractor, you need a BAA with them too.
Covered entity hospital, clinic, health plan Business associate your SaaS, cloud host, billing or analytics Subcontractor any vendor you use that also touches PHI BAA BAA A signed BAA is required at every link where PHI is shared

If you are a business associate and you use a subcontractor that also touches PHI, your cloud provider, a support tool, a data processor, you are required to have a BAA with them as well. The chain of responsibility follows the data.

What a BAA must contain

A compliant BAA covers a defined set of commitments. At a minimum, it should address these.

ElementWhat it commits the business associate to
Permitted usesHow PHI may and may not be used and disclosed
SafeguardsImplementing appropriate protections for the data
Breach reportingNotifying the covered entity of any breach of PHI
SubcontractorsEnsuring any subcontractors agree to the same terms
Return or destructionReturning or destroying PHI when the contract ends

The signing trap to avoid

The most common and dangerous mistake is signing a BAA you cannot actually honour. A BAA commits you to real safeguards on PHI. Signing one when those controls are not genuinely in place does not create compliance, it creates documented, legally binding exposure. The signature must be backed by controls that operate.

Sign only what you can back
A BAA is a promise about your security. Before you sign, make sure the access control, encryption, logging, and breach process it commits you to are real and running, not aspirational.

The lean-team path to BAA-ready

Being able to sign a BAA with confidence comes down to one thing: having the safeguards it commits you to already in place and evidenced. For a lean team, assembling those across separate tools is slow, and it is what makes founders hesitate at the signature line.

Sign the BAA with confidence.

Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Put the safeguards a BAA requires on one platform, evidenced automatically, so your signature is backed by controls that run. No security team required.

Book a Demo →

Frequently asked questions

What is a business associate agreement?

A BAA is a HIPAA-required contract between a covered entity and a vendor that handles protected health information on its behalf. It makes the vendor’s HIPAA obligations explicit and legally binding, covering how PHI is used, protected, and reported.

When do I need a BAA?

Whenever you create, receive, store, or transmit PHI on behalf of a covered entity. A signed BAA is required before any PHI changes hands, even if you do not consider yourself a healthcare company.

Do I need a BAA with my subcontractors?

Yes. If you are a business associate and use a subcontractor that also touches PHI, you must have a BAA with them too. HIPAA obligations flow down every link in the chain where PHI is shared.

What must a BAA include?

At a minimum: permitted uses and disclosures of PHI, a commitment to appropriate safeguards, breach reporting to the covered entity, terms binding subcontractors, and return or destruction of PHI when the contract ends.

What happens if I sign a BAA I cannot meet?

You create legally binding exposure. A BAA commits you to real safeguards; signing without those controls in place does not create compliance, it documents a promise you are not keeping. Sign only what your controls can back.

Who provides the BAA?

Usually the covered entity provides its standard BAA, though business associates often have their own. Either way, both parties must sign before PHI is shared, and the terms must reflect HIPAA’s required commitments.