The business associate agreement is the contract that lets health data move between a healthcare customer and a vendor. If your product touches PHI, it is the document that unlocks the deal.
TL;DR
A business associate agreement (BAA) is the HIPAA contract between a covered entity and a vendor that handles protected health information on its behalf. It makes your HIPAA obligations explicit and legally binding.
A covered entity cannot share PHI with you until it is signed, so it is often the gate to a healthcare deal. The obligation flows downhill: if you pass PHI to a subcontractor, you need a BAA with them too.
On this page
What is a business associate agreement?
A business associate agreement is a written contract required by HIPAA whenever a covered entity, such as a hospital or health plan, lets another organisation handle protected health information on its behalf. That other organisation is the business associate, and for most software companies serving healthcare, that is you. The BAA sets out how you will protect the data and makes your HIPAA responsibilities legally binding.
When you need a BAA
The rule is simple: if you create, receive, store, or transmit PHI on behalf of a covered entity, you need a signed BAA before any of that data changes hands. This catches many companies that do not think of themselves as healthcare businesses, a cloud host, an analytics tool, a billing platform. If PHI flows through your product for a healthcare customer, a BAA is required.
How the BAA chain works
HIPAA obligations do not stop at the first vendor. They flow down every link where PHI is shared.
If you are a business associate and you use a subcontractor that also touches PHI, your cloud provider, a support tool, a data processor, you are required to have a BAA with them as well. The chain of responsibility follows the data.
What a BAA must contain
A compliant BAA covers a defined set of commitments. At a minimum, it should address these.
| Element | What it commits the business associate to |
|---|---|
| Permitted uses | How PHI may and may not be used and disclosed |
| Safeguards | Implementing appropriate protections for the data |
| Breach reporting | Notifying the covered entity of any breach of PHI |
| Subcontractors | Ensuring any subcontractors agree to the same terms |
| Return or destruction | Returning or destroying PHI when the contract ends |
The signing trap to avoid
The most common and dangerous mistake is signing a BAA you cannot actually honour. A BAA commits you to real safeguards on PHI. Signing one when those controls are not genuinely in place does not create compliance, it creates documented, legally binding exposure. The signature must be backed by controls that operate.
The lean-team path to BAA-ready
Being able to sign a BAA with confidence comes down to one thing: having the safeguards it commits you to already in place and evidenced. For a lean team, assembling those across separate tools is slow, and it is what makes founders hesitate at the signature line.
Sign the BAA with confidence.
Osto is the one-stop cybersecurity and compliance platform built for fast-moving startups. Put the safeguards a BAA requires on one platform, evidenced automatically, so your signature is backed by controls that run. No security team required.
Frequently asked questions
What is a business associate agreement?
A BAA is a HIPAA-required contract between a covered entity and a vendor that handles protected health information on its behalf. It makes the vendor’s HIPAA obligations explicit and legally binding, covering how PHI is used, protected, and reported.
When do I need a BAA?
Whenever you create, receive, store, or transmit PHI on behalf of a covered entity. A signed BAA is required before any PHI changes hands, even if you do not consider yourself a healthcare company.
Do I need a BAA with my subcontractors?
Yes. If you are a business associate and use a subcontractor that also touches PHI, you must have a BAA with them too. HIPAA obligations flow down every link in the chain where PHI is shared.
What must a BAA include?
At a minimum: permitted uses and disclosures of PHI, a commitment to appropriate safeguards, breach reporting to the covered entity, terms binding subcontractors, and return or destruction of PHI when the contract ends.
What happens if I sign a BAA I cannot meet?
You create legally binding exposure. A BAA commits you to real safeguards; signing without those controls in place does not create compliance, it documents a promise you are not keeping. Sign only what your controls can back.
Who provides the BAA?
Usually the covered entity provides its standard BAA, though business associates often have their own. Either way, both parties must sign before PHI is shared, and the terms must reflect HIPAA’s required commitments.

